Skip to content
residency.fyi

Privacy Policy

Last Updated: October 2026

Your Privacy Matters

residency.fyi is committed to protecting your privacy. This policy explains how we collect, use, and protect your information.

1. Information We Collect

1.1 Automatically Collected Information

When you use our Service, we automatically collect:

  • Browser type and version
  • Device information (type, operating system)
  • IP address (anonymized)
  • Pages visited and time spent on pages
  • Referring website
  • Date and time of visits

This information is collected through cookies and similar tracking technologies.

1.2 Information You Provide

When you send a report with "Report a problem with this page", we receive:

  • The text you write, and the kind of problem you chose
  • The program page you sent it from
  • When you sent it

The form has no email box and asks for no name or contact details. We can't reply to you, so each report gets a reference number (FB- and eight characters) that appears once, after you send it. Don't put personal details in the text. Earlier versions of the form had an optional email box; we no longer collect addresses and delete any we still hold.

The form includes one hidden field that people never see. A report that fills it is discarded without being stored.

1.3 How reports are handled

  • It is read only by the site owner.
  • It is never published.
  • A fact on the site changes only after the program's CaRMS page has been checked.
  • Corrections are listed on the corrections page by reference number, without your text.

By sending a report you agree to it being handled this way. The rest of the site works without the form.

1.4 Local Storage

We use browser local storage to:

  • Remember your recently viewed programs
  • Save your comparison selections
  • Store preferences (view mode, filters)

This data is stored only in your browser and is not transmitted to our servers.

2. How We Use Your Information

We use collected information to:

  • Provide and improve the Service: Analyze usage patterns to enhance features and user experience
  • Maintain security: Detect and prevent abuse, spam, or malicious activity
  • Respond to feedback: Address reported errors and improve data accuracy
  • Analytics: Understand how users interact with the Service (via Vercel Analytics)

We do NOT sell, rent, or share your personal information with third parties for marketing purposes.

3. Cookies and Tracking Technologies

3.1 Essential Cookies

Required for the Service to function properly:

  • Session management
  • Admin authentication (for feedback management)

3.2 Analytics Cookies

We use Vercel Analytics to understand usage patterns. This service:

  • Does not use cookies
  • Does not collect personal information
  • Provides aggregated, anonymized analytics
  • Is privacy-focused and GDPR-compliant

Learn more: Vercel Analytics Privacy

3.3 Your Choices

You can control cookies through your browser settings. Note that disabling cookies may affect the functionality of the Service.

4. Data Storage and Security

4.1 Where We Store Data

  • Hosting: Vercel (United States)
  • Database: Neon PostgreSQL (may be stored in various locations)
  • Local Storage: Your device (recently viewed programs, preferences)

4.2 Security Measures

We implement reasonable security measures including:

  • HTTPS encryption for all data transmission
  • Secure database connections
  • Password-protected admin access
  • Regular security updates

However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

5. Data Retention

  • Analytics data: Anonymized and aggregated, retained as needed for analysis
  • Feedback reports: The text of a report is deleted 12 months after the report is closed. The form collects no email address; any address left over from the old form is deleted
  • Local storage data: Retained in your browser until you clear it

6. Third-Party Services

We use the following third-party services:

Vercel (Hosting & Analytics)

Privacy Policy: vercel.com/legal/privacy-policy

Neon (Database)

Privacy Policy: neon.tech/privacy-policy

OpenStreetMap (Map Tiles and Data)

Program pages and the map load map tiles from OpenStreetMap servers, so your browser sends them its IP address. Privacy Policy: OSM Foundation Privacy Policy

Overpass API (Places Near Each Program)

The place counts in each program page's Location section are fetched by your browser from a public Overpass API server (overpass-api.de), which sees your IP address. We send it only the city's coordinates.

7. Your Rights

You have the right to:

  • Access: Request information about data we hold about you
  • Deletion: Request deletion of your data (limited, as we collect minimal personal data)
  • Opt-out: Disable cookies and tracking through your browser
  • Correction: Request correction of inaccurate information

To exercise these rights, use "Report a problem with this page" on any program page and choose "A question about my data, or a removal request". There is no contact address yet, and the form collects none of your details, so we can't reply. Say what you want fixed or removed; we act on it without a reply.

8. Children's Privacy

Our Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you are under 18, please do not provide any information through the Service.

9. International Users

Our Service is hosted in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States where our servers are located.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Data We Don't Collect

To protect your privacy, we explicitly do NOT collect:

  • Your name (unless voluntarily provided in feedback)
  • Medical school information
  • Application details or decisions
  • CaRMS identification numbers
  • Credit card or payment information (Service is free)
  • Precise geolocation data

12. Program Contacts

Program pages list the program director and the contacts CaRMS publishes for applicants: names, job titles, and work email addresses and phone numbers. We show them so applicants can contact the program, and only for the current match cycle. When a cycle is archived, its pages drop the names and keep the link to the CaRMS program page. If CaRMS lists a personal email address for someone (gmail, hotmail and similar), we show their name and title but not the address, and link to the CaRMS program page instead.

Program directors. For some program directors we also link to their profile on their university's or department's own website and quote one or two lines from it about their research or clinical interests, with the page and the date we checked it. We find these pages only through links on the program's own websites, show them only when the name, school and role match CaRMS, and re-check them at each data refresh. Other staff never get this.

What we never do with these entries:

  • Add publication lists, college register details or staff biographies, or add anything about people other than program directors
  • Show photos of anyone
  • Take anything from social media, professional networking profiles or rating sites, or link to them
  • Copy personal data about these people from anywhere other than CaRMS and, for program directors, their own official faculty profile

Fixes and removals. If an entry is wrong (a wrong title, someone who has left), or you are listed and want your name taken off residency.fyi, tell the privacy contact (see section 13). This covers director profile links and quotes too. We remove the entry on request, without asking you to explain or prove anything, within 7 days. We do this even when CaRMS still lists you. The program office is the only place that can change the CaRMS listing itself.

13. Contact

Privacy contact, residency.fyi

For questions about this Privacy Policy, or to have a program contact entry fixed or removed, open the program page where the entry appears and use "Report a problem with this page" at the bottom. Choose "A question about my data, or a removal request", and say which entry it is and whether you want it fixed or removed. The form collects no email address, so we can't reply; we act on the request without one. There is no contact address yet.

Privacy-First Approach

We collect only the minimum data necessary to provide and improve the Service. Your privacy is important to us.