Clearcharge

Privacy policy

Last updated 2026-08-21.

What we collect

What we don't do

Data retention

We hold no account data, because there are no accounts. Individual visit records from our own counting are deleted after 90 days, leaving only daily totals. Nothing we retain describes an individual visitor beyond that window.

How the site is delivered

The site is served through Cloudflare, which sits between your browser and our server to provide encryption, caching, and protection against attacks. This means Cloudflare handles every request to the site and sees the web address you visited and your IP address, in the same way our own web host does. Cloudflare is an infrastructure company — it does not run an advertising network, and we do not permit it to use this traffic for advertising.

Analytics

There are three counters here and they are genuinely different things, so they get three descriptions rather than one comfortable summary. Cloudflare Web Analytics, if enabled, reports aggregate page-view counts — it uses no cookies, does not fingerprint devices, and does not track you across sites, and it is covered immediately below. Umami, if enabled, is analytics software we run on our own server; it is described further down, and because we host it, nothing it collects goes to anybody else. And we count visits on our own server in a third way that does use two cookies, which has its own section.

Cloudflare does receive the web addresses you visit here, including what you searched for. We would rather be exact about this than word it carefully enough to mislead.

Two separate things are true. First, Cloudflare delivers this site, so every request passes through them by definition — the address /search?code=90834 is part of the request itself, and there is no version of using a delivery network in which that is hidden from it. Second, the analytics script reports the address of each page view, and we have confirmed by inspecting what it actually transmits that this includes the full address, query parameters and all. Cloudflare states that it does not log query parameters. We cannot verify what happens after the data reaches them, so we describe what is sent rather than what we are told is kept.

Concretely: a code such as 90834 (a psychotherapy session) or 87389 (an HIV test) is visible to Cloudflare together with your IP address, in the same way it is visible to any company that hosts or delivers a website you use. It is not visible to advertisers, and Cloudflare does not operate an advertising network. Price pages like /price/ga/psychotherapy-45-minutes carry the procedure in the address for the same reason.

An earlier version of this page said analytics did not receive what you searched for. That was written when the site was served directly and used a different analytics provider that allowed the address to be rewritten before reporting. It stopped being true when we moved behind Cloudflare, and we corrected it as soon as we checked rather than leaving a comfortable sentence in place.

If you would rather look up a price without a procedure appearing in any address we transmit, the source files are public: every hospital publishes its own, and each hospital page here links to it. You can read them without going through us at all.

Umami, the analytics we run ourselves

If enabled, we use Umami, open-source analytics software. We do not use their hosted service — we run a copy on our own server, so what it collects is written to a database we control and is sent to no one. It is not in the third-party list below for that reason, and that is the whole point of running it rather than buying it.

It sets no cookies. It identifies a visit by taking a one-way hash of your IP address, your browser’s user-agent string and the site’s name, mixed with a secret value that is replaced every month. Your IP address is used for that calculation and to look up a country, and is not stored. Because the secret changes monthly, two visits either side of that change cannot be connected, and the stored identifier cannot be turned back into an address.

It does not receive which procedure you looked at. This is the same promise the section below makes about our own counting, and it is kept the same way: before anything is sent, the address is replaced with the shape of the page rather than the page. A visit to /price/ga/atlanta/hiv-test is reported as /price/<state>/<metro>/<slug>. The page title goes the same way wherever it could name what the address did, and the address of the page you arrived from is reduced to that site’s name with the rest thrown away, because on this site that address is usually the previous search.

That is a capability we lost once and have got back. The section above records that an earlier version of this page wrongly claimed analytics did not receive your searches; that claim dated from a provider whose reporting we could rewrite before it was sent, and it stopped being true when we moved behind Cloudflare. Umami can be rewritten, so for this counter the original promise holds again. It does not undo what Cloudflare receives, which is described above and unchanged.

What it does record: the shape of the page, the site you arrived from, your browser, operating system, device type, screen size, language, and country. Nothing you typed, no procedure, no address, no cookie, and nothing that follows you to another website.

Visit counting on our own server

We count visits ourselves, on our own server, and keep the results there. Nothing in this section is sent to a third party.

Why we bother, given the analytics above. The Cloudflare counter is a small script that runs in your browser, and it is on the blocklists that most ad and tracker blockers use. That is a perfectly reasonable thing for a blocker to do, but it means that counter cannot see anyone running one — commonly between a tenth and a third of visitors. We would rather know roughly how many people this site actually helps than quote a number we know is missing a chunk. Counting on our own server sees those visits, because your browser has already made the request by the time we count it.

The two cookies, in full. Both hold a random number generated when you arrive. Neither is derived from anything about you, and neither can be linked to you by us or by anyone else.

What we store, and what we deliberately do not. For each page view we record the time, which kind of page it was, whether it was a phone, the website you came from if you followed a link from somewhere else, whether the request came from a data centre rather than an ordinary home or mobile connection, and — on a price page — which state and metro area's prices the page covers. We do not store your IP address, your browser's identity, anything you typed, or which procedure you looked at.

The data-centre check, and why your address is not kept. Most of what reaches this site is automated. A great deal of it now arrives pretending to be an ordinary web browser, so the only reliable way to tell it apart is that it comes from a company that rents out servers rather than from a home or phone connection. When a page is served we compare the address the request came from against a list of those companies' published address ranges, and we write down the answer — yes or no — and nothing else. The address itself is never written to our database and never sent anywhere; it is used for that one comparison and then it is gone. This is the same bargain as the cc_v cookie below: we keep the fact we need to count properly, and not the thing that could identify you.

Two honest caveats. If you use a VPN, your request arrives from a data centre, so this will say yes for you even though you are a person — it is a note about the connection, not a judgement about the visitor, and nothing on the site treats you differently for it. And we do not delete anything on the strength of it: the flag sits beside the visit so we can count with and without it, rather than quietly removing visits we have decided do not count.

The state and metro are about the page, not about you. If someone reads the Savannah page, we record that the Savannah page was read. We are not looking up where you are, and nothing here tells us — you could be reading it from anywhere. We keep it because it tells us which parts of Georgia this site is actually reaching, and it says nothing about your health.

That last one is a real choice with a real cost. We record that a price page was read, not which price page — so we can see that the price pages are worth having, and we cannot see that someone read the page for an HIV test. It makes the numbers less useful to us. We think that is the right trade on a site about medical prices, and we would rather say plainly that we gave something up than imply the question never came up.

The cc_v number is never written down. It stays in your browser; our records only note whether a visit arrived carrying one. So we can count returning visitors without ever holding anything that links one of your visits to another — and because it only exists in your browser, clearing your cookies genuinely erases it.

How to switch it off. If your browser or an extension sends the Global Privacy Control signal, or the older Do Not Track one, we count nothing and we delete both cookies if you already have them. Most privacy-focused browsers and extensions send one of these; in Firefox and Brave it is a checkbox in settings. Blocking cookies for this site works too. Nothing about the site behaves differently either way — there is no wall, no banner, and no reduced version.

How long we keep it. Individual page-view records are deleted after 90 days. What survives is daily totals — how many visits on a given day, how many were phones — which are counts, with nothing in them that could refer to a person.

Error monitoring

If enabled, we use Sentry to report unhandled software errors so we can find and fix bugs. When the site fails, Sentry receives the error, the stack trace, and the page path where it happened.

It does not receive what you searched for. Search terms travel in the web address — /search?code=90834 is a psychotherapy session, and that is not something a third party should learn about you in exchange for a bug report. Before anything is sent, we strip the query parameters from the address and remove the referring-page header, so Sentry sees that an error occurred on /search but not which procedure was being looked up. We also leave Sentry's personal-data collection switched off, so cookies, login headers, and your IP address are not attached.

Sentry is a third-party service and processes this data on its own systems under its own terms. If you would rather no error data left our servers at all, that is a reasonable position — the site works identically with error monitoring switched off, and it is off by default.

Third parties we share data with

In full, and only when the relevant feature is in use:

That is the complete list. We do not send your data anywhere else. Our own visit counting adds nobody to it — those records are written to our own database and stay there — and neither does Umami, for the same reason: we run the software ourselves rather than sending anything to the company that writes it. A list like this is only worth reading if the things missing from it are missing for a stated reason rather than by oversight, so: those two are absent because nothing leaves our server.

Contact

Questions about this policy or your data can be sent to [email protected]. There is more about who runs this site and how it is paid for on the about page.