Privacy notice
In brief: HIMBY uses the health information and location you enter to find relevant services. A clear search is handled by HIMBY's deterministic routing. When a request is ambiguous, its text may be sent to OpenAI to extract a structured care intent. HIMBY does not sell health information or use it for advertising.
Who is responsible for your data
HIMBY (Health In My Backyard) is the data controller for information processed by this service. Privacy questions, rights requests, account deletion requests, and requests to withdraw consent can be sent to himby.consulting@gmail.com.
What we process and why
| Information | Purpose | UK GDPR basis |
|---|---|---|
| The care or health need typed into the search box and the preferences selected | To understand the request, select compatible service routes, and rank suitable providers | Consent under Article 6(1)(a) and explicit consent for health data under Article 9(2)(a) |
| Postcode, search radius, and derived coordinates | To find services near the location entered and apply GP catchment or distance rules. The exact postcode is used for the active search but is not stored in saved-service records or account settings. | Consent under Article 6(1)(a) |
| Hashed search and postcode fingerprints, result counts, route IDs, timing, errors, and technical browser identifiers | To secure the service, diagnose failures, and measure search reliability without retaining raw health text in routine telemetry | Legitimate interests under Article 6(1)(f): operating and improving a safe, reliable service |
| Account email, authentication identifier, preferences, and saved provider IDs | To provide sign-in, account settings, and saved services. A saved service may retain only the outward postcode area; its originating health query is not saved. | Contract under Article 6(1)(b) |
When OpenAI is used
HIMBY does not need OpenAI for every search. Clear, high-confidence requests can follow deterministic rules without an OpenAI call. For an ambiguous free-text request, HIMBY may send the text of that request and the selected funding preference to OpenAI so it can return constrained structured intent fields. OpenAI does not choose the final provider list: HIMBY validates route compatibility, provider scope, supply, and safety deterministically.
OpenAI states that API data is not used to train its models by default. Unless a different eligible retention control is configured, API content may be held in abuse-monitoring logs for up to 30 days. See OpenAI's API data-controls documentation. Do not submit free-text health information if you do not consent to this possible processing.
Urgent safety searches
Language indicating suicide, self-harm, overdose, or immediate danger is intercepted by a local deterministic safety rule. HIMBY then displays NHS urgent-support information instead of sending the text to OpenAI or showing a routine provider ranking. No automated screen can detect every emergency. If anyone is in immediate danger, call 999 or go to A&E.
Service providers and international processing
HIMBY uses service providers to operate the product. These currently include Clerk for identity and authentication, Heroku for application and database hosting, Redis for short-lived cache and progress data, OpenAI for selected ambiguous intent extraction, and OpenStreetMap geocoding only if the local postcode lookup cannot resolve a postcode. Some providers or their subprocessors may process data outside the UK. HIMBY relies on the provider's applicable data-processing terms and lawful transfer safeguards, such as UK adequacy regulations or the UK International Data Transfer Addendum, where required.
Retention and minimisation
- Raw health-query text is used to answer the active request and is not placed in routine telemetry, Redis keys, saved-service records, or account settings.
- Choice-pool result snapshots expire after about one hour in Redis, with a 15-minute in-process fallback. Clarification state normally expires after 10 minutes.
- Aggregate reliability counters are normally retained for up to 45 days and use fingerprints rather than raw search text or exact postcodes.
- Operational provider logs are intended to be short-lived and contain fingerprints, route labels, result counts, and errors rather than raw health text.
- Account records and saved services remain until the account or items are deleted, subject to any legal need to retain limited records.
- Authentication sessions normally expire after 30 days.
Cookies and browser storage
HIMBY uses essential browser storage for authentication state, language, a random security identifier, and interface state. Its current first-party analytics records only allow-listed aggregate events such as a page view or completed search. These counts do not contain the health query, postcode, provider identifier, IP address, cookie identifier, or advertising profile. Core search does not depend on advertising cookies.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, or portability of your personal data, object to legitimate-interest processing, and withdraw consent at any time. Withdrawal does not make earlier consent-based processing unlawful. Email himby.consulting@gmail.com to exercise a right. You may also complain to the Information Commissioner's Office.
Automated results, children, and medical advice
HIMBY provides information and navigation, not a diagnosis, clinical decision, emergency response, or guarantee of eligibility or availability. The service is not designed for children under 13 to use independently; a parent or guardian should assist. Contact a provider or qualified healthcare professional before making an important care decision.
Changes to this notice
The version date above changes when this notice or the underlying processing materially changes. If consent is required for a changed health-data use, HIMBY will request it again.