# Privacy policy: Squire browser extension

_Last updated: 19 September 2026_

Squire Health BV, Sint-Pietersnieuwstraat 11, 9000 Ghent, Belgium, enterprise
number BE 1017.608.291 ("Squire", "we") makes the Squire browser extension. This policy covers the extension. Your
use of the Squire app is covered by your organization's agreement with Squire.

## What the extension does

It sends a report from the Squire app into the note field of the electronic
health record (EHR) you have open in another tab of the same browser.

## What it handles

**Reports you send.** When you click Send to EHR in the Squire app, the
extension passes the report text to your EHR tab and writes it into the note
field. The text is not stored by the extension and not sent anywhere else.

**Open tabs.** The extension reads the address and title of open tabs to find
the Squire app and your EHR. This stays in your browser.

**Pages you set up.** When you set up a page, the extension stores in your
browser:

- the site's address, without the path or query string,
- how to find the fields you picked, and what those fields look like,
- which EHR the Squire app named when you sent to that page, and when,
- the structure of the page, with all text, form values, links, scripts, styles
  and media removed.

When you are signed in, the Squire app reads these setups and stores them with
your Squire account and organization. Squire staff use them to add built-in
support for your EHR, so it works for others without setting it up.

**Supported EHRs.** The Squire app gives the extension the list of EHRs Squire
supports. The extension stores it in your browser.

**Crash reports.** When part of the extension fails, it sends a report to our
error tracking provider, Sentry (Functional Software, Inc., processing in the
EU), so we can fix it. A report holds the error, where in our own code it
happened, the extension's version and your browser's name. It never holds report
text, anything read from the page you were on, or anything that identifies you.
Web addresses in a report are cut back to the site (`https://ehr.example`), never
the full address, which can name a patient. In Firefox, crash reports are only
sent if you allow technical and interaction data, when you install the extension
or later in the browser's add-ons settings.

## What it does not do

Apart from crash reports, the extension makes no network requests of its own. It
has no analytics or advertising, stores no report text or patient data, does not
track what you do, and does not sell data. The only third party it shares data
with is Sentry, for crash reports.

## Why we may process this data (legal basis)

- **Running the extension and sending reports to your EHR:** performance of the
  agreement between Squire and your organization (Art. 6(1)(b) GDPR), and our
  legitimate interest in providing a working product (Art. 6(1)(f)).
- **Storing your page setups with your Squire account and using them to build
  built-in EHR support:** our legitimate interest in improving and extending
  the product (Art. 6(1)(f)).
- **Crash reports in general:** our legitimate interest in keeping the
  extension working and secure (Art. 6(1)(f)).
- **Crash reports in Firefox:** your consent (Art. 6(1)(a)), which you can
  withdraw at any time in the browser's add-ons settings.

## Permissions

- **All sites:** EHRs run on many different sites, including ones hosted by
  your practice or hospital, so Squire cannot list them in advance. The
  extension only runs on the Squire app until you send a report to an EHR tab
  or set up a page. It does not read other pages.
- **Tabs:** to find the Squire and EHR tabs.
- **Scripting:** to write the report into your EHR, and to show the overlay for
  setting up a page.
- **Storage:** for page setups and the list of supported EHRs.

## Keeping and deleting data

Data stored by the extension stays in your browser until you remove the setup
from the extension's popup, or remove the extension. Crash reports are kept by
Sentry for 90 days. Removing a setup in the extension also removes it from your
Squire account, but Squire keeps a copy to build support for your EHR, until
your organization's Squire account is deleted. To have it deleted sooner, write
to hello@squire.eu.

## Your rights

Under the GDPR you can ask for access to, correction of or deletion of your
personal data, and object to its use. Write to hello@squire.eu. You can also
complain to the Belgian Data Protection Authority
(https://www.dataprotectionauthority.be).

## Changes

We will update this page when the extension handles data differently, and
change the date at the top.

## Contact

Squire Health BV, Sint-Pietersnieuwstraat 11, 9000 Ghent, Belgium.
Enterprise number BE 1017.608.291.
hello@squire.eu
