Connector privacy notice
Last updated September 28, 2026. This notice covers the public /api/v1/ directory endpoints operated by GLP-1 Care Map.
Information sent to the API
The connector sends a ZIP code or state, directory filters, pagination values, or a clinic ID. Normal HTTP requests also include technical information such as an IP address and user agent. Do not send patient records, names, email addresses, symptoms, insurance identifiers, or conversation transcripts.
How requests are handled
The API uses location and filters to read public directory data from our database. The connector handlers do not write searches to the site's search log, set cookies, or create patient profiles. They do not send requests to providers or book appointments.
For rate limiting on Vercel, the API keeps an IP-derived value and request count in temporary server memory. The value uses a random key for that server process. Entries expire after one minute and are removed on a subsequent request, or when the process ends. On other hosts, requests share one temporary bucket.
Vercel hosts the service and Turso serves the directory database. Hosting and database infrastructure may retain operational logs under the operator's account settings and the providers' policies. The API does not promise that infrastructure retains no request metadata. The application's unexpected-error log contains a generic error label, without the query or database error details.
Your assistant and external links
Muse and other assistants handle conversations and API results under their own policies. Their history may retain information after a connector is disconnected. Opening a clinic or provider link is a separate request to that website. Its own privacy policy applies.
Questions and corrections
For listing corrections, use the clinic submission form. Do not include patient information.