What OnCo collects, where it lives and what leaves your device and where it goes, written from the code that runs the site. The site is open source, so every statement here can be checked against the file it describes.
Last updated Terms of useHistory of this page
OnCo ([legal entity and address]) runs onco.cc and is the controller for the small amount of personal data the site touches. The code that this policy describes is public at github.com/judegomila/OnCo.
The site is built as a static export and served by Vercel. Like any web host, Vercel logs each request (the address requested, the time, your IP address and browser type) for security and performance, and uses that log to run and protect the service. We add nothing to those logs and do not use them to identify visitors. See Vercel's privacy policy for how long they are kept.
The site can use Google Analytics (gtag.js, property G-2TTJ25WSN8) for one thing: to see which pages are read and how often, so we know what to build next. It is gated behind your choice. The pages we publish contain no Google script at all; the first time you visit, a small bar at the foot of the page asks whether to count your visit, with two answers, Allow and No thanks. Until you answer, nothing is loaded and no cookie is set.
If you press Allow, the browser writes onco:analytics = granted to local storage and inserts the standard Google loader followed by a plain gtag('config') call, then and on every later visit while that choice stands. No advertising features are switched on and no extra parameters are passed (the snippet sets no IP anonymisation option; how Google Analytics 4 handles IP addresses is described in Google's documentation). Through it Google receives the pages you view, the time, the page you came from, your device, browser and language, and a rough location derived from your IP address, and it sets the _ga cookies listed below so that repeat visits can be told apart.
If you press No thanks, the browser writes denied, the loader is never inserted and no cookie is set. If your browser sends the Global Privacy Control signal, we read it as No thanks and do not show the bar at all; a choice you make on the site afterwards takes precedence. Changing from Allow to No thanks stops further measurement on the spot (Google's ga-disable flag) and expires the _ga cookies the page can reach.
You can change your choice at any time here, or with the Analytics choice link in the footer of every page, which brings the bar back:
Beyond that, you can block googletagmanager.com with a content or tracker blocker, use your browser's tracking protection, or install Google's own opt-out add-on. How Google uses data from sites that use its services is at policies.google.com/technologies/partner-sites, and Google's privacy policy is at policies.google.com/privacy.
onco.cc is the public, signed-out site. It has no sign-in of its own, keeps no session and holds no account data, neither in your browser nor on any server. The Sign in/up control in the header is a plain link to the separate signed-in site, me.onco.cc, carrying the address of the page you were on so you can come back to it. Nothing about you travels with that link beyond the page address itself.
me.onco.cc is a different application with its own sign-in and its own database; that is where a role, a cancer type and case details can be stored on an account. What it collects and how it is kept are set out in its own privacy notice, which applies from the moment you arrive there. This policy covers onco.cc only.
Your cancer and reading mode. For me lets you choose a cancer, a stage, biomarkers, treatments you have had, a country or postcode and whether you read as a patient, caregiver or clinician. All of it is written to local storage under onco:profile:v1, on this device only, and read back by For me, the cancer hubs, the trials list and search. It is never sent to OnCo or anyone else and does not follow you to another browser or device.
Saved items. The pages you press Watch on, the table views you save and your appointment preparation notes are browser-only in the same way. The Saved page checks for changes by fetching OnCo's own static data files for the pages on your list; export and import move the lists between browsers as a file you keep.
Clearing. Change or clear your cancer and reading mode on For me, remove watched pages and saved views on Saved, or use your browser's site data controls for onco.cc to remove everything in the table below from the device.
OnCo's own code sets no cookies; the only cookies come from Google Analytics, and only once you have pressed Allow. Everything else is local storage, session storage or the service worker cache, all of it on your device.
| Name | Where | What it holds |
|---|---|---|
| _ga, _ga_* | Cookie (set by Google, only after you press Allow) | Google Analytics visitor and session identifiers, so repeat visits can be told apart. Not set while your analytics choice is No thanks or unmade. |
| onco:analytics | Local storage | Your analytics choice: granted or denied. Absent until you choose. |
| onco:theme | Local storage | Light, dark, high-contrast or system theme. |
| onco.layer | Local storage | Reading level (technical, plain, simple) and site language. |
| onco:region | Local storage | The region you chose for approvals and access. |
| onco:profile:v1 | Local storage | Your browser profile for For me and the hubs: cancer, stage, biomarkers, treatments had, country or postcode if you typed one, and reading mode. |
| onco:watchlist:v1 | Local storage | Pages you pressed Watch on, with the dates you last saw them. |
| onco:saved-views:v1 | Local storage | Table views you saved: a name and the address that reproduces the filters. |
| onco:prep:v1, onco:prep-sheet:v1 | Local storage | Ticks, questions and notes on the appointment preparation pages. |
| onco:shortcuts:v1 | Local storage | Whether keyboard shortcuts are on or off. |
| onco:missed-paths | Local storage | The last fifty addresses this browser asked for that did not exist, so the not-found page can suggest where you meant to go. |
| onco:stars | Local storage | The GitHub star count shown in the header, cached for an hour. |
| onco.translate-offer.dismissed | Local storage | That you dismissed the offer to switch language. |
| onco-v3-pages, -shell, -assets, -data, -media | Cache storage (service worker) | Copies of pages you have visited (up to 200), the site's scripts and styles, its data files and images, so the site works offline. |
To clear any of it, use your browser's site data or cookie controls for onco.cc; the cancer and reading mode can also be changed or cleared on For me.
Any cancer type, stage, biomarker, treatment or reading mode you choose on OnCo is sensitive information about health. All of it is kept only on your device, in the storage listed above, and is never sent to OnCo or to Google. No health information leaves your device through onco.cc. Anything you choose to store on an account at me.onco.cc is governed by that site's privacy notice.
Two limits are outside our control and worth knowing. First, the address of a page you read (for example a page about one cancer) is part of an ordinary page view, so it is visible to Vercel in its request log and, if you have allowed analytics, to Google Analytics as a page view. Second, if you type a condition, a drug or a place into a tool that queries ClinicalTrials.gov, Europe PMC or OpenStreetMap, that query goes to that service from your browser (next section).
Besides Vercel and Google, some features fetch from other services directly from your browser, only when you use them:
Each of these sees your IP address and the request, as any website you visit does, and each has its own privacy policy. Links that leave onco.cc open in a new tab; those sites' policies apply once you are there.
OnCo shows no advertising, loads no advertising trackers and does not sell, rent or share personal data for marketing or any other purpose. The only measurement is Google Analytics as described above. Nothing about you is used to train models or shared with data brokers.
Under the EU General Data Protection Regulation and the UK GDPR you can ask to see the personal data an organisation holds about you, have it corrected or deleted, restrict or object to its use, receive a copy in a common format (portability), and complain to your supervisory authority. Under the California Consumer Privacy Act you can ask what is collected, have it deleted or corrected, opt out of sale or sharing (we do neither), and not be treated differently for asking.
Most of these you can do yourself:
OnCo is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe we hold any, contact us and we will have it removed.
Vercel and Google are companies based in the United States, so request logs and analytics data may be processed there. Each publishes the legal safeguards it relies on for data moved out of the EU, the UK and other places with transfer rules; we cannot verify those arrangements for you here, so please see Vercel's and Google's policies for the current terms.
This policy changes when the code changes. The date at the top of the page is the date this page was last built, and every earlier version is in the page's history on GitHub.
Open an issue at github.com/judegomila/OnCo/issues or write to [contact email]. Security matters are covered in the repository's security policy.