CClinicalTrials.gg

Privacy Policy

Last updated 2026-08-31

This policy covers ClinicalTrials.gg. It describes what we collect, why, who else sees it, how long we keep it, and how to have it removed.

You can read every study record on this site without an account and without being tracked. Everything below applies only once you sign in, post, follow a study, or receive email from us.

Who is responsible

ClinicalTrials.gg is run by Yongjang Jo, an individual, at Sanseong-daero 136, Seongnam, Gyeonggi, Republic of Korea. “ClinicalTrials.gg” is the name the site trades under; the person responsible for your data is the named individual above.

Yongjang Jo is also the data protection officer for the purposes of Korean law. Privacy enquiries, and any request about your own data, go to contact@clinicaltrials.gg.

Which law applies

This site is operated from the Republic of Korea, so Korean personal data protection law applies to it.

The site is in English and open to anyone, so people in the European Economic Area and the United Kingdom use it too. Where that is the case, the GDPR and UK GDPR apply to their data as well, and this policy is written to meet both. Nothing in our Terms of Use changes that — data protection law applies by its own terms and cannot be contracted away.

We treat people in the EEA and the UK as an intended audience rather than an incidental one. This site is in English, carries records from European sponsors and trial sites, and applies no geographic limit, so any other reading would not be credible. Article 3(2) therefore applies to us directly, and we do not rely on being outside its reach.

What we do not do

There is no analytics, no advertising network, no tracking pixel and no third-party script on any page of this site. We do not sell or share personal data with advertisers or data brokers, and we do not build profiles for advertising.

The only cookie we set is the sign-in session cookie described below. Signed-out visitors are set no cookies at all.

What we collect, and why

Your email address, when you sign in. Either you give it to us for a sign-in link, or Google gives it to us when you sign in with Google. It is how we identify your account and how we send the mail you have asked for. We also store Google’s stable account identifier so that signing in again reaches the same account.

A display name. It is pseudonymous by default and it is the only name this site ever shows beside anything you write.

A real name, optionally. We ask researchers and industry accounts for one. It is displayed nowhere today and is not used for anything today. You can leave it empty.

What kind of person you said you are — researcher, industry, investor or patient — asked once at sign-up. It is displayed nowhere and, in particular, never appears next to a comment.

Your IP address, recorded with a sign-in link request so that the same address cannot request an unlimited number of them. It is not attached to your browsing.

What you write and what you follow — your comments, your reports of other comments, and the studies you follow.

Health-related information — read this part

Two things on this site can say something about your health, and we would rather be blunt about them than bury them.

The studies you follow.A list of the trials one person watches can imply a diagnosis, especially alongside a sign-up answer of “patient”. We treat that combination as health-related information: it is shown to nobody, never used to target anything, and deleted outright when you close your account.

What you write in a comment. Comments are public, visible to anyone on the internet, and indexed by search engines. If you describe your own condition or treatment in one, you are publishing it. Please do not post anything about your health, or anyone else’s, that you would not want attached to your display name permanently.

You can report a comment that exposes personal data — yours or somebody else’s — and it is hidden pending review rather than after it.

The basis for holding that answer is your explicit consent — nothing else. Health-related information is special-category data under Article 9 of the GDPR and 민감정보under Article 23 of the Korean Act, and both want a consent asked separately rather than folded into signing up. So we ask separately: choosing “patient, participant or caregiver” shows a box explaining what the answer implies, and the answer is not stored unless you tick it. We record when you did.

Change that answer, or close the account, and the consent is withdrawn — we delete the record of it rather than keep it, because a note saying you once answered “patient” would carry the same implication the consent was protecting. Choosing that answer again asks again.

Nothing on this site is gated on it. “Prefer not to say” costs you no feature, and following a study is not gated on it either — following alone, without that answer, is not treated as a statement about your health.

Email we send

Sign-in links and confirmations, because you asked to sign in.

A digest about studies you follow, if you have left it on. Every digest carries a one-click unsubscribe, and turning it off does not unfollow anything.

Questions to study contacts. When a comment is marked as a question for the study team, we may email the contact address ClinicalTrials.gov itself publishes on that study’s record. Those people never signed up here, so every such message carries a way to stop — for that study or for all of them — and we honour it permanently. There are daily limits per study and per asker.

Who else sees it

We use three outside services, and no others:

  • Google, if and only if you choose to sign in with Google. Google tells us your email address and account identifier; we tell Google nothing about what you do here.
  • Amazon SES delivers our email, from the AWS us-east-1 region in the United States. It necessarily handles the recipient address and message content. This is the only part of the service that sends personal data outside Korea, and the terms it travels under are set out below.
  • Amazon S3 stores encrypted database backups, in the AWS ap-northeast-2 region in Seoul. They are deleted automatically after 30 days.

Study records themselves come from ClinicalTrials.gov and contain no information about you. We do not send anything to the registry when you read a study.

Email is the only thing that leaves Korea. Database backups were moved to Seoul on 30 August 2026 and no longer do.

For users in the European Economic Area and the United Kingdom, that transfer is made under the Standard Contractual Clauses adopted by the European Commission. Those clauses form part of the AWS Service Terms and apply automatically whenever AWS services move data out of the EEA; a UK Addendum on the same terms covers the United Kingdom.

For users in Korea, it is a transfer abroad under the Personal Information Protection Act. What is transferred, to whom, where, why, for how long, and how to avoid it are set out under Transfers abroad below.

Cookies

One cookie, set only after you sign in. It holds a signed token identifying your account, is marked httpOnly so scripts cannot read it, is restricted to this site, and expires after 30 days. Signing out deletes it.

There are no analytics, preference or advertising cookies, so there is nothing here to consent to or opt out of.

How long we keep it

  • Sign-in links expire after 15 minutes and work once.
  • A link that also grants a study team badge expires after 7 days; a badge confirmation link expires after 48 hours.
  • Your session expires 30 days after you sign in.
  • Account data is kept until you close the account.
  • Encrypted backups are deleted automatically after 30 days, which is the outer limit on how long anything survives a deletion.
  • A request to stop receiving study questions is kept indefinitely — deleting it would mean emailing that address again.

Closing your account

You can close your account from your account page. When you do:

  • Your email addresses and sign-in methods are deleted.
  • Every study you follow is deleted.
  • Your real name is deleted and your category is reset.
  • Your comments have their text erased and are marked removed. The empty row stays so that replies underneath a question do not lose their shape — nothing you wrote remains readable.
  • Every device is signed out immediately.

What is left is an account row with no name, no address and no content. Backups taken before you closed the account expire on their own within 30 days.

Your rights

You can ask us what we hold about you, correct it, have it deleted, or get a copy of it. You can also object to how we use it, or ask us to restrict that use. Closing your account does most of this immediately and without asking anyone.

For anything else, write to contact@clinicaltrials.gg. We will answer within 30 days.

If you are in Korea, you may complain to the Personal Information Protection Commission. If you are in the EEA or the UK, you may complain to your national supervisory authority.

Children

You must be 18 or older to hold an account here. We ask you to confirm it when you set your account up, and we record that you did and when. We do not knowingly keep data about anyone younger; if we learn that an account holder is under 18, we close the account and delete the data.

Reading needs no account. Every study record on this site, including the many that concern children, is readable by anyone without signing in or being asked anything.

We do not ask for your date of birth. A confirmation that you meet the age requirement tells us what we need; a birth date would be one more piece of personal information to hold and protect for no further benefit.

Disclosures required by Korean law

The site is operated from Korea, so the 개인정보 보호법 (Personal Information Protection Act) applies. Article 30(1) lists what a processing policy must contain. Everything above already says most of it; this section restates it in the order and under the names the Act uses, so that each required item can be found.

1. Purposes of processing

To operate an account and sign you in; to show a name beside what you post; to run the discussion, including moderation and reports; to send the study digest you asked for; to pass a question you marked to the study’s registry contact; to confirm a study team badge against the address the registry publishes; and to limit abuse of the sign-in link. Personal data is used for nothing else, and for no advertising purpose.

2. Processing and retention periods

See “How long we keep it” above. In summary: sign-in links 15 minutes, badge-grant links 7 days, badge confirmations 48 hours, sessions 30 days, backups 30 days, and account data until you close the account.

3. Provision to third parties

None.We do not provide personal data to any third party for that party’s own purposes. The outside services listed above are entrusted processors, which is a different thing and is item 4.

One case is worth naming because it looks like an exception and is not: when you mark a comment as a question for a study team, the comment text and the fact that it came from this site are emailed to the contact address ClinicalTrials.gov publishes. Your email address is not disclosed to them.

3-2. Destruction procedure and method

Data is destroyed when the purpose ends — for account data, when you close the account, which happens immediately and without review. Identities, follows and the real name are deleted outright from the database; comment text is overwritten with an empty value. Encrypted backups holding earlier copies expire automatically 30 days later under a storage lifecycle rule, which is the outer bound on destruction.

3-3. Sensitive information that may become public

Comments are public. If you write about your own health in one, that information becomes public, and this site cannot make it private again for you once it is indexed elsewhere.

You can avoid this entirely: reading needs no account, and following a study is private and shown to nobody. To keep something non-public, do not put it in a comment. You may delete your own comment at any time, and closing your account erases the text of everything you wrote.

4. Entrusted processing

ProcessorTaskLocation
Amazon Web ServicesEmail delivery (SES)United States
Amazon Web ServicesEncrypted database backups (S3)Republic of Korea

Signing in with Google is deliberately not in this table. Nothing is handed to Google to process on our behalf: you authenticate with Google, and Google tells us an address. That is neither entrusted processing nor provision to a third party, and listing it as either would describe the arrangement wrongly. What Google receives, and when, is set out under “Who else sees it” above.

4-2. Pseudonymised data

None. We do not process pseudonymised data under Articles 28-2 or 28-3.

5. Your rights, and how to exercise them

See “Your rights” above. Most of them you can exercise yourself from your account page without asking anyone; for the rest, write to contact@clinicaltrials.gg. Accounts are for people aged 18 or over, so no request is expected from a legal representative acting for a child; one would be handled at the same address.

6. Data protection officer

Yongjang Jo — contact@clinicaltrials.gg. The same address receives requests to see your own data.

7. Automatic collection devices, and how to refuse them

The only cookie is the sign-in session cookie described above. There is no analytics cookie, no advertising cookie and no third-party script, so there is nothing here that tracks you.

You can refuse cookies in your browser settings, under privacy or site data. Refusing them does not affect reading anything on this site; it does prevent staying signed in, because the cookie is what holds the session.

8-1. Transfers abroad

One transfer: Amazon Web Services, United States, receiving the recipient address and message content of email we send, for the purpose of delivering it, for as long as delivery and its logs require. It happens at the moment each message is sent, over an encrypted connection to the AWS Simple Email Service API; there is no bulk export and no scheduled batch. Backups were moved to Seoul on 30 August 2026 and no longer leave Korea. You can avoid the transfer entirely by not holding an account, since no email is sent to anyone who does not have one.

8-2. Security measures

  • There are no passwords to steal — sign-in is by emailed link or Google, so no password is set, stored, or reused from elsewhere.
  • Sign-in and confirmation links are stored only as hashes, so a copy of the database cannot be replayed as a login.
  • The session cookie is httpOnly, restricted to this site, and sent only over HTTPS.
  • All traffic is encrypted in transit.
  • Each outside service has its own credentials with its own limited permissions, so one leaked key does not reach the others.
  • Backups are encrypted and expire automatically after 30 days.

8-3. Where to complain

Write to us first if you can. You may also go to any of these, independently of us:

  • Personal Information Dispute Mediation Committee — kopico.go.kr, 1833-6972
  • Personal Information Infringement Report Centre — privacy.kisa.or.kr, 118
  • Supreme Prosecutors’ Office, cybercrime — 1301; National Police Agency, cybercrime — 182

Changes

If this policy changes in a way that affects what we collect or who we share it with, we will say so on this page and date it. This version is dated 2026-08-31.