← MedHound

Browser Extension Privacy Policy

What the MedHound Portal Companion browser extension accesses and why.

Last updated 17 July 2026 · version 2026-07-17

This policy covers the MedHound Portal Companion browser extension. The extension helps a clinician sign in to their practice's provider portals and open the record they clicked in MedHound. It is a companion to the MedHound web app and sits alongside that app's overall Privacy Policy; this page explains the extension specifically.

1. What the extension accesses

A device pairing token. When you are signed in to MedHound, the extension is issued a revocable per-browser token, stored only on your device (in the browser's extension storage). It identifies this browser to MedHound; it is not a password and grants no access beyond your own practice.

Your practice's provider-portal login credentials, transiently. To fill a portal's sign-in form, the extension requests the relevant username and password from MedHound at the moment of sign-in. Those credentials exist only briefly in the page's memory to complete the sign-in and are discarded immediately after. The extension never stores them.

The list of your practice's provider portals (names and web addresses), so it knows which sites to act on.

2. What it does NOT do

It does not track your browsing, run analytics, or collect data for advertising. It does not sell or share data with third parties. It only acts on your practice's provider portals and on the MedHound app itself, never on other websites you visit.

3. Permissions and why

Access to your provider portals: to detect the sign-in form and fill it, and to open the record you clicked. Auto-login only runs on the portals your practice holds credentials for.

Access to MedHound (app.medhound.com.au): to pair this browser and to fetch the credentials and portal list described above.

Local storage: to keep the device token and short-lived navigation state on your device.

The extension contains no remote or hosted code; all of its logic ships inside the extension package and is reviewed by the Chrome Web Store.

4. Where data is handled

Credentials and patient data are held by the MedHound service in Australia and are encrypted; the extension only receives what it needs, when it needs it, over an encrypted connection. Each delivery of a credential to the extension is recorded in MedHound's audit trail.

5. Removing it / revoking access

You can revoke a browser at any time from MedHound settings (Account → Browser extension), which immediately stops it working, or uninstall the extension from your browser. Turning off the single "Auto-login" switch in the extension also stops it acting on any portal.

The pairing token is held only on your device and is destroyed when you revoke that browser or uninstall the extension. Records of credential deliveries remain in MedHound's audit trail, as described in the MedHound Privacy Policy.

6. Contact

Questions, access or correction requests, and privacy complaints about the extension: [email protected]. We will acknowledge your enquiry and respond within a reasonable period.