Chrome Extension Privacy Policy
Last updated: October 1, 2026 · applies to Maneiro Clinical Sidecar 8.9.0 and later
This page describes how the Maneiro Clinical Sidecar Chrome extension handles data. It is the privacy disclosure referenced on the extension's Chrome Web Store listing. Maneiro Health Technologies Inc. publishes the extension for eye-care clinics that have a Maneiro account.
Single purpose
The extension has one purpose: to connect a signed-in clinic user's RevolutionEHR browser tab to their clinic's Maneiro account. It syncs the day's schedule and the chart the user opens to Maneiro, opens charts from Maneiro links, and enters content a clinician has approved in Maneiro (for example pretest results, tasks and exam notes) into RevolutionEHR.
Until you sign in with a Maneiro clinic account, the extension does nothing except show a "Sign in to Maneiro" prompt. It does not run on, read from, or write to any EHR page, and it sends nothing to Maneiro or anyone else.
Data the extension handles (only after you sign in)
To work, the extension reads the information your EHR loads into its own pages, including the network responses that page receives. It does this only on your EHR's pages, and only while you're signed in to Maneiro.
- Health information shown on the RevolutionEHR pages you open: for example exam findings, visual acuity, eye pressure, refraction, diagnoses, medications, history, appointments and pretest data for the patient on screen.
- Personally identifiable information: the patient's name, date of birth and chart number as shown in RevolutionEHR, and your own Maneiro username and name.
- Authentication information: you sign in either on the Maneiro website (app.maneiro.ai opens in a tab and hands the extension a one-time code) or by typing your Maneiro or RevolutionEHR username and password in the extension, which sends them once, over TLS, to Maneiro only (Maneiro checks RevolutionEHR credentials with RevolutionEHR the same way its website does). The extension never stores your password. It receives its own sign-in for your shift: a short-lived access token kept only in the browser's in-memory extension session storage, and a renewal token kept in the extension's local storage so the sign-in survives a browser restart. The renewal token is replaced every time it is used, works only together with a key that is created on this device and cannot be copied out of the browser, and stops working after 30 minutes without activity (your clinic can set this from 15 to 60 minutes), after 10 hours at most whatever the activity, when you sign out, or when your clinic or Maneiro ends the session. Activity means your own clicks, typing or scrolling on your EHR's pages or Maneiro's pages; background updates do not count. The extension stores the time of your last activity on your device only, to manage sign-out. None of these tokens is ever placed in Chrome Sync, in a web address, or in the extension package.
- Audio: this version of the extension does not record audio or use the microphone.
- Website content and location of the EHR tab: the address and page content of the RevolutionEHR tab, used to know which chart and screen you are on.
What the extension does not do
- It does not run on any website other than RevolutionEHR (revolutionehr.com, revolutionehr.ca) and app.maneiro.ai.
- It does not read your browsing history, other tabs, passwords for other sites, or payment information.
- It does not write anything into RevolutionEHR without a clinician's explicit action.
- It does not load or run code from the internet; all of its code ships in the reviewed package.
Where data goes
The extension sends data only to the Maneiro service at https://app.maneiro.ai, over TLS, authenticated as the signed-in user and limited to that user's clinic. Patient identifiers are sent in the body of encrypted requests, not in web addresses.
Storage. Maneiro's service stores patient data in your clinic's Maneiro account on managed cloud infrastructure. This includes charts, briefs, letters, transcripts and audit records. Stored data is encrypted at rest at the storage level (the RDS database and S3 file storage).
Service providers. To provide a feature you request (for example drafting a brief or letter), the Maneiro service may send the minimum necessary text to a service provider. The extension itself records no audio; audio only reaches Maneiro when a clinician uses the voice scribe in the Maneiro web app. AI text providers receive text only after names, health numbers and other identifiers are automatically removed. This removal is automated and may occasionally miss something. One provider may keep this text for up to 30 days for abuse monitoring, then deletes it. No provider may use it to train models. Voice-scribe audio is sent to a transcription provider to produce the transcript. Our main provider keeps no audio or transcript after returning the result. If it is unavailable, audio may go to Amazon Transcribe in Canada, which may keep it under its own service terms.
Service providers outside Canada may process data for us; while they do, it is subject to the laws of that country, including lawful access by its authorities.
Our service providers are listed at maneiro.ai/subprocessors.
How long data is kept
What the extension sends is stored in your clinic's Maneiro account. We keep it for as long as your clinic uses Maneiro, as set out in your clinic's agreement with us. When a clinic stops using Maneiro, we return or delete its data as that agreement provides. AI providers that process text for us may keep de-identified text for up to 30 days, as described in our main privacy policy.
Limited use
Maneiro's use and transfer of information received through this extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Health information and personally identifiable information are used only to provide the clinical workflow service the user requests. We do not sell this data, do not transfer it for purposes unrelated to that service, do not use it for advertising, and do not use or transfer it to determine creditworthiness or for lending. Maneiro staff do not read it except with the clinic's permission for support, for security or abuse investigations, or where the law requires.
Browser permissions
- storage: keep the shift sign-in (access token in session storage, cleared when the browser closes; renewal token in local storage, removed at sign-out or when the session ends), the time of your last activity and your clinic's sign-out setting (local storage on this device only, removed at sign-out), and non-sensitive preferences.
- scripting: after sign-in, connect RevolutionEHR pages to Maneiro (read the open schedule/chart, open charts from Maneiro links) and carry out clinician-approved chart entries. The scripts are registered only while you are signed in and are removed when you sign out.
- alarms: renew the shift sign-in shortly before its access token expires; check once a minute whether the sign-out limits above have been reached; and, only while you are signed in to Maneiro and a RevolutionEHR tab is open, a check every 10 minutes that keeps the RevolutionEHR session from timing out during your shift. That keep-alive stops the moment you sign out of Maneiro or close your last RevolutionEHR tab, and ends with the sign-in after 30 minutes without activity (or your clinic's setting) or 10 hours at most. It can be turned off.
- Host access to revolutionehr.com and revolutionehr.ca: the EHR the extension works with.
- Host access to app.maneiro.ai: the Maneiro service the extension talks to, "Open in Maneiro" links, and a demonstration page with made-up patients used only by Maneiro demo accounts. The Maneiro website at app.maneiro.ai is also the only website allowed to send the extension a message, and only to hand over a sign-in the extension itself started.
Your choices
- Sign out from the toolbar button at any time; the extension stops working on EHR pages immediately (already-open tabs stop on their next reload, and no further data is sent).
- Remove the extension from chrome://extensions at any time.
- Clinics can ask for access to, correction of, or deletion of their data at support@maneiro.ai. Patient requests are handled with the clinic, which controls the patient record.
Children
The extension is for clinic staff and is not directed at children. Charts may concern patients of any age; that data is handled as clinical data under the clinic's professional and legal obligations.
Changes
We update this page when the extension's data handling changes, and change the date above.
Contact
Privacy Officer: Dr. Henry Reis, Maneiro Health Technologies Inc., 2415 Kingsway. Contact: support@maneiro.ai.
Maneiro Health Technologies Inc., 2415 Kingsway · support@maneiro.ai · general policy: maneiro.ai/privacy