ChartAssist
← ChartAssist Add to Chrome

Legal

Privacy Policy — GRTechnologies ChartAssist

Last updated: 21 September 2026

What this extension does

GRTechnologies ChartAssist is a Chrome browser extension that fills in fields on EMSCharts patient care reports (PCRs) with default values you configure. To restrict use to authorized personnel, it requires you to sign in before the tools are enabled.

Patient data

ChartAssist never stores or transmits patient data or PCR content. No protected health information (PHI) is saved on your computer, sent to our servers, or sent anywhere else.

To fill a field, the extension does read what is already in it, inside your browser, so it can add to your text rather than overwrite it, or warn you when a different value is already selected. That reading happens only on the page and only at the moment you click a button; the value is never saved or sent anywhere.

On pages with pick-lists (such as the Mental and Neurological findings), the extension asks EMSCharts itself for that list of options, using your existing EMSCharts sign-in, so it can select the right entries. This request goes only to EMSCharts, never to us, and contains no patient information.

What is sent to our sign-in service

Our sign-in service runs on Supabase and is reached over HTTPS. Only the extension popup and the crew-admin console talk to it — EMSCharts pages never do. It receives:

  • When you sign in: your email address and password, or a temporary access code.
  • When you create an account: your email address, a password you choose, and — if your email isn't already approved — the crew you ask to join.
  • While you create an account: the text you type into the crew search box (to find matching crews), and your email address (to check whether it is already approved).
  • While you're signed in: your session token (never your password), to keep you signed in, confirm your account is still approved, look up your role and crew, and record when you accept the Terms of Use.
  • When you use an access code: the code, and your IP address. The IP address is used only to block repeated guessing (a limit of 5 failed attempts in 15 minutes). Records more than a day old are deleted each time a code is successfully redeemed.
  • If you are a crew admin: the changes you make in the console — email addresses you pre-approve, and approvals, denials, role changes and removals for members of your crew.

Your password is sent to the sign-in service, which stores only a secure hash of it. The extension never keeps your password.

Email

We send email only from our servers, never from the extension, using Resend as our email provider:

  • your account confirmation code, password-reset code, and a notice when your password changes;
  • a notice when a crew admin approves your access request;
  • to a crew's admins, a reminder naming anyone whose access request has been waiting more than 10 minutes.

Stored on your computer

Stored in Chrome's chrome.storage.sync, which Chrome can sync across your signed-in Chrome devices under Google's Privacy Policy:

  • The template defaults you enter on the Options page (for example a default chief complaint). This is generic text you choose, not data from any report.

Stored in chrome.storage.local, on this computer only:

  • Your sign-in session, including when it expires. For an access-code sign-in, only the code's last 4 characters are kept, so the popup can show which code you're using; the full code is not stored.
  • Your email address, only if you tick "Remember my email".
  • Your crew's name and whether you're a crew admin or QA auditor, so the popup and Options page can show the right controls without waiting on the network.
  • Display settings: light/dark theme, QA Mode on or off, and where you dragged the toolbar.
  • A diagnostic record if the extension can't find fields it expects on an EMSCharts page (for example after an EMSCharts update): which fields were missing, the page's address path (such as /pr/page2.cfm — without the part of the address that identifies a report), and the time. It contains no field content.

Your session token is sent only to our sign-in service; nothing else stored on your computer is sent anywhere except your template defaults, through Chrome's own sync.

Accounts, retention, and deletion

Your account record — email address, the crew you belong to, your role, approval status, and when you accepted the Terms — is held by our sign-in service. It is the minimum needed to run sign-in and crew-admin approvals; no patient data or PCR content is ever part of it. Crew admins can see the email address, role and status of the members of their own crew, and nobody else's.

  • Who controls it. The account data is administered by the crew/organization that uses the extension; the maintainer operates the shared service on their behalf.
  • Retention. Account data is kept while your account is active. It is removed when a crew admin removes you or deletes your pre-approval, when an access request is denied, or when you ask for deletion (below). Access-code sign-ins create no account; the service records only when each code was used, and the IP-address records described above.
  • How to request deletion. Ask your crew admin to remove your account from the crew-admin console, or contact us using the address in Contact below. Removing your account deletes its sign-in record.
  • On your computer. Signing out — or Chrome being signed out of its Google account — removes your session, your crew name and your admin/QA status. Your remembered email stays until you sign in with "Remember my email" unticked; your template defaults stay until you clear them on the Options page (Reset all, then Save); and your display settings stay until you change them. Removing the extension or clearing your browser data removes all of it.

Permissions this extension requests

  • storage — to keep your template defaults, settings and sign-in session in your own browser (see Stored on your computer).
  • identity — so the extension is told when Chrome is signed out of its Google account, and can end your ChartAssist session at that moment. This is what stops the next person on a shared workstation from picking up your signed-in session. The extension is notified of the event only: it cannot and does not read your email address, your name, or any other account detail, which would require a separate permission (identity.email) that ChartAssist does not request. Nothing about your Google account is stored or transmitted anywhere.
  • Host access to *.emscharts.com/pr/* — so the toolbar can read and fill fields on EMSCharts PCR pages, and fetch EMSCharts' own pick-list options (see Patient data). These are the only pages it runs on.
  • Host access to our Supabase project — so the popup can sign you in and crew admins can use the console.

HIPAA

This extension is not a covered entity or business associate under HIPAA. It does not store, transmit or retain protected health information (PHI); the only contact it has with report content is reading a field momentarily inside your browser, as described under Patient data. Compliance with HIPAA and your organization's privacy policies when using EMSCharts remains your responsibility.

Problem reports (optional)

The extension popup's "Report a Problem" link and the Report a Problem form on this website are separate from the extension itself — using them is voluntary and not required to use ChartAssist. Submitting a report sends the text you type into the form, the page/feature/frequency options you choose, the extension version, your email address (only if you choose to give one), and your browser's user-agent string.

  • No patient information, ever. The form asks you not to include any, and PHI does not belong in a problem report regardless of what you submit through it.
  • Delivery. A submitted report is emailed to our support inbox via Resend. If you gave an email address, a copy of your report is also emailed to you. It is not stored in a database — the support inbox is the record.
  • Spam protection. The form runs a Cloudflare Turnstile challenge before sending. Your IP address is passed to Turnstile for that check and used to limit how often the form can be submitted; we don't store it.
  • Retention and deletion. Reports are kept in the support inbox for as long as needed to investigate and respond, then deleted. Contact us using the address in Contact below to request earlier deletion of a report you submitted.

Requesting ChartAssist for your agency (optional)

The "My Agency Isn't Listed" form, linked from the extension's sign-up screen, is also separate from the extension and voluntary. Submitting it sends your agency's name, your email address, whether your agency uses EMSCharts, how many testers you'd want, any comments you add, and how you heard about us.

  • Delivery. The request is emailed to our sales inbox via Resend. It is not stored in a database — the inbox is the record.
  • Spam protection. The same Cloudflare Turnstile check and submission limit as the problem-report form apply, with your IP address used the same way and not stored by us.
  • Retention and deletion. Requests are kept while we follow up with your agency. Contact us using the address in Contact below to have yours deleted.

Service providers

  • Supabase — runs our sign-in service and database.
  • Resend — delivers our email.
  • Cloudflare — hosts this website and the images in our emails, runs the Turnstile spam check on our forms, and forwards email sent to our support address.
  • Google — Chrome's own sync carries your template defaults between your devices.

Like most online services, these providers keep standard technical logs (such as request times and IP addresses) under their own privacy policies.

Changes to this policy

If this policy changes, the updated version will be posted on this page with a revised date above.

Contact

For questions, privacy requests, or account deletion, email support@grtechsupport.com. For a security or privacy vulnerability, email the same address and please report it privately rather than publicly.

Gardner Responder Technologies All tools Privacy Terms © Gardner Responder Technologies

ChartAssist is an independent tool — not affiliated with or endorsed by emsCharts, Inc., ZOLL Data Systems, or ZOLL Medical Corporation.