LEGAL TEMPLATE / NOT LEGAL ADVICE

Privacy policy.

This operational template describes the intended product behavior and should be reviewed by qualified counsel before launch.

Data we process

We process account details, subscription status, product usage totals, and provider-roster data you submit. The service is intended for public provider and business information. Do not upload patient data or protected health information.

How files are handled

Anonymous uploads are processed for validation and are not intended for permanent storage. Saved rosters are retained at the user’s direction using normalized public provider fields needed for revalidation. Raw uploads should be deleted after processing under the configured retention job.

Service providers

Supabase may provide authentication and database services, Stripe processes billing, Resend sends transactional email, CMS/NPPES supplies public provider data, and the hosting platform runs the application. Their own terms apply.

Your choices

Account holders can delete saved rosters and request account deletion. Subscription billing can be managed through the customer portal. Operational backups may take a limited period to expire.

Security and contact

We use authorization checks, row-level security, signed webhooks, input limits, and server-only secrets. No internet service can guarantee absolute security. Questions and deletion requests can be sent to the address above.