Legal

Privacy Policy

What we collect, why we collect it, and the choices you have.

Effective date: September 21, 2026 · Last updated: September 21, 2026

1. Scope

This policy describes how ClaimetryX™ handles information on the public site, the member workspace, Ask ClaimetryX, the Denial Center, licensed publications, and the certification Academy.

2. What we collect

  • Account information: your email address, and the display name and organization you choose to provide.
  • Subscription and purchase records: plan, seat quantity, purchase and license records, and the payment processor's transaction identifiers. Card numbers are handled by the payment processor and never reach our systems.
  • Learning records: enrollments, module and lesson progress, assessment attempts, scores, and issued credentials.
  • Questions you submit to Ask ClaimetryX, and the answers returned, so your history is available to you.
  • Contact and demo requests you send us: name, work email, organization, reason, and message.
  • Anonymous site usage: page paths, timestamps, and coarse traffic counts. These records carry no user identifier.

3. We do not want patient data

ClaimetryX is not a clinical or claims-processing system and is not intended to receive protected health information. Do not submit patient names, dates of birth, member or account numbers, addresses, or any other patient identifier anywhere on the platform.

PHI Prevention Mode screens submissions before they are processed and blocks input that appears to contain identifiers. It reduces risk but does not replace your own de-identification.

ClaimetryX is designed as a reference and training platform that should not receive protected health information. ClaimetryX does not represent that this zero-PHI design alone resolves your organization's HIPAA or business-associate analysis. You should evaluate your own relationships, contracts, and legal obligations with your advisers.

4. Why we use it

  • To provide the service you signed up for: authentication, entitlements, content access, and downloads.
  • To deliver and support purchases, licenses, and credential verification.
  • To answer your questions and maintain your Ask history.
  • To understand aggregate traffic so we can improve content and navigation.
  • To meet legal, tax, and accounting obligations.

5. When information is shared

We do not sell personal data and we do not share it for advertising.

We rely on the service providers listed below to operate the platform. They process data only to provide those services to us.

Credential verification is intentionally public: a certificate number entered on the verification page confirms the credential and its status.

6. Service providers we use

This is the current list of providers involved in operating ClaimetryX. We list only providers actually configured in the platform today, and we will update this section if it changes.

  • Lovable — application platform, including hosting, the managed database, authentication, private file storage, and the gateway used for Ask ClaimetryX model calls.
  • Cloudflare — edge delivery of the application.
  • Stripe — payment processing, subscriptions, and one-time purchases. Card details are entered with Stripe and are not stored by us.
  • Resend — delivery of transactional email such as license and account messages.
  • Firecrawl — retrieval of publicly available official payer and government pages used as sources for Ask ClaimetryX answers. Your question text is used to search public sources; do not include patient identifiers in it.
  • Google Fonts — delivery of the web fonts used by the site.

7. How long we keep it

We do not publish a fixed deletion deadline, because records may sit in provider backups and infrastructure logs that we do not control. We delete or de-identify records in our own systems when we act on a verified request, and we do not claim a guaranteed backup-purge timeline.

  • Account, subscription, license, and certification records: for as long as your account exists, and afterwards where retention is required for tax, licensing, or credential-verification purposes.
  • Ask conversations: until you delete them, or until your account is deleted.
  • Contact and demo requests: until the request is closed and our normal business-record period ends.
  • Anonymous usage records: retained in aggregate. They carry no user identifier and cannot be traced back to you.
  • Download links for purchased files: issued on request and short-lived (currently two minutes) rather than stored as durable links.

8. Your choices and how requests are handled

You can update your profile, change your password, cancel a subscription, and delete Ask conversations from your account page.

You can ask us to correct or delete your personal information, or to provide a copy of it, through the contact page using the “Security or privacy concern” reason. We confirm that the request comes from the account holder before acting on it, tell you what we can and cannot delete, and keep records where law or a license obligation requires it.

Please keep these requests free of patient identifiers.

9. Security

Access is authenticated, and member content and purchased files are authorized on the server for every request. Details are on the Trust & Security page.

10. Reporting a security or privacy incident

If you believe you have found a vulnerability, or that information was exposed or sent to us in error, report it through the contact page using the “Security or privacy concern” reason. Include enough detail to reproduce or locate the issue, and never include patient identifiers.

We review reports as they arrive, investigate, and respond to the reporter. Where a confirmed incident affects personal information, we notify affected account holders and, where applicable, act on notification obligations that apply to us. We do not commit to a specific notification deadline on this page, because the applicable timeline depends on the facts and the law that applies.

Please do not run load, denial-of-service, or automated scanning tests against the platform.

11. Changes to this policy

If we make a material change, we will update this page and the last-updated date above. Continued use after an update means you accept the revised policy.

12. Contact

Privacy questions and data requests can be sent through the contact page.