Legal

Privacy Policy

Last updated 2026-07-12

This policy describes how Patientary (“Patientary”, “we”, “us”) collects, uses and protects information when you use our website, API and MCP server (the “Service”). Patientary is a reference tool over public healthcare data — provider directory records from the CMS NPPES registry, ICD-10-CM diagnosis codes from the official CMS release, and NUCC provider-taxonomy codes. It is not affiliated with, endorsed by, or operated by CMS, NUCC, or any other standards body, and provides no medical, coding, billing or legal advice. See our Data & Methodology page for source detail.

No patient data — and we don’t want any

Patientary looks up publicly-registered provider and coderecords — it does not accept, store or process patient records, medical charts, claims, or any other Protected Health Information (PHI). Please don’t submit patient identifiers, patient names, or any PHI to the Service in search queries, API requests or support messages; if you accidentally do, contact us at hello patientary.comand we’ll delete it.

Information we collect

  • Account information — your name, email address and password (or sign-in provider identifier) when you create an account.
  • Search & watch data — the NPIs, provider names and ICD-10 codes you search or validate, and any provider you choose to monitor for registry changes.
  • API usage data— your API key (stored hashed), the endpoints you call, timestamps, response status and request volume, used for rate limiting, billing and the inspectable request log in your dashboard. We do not log full request bodies of batch-validation calls beyond what’s needed for billing counts.
  • Billing information — if you subscribe to a paid plan, payment is processed by Stripe; we store your plan, billing status and Stripe customer reference, never your full card number.
  • Usage data — basic product analytics (pages viewed, features used, device/browser type) and error reports sent to our monitoring provider when something breaks.

How we use your information

  • To operate the Service: run your lookups, enforce API rate limits and monthly quotas, and check your monitored providers on a schedule.
  • To send monitoring alerts you sign up for and essential account/billing emails.
  • To process payments for paid plans via Stripe, and to meter usage-based overage.
  • To diagnose and fix bugs, and to understand which features are useful so we can improve them.
  • To keep the Service secure and prevent API abuse (including by automated/agent traffic).

We do not sell your personal information, and we do not use your search, watch or API request data to train third-party models.

Data storage & security

Your account, search, watch and API usage data is stored in Supabase (Postgres), an encrypted database with access restricted to the systems and personnel that need it to operate the Service. We use industry-standard transport encryption (HTTPS/TLS) for all data in transit, and API keys are stored hashed, never in plaintext.

Data retention & your choices

You can revoke an API key, delete a monitored provider, or delete your account at any time. If you close your account, we honor deletion requests and remove your account, search and API usage data within a reasonable period, except where we’re required to retain billing records for tax or legal purposes.

Cookies & analytics

We use a small number of cookies required to keep you signed in, plus privacy-conscious product analytics to understand feature usage in aggregate. We don’t use third-party advertising trackers.

Third parties

We share data with the vendors that operate the Service on our behalf — our database and hosting providers, Stripe for billing — each bound to use it only to provide their service to us. Provider and code lookups are served from CMS NPPES, the CMS ICD-10-CM release and NUCC; searching a name or code does not create any relationship between you and those bodies.

Children

The Service is intended for medical billers, coders, health-tech developers and the businesses and agents building on top of them, and is not directed to, or knowingly used by, children under 16.

Changes to this policy

If we make a material change to this policy, we’ll update the date above and, where appropriate, notify you by email.

Contact

Questions about this policy or your data — including requests to access, export or delete it — can be sent to hello patientary.com.