Skip to content

Mobile App Privacy Policy

Effective Date: April 21, 2026 | Last Updated: September 26, 2026

This policy covers the HCC Buddy iPhone app. Version 1.0.0 includes ICD-10-CM and guideline searches, provider lookup, saved codes, controlled Coding Notes and account settings. Version 1.0.1 adds Ask Buddy and Apple subscriptions. The sections below identify practices that apply only to version 1.0.1.

You can create an account with email and password and request a password reset in the app. Version 1.0.1 adds Google and Apple sign-in. The emailed password-reset link opens on the website. Website features and browser analytics are covered by the website privacy policy. Check mobile access and support for availability. A private test build is separate from a public store release.

1. Reference use and patient information

HCC Buddy is a coding-reference tool. Search for codes, diagnosis names or guideline terms without patient details. Do not enter Protected Health Information (PHI), including patient names, member IDs, dates of birth or other patient-linked identifiers. Input checks cannot guarantee that every identifier will be detected.

2. Information used by the app

  • Reference searches: search text and your selected ICD-10-CM edition, HCC model and year are sent to HCC Buddy's reference services. Provider lookup sends the provider name or NPI and any state filter you choose. These public requests do not attach your account token. They still reach our hosting services and can produce operational request or error records.
  • Account and security: email sign-in uses your email and password. In version 1.0.1, Google or Apple sign-in sends us a credential to verify your identity. We receive your email address and a provider account identifier; Apple can let you share a private relay email address instead of your personal address. If multi-factor authentication is enabled, you also provide a verification or recovery code. We keep account and security records to authenticate you and protect access. Your account profile can include a name provided during signup. Account records can include identifiers and IP addresses.
  • Saved work: bookmarks, code basket entries and Coding Notes are stored by the service and linked to your account. Coding Notes contain a code and edition, controlled review choices and selected official references. There is no freeform note field in this version.
  • Ask Buddy in version 1.0.1: if you use Ask Buddy, your question, recent conversation context and retrieved coding references will be sent through our backend to OpenAI to produce an answer. The app will keep the conversation only during that session, and our routine usage records will omit the question and answer text. We will still record account-linked usage, source and model details needed to enforce limits and run the service. HCC Buddy will also use these account-linked usage counts to measure feature use. This first-party measurement is separate from the website analytics tools described below. A free account will have three Ask turns per day, shared with the website. An account trial or Pro subscription will provide more access under the applicable plan terms. Do not enter PHI in a question or follow-up. Screening may miss an identifier.
  • Account emails: the shared account service sends security and account messages, plus product onboarding emails that can include product and plan offers.

3. Information on your device

Recent lookups store up to ten code references with their ICD-10-CM edition and lookup time on your device. They do not store the search phrase. This history is separate from your account and can be used without signing in. Deleting your account does not clear these device records; use Clear recent lookups in the app.

Session credentials and the App Lock preference use iOS secure storage. Optional Face ID, Touch ID or device-passcode checks are handled by iOS. HCC Buddy receives the authentication result, not your biometric template or device passcode.

These reference features do not request access to your location, contacts, photos, microphone, camera or HealthKit data. The app does not use an advertising identifier or track you for advertising. Google's sign-in SDK declares some data use for analytics, as described below. Browser activity after opening a website link is separate.

4. Free use and subscriptions

Version 1.0.0 has no in-app purchases. Free guest reference search does not require an account or subscription. In version 1.0.1, Apple processes iPhone subscriptions through in-app purchase. We receive verified purchase identifiers, product and transaction details, and subscription status from Apple so we can grant access, restore purchases and handle refunds or expiration. We will link that purchase record to your HCC Buddy account. We will not receive your full payment card details from Apple. Website subscriptions use Stripe, as described in the website privacy policy. Active Pro access may be recognized on both website and iPhone when you sign in to the same HCC Buddy account. Apple and Stripe handle billing separately.

5. Service providers and diagnostics

Version 1.0.1 offers Google sign-in. The Google Sign-In iOS 9.2.0 SDK's privacy manifest declares that it may collect name, email address, phone number, coarse location, user ID, device ID, other data and other usage data. It marks these categories as linked to you and not used for tracking. The manifest lists analytics as a purpose for other data, user ID, device ID and other usage data. This SDK disclosure does not mean HCC Buddy asks for location permission or your phone number. See Google's privacy policy.

In version 1.0.1, Sign in with Apple lets you share your email or an Apple private relay address. Apple also gives us a provider account identifier. We store an Apple refresh token in encrypted form on our server so we can request revocation when you delete your account. If Apple revocation cannot be confirmed, the app will direct you to manage HCC Buddy under Apps Using Your Apple Account in iOS Settings. See Apple's Sign in with Apple privacy notice.

Mobile Ask in version 1.0.1 sends questions and coding context to OpenAI. We set optional response storage off for those calls. That setting does not remove OpenAI's default abuse monitoring: its API documentation says prompts and responses may appear in logs kept for up to 30 days, with stated exceptions. We do not promise zero retention by OpenAI. See OpenAI's API data controls.

Fly.io, Supabase and Vercel provide backend, database and web hosting. Resend delivers account and product emails. Reference requests and account activity can create operational records, including request metadata, query information or IP addresses. These records may be retained beyond the time needed to answer a request for service operation and security.

Email-and-password account creation uses Cloudflare Turnstile in an embedded verification page to prevent automated signups. Cloudflare processes device and connection signals for this check. The verification page does not receive your email or password and does not load website analytics. See Cloudflare's privacy policy.

The backend uses Sentry for errors and performance diagnostics. Backend request-body capture and exception-local capture are disabled, but reports can still include request and error metadata. The iPhone app's own Sentry reporting is disabled in this version.

Website links open outside the app. The website uses separate analytics, including Google Analytics, Microsoft Clarity and Vercel analytics tools. The app does not append an account token or advertising identifier to these links. See the website privacy policy for browser data practices and choices.

6. Your controls and deletion

  • Clear recent lookups: use this control in the app to remove local code history. It does not delete saved account work.
  • App Lock: turn the local lock on or off in Account.
  • Saved work: remove saved codes or Coding Notes from their controls in the app.
  • Delete your account: open Account, then Delete Account. Review the deletion preview before confirming. Deletion removes personal account data and private saved work covered by that process. Shared-team records can remain with the team. Operational records and provider backups can follow separate retention schedules; deletion is not an immediate purge of every backup or service log. For accounts using Apple sign-in in version 1.0.1, we will also attempt to revoke its authorization and tell you when manual revocation is needed.
  • Apple subscriptions in version 1.0.1: deleting your HCC Buddy account will not cancel an Apple subscription. You can manage or cancel it in your Apple account. If you delete an account with App Store purchase history, including expired or refunded purchases, we may keep minimum transaction records and purchase-account identifiers after deletion to enforce purchase ownership and handle purchase status or refunds. Ask support about a later restore.

Clearing device history, signing out and deleting your account are separate actions. Contact us below for questions about retained data or a deletion request.

7. Age requirement

HCC Buddy is a professional coding-reference tool intended for adults. You must be at least 18 to create an account under our Terms of Service.

8. Changes

We post changes on this page and update the date above. Check the information supplied with a private test build for any differences specific to that build.

9. Contact

Privacy questions: privacy@hccbuddy.com. Support: hccbuddy.com/mobile-support.