Skip to content

Privacy

Privacy Policy

HCC Buddy privacy policy. Learn how we handle your data, protect your privacy, and keep your coding sessions secure.

Effective Date: March 1, 2026 | Last Updated: September 5, 2026

HCC Buddy (“we,” “our,” or “the Service”) is a web-based ICD-10-CM Encoder and Ask Buddy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.

1. Information We Collect

We collect only the minimum information necessary to operate the Service:

  • Account information: Your email address and a hashed password when you register.
  • Chat queries: Questions you type into the coding assistant chat and relevant coding context are processed to generate a response. Routine query records retain account-linked usage, source and model metadata with question and response text redacted. Users must not submit Protected Health Information (PHI) in chat queries.
  • Uploaded documents: PDF documents (payer guidelines, coding reference documents) you upload are processed for indexing and stored on our server. We do not accept documents containing patient-identifiable data.
  • Usage data: Basic usage statistics such as number of queries and tokens used, tied to your account.
  • Saved work: Bookmarks, code collections, coding notes, saved practice explanations and source-change subscriptions are associated with your account. Team references, review decisions and revision history are available to authorized members of that team.
  • Payment information: When you subscribe to a paid plan, your payment card details are collected and processed directly by Stripe. We do not store your full card number, expiration date, or CVV on our servers. We receive only a reference ID, subscription status, and billing email from Stripe.

2. Information We Do NOT Collect

  • We do not request patient names, member IDs, dates of birth, Social Security Numbers or other Protected Health Information (PHI). Do not submit patient information through the Service.
  • We do not request your general browsing history outside HCC Buddy.
  • We do not sell, rent, or share your data with third parties for marketing purposes.

3. How We Use Your Information

  • To authenticate your account and maintain your session.
  • To respond to coding questions using our configured language-model providers.
  • To index uploaded reference documents for your personal knowledge base.
  • To process subscription payments via Stripe.
  • To monitor usage, diagnose errors, and maintain service reliability.

4. Third-Party Services

HCC Buddy uses the following third-party services:

  • Website analytics: Google Analytics, Microsoft Clarity and Vercel Analytics can be enabled to measure page visits, navigation and product use. Clarity can receive an internal account identifier to associate sessions with product events.
  • Language-model providers: Our configured providers include OpenAI, Anthropic and Google. Coding questions, conversation context and retrieved reference material can be sent to the selected provider to produce an answer. Provider selection can change with availability and the request. See the privacy information from OpenAI, Anthropic and Google.
  • Stripe: Payment processing for subscriptions. Stripe collects your payment card information, billing address, and transaction details directly. We never see or store your full card number. See Stripe's Privacy Policy.
  • Sentry: Error monitoring and performance tracking. Sentry receives technical error logs (stack traces, request metadata) to help us diagnose and fix issues. Diagnostic reports can include error details and request metadata. They are separate from routine query-usage records. See Sentry's Privacy Policy.
  • Fly.io: Application hosting. Our backend runs on Fly.io infrastructure. See Fly.io's Privacy Policy.
  • Vercel: Website hosting. Our frontend is hosted on Vercel. See Vercel's Privacy Policy.
  • Supabase: Database hosting. Our PostgreSQL database is hosted on Supabase infrastructure. See Supabase's Privacy Policy.

5. Cookies and Local Storage

HCC Buddy uses essential cookies and browser local storage for authentication (session tokens) and user preferences (such as display settings) and saved-work recovery. Enabled analytics services can also use cookies or browser identifiers for measurement and session analysis. Browser settings can restrict cookies and site storage; clearing essential storage signs you out and can remove local drafts.

6. Data Storage and Security

  • Your account data and uploaded documents are stored in a PostgreSQL database hosted on secure infrastructure.
  • Passwords are never stored in plain text -- they are hashed using bcrypt.
  • Access tokens expire automatically. Session handling distinguishes supported client types, including the web, extension and mobile app.
  • We implement industry-standard security measures including rate limiting, input validation, and encrypted transport (HTTPS).
  • Database backups are encrypted and stored in Cloudflare R2 with automatic retention policies.

7. HIPAA & Protected Health Information

HCC Buddy is not a HIPAA covered entity and does not operate as a Business Associate under HIPAA regulations. We do not enter into Business Associate Agreements (BAAs).

HCC Buddy is an informational reference tool for ICD-10-CM codes and HCC categories. It is designed so that no Protected Health Information (PHI) is needed to use any feature.

Our system scans supported inputs for patterns associated with member IDs, Social Security Numbers and patient-identifiable data. Some checks run on our servers after submission. These checks are safeguards, not a guarantee that every identifier will be detected.

If PHI is accidentally submitted despite these safeguards, we will delete the data from our logs within 72 hours of discovery or notification. To report accidental PHI submission, contact privacy@hccbuddy.com immediately.

Users are solely responsible for ensuring they do not submit PHI through any feature of the Service.

8. Data Retention

We retain your account data and uploaded documents for as long as your account is active. You may request deletion of your account from the Account page or by contacting us at the email below. The Account page provides export and deletion controls and shows team ownership requirements before deletion. Personal account data is removed within 30 days. References and review history that belong to a shared team can remain with that team; the deletion preview explains retained shared records separately from your personal saved work.

9. Data Breach Notification

In the unlikely event of a data breach that affects your personal information, we will notify affected users via email within 72 hours of becoming aware of the breach, in accordance with applicable law.

10. Your Rights

You have the right to:

  • Access the data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and all associated data.
  • Withdraw consent at any time by discontinuing use of the Service and requesting account deletion.

California residents (CCPA): You have the right to know what personal information we collect, request its deletion, and opt out of the sale of personal information. We do not sell personal information.

11. Children's Privacy

HCC Buddy is intended for use by healthcare coding professionals. We do not knowingly collect information from anyone under the age of 18.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. Changes will be posted on this page with an updated effective date. Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or wish to request data deletion, please contact: