Last updated July 28, 2026
Privacy Policy
This page explains what we actually store, what the software refuses to accept, and the one judgment call worth being explicit about.
What we collect
Account information — your name, professional credential, email address, license labels you choose to add, and a hashed password. We never store your password itself.
Workspace content — the clinics you cover, your staff roster and their credential types and expiry dates, service menus, malpractice policy details, protocol documents and their signed versions, chart review attestations, and supervisory hour entries.
Billing information — a Stripe customer identifier and subscription status. Card numbers go directly to Stripe and never reach our servers.
Operational logs — ordinary server logs needed to run and secure the service. We do not run third-party advertising or analytics trackers.
What the software refuses to accept
Chart reference fields accept record locators only. The input is validated: entries containing spaces, narrative text, Social Security numbers, email addresses, phone numbers, or dates of birth are rejected, and so are tokens with no digits — because those are usually names. Findings and note fields are screened for the same direct identifiers.
The honest part about chart IDs
A medical record number is itself a direct identifier under the HIPAA Safe Harbor de-identification standard (45 CFR 164.514(b)(2)(i), item 8). We store chart IDs anyway, deliberately: an attestation that cannot point at which charts were reviewed does not document anything. Rather than claim a de-identification status we would be arguing about later, we state it plainly — chart IDs are stored, everything else about the patient is not, and the ID is meaningless to anyone without access to your EMR.
If your arrangement requires a Business Associate Agreement, ask and we will sign one.
How we use it
To operate the service, produce your records and binder, run the state rules engine, process your subscription, send transactional email about your account, and secure the system. That is the complete list.
We do not sell your data, share it with advertisers, or use your workspace content to train machine learning models.
Who else touches it
Stripe processes payments and holds your billing details under its own privacy policy. Our hosting provider stores the database on our behalf. We do not disclose your records to anyone else except when legally compelled — and if we are compelled, we will tell you unless the law forbids it.
Retention and deletion
We keep your records for as long as your account exists, because that is the point of the product — a supervisory record you may need to produce years later. Signed records are append-only and cannot be edited or deleted through the product.
You can ask us to delete your account and everything in it at support@standingmd.com. We will confirm what will be destroyed before doing it, and we will do it within 30 days. Export your binder first — deletion is not reversible.
Demo workspaces contain fictional data and are deleted automatically after 7 days.
Your choices
You can view your account information and workspace content from inside the product at any time. Depending on where you live you may have rights over your personal data — email us and we will honor them rather than make you cite a statute.
Changes and contact
Material changes to this policy will be announced in the product before taking effect. Questions: support@standingmd.com. See also our Security page and Terms.