Legal
Privacy Policy
Effective August 28, 2026 · Last updated August 28, 2026
CarePathIQ is software for building evidence-graded clinical care pathways. This policy explains what we collect, why, and what we do not do. It is written from what the software actually does, and it is checked against the code rather than drafted from intent.
The short version
We do not hold patient information. We do not sell data, run advertising, or use third-party analytics or cross-site tracking. We store the pathways you save so you can come back to them, the account details needed to sign you in, and a record of how you use the Studio that is keyed to your NPI. We may describe aggregate, de-identified patterns in research and publications. The two things most people do not expect are in Product analytics and in the note about pathway titles under Pathways you save — both are spelled out below rather than buried.
What we collect
Account information
Your name, email address, your National Provider Identifier, your ORCID iD if you sign in with ORCID, your stated role, institutional affiliation if you provide one, your plan, and your approval status. Registration is reviewed by a person before access is granted.
Pathways you save
When you save a pathway, its content is stored on our infrastructure so you can return to it and so it can be shared with people you invite. Pathways are retained for 365 days from the last time you write to them, and are limited to 1 MB. You can delete a pathway at any time.
One exception you should know about. If your account is linked to an institution, the title of each pathway you save — along with your member identifier and any training-program details on your record — is added to an index shared within that institution. The pathway itself is not shared: only the title. This exists so a program can see what its people are working on. You can switch it off for your own account in your identity settings, and if you do, nothing of yours is added to that index.
Files you upload
Media you attach to a pathway is stored on our infrastructure. Local policy or guideline documents you upload to ground a pathway are read in your browser, and the extracted text is sent to the AI provider as part of the request that generates your pathway — see AI processing below.
Product analytics
The Studio records how it is used, keyed to your NPI. This is our own system: no third party receives it, and it is not advertising or cross-site tracking. What it holds:
- Your professional record. Your name, credential, specialty and practice state, drawn from NPPES — the public federal provider registry — when you first sign in, together with an institution inferred from that registry entry.
- An event log. One row per action you take in the Studio: what the action was, when it happened, and a small amount of metadata about it. It is a per-event log, not a running total; we aggregate it when we read it, not when we write it.
- The condition you are scoping. Each event carries the clinical condition text you typed for the pathway you were working on. It passes through a filter that strips patterns resembling identifiers and truncates it, but it is text you wrote and we hold it.
- Your browser and referring page, recorded once when a session starts.
What it does not hold: the content of your pathway — the nodes, recommendations, evidence and text you author — and the content of anything you send to the AI.
We currently keep this log indefinitely. We would rather tell you that than quote a retention period we do not enforce. You can ask us to delete your analytics record at any time, and we will.
AI usage
When you use the shared AI allowance, we record the number of requests your account made in a calendar month and an estimated cost, held against a random identifier for about 60 days. We do this to enforce a fair-use cap and a monthly budget. The content of those requests and responses is not stored.
Review programs
If you run a case-review program, we store the structured codes and ratings reviewers submit. By default this is codes only — no free-text clinical narrative. Verbatim narrative can only be stored where your institution has an executed business associate agreement with us and has explicitly enabled it. The system refuses otherwise, and refuses on any uncertainty.
Ordinary server records
Requests to our services generate logs containing IP address, timestamp and user agent, kept for security and troubleshooting.
What we do not collect
- Patient information. No protected health information is held anywhere in the product except through the single, BAA-gated case-review path described above.
- Your own AI key. If you supply your own Google Gemini key it stays in your browser and travels directly to Google. We never receive the key itself. We do store a one-way hash of it, which we use to recognise your account — a hash cannot be turned back into the key.
- Advertising and third-party trackers. No advertising, no third-party analytics, no cross-site tracking, and no cookies beyond what is required to keep you signed in.
- Pathway logic running in your EHR. Where a pathway is deployed as a clinical decision support service, that service runs inside your own infrastructure. Patient context passes to your endpoint, not to us. This is by design and it is not a configuration we offer to host.
AI processing
Generating a pathway sends the text you have entered — including any policy or guideline text you uploaded for grounding — to Google's Gemini API. If you supply your own key, that request goes directly from your browser to Google. If you use the shared allowance, it passes through our proxy, which adds the key and records the usage counters described above; the proxy does not log the request or response body. Google's handling of that data is governed by their terms.
Aggregate and de-identified use
We may compute aggregate, de-identified statistics from how the product is used — for example, how many pathways include a risk stratification, how often cited evidence supports the recommendation attached to it, or how long authoring takes. We may describe these aggregate results publicly, including in research publications, conference presentations and product materials.
We will not identify you, your pathway content, or your institution in anything we publish without your specific agreement. Where analysis of this kind constitutes human subjects research or quality improvement requiring institutional review, we will obtain the appropriate determination before conducting it, not afterwards.
Who else processes your data
- Cloudflare — hosting, storage and the databases behind the product
- Google (Gemini API) — AI generation, as described above
- Resend — transactional email such as sign-in links and invitations
- ORCID — optional identity verification, if you choose to sign in that way
- NPPES, PubMed and NLM terminology services — outbound queries to public federal registries for provider details, literature and clinical codes
- jsDelivr — a public CDN serving the diagram library. Loading it exposes your IP address to that CDN, as with any web font or script.
We do not sell your data and we do not share it with advertisers.
Retention
- Pathways: 365 days from the last write, or until you delete them.
- Pathway titles in an institution index: until you delete the pathway or opt out.
- Account records: for as long as your account is open, and afterwards only as required for legal or accounting purposes.
- Product analytics: indefinitely at present, as described above, or until you ask us to delete your record.
- AI usage counters: about 60 days.
- Server logs: a short operational period.
Your choices and rights
You can export any pathway you have authored at any time, in several formats, and delete it. You can opt out of the institution title index in your identity settings. You can request a copy of the account and analytics data we hold, ask us to correct it, ask us to delete your analytics record, or ask us to close your account entirely. Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA; we apply the same handling to everyone regardless.
To make any of these requests, email contact@carepathiq.org.
Children
The product is intended for clinicians, trainees and healthcare professionals. It is not directed to anyone under 18.
Changes
If we change this policy we will update the date above and, for material changes, tell account holders directly.
Contact
See also the Terms of Use.