Legal

Privacy Policy

Effective Date: June 23, 2026 · Last Updated: June 23, 2026

CertioAI (“we,” “us,” or “our”) operates the website certioai.com (the “Site”) and related services, including the PA-Alert web application and browser extension. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Site, use our services, or interact with us. By using the Site or our services, you agree to the collection and use of information in accordance with this policy.

In plain terms
No PHI ever leaves your browser — only CPT/ICD codes, payer IDs, hostnames, and timestamps.
We execute a standard HIPAA Business Associate Agreement before any account is activated.
We never sell, rent, or trade your personal or practice information.
01

Information We Collect

Information You Provide Directly

When you use our contact form, book a consultation, sign up for a subscription, or engage our services, we may collect:

  • Name, email address, and phone number
  • Company, practice, or organization name
  • Project or inquiry details
  • File attachments you choose to upload

Note: Users are instructed never to upload unprotected health information via standard contact forms.

Information Collected Automatically

When you visit the Site, we may automatically collect your IP address, browser type and version, pages visited and time spent, referring website, and device type and operating system.

Information from Third-Party Services

If you interact with us through third-party platforms (LinkedIn, X/Twitter, scheduling tools), we may receive basic profile information you have made publicly available.

02

How We Use Your Information

We use the information we collect to:

  • Respond to your inquiries and scheduling requests
  • Deliver coaching, technical optimization, and automation workflows
  • Send transactional communications related to services you have requested
  • Maintain, optimize, and update our local-first PA-Alert architecture
  • Comply with legal obligations

We do not sell, rent, or trade your personal or practice information to third parties for marketing purposes.

03

How We Share Your Information

We may share your information only in these limited circumstances:

Service Providers. With trusted vendors who assist in operating our Site or delivering infrastructure services (e.g., secure web hosting, encrypted email, scheduling tools), bound by strict confidentiality and data-protection obligations.
Legal Requirements. When required by law, regulation, legal process, or enforceable governmental request.
Business Transfers. In connection with a merger, acquisition, or sale of assets, with explicit notice provided to you.
With Your Consent. When you have given us explicit permission.
04

PA-Alert Widget & Extension

Local-first by design
Local-First Processing. PA-Alert runs natively inside your authorized browser session. It evaluates on-screen text components to identify billing codes (CPT and ICD) and payer identifiers in real time.
Data Restrictions. No patient names, complete dates of birth, medical record numbers (MRNs), or other direct Protected Health Information (PHI) are ever scraped, logged, or transmitted by the active interface overlay during daily operation.
The Data Logging Minimum. The extension only transmits structured, PHI-free metadata elements (CPT codes, ICD codes, payer identifiers, hostnames, and timestamps) to our secure servers to accurately confirm localized Illinois routing paths.

4.1  HIPAA Compliance & Business Associate Agreements

CertioAI operates as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). For independent medical groups deploying our active web widget or utilizing our historical claims-intelligence pipelines:

  • Standard BAA executed up front. CertioAI provides and executes a standard HIPAA-compliant Business Associate Agreement with all clinical practices prior to account activation or installation.
  • De-Identification Pipeline. Any backend ingestion of claim outcomes, billing exports, or X12 835 remittance data is processed through an automated, client-side de-identification utility that strips all 18 HIPAA identifiers before any metadata touches our network — so no raw PHI is aggregated, stored, or processed on CertioAI servers.
05

Cookies and Tracking Technologies

Essential Cookies. Required for standard site functionality, including secure session management.
Analytics Cookies. To understand general visitor traffic trends (e.g., Google Analytics). These collect aggregated, anonymized usage data.

You can control cookies through your individual browser settings. Disabling cookies may affect specific interactive site capabilities. We do not use tracking cookies for advertising or retargeting.

06

Data Retention

We retain practice metadata and communication records only as long as necessary to fulfill the operational purposes described in this policy, unless a longer retention period is required by law. Contact form submissions and consultation records are retained for up to 3 years after your last interaction with us, unless you request earlier deletion.

07

Data Security

We implement strict administrative, technical, and physical safeguards — including AES-256 encryption at rest and TLS 1.3 in transit — designed to protect operational data. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

08

Your Rights

All Users

  • Request access to the professional data we hold about your practice
  • Request correction of inaccurate operational information
  • Request structural deletion of your professional record
  • Opt out of non-essential communications

To exercise any of these rights, contact us at hello@certioai.com.

California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to Know the categories and specific pieces of personal information we have collected.
  • Right to Delete your personal information, subject to certain exceptions.
  • Right to Opt-Out of Sale. We do not sell personal information, so no opt-out is necessary.
  • Right to Non-Discrimination for exercising your privacy rights.

To submit a verifiable consumer request, email hello@certioai.com with the subject line “CCPA Request.”

European Economic Area / UK Residents (GDPR)

If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation:

  • Legal Basis. We process your data based on consent, contract performance, and legitimate interests.
  • Right to access, rectify, erase, restrict, or port your personal data
  • Right to withdraw consent at any time without affecting prior processing
  • Right to lodge a complaint with your local data protection authority

Contact us at hello@certioai.com to exercise these rights.

09

Third-Party Links

The Site may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.

10

Children’s Privacy

Our Site and services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 16, we will take steps to delete it promptly.

11

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last Updated” date. Your continued use of the Site after changes are posted constitutes your acceptance of the revised policy.

12

Contact Us

If you have questions about this Privacy Policy, your data-handling boundaries, or to execute a standard BAA, contact us at:

CertioAI
Chicago, IL