What we collect
- Your email address. It is your account. We use it to send one-time sign-in links and messages about reports you run.
- Three profile answers, if you give them: your profession, your timeline, and your target area. They set the lens your reports are read through.
- Your searches and reports. The markets you analyze and the reports the engine produces are stored so you can return to them.
- Purchase records. If you buy a Deep Report we keep the ledger entry: what was bought, when, and its status. Card details never touch our servers (see §04).
- Technical basics. IP address and timestamps, used for rate limiting and abuse prevention, and standard server logs.
What we do not collect
- No passwords. Sign-in is a one-time email link. There is no password database to breach.
- No card numbers. Payments are handled entirely by Stripe; we see the receipt, not the card.
- No advertising trackers. No ad pixels, no cross-site tracking, no data brokers.
- No patient data. Nodexa analyzes markets, not patients. Nothing on this platform touches PHI, and it is not intended to.
How we use it
To run the Service: generate your reports, keep them available to you, enforce daily limits, fulfill purchases, answer your messages, and keep the platform safe. We also look at aggregate, de-identified usage (how many reports ran, which states are popular) to improve the product.
We do not sell personal information. We do not rent it, trade it, or share it with advertisers. If that ever changed, this policy would change first and you would be told.
Who touches the data
A small set of processors, each doing one job:
- Stripe processes payments. Your card details go to Stripe directly and stay there.
- Resend delivers our email (sign-in links, notifications).
- Google Maps Platform renders the report map and powers place lookups. Google's own terms apply to map content.
- Anthropic generates the written market narrative from aggregate report figures. No personal information about you is included in those requests.
- Amazon Web Services hosts the platform and database in the United States.
Public data sources (the federal provider registry, U.S. Census, state fee schedules) are inputs to your reports; nothing about you is sent to them.
Cookies and local storage
- One session cookie keeps you signed in. It is HttpOnly, cryptographically signed, and expires after 30 days or when you sign out.
- Local storage may briefly hold a search you typed before signing in, so it can run after you sign in. It clears itself.
If we add product analytics later (to see which features help and which confuse), this section will name the tool before it ships. There are no analytics cookies today.
Retention and deletion
Your account, reports, and purchase ledger are kept while your account exists. Sessions expire after 30 days. Sign-in links expire in about 20 minutes and are single use.
Want out? Ask through the contact form and we delete your account and reports. Purchase records may be retained where tax and accounting law requires it; everything else goes.
Security
Traffic is encrypted with TLS. Sessions are server-side and revocable, carried by a signed HttpOnly cookie. Sign-in links are single use and short-lived. There are no passwords to leak. Access to production systems is restricted to the people who operate the platform.
No system is breach-proof. If an incident affects your data, we will tell you what happened and what we did about it.
Your rights
Wherever you live, we extend the same courtesies: ask what we hold about you, ask for a correction, ask for a copy, or ask for deletion. Depending on your jurisdiction (including the EEA, UK, and California) some of these are legal rights; here they are house policy. One request through the contact form starts any of them, and we do not discriminate against accounts that exercise them.
Children
The Service is for professionals and is not directed to anyone under 18. We do not knowingly collect information from children; if we learn we have, we delete it.
Changes to this policy
When this policy changes, the version number and effective date at the top change with it. Material changes get an in-product notice or an email before they take effect.
Contact
Privacy questions and requests go through the contact form. It lands with the person who runs the platform.