Legal

Privacy Policy

This draft describes the categories of information Harpy collects, the service providers involved, and the boundaries around feedback links, AI, and public listing data. Harpy does not accept protected health information.

Draft updated June 30, 2026 · Not final until counsel-approved

Counsel review draft. This page is a practical starting point for legal review, not legal advice. Counsel should compare it against Harpy’s actual launch posture, contracts, vendors, and state-law obligations before it is treated as final.

1. Who we are

Provider CARE Consulting LLC, doing business as Harpy (“Harpy,” “we,” “us,” or “our”), provides patient-experience tools for individual clinicians working in healthcare, dental, and allied-health settings. A clinician subscribes for her own account, and the account is hers rather than her employer’s.

This Privacy Policy describes how we collect, use, disclose, and protect information when people visit our websites, join our waitlist, create or use a Harpy account, contact us, connect a third-party service, or use a feedback link connected to a clinician.

2. Scope and clinician responsibility

This Policy covers information about the clinicians who use Harpy, website visitors, waitlist contacts, support contacts, and people who submit feedback through Harpy links. A clinician may have her own professional, employer, or state-law obligations to the people she cares for.

A clinician remains responsible for using Harpy consistently with those obligations, including any notices or permissions her setting requires before she shares a feedback link. Harpy supports those obligations as described in this Policy and applicable law.

3. Information you provide directly

We collect information clinicians provide directly to us, including account details, name, email address, role and specialty, the practice location and website she chooses to associate with her profile, phone number, waitlist submissions, support messages, and legal or security inquiries.

For paid subscriptions, our payment processor may process billing contact details, tax information, payment method tokens, transaction records, and invoice history. Harpy does not receive or store full payment-card numbers.

4. Website, device, and analytics information

When people visit Harpy websites or use the Service, we collect technical information such as IP address, device and browser type, pages viewed, referring pages, approximate location inferred from network data, timestamps, event data, diagnostics, and other information needed to understand whether the website or Service is working.

Harpy currently uses Google Analytics and Vercel Web Analytics on the marketing website. Google Analytics may use cookies, tags, or similar technologies and may collect information directly from a visitor’s browser according to Google’s own privacy terms. Vercel Web Analytics provides aggregate website-usage and performance signals.

5. Authentication and connected accounts

Harpy runs its own authentication. Accounts, credentials, and sessions are stored in Harpy’s own database rather than handed to a third-party identity vendor. We store the information needed to sign a clinician in and keep her account secure, including email address, display name, hashed credential material, session records, and sign-in security events.

If Harpy offers sign-in or a listing connection through a third-party provider and a clinician chooses it, that provider may process the sign-in request, device information, account identifiers, profile information, email address, and consent-screen interactions under its own terms and privacy notices. In that case Harpy may also store provider identifiers, authorization metadata, and tokens or token references needed to maintain the connection, and uses them only to authenticate the clinician and provide the connection she asked for.

6. Google Maps, Places, and public listing data

Harpy may use Google Maps Platform, Places, or related services to help a clinician find the public business listing where her care is reviewed and to understand public reputation signals. Those workflows may involve Google receiving search queries, map or place interactions, IP address, device information, location-derived signals, and other information described in Google’s privacy terms.

Depending on the feature enabled, Harpy may process public listing information such as place IDs, business names, addresses, phone numbers, websites, categories, hours, photos, ratings, review counts, public review text, reviewer display names, public responses, and related platform metadata. This is information the platform already publishes.

Public listing and review data can still be sensitive in context. Harpy treats it as reputation data, not as permission to disclose protected health information or to use review content in a way that violates platform rules, professional duties, or applicable law.

7. Feedback-link data and data minimization

Harpy is designed to collect less data where less data is enough. The patient feedback link is tap-only. It does not ask a patient for a name, email address, phone number, login, appointment time, or free-text narrative, and there is no field in which a patient could type one. Feedback links use opaque tokens and structured selections rather than patient identifiers.

We may collect the structured selections submitted through the feedback link, the token or link context needed to route the feedback to the correct clinician, timestamps, device and browser diagnostics, abuse-prevention signals, and limited operational logs. We do not sell patient feedback, use it to build advertising profiles, or use it to decide who is invited to leave a public review. Every patient who is asked to rate a visit is shown the same public-review option, regardless of what she selected.

8. Protected health information

Do not submit protected health information (“PHI”) to Harpy. No plan permits it. Harpy does not accept PHI, does not have a Business Associate Agreement with any vendor, and does not act as a business associate.

This is enforced by the design of the product, not only by this Policy. The patient feedback link collects no name, contact detail, login, appointment time, or free text, so there is nowhere for a patient identifier or a clinical detail to be entered. Harpy may refuse, suspend, or remove any use of the Service that appears to route PHI into it.

9. AI processing

Harpy uses OpenAI to classify review text that is already published publicly on a review platform, and to support features such as summarization or drafting. AI inputs are limited to that public text and to non-PHI product data. PHI is never sent to an AI provider, because Harpy does not hold any.

For eligible OpenAI API calls, store=false is our required implementation standard where supported. That setting is a no-store minimization control. It is not the same thing as contracted Zero Data Retention, Harpy does not have contracted Zero Data Retention, and we do not describe it as one.

10. How we use information

We use information to provide, maintain, secure, and improve Harpy; create and administer accounts; authenticate users; process billing; support users; send service, legal, and security notices; analyze aggregate usage; debug and prevent abuse; comply with law; and enforce these agreements.

We may use aggregated or de-identified information to understand product quality and website performance, provided that this information does not identify a specific person.

11. How we disclose information

We disclose information to service providers that help us operate Harpy. Today those are Vercel (website and application hosting, plus web analytics), Neon (our Postgres database), Loops (transactional email), Stripe (payments), Cloudflare Turnstile (bot mitigation), Google (analytics, maps, places, and public listing data), and OpenAI (classification of public review text). These providers may process information only to provide services to Harpy or as otherwise permitted by law and contract.

Harpy does not have a Business Associate Agreement with any of these providers, and does not need one, because Harpy does not collect or process protected health information. Email we send is an account, billing, or security notification that links back into the Service; we do not put patient content in the body of an email.

We may also disclose information when required by law, to protect the security or integrity of the Service, to prevent fraud or abuse, in connection with a business transaction, or with your direction or consent. We do not sell personal information or share it for cross-context behavioral advertising.

12. Cookies, tags, and third-party choices

Harpy websites may use cookies, scripts, tags, local storage, or similar technologies for analytics, security, session management, preference storage, and performance measurement. You can control cookies through your browser settings, though disabling some technologies may affect website or Service functionality.

Google offers its own account, advertising, and privacy controls. Those controls apply to the information Google processes as an independent provider, including Google Analytics and Google Maps Platform interactions.

13. Retention

We retain information for as long as reasonably needed to provide and secure the Service, comply with legal obligations, resolve disputes, enforce agreements, maintain security and audit records, and support ordinary business operations.

This Policy does not claim that event-level TTL deletion, rollups, dissolve behavior, durable co-occurrence matrices, or snapshot substitution are live controls unless those controls are separately implemented and evidenced.

14. Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, encrypted transport, least-privilege patterns, vendor review, operational monitoring, and separation between clinician identity, patient feedback links, and public listing data where appropriate. The most important control is what we do not collect: there is no protected health information in Harpy to protect.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We keep public security claims tied to implemented controls and available evidence. Harpy does not hold a SOC 2 report or HITRUST certification, and does not claim to be “HIPAA certified” — no such certification exists.

15. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, or port personal information, or to object to or restrict certain processing. Clinicians can contact us using the details below. Because the feedback link collects no patient identifiers, we generally cannot connect a submission to a particular patient, and so cannot look one up, correct one, or delete one on request.

Where a clinician has connected a third-party account, she can also use that provider’s own account controls to manage the connection, subject to Harpy’s ability to continue providing the requested integration.

16. Children’s privacy

Harpy is intended for use by clinicians and is not directed to children. We do not knowingly collect personal information directly from children through the Service.

17. International visitors

Harpy is operated from the United States. If you access the Service from outside the United States, information may be processed in the United States or other locations where Harpy and its service providers operate.

18. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will provide notice as required by law and update the “last updated” date above.

19. Contact

Questions about this Policy or your information can be sent to legal@harpy.rocks.