Legal
Privacy Policy
This policy describes what information RateScope collects through the public site and authenticated workspace, how it is used, which service providers support the platform, and how exact payer-contracted economics are stored and protected as org-confidential product data.
Effective date
August 2, 2026
Contact
Scope of this policy
This Privacy Policy applies to information collected through the RateScopepublic site and subscription platform. It covers the public benchmark preview pages, programmatic payer-rate reference pages, the subscriber account and workspace, subscription billing and commerce flows, and all related features and APIs.
This policy does not create a patient-data or clinical-record service. The platform is a benchmark information product and should not be used to submit treatment records, patient charts, insurance member numbers, or other protected health information.
Geographic scope.RateScope’s paid Service is offered only to U.S.-based organizations for use in the United States. The public website may be accessible from other countries, but RateScope does not market or offer paid subscriptions outside the United States. This availability restriction is not a representation that all processing or service-provider infrastructure is physically located in the United States.
When you submit your email address through a waitlist or notify-me form, we collect that address to send you the notification you signed up for — for example, when subscriptions open or when coverage you asked about becomes available. We do not share waitlist email addresses with third parties and do not use them for marketing beyond the notifications you requested. To remove your address from the waitlist at any time, email support@ratescope.co.
Information we collect
We collect information in the following categories:
- Account and authentication data. When you create an account, authentication is handled by Clerk. We receive account identifiers, email address, and profile metadata needed to operate the subscription service.
- Subscription and billing data. Subscription state, plan tier, billing cadence, and transaction identifiers are managed through Stripe. We do not store full payment card numbers; payment data is processed by Stripe as our payment processor. Hyboria, Inc. d/b/a RateScope is the seller and merchant.
- Practice profile data. Subscriber-provided practice information such as credential type, state, payer panels, and practice structure — used to personalize benchmark context and workspace features.
- Practice economics you save. Subscriber-entered business economics about your own practice — for example, private-pay and cash session fees, sliding-scale ranges, out-of-network expected collections, caseload and utilization figures, collections performance, and overhead. You provide these values to power your own workspace analysis. They are first-party account data: we use them to deliver your own private analyses and comparisons, they are excluded from product telemetry by the same architectural guard that protects exact payer-contracted rates, and they are never shared with, visible to, or used to generate output for any other subscriber.
- Usage and interaction data. Page views, workspace navigation, feature engagement, and related analytics events — used to measure product performance and improve the service.
- Error and diagnostic data. When the site or browser reports a failure, diagnostic information such as page URLs, browser context, and technical debugging information may be sent to our error-monitoring provider.
- Support communications. Content of emails, support requests, and other communications you send to us.
Exact payer-contracted economics — standard storage
Paid subscribers can save their exact payer-contracted rates and related economics in the RateScope workspace to compare, plan, model, and review their reimbursement position. This section describes how those exact values are stored, who can access them, and the protections that apply by default.
Storage model — org-confidential product data. Exact payer-contracted economics are stored on RateScope servers as org-confidential product data, scoped to your organization. Through the product, only authenticated and authorized members of your organization may read or write Exact Economics. Infrastructure service providers may process the data solely as needed to host, secure, and operate the Service under contractual restrictions and confidentiality obligations. No other subscriber organization can access the values through the product.
Access protections. Reading or writing exact payer-contracted economics requires an authenticated session that has satisfied multi-factor authentication (MFA). Access events are written to audit logs that record the actor, the organization scope, the timestamp, and the operation, but never the exact dollar value. Data is encrypted in transit (TLS 1.2 or higher) and at rest with industry-standard encryption.
Personnel access. RateScope personnel do not have routine support access to Exact Economics, and ordinary support is customer-mediated. Any exceptional access needed to address a security or data-integrity incident or valid legal process is limited, authorized, access-controlled, and logged.
Telemetry and log redaction. Exact payer-contracted rate values are structurally excluded from product telemetry, application logs, error-monitoring payloads, and any other diagnostic surface. The redaction is enforced by an architectural guard at the event-emission layer, not by an after-the-fact policy. The exact dollar amount of a payer-contracted rate does not appear in PostHog, Sentry, or any internal log stream.
No pooling, benchmarks, or cross-customer outputs.Under this contract epoch, we do not combine Exact Economics across subscriber organizations, use Exact Economics to produce peer benchmarks, cohort statistics, recommendations, or other cross-customer output, or use Exact Economics to generate output for another subscriber. We may use value-free operational measurements and diagnostics that do not contain Exact Economics values. RateScope does not use saved payer-contracted rates or practice-economics values to produce peer benchmarks, cross-customer outputs, or output for any other subscriber. Any future use of previously saved data for a subscriber-powered peer benchmark or other cross-customer purpose would be a material new purpose requiring a new contract epoch, conspicuous notice, and the subscriber’s affirmative reacceptance before that previously saved data could become eligible. Silence, continued use, or acceptance of editorial updates will not make previously saved data eligible.
Subpoena and legal process. We may disclose Exact Economics only to the extent required by valid legal process served on RateScope. Unless prohibited by law or an emergency makes prior notice impracticable, we will give the affected subscriber reasonable advance notice and an opportunity to seek protective relief. We will disclose only the portion we reasonably believe is legally required.
Retention.Exact payer-contracted economics are retained for as long as your subscription is active. If you cancel without requesting account deletion, they are retained for 90 days in case you reactivate, then permanently deleted. A confirmed sole-owner account deletion request is separate: that account’s exact economics are deleted and are not retained for reactivation. When a member deletes their profile from a shared organization, the organization’s exact economics remain under its surviving owners’ control and the departing member’s identity linkage is removed. You may delete individual values or the full org-confidential dataset at any time from your workspace’s Practice → Contract Rates page; deletion is permanent.
How we use information
We use information to operate and improve the service, including to:
- authenticate your account and maintain your subscription;
- process billing, manage plan upgrades and downgrades, and handle cancellations;
- personalize benchmark context based on your practice profile;
- compute and display private rate-position and practice analytics in your workspace using public TiC data, payer-contract economics, and practice economics you choose to save;
- measure which platform features, benchmark pages, and content are useful;
- improve product features, quality, and reliability using usage measurements and diagnostics that do not include your saved payer-contracted rates or practice-economics values;
- debug site failures, prevent abuse, and maintain operational logs;
- send transactional emails such as subscription confirmations, payment receipts, and support responses; and
- respond to support, deletion, correction, or legal notice requests.
Server-side telemetry never carries exact payer-contracted rates. Any exact rate you enter into the platform follows one of three persistence paths: (1) it stays in your browser for unsubmitted session use, (2) it is held in device-local storage where you have opted into local persistence, or (3) it is stored as org-confidential product data on RateScope servers under the access protections described in the Exact payer-contracted economics section. The exclusion of exact payer-contracted rates from telemetry, application logs, error-monitoring payloads, shared benchmarks, and cross-customer outputs is an architectural constraint, not merely a policy.
Service providers and systems
The platform uses third-party tools and hosted services, including:
- Vercel for site hosting, application infrastructure, and blob storage.
- Clerk for account authentication, session management, and organization features.
- Stripe for subscription billing and payment processing, as our payment processor.
- PostHog for product analytics, interaction measurement, and feature-flag support.
- Sentry for error monitoring and diagnostic telemetry.
- Resend for transactional emails such as subscription confirmations, payment receipts, and support responses.
- Vercel Blob and Supabase for operational data storage and infrastructure.
Each provider processes data only as needed to deliver the described function and is subject to its own privacy and security terms. We share with service providers only the data they need to perform their services on our behalf.
Retention and security
We retain subscriber account data — profile, practice metadata, roster, and subscription state — for as long as your subscription is active. If you cancel without requesting deletion, your account data is retained for 90 days to allow reactivation, then deleted within 30 days of the retention window closing. A confirmed account deletion request is a separate permanent process and does not use that reactivation window.
For public-site interactions, analytics events, and support communications, we retain information as reasonably needed for platform operations, troubleshooting, abuse prevention, and legal compliance.
Public TiC benchmark data is not subscriber account data and remains after account closure.
Confirmed account closure.Once we verify and complete a confirmed account closure, we delete linkable account content, including profile and workspace data, saved payer-contracted rates, practice economics, and subscriber-derived usage records. If a user leaves an organization that has another surviving owner, organization data remains under the control of the surviving organization and the departing user’s identity linkage is removed.
Restricted evidence. After closure, we may retain only the minimum information reasonably necessary to complete payment, tax, accounting, chargeback, and fraud-prevention obligations; preserve evidence relating to an existing or reasonably anticipated claim, investigation, or legal hold; enforce these Terms; or document acceptance, cancellation, and deletion events. Any retained evidence is access-restricted, separated or tombstoned where practicable, excluded from product and ordinary analytics use, and deleted when the applicable obligation or hold ends. This exception does not permit retention of saved payer-contracted rates or practice-economics values for product development, benchmarking, analytics, marketing, or commercial reuse.
We do not currently retain subscriber-derived anonymous aggregates after closure. Any future aggregate-retention process would require a separately approved legal and product basis and proof that its output is irreversible, non-linkable, and non-reconstructive.
Exact payer-contracted economics stored as org-confidential product data are governed by the separate retention rules in the Exact payer-contracted economics section above.
Deletion timing. You can request deletion of your account data at any time by emailing support@ratescope.co. We complete verified deletion requests without undue delay and ordinarily within 30 days. If applicable law permits or requires additional time, we will notify you of the extension and the reason before the initial period expires.
When a confirmed deletion completes, we retain for up to 90 days a minimal, value-free record confirming the deletion itself. This record exists only to prove the deletion was carried out and to prevent delayed or replayed provider events from re-creating deleted data. It contains no account content, no saved rates or practice economics, and no information that could re-link the deleted data to you, and it is permanently purged when the period ends. We permanently purge that record and its dependent replay-suppression fingerprints after the 90-day period.
Data is encrypted in transit (TLS 1.2 or higher) and at rest with industry-standard encryption. Access is logged and access reviews are conducted as needed. No internet-connected service can guarantee absolute security, but we use commercially reasonable measures to protect operational data.
Your choices and requests
Privacy and support requests are handled through support@ratescope.co.
- You can ask to access, correct, or delete account information associated with your subscription.
- You can delete exact payer-contracted economics stored as org-confidential product data at any time from your workspace's Practice → Contract Rates page; deletion is permanent.
- You can cancel your subscription at any time through the account portal.
- You can send support questions, legal notices, or privacy concerns to the same address.
Children and sensitive data
The service is not directed to children and is not intended to collect data from minors. We also do not want patient records, diagnosis information, treatment notes, insurance member numbers, clinical identifiers, or other protected health information submitted through the platform.
RateScope is not designed to receive patient records or PHI and does not enter into business associate agreements for the launch Service. Do not submit patient names, member identifiers, diagnosis or treatment information, clinical records, or other patient-level data.
Changes and contact
We may revise this Privacy Policy over time as the platform, analytics stack, or legal posture changes. If we make material changes, we will notify active subscribers by email before the changes take effect and post the revised version here with an updated effective date.
- Brand/operator name: RateScope
- Legal entity: Hyboria, Inc. d/b/a RateScope, a Delaware corporation
- Notice address: 8063 Challis Rd. #1054, Brighton, MI 48116
- Governing law: Delaware
Contact support@ratescope.co for privacy requests, deletion requests, support questions, or legal notices.