Legal
Privacy Policy
Last updated: March 2, 2026
What We Collect
When you use WinTheP2P, we may collect the following information:
- Account information: Email address and encrypted password when you create an account.
- Usage data: Denial reasons, diagnoses, treatments, payer names, and specialties you enter into the prep tool. These are used solely to generate your P2P call scripts.
- Payment information: Processed securely by Stripe. We never store your credit card details.
- Email subscriptions: If you opt into our mailing list, we store your email address.
- Analytics: Anonymous usage analytics via Vercel Analytics (no personal data).
How We Use Your Data
- To generate P2P call preparation scripts based on your inputs.
- To save your script history if you have an account.
- To process payments and manage your subscription.
- To send occasional product updates if you subscribed to our email list.
- To improve the product based on aggregate, anonymized usage patterns.
HIPAA and Patient Data
WinTheP2P is designed to be used without any Protected Health Information (PHI). The tool works with clinical scenarios (diagnosis, treatment, denial reason) -- not patient identifiers. We strongly advise users to never enter patient names, dates of birth, medical record numbers, or any other identifying information. WinTheP2P is not a HIPAA-covered entity or business associate.
Data Storage and Security
Your data is stored securely in Supabase (hosted on AWS) with row-level security enabled. All data is encrypted in transit (TLS) and at rest. Passwords are hashed and never stored in plain text.
Third-Party Services
- Supabase: Database and authentication.
- Stripe: Payment processing.
- Vercel: Hosting and analytics.
- Google AI: Script generation (no user data is stored by the AI provider).
Your Rights
You may request to:
- Access all personal data we hold about you.
- Delete your account and all associated data.
- Unsubscribe from marketing emails at any time.
- Export your script history.
Contact us at hello@winthep2p.com for any data requests.
Cookies
We use essential cookies for authentication sessions only. We do not use tracking cookies or third-party advertising cookies.
Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to registered users.