MCMedicalCodingSoftware
Legal

Privacy Policy

Last updated September 11, 2026.

The short version: we collect an email address so you can have an account, we count visits to our own pages so we know which ones are worth keeping, and almost nothing else. There are no ads, no third-party trackers, no advertising pixels and no data sold or shared with anybody — not on the paid product and not on the free code pages. You can verify most of that with your browser’s network tab in about ten seconds, which is rather the point.

1. We do not want patient data

Nothing in MedicalCodingSoftware.org needs a patient record. You bring codes; we bring rules. There is no field anywhere that asks for a name, a date of birth, a chart, or an account number, and there is no integration that pulls one in.

That is a deliberate design choice rather than a promise about our diligence: we cannot leak protected health information we never receive. It also means we are not a HIPAA business associate and this is not a HIPAA-covered channel — so please do not paste chart notes into the scrubber, the notes field, or the contact form. If you do, tell us and we will delete it.

2. What we actually store

  • Your account: email address, a hash of your password (never the password), and when you signed up.
  • Your subscription: trial and renewal dates, status, payment references, and which lifecycle emails we have sent you so we do not send them twice.
  • Your work: the code lists and per-code notes you choose to save. Readable only by you — the database enforces that at the row level, not just in the application.
  • Anything you send us: an error report on a code page, a message through the contact form, or a message you choose to leave for a human in the live chat (with the conversation attached so you don’t have to repeat yourself), plus the address you gave us to reply to.
  • Your visit: which of our pages you opened, when, how long the page was actually in front of you, which site or search engine sent you, and — worked out from the connection itself — your IP address, the country and city it resolves to, and your browser and operating system. This is our own counter, running on our own servers. Section 3 says exactly how it works and what it deliberately cannot do.

3. What we deliberately do not store

This section matters more than the last one, because it is the part most tools get wrong.

  • What you search for. Lookups are answered and forgotten. There is no search history, per-account or otherwise, because there is no table to put one in.
  • What you scrub. The diagnosis sets you paste into the claim check are processed in the request and never written down. The same is true of the coverage, fee, and RAF tools.
  • What you say in the live chat. Replies are generated in the moment and the conversation is held only in your browser’s memory — close the window and it is gone. We keep no transcript. What you type is sent to Anthropic, our AI provider, to produce the answer, along with the page you asked from and, if you are signed in, your own subscription status — never anyone else’s, and never your saved lists or notes (section 5). The one thing that ever reaches our database is a message you explicitly choose to leave for a human.
  • Your card number. It goes to our payment provider and never touches our servers.
  • Third-party analytics. No Google Analytics, no tag manager, no Meta pixel, no session recording, no heatmaps, no advertising pixels, no data broker. No page on this site sends anything about you to another company behind your back; the one flow you control yourself is the live chat, which sends nothing until you press send, and then only your message and the account context described in section 3. We count our own pages ourselves, and the results go into our own database and nowhere else.

How our own visit counter works, and what it cannot do

This changed in August 2026. Until then we counted nothing at all and this page said so. We now count visits to our own pages, because running a reference site of 98,000 pages with no idea which of them anybody reads is not a sustainable way to decide what to fix. Here is precisely what that means.

  • Nothing is stored on your device. No cookie, no local storage, no session storage, no fingerprinting script. That is why there is still no cookie banner: consent rules attach to putting things on your device, and we put nothing there.
  • You are not followed between days. Repeat visits within one day are joined up using a one-way hash of a secret that we generate fresh every night and then destroy. Once it is gone, nobody — including us — can work out that yesterday’s visitor and today’s are the same person.
  • You are not followed between sites. There is nothing to follow you with. The counter runs only here, and it has no way of knowing where else you have been.
  • Your IP address is deleted on a clock. We keep it for 30 days, because operating a site occasionally requires one — an abuse case, a support question, a bot flood. After that a nightly job erases it. The country and city stay; the address does not.
  • What you type is still never recorded. The counter is sent a page address with the query string stripped off, so a lookup you ran or a code set you pasted cannot reach it even by accident. The rule in the bullets above has not been relaxed for analytics.

If you would rather not be counted at all, send the Global Privacy Control signal — most privacy-focused browsers and extensions do this for you — and write to us so we can confirm it is switched on for your request. You can also ask us to delete the visit records associated with your account under section 7; anonymous visit records cannot be located to delete, because by then they are no longer connected to anybody.

4. Cookies

One kind: the session cookie that keeps you logged in. It is strictly necessary for the product to work, it is not used to track you, and it is not shared. That is why there is no cookie banner — we have nothing to ask consent for.

An anonymous visitor reading the free code pages is not given a cookie at all. Those pages are rendered without ever touching the session, and our visit counter deliberately does not use one either — see section 3.

The sign-up, log-in and password-reset forms embed Cloudflare’s bot check (Turnstile). It runs in its own Cloudflare frame, sets nothing on our site, and is there to stop automated sign-ups — not to track you. See section 5.

5. Who else processes it

We are a small operation and we run on other people’s infrastructure. These are all of them. We do not sell your data, we do not share it for advertising, and nobody on this list is permitted to use it for their own purposes.

Vercel · Hosting and content delivery

Request logs — IP address, URL, timestamp, user agent — kept briefly for operations and abuse prevention.

Supabase · Authentication and database

Your email address, password hash, subscription state, and the lists and notes you create. Hosted in the United States.

Lunastric (with Stripe) · Payments

Card details go to them, never to us. We receive only the outcome — paid or not — and an amount and a reference.

Resend · Email delivery

Your email address and the contents of the account emails we send you: trial reminders, renewal notices, password resets.

Cloudflare · DNS, routing mail sent to our support address, and the bot check (Turnstile) on the sign-up, log-in and password-reset forms

Messages you email to us, in transit. On those three forms only, Turnstile runs in a Cloudflare frame and sees your IP address and browser characteristics to decide whether you are a person — never what you type into the form.

Anthropic · Generates the replies in the live chat

What you type into the chat window, the address of the page you asked from, and — if you are signed in — your own subscription status (so the assistant can answer questions about your trial or renewal). Sent only when you press send, kept by them briefly for abuse prevention, and not used to train their models. We keep no transcript ourselves — see section 3.

6. How long we keep it

Your account and your saved work stay as long as your account does — including after a subscription lapses, which is deliberate: your lists remain readable rather than being deleted out from under you. Records of payments are kept for as long as tax and accounting rules require, which is the one category we cannot delete on request. Messages you send us are kept while the matter is open and for a reasonable period afterwards, because a billing dispute six months later needs the original message.

Visit records are on a shorter and stricter clock. The IP address is erased after 30 days. The nightly secret that links repeat visits within a day is destroyed after two days, which is what makes older visits permanently unlinkable. The individual page-view rows are deleted after roughly 13 months, leaving only daily totals — how many people read a page on a given day, with nothing attached to anybody.

7. Your rights

Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete your account and everything in it. If you are in the UK, the EEA, or a US state with a privacy statute, those are rights you have by law; we extend the same handling to everybody rather than sorting people by jurisdiction.

Ask through the contact form or at support@medicalcodingsoftware.org. We aim to do it within thirty days, and we do not charge for it. Deletion is permanent and we cannot undo it, so we will confirm with you once before we run it.

8. Security, honestly stated

Everything is served over HTTPS. Passwords are hashed by our auth provider and are not readable by us. Your lists and notes are protected by row-level security in the database, so a bug in the application layer is not on its own enough to expose them to another user.

We are not going to claim a certification we do not hold. There is no SOC 2 report and no penetration-test letter to send you. What we can say is that the amount of sensitive data here is small on purpose, and the most effective security measure we have taken is not collecting things.

If you find a vulnerability, please tell us at support@medicalcodingsoftware.org before telling anyone else. We will not threaten you for it.

9. Children

This is a professional tool and it is not intended for anyone under 16. We do not knowingly collect information from children.

10. Changes

If we change anything material here — a new processor, a new category of data — we will update the date at the top and email subscribers. We will not quietly start collecting something this page says we do not.