Privacy Policy

This policy explains what information upgRATE collects, how we use it, and the choices you have. We've tried to write it in plain English. If anything is unclear, email privacy@upgrate.ai.

What we collect

When you create an account or use upgRATE, we collect:

  • Account information: your name, email, and sign-in credentials.
  • Practice information: NPI, EIN, license types, service locations, and in-network payers you tell us about.
  • Usage information: basic logs of when and how you use the app (pages viewed, actions taken), used to operate and improve the product.

We do not collect protected health information (PHI) about your patients. upgRATE is a contracting and benchmarking tool; it doesn't handle claims or patient records.

How we use it

  • To run the product — look up your rates, generate benchmarks and letters, track responses.
  • To send you transactional emails about your account, your negotiations, and product updates you've opted into.
  • To improve the product — aggregated, de-identified usage patterns inform what we build next.

What we don't do

  • We don't sell your data. Not to marketers, not to payers, not to anyone.
  • We don't share your practice data with any insurance company.
  • We don't use your data to train third-party AI models.

Data sources we use

Rate benchmarks come from publicly available Machine-Readable Files (MRFs) published by insurers under the CMS Transparency in Coverage rule. Provider directory data comes from NPPES, the federal NPI registry. Neither source contains information about individual patients.

Where your data lives

Practice data is stored in AWS (Aurora PostgreSQL) in the United States, encrypted at rest and in transit. Access within our team is limited to personnel who need it to operate the product.

Subprocessors

We use a small number of trusted vendors to run the service:

  • Amazon Web Services — hosting, database, and storage
  • Vercel — frontend hosting
  • Resend — transactional email delivery
  • Google — optional OAuth sign-in

Your rights

You can request a copy of your data, correct inaccuracies, or delete your account at any time by emailing privacy@upgrate.ai. Deletion is typically processed within 30 days.

Cookies

We use a small number of first-party cookies strictly required to keep you signed in and remember basic preferences. We don't use third-party advertising or cross-site tracking cookies.

Contact

Questions about this policy? privacy@upgrate.ai.