Privacy Policy
Effective August 12, 2026.
This policy explains how ProgramMetrics handles information on the public website and in the limited Essential Insights controlled beta. The controlled beta is invite-only. Public live checkout is not available.
Information ProgramMetrics collects
ProgramMetrics collects only information needed to operate the website, evaluate beta applications, provide account access, support the controlled beta, maintain transaction and entitlement records, and respond to support requests.
- Website and beta applications: name, email address, optional organization and role, general organization type, general dataset-size category, product interests, and general workflow feedback submitted through the beta application.
- Account access: email-based authentication and the technical account/session information needed to authenticate a user and verify Essential Insights access.
- Controlled-beta transaction records: test-mode checkout, transaction, entitlement, allowance, refund-review, and related service-status metadata. The controlled beta uses Stripe test mode and does not process a real payment.
- Support: reply email, issue category, approximate time, timezone, browser information, an optional ProgramMetrics reference, and a short description. Support requests must not contain dataset contents, payment details, credentials, or other customer-level data.
Customer datasets and browser-local processing
Essential Insights is limited to one eligible, properly de-identified UTF-8 CSV that the customer is authorized to analyze. The controlled-beta application is designed to process the selected CSV in the customer's browser session. The source CSV is not intended to be uploaded to ProgramMetrics, Supabase, Stripe, Netlify, Formspree, or another vendor as part of the analysis.
The selected file is held in browser memory for the active session and is not restored after the customer removes the file, refreshes, or ends the session. Customers must download any approved outputs they want to keep before ending the session.
Automated screening is a supplemental safeguard only. It may not detect every identifier and does not certify legal de-identification.
Prohibited data
Do not select, upload, paste, email, or otherwise provide names, identifying initials, street or full mailing addresses, email addresses, telephone numbers, Social Security numbers, medical-record or patient numbers, student or government identification numbers, full dates of birth, financial-account or payment-card information, passwords, credentials, authentication tokens, security secrets, identifiable health information including PHI, FERPA-protected identifiable education records, or other legally restricted identifiable data.
Open-ended case notes, clinical notes, narratives, comments, or other free-text fields that may identify a person are prohibited during the controlled beta.
Indirect identification and anonymous identifiers
Removing names alone may not properly de-identify a dataset. Customers must consider dates, geographic information, small groups, rare characteristics, and combinations of fields that could identify someone.
Anonymous record identifiers are allowed only when ProgramMetrics cannot use them to identify or contact an individual. Customers must retain every re-identification key outside ProgramMetrics and must not provide that key to ProgramMetrics.
Service providers
ProgramMetrics uses service providers only for defined operational functions. These providers may process the limited information needed for their role:
- Formspree processes beta applications and selected public forms.
- Supabase supports controlled-beta authentication and ProgramMetrics account, transaction, entitlement, and service-control records.
- Stripe provides the controlled-beta test-mode checkout used to exercise the $49 purchase-to-access workflow. No real payment is processed during that test.
- Netlify hosts the private beta application and its server-side functions.
ProgramMetrics does not sell personal information. ProgramMetrics does not authorize these providers to receive the customer's source CSV as part of Essential Insights analysis.
Retention and deletion
ProgramMetrics seeks to retain only information needed for the purpose for which it was collected. Support submissions are retained for no more than 14 days and then deleted under the controlled-beta support process. Account, transaction, entitlement, security, and service-control records may be retained as reasonably necessary to operate the beta, maintain transaction history, investigate failures, prevent abuse, and document service actions.
ProgramMetrics does not create long-term customer-file storage for the Essential Insights source CSV in the controlled beta.
Security and incidents
ProgramMetrics uses technical and organizational safeguards appropriate to the limited beta, including restricted access, browser-local analysis design, server-verified account and entitlement controls, and minimized support intake. No internet service can guarantee absolute security.
If ProgramMetrics determines that information in its custody has been compromised, it will evaluate the incident and provide notices required by applicable law.
Customer responsibility
Customers are responsible for having authority to use their data, preparing it for the controlled beta, verifying de-identification, and reviewing outputs before relying on them. ProgramMetrics does not perform legal de-identification and does not certify HIPAA, FERPA, or other regulatory compliance.
Changes and questions
ProgramMetrics may update this policy as the beta changes. Material changes will be reflected by a new effective date before the changed practice is used.
Questions can be sent to hello@programmetrics.io.