Privacy & Security Rules
Effective July 30, 2026.
This interim policy applies only to the informational ProgramMetrics website, visitor email inquiries, and the current inactive product presentation.
The public website currently presents product information and accepts email inquiries. Checkout, payment processing, customer file uploads, paid outputs, and Studio access are unavailable.
Initial-launch data rule
ProgramMetrics will accept only properly de-identified, structured data that the customer is legally authorized to analyze. Customers must de-identify data before any future submission and confirm their legal authority to use it.
ProgramMetrics does not perform legal de-identification or certify that customer data meets HIPAA, FERPA, or another regulatory standard.
Prohibited data
Do not provide names, street addresses, email addresses, phone numbers, Social Security numbers, medical-record numbers, student-identification numbers, full dates of birth, payment-card or banking data, passwords, credentials, authentication tokens, security secrets, identifiable health information including Protected Health Information (PHI), FERPA-protected identifiable education records, or other legally restricted or regulated identifiable data.
Open-ended narrative fields, case notes, comments, and other free-text fields that may contain identifying information are prohibited during the initial launch.
Indirect identification and anonymous identifiers
Removing names alone may not properly de-identify a dataset. Customers must consider dates, geographic information, small groups, rare characteristics, and combinations of fields that could identify someone.
Anonymous record identifiers are allowed only when ProgramMetrics cannot use them to identify or contact an individual. Customers must retain every re-identification key outside ProgramMetrics and must not provide that key to ProgramMetrics.
Planned private Studio processing
- The private Studio design keeps supported processing in the browser by default.
- The design does not create long-term ProgramMetrics customer-file storage by default.
- Browser-local processing does not eliminate privacy or re-identification risk.
- This description does not represent a currently active upload service.
Any future automated screening or checkbox confirmation will be a supplemental safeguard only. It will not prove de-identification or replace the customer’s responsibility.
Contact information and third parties
ProgramMetrics may use basic contact information supplied by a visitor to respond to inquiries and send related service communications. ProgramMetrics does not sell contact information.
Beta tester applications are processed by Formspree and delivered to ProgramMetrics. Formspree receives the information entered in the application form. Do not enter or submit spreadsheet data, record-level information, or identifiable, confidential, regulated, or sensitive information. Review Formspree's Privacy Policy for information about its data practices.
Website hosting and other disclosed third-party services may have their own privacy practices. Visitors should review those providers' policies when applicable.
Customers will remain responsible for reviewing and validating future outputs before relying on them.
This policy may be updated before checkout, uploads, paid services, or customer access are activated.
Questions can be sent to hello@programmetrics.io.