Direct identifiers
Names, street addresses, email addresses, phone numbers, Social Security numbers, medical-record numbers, student-identification numbers, and full dates of birth are prohibited.
Initial-launch data boundary
ProgramMetrics will accept only properly de-identified, structured data that the customer is legally authorized to analyze. Checkout, uploads, and customer access are currently unavailable; these rules describe the planned initial launch.
The private Studio design keeps supported processing in the browser by default. Browser-local processing does not eliminate privacy or re-identification risk and does not replace customer responsibility.
Do not upload, submit, or process any prohibited category through ProgramMetrics.
Names, street addresses, email addresses, phone numbers, Social Security numbers, medical-record numbers, student-identification numbers, and full dates of birth are prohibited.
Prohibited financial and security data includes payment-card or banking data, passwords, credentials, authentication tokens, and security secrets.
Identifiable health information, FERPA-protected identifiable education records, and other legally restricted or regulated identifiable data prohibited by the Terms of Service or Privacy Policy are prohibited.
Open-ended narrative fields, case notes, comments, and other free-text fields that may contain identifying information are prohibited during the initial launch.
Removing names alone may not properly de-identify a dataset. Customers must consider dates, geographic information, small groups, rare characteristics, and combinations of fields that could identify someone.
Anonymous record identifiers are allowed only when ProgramMetrics cannot use them to identify or contact an individual. Customers must keep every re-identification key outside ProgramMetrics and must not provide that key to ProgramMetrics.
Customers must de-identify data before any future submission and confirm they have the legal authority to use it. ProgramMetrics does not perform legal de-identification or certify that customer data meets HIPAA, FERPA, or another regulatory standard.
Any future automated screening or customer confirmation will be a supplemental safeguard only. It will not prove de-identification, eliminate privacy risk, or replace the customer’s responsibility.
Properly authorized workforce data may be used only when it is properly de-identified, structured, and contains none of the prohibited categories above.