Controlled-beta data boundary

Use only properly de-identified, structured data.

Essential Insights is available only to selected controlled-beta testers. The beta accepts one eligible, properly de-identified UTF-8 CSV that the customer is legally authorized to analyze. Public live checkout remains unavailable.

Browser-local does not mean risk-free

The Essential Insights beta is designed to process the selected CSV in the customer's browser session. Browser-local processing reduces unnecessary data transfer but does not eliminate privacy or re-identification risk and does not replace customer responsibility.

What stays in the browser

The source CSV is intended to remain in browser memory during Essential Insights analysis rather than be uploaded for server-side processing. The file is not restored after it is removed, the page is refreshed, or the browser session ends. Customers must download any approved outputs they want to keep before ending the session.

ProgramMetrics account, entitlement, transaction, service-control, and support metadata are separate from the source dataset and may be processed by the service providers described in the Privacy Policy.

Prohibited identifiers and data

Do not select, upload, paste, email, or otherwise provide any prohibited category through ProgramMetrics.

Direct identifiers

Names, identifying initials, street or full mailing addresses, email addresses, phone numbers, Social Security numbers, medical-record or patient numbers, student or government identification numbers, and full dates of birth are prohibited.

Financial and security data

Prohibited financial and security data includes financial-account or payment-card information, passwords, credentials, authentication tokens, and security secrets.

Identifiable regulated data

Identifiable health information including PHI, FERPA-protected identifiable education records, and other legally restricted identifiable data are prohibited during the controlled beta.

Structured fields only

No risky free text

Open-ended case notes, clinical notes, narratives, comments, and other free-text fields that may contain identifying information are prohibited during the controlled beta.

Indirect identification matters

Removing names alone may not properly de-identify a dataset. Customers must consider dates, geographic information, small groups, rare characteristics, and combinations of fields that could identify someone.

Anonymous identifiers

Anonymous record identifiers are allowed only when ProgramMetrics cannot use them to identify or contact an individual. Customers must keep every re-identification key outside ProgramMetrics and must not provide that key to ProgramMetrics.

Automated screening is supplemental

ProgramMetrics screens for supported format limits and patterns associated with prohibited data before and during the controlled-beta journey. Screening may miss an identifier and does not prove legal de-identification, eliminate privacy risk, or certify compliance.

Customers remain responsible for preparing the dataset, confirming authorization, verifying de-identification, and reviewing outputs before relying on them.

Security controls

The controlled beta uses secure account access, server-verified entitlement controls, browser-local analysis design, minimized support intake, restricted service roles, and a defined attempt lifecycle. ProgramMetrics also limits support submissions to non-dataset information and deletes controlled-beta support requests after no more than 14 days.

No internet service can guarantee absolute security. If a privacy or security concern is suspected, do not send the affected dataset or credentials. Use the ProgramMetrics support or contact channel with only non-sensitive details.