Initial-launch data boundary

Use only properly de-identified, structured data.

ProgramMetrics will accept only properly de-identified, structured data that the customer is legally authorized to analyze. Checkout, uploads, and customer access are currently unavailable; these rules describe the planned initial launch.

Browser-local does not mean risk-free

The private Studio design keeps supported processing in the browser by default. Browser-local processing does not eliminate privacy or re-identification risk and does not replace customer responsibility.

Prohibited identifiers and data

Do not upload, submit, or process any prohibited category through ProgramMetrics.

Direct identifiers

Names, street addresses, email addresses, phone numbers, Social Security numbers, medical-record numbers, student-identification numbers, and full dates of birth are prohibited.

Financial and security data

Prohibited financial and security data includes payment-card or banking data, passwords, credentials, authentication tokens, and security secrets.

Identifiable regulated data

Identifiable health information, FERPA-protected identifiable education records, and other legally restricted or regulated identifiable data prohibited by the Terms of Service or Privacy Policy are prohibited.

Structured fields only

No free text

Open-ended narrative fields, case notes, comments, and other free-text fields that may contain identifying information are prohibited during the initial launch.

Indirect identification matters

Removing names alone may not properly de-identify a dataset. Customers must consider dates, geographic information, small groups, rare characteristics, and combinations of fields that could identify someone.

Anonymous identifiers

Anonymous record identifiers are allowed only when ProgramMetrics cannot use them to identify or contact an individual. Customers must keep every re-identification key outside ProgramMetrics and must not provide that key to ProgramMetrics.

Customer responsibility

Customers must de-identify data before any future submission and confirm they have the legal authority to use it. ProgramMetrics does not perform legal de-identification or certify that customer data meets HIPAA, FERPA, or another regulatory standard.

Any future automated screening or customer confirmation will be a supplemental safeguard only. It will not prove de-identification, eliminate privacy risk, or replace the customer’s responsibility.

Properly authorized workforce data may be used only when it is properly de-identified, structured, and contains none of the prohibited categories above.