Skip to content

Privacy

No formal policy yet. Here is what the site actually does today.

Status

A reviewed privacy policy has not been published. The description below is accurate for the site as currently deployed. A formal policy needs a legal entity behind it, which does not exist yet.

If you browse without an account

The pages are static and the fonts are served from this domain rather than a font CDN. The one third-party script is Google Analytics, described below. Nothing else about you is collected and no advertising pixels are used.

If you create an account

We store your email address, and your name and company if you choose to give them. Your password is never stored — only a scrypt hash of it, which cannot be reversed back into the password.

API keys are held the same way. Only a SHA-256 of each key is stored, which is why a key is shown once at creation and never again. We count requests per account per billing period to enforce your plan's ceiling, and record which key made them so you can see it on your usage page.

An audit log records account events — signing in, creating or revoking a key, changing your password or plan — with the time and the originating IP address. It exists so that you and we can tell what happened to an account.

Cookies

Signing in sets two. One is the session itself: a random token, marked HttpOnly so scripts cannot read it, holding nothing about you — the server looks it up. The other records only that somebody is signed in, so the header can show the right link; it carries no identity. Both are removed when you sign out. Google Analytics sets its own, below.

Google Analytics

This site loads Google Analytics 4 (measurement ID G-9XLKRMTB08) on every page. It sets its own cookies and sends Google your IP address, the pages you view, and general device and referrer information. Google processes that data under its own terms, and we have no way to tie it back to your account.

There is no consent banner yet. If you would rather not be measured, browser tracking protection or an ad blocker will stop it, and we will not treat you differently for it.

Payments

None are taken. No card details are collected anywhere on this site, and no payment processor is connected. Choosing a paid plan today changes your quota and charges nothing.

Email

No mail is currently sent. Verification and password-reset tokens are generated and stored hashed, but no transport is configured, so nothing reaches your inbox yet.

The demo API

The public Explorer endpoint applies a rate limit keyed on your IP address. That value is held in memory for at most sixty seconds to count requests, and is not written to disk, logged, or shared.

What the hosting provider sees

Standard server request logs — address, timestamp, path, user agent — are handled by the hosting platform under its own terms. We do not add to them.

The data we serve

The healthcare dataset contains no personal information. It is facility-level aggregate data published by the Centers for Medicare & Medicaid Services. There is no patient-level or provider-individual data in it.

What is still missing

This is a factual description, not a reviewed policy, and it does not attempt to state a legal basis for any of the above. A formal policy needs a legal entity behind it, which does not exist yet. Payments and email are the two things described here that have not shipped; when they do, this page changes with them.

Questions: hello@vemon.io.