MCMCB Pro
Legal

Privacy Policy

Last updated August 4, 2026.

The short version: we collect an email address so you can have an account, and almost nothing else. There are no ads, no trackers, no analytics scripts, and no third-party pixels anywhere on this site — not on the paid product and not on the free code pages. You can verify most of that with your browser’s network tab in about ten seconds, which is rather the point.

1. We do not want patient data

Nothing in Medical Coding & Billing Pro needs a patient record. You bring codes; we bring rules. There is no field anywhere that asks for a name, a date of birth, a chart, or an account number, and there is no integration that pulls one in.

That is a deliberate design choice rather than a promise about our diligence: we cannot leak protected health information we never receive. It also means we are not a HIPAA business associate and this is not a HIPAA-covered channel — so please do not paste chart notes into the scrubber, the notes field, or the contact form. If you do, tell us and we will delete it.

2. What we actually store

  • Your account: email address, a hash of your password (never the password), and when you signed up.
  • Your subscription: trial and renewal dates, status, payment references, and which lifecycle emails we have sent you so we do not send them twice.
  • Your work: the code lists and per-code notes you choose to save. Readable only by you — the database enforces that at the row level, not just in the application.
  • Anything you send us: an error report on a code page, or a message through the contact form, plus the address you gave us to reply to.

3. What we deliberately do not store

This section matters more than the last one, because it is the part most tools get wrong.

  • What you search for. Lookups are answered and forgotten. There is no search history, per-account or otherwise, because there is no table to put one in.
  • What you scrub. The diagnosis sets you paste into the claim check are processed in the request and never written down. The same is true of the coverage, fee, and RAF tools.
  • Your card number. It goes to our payment provider and never touches our servers.
  • Behavioural analytics. No Google Analytics, no tag manager, no session recording, no heatmaps, no advertising pixels. None of it is loaded, so none of it is collected.

4. Cookies

One kind: the session cookie that keeps you logged in. It is strictly necessary for the product to work, it is not used to track you, and it is not shared. That is why there is no cookie banner — we have nothing to ask consent for.

An anonymous visitor reading the free code pages is not given a cookie at all. Those pages are rendered without ever touching the session.

5. Who else processes it

We are a small operation and we run on other people’s infrastructure. These are all of them. We do not sell your data, we do not share it for advertising, and nobody on this list is permitted to use it for their own purposes.

Vercel · Hosting and content delivery

Request logs — IP address, URL, timestamp, user agent — kept briefly for operations and abuse prevention.

Supabase · Authentication and database

Your email address, password hash, subscription state, and the lists and notes you create. Hosted in the United States.

Lunastric (with Stripe) · Payments

Card details go to them, never to us. We receive only the outcome — paid or not — and an amount and a reference.

Resend · Email delivery

Your email address and the contents of the account emails we send you: trial reminders, renewal notices, password resets.

Cloudflare · DNS, and routing mail sent to our support address

Messages you email to us, in transit.

6. How long we keep it

Your account and your saved work stay as long as your account does — including after a subscription lapses, which is deliberate: your lists remain readable rather than being deleted out from under you. Records of payments are kept for as long as tax and accounting rules require, which is the one category we cannot delete on request. Messages you send us are kept while the matter is open and for a reasonable period afterwards, because a billing dispute six months later needs the original message.

7. Your rights

Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete your account and everything in it. If you are in the UK, the EEA, or a US state with a privacy statute, those are rights you have by law; we extend the same handling to everybody rather than sorting people by jurisdiction.

Ask through the contact form or at support@medicalcodingsoftware.org. We aim to do it within thirty days, and we do not charge for it. Deletion is permanent and we cannot undo it, so we will confirm with you once before we run it.

8. Security, honestly stated

Everything is served over HTTPS. Passwords are hashed by our auth provider and are not readable by us. Your lists and notes are protected by row-level security in the database, so a bug in the application layer is not on its own enough to expose them to another user.

We are not going to claim a certification we do not hold. There is no SOC 2 report and no penetration-test letter to send you. What we can say is that the amount of sensitive data here is small on purpose, and the most effective security measure we have taken is not collecting things.

If you find a vulnerability, please tell us at support@medicalcodingsoftware.org before telling anyone else. We will not threaten you for it.

9. Children

This is a professional tool and it is not intended for anyone under 16. We do not knowingly collect information from children.

10. Changes

If we change anything material here — a new processor, a new category of data — we will update the date at the top and email subscribers. We will not quietly start collecting something this page says we do not.