What we collect, and what we do not.
Your account email, one sign-in cookie, the de-identified denials you send, the packets and decisions on your record, and the identifiers Stripe gives us after a payment.
Last updated 17 September 2026. This page says what Strategic Innovations AI collects on strategic-innovations.ai, why, who processes it, how long we keep it, and how to have it removed.
What we collect
- Account data. Your email address, a hash of your password, and whether you have confirmed the address. Passwords are never stored in clear text.
- Cookies. One cookie, si_session, keeps you signed in for up to seven days. No advertising or tracking cookies.
- What you send us. For a free or paid packet: your name, email, practice, role and the denial you paste, which must not identify a patient. For a pilot brief: the workflow you describe. For the contact form: what you write.
- Documents. Only on a managed pilot, only after a signed Business Associate Agreement is recorded, and only through the upload in your console.
- Packets and decisions. The drafts we prepare, the packets in your console, and each decision, correction and reviewer name.
- The sealed record. Each action on a pilot is an event in a chain you can verify. Events carry identifiers, statuses and fingerprints (SHA-256 digests); a denial you send is recorded as its fingerprint, not its text.
- Purchases. Stripe processes card payments. We receive the Stripe customer, session and subscription identifiers, the amount and the email used at checkout. We never see or store card numbers.
- Server logs and limits. Cloudflare records requests to the site (address, path, user agent, status) for security and capacity, and we count sign-in and request attempts per network address for up to an hour to stop abuse. We read aggregate counts; we do not build profiles.
What we do not do
- We do not sell or rent personal data.
- We do not run third-party analytics or advertising scripts on this site.
- We do not use your denials, documents, packets or decisions to train models.
- We do not send patient information by email. Our emails carry notices and links.
Health information
Free and paid packets are for de-identified denials only, and the form asks you to confirm that. A managed pilot that handles patient information runs only under a signed Business Associate Agreement, with the data sources and access named in the pilot design; documents then go through the console upload.
Who processes data for us
- Cloudflare: hosting, the database, file storage, the daily off-site copy of the record, email delivery, and Workers AI, where the model that drafts packets runs.
- Stripe: payments.
How long we keep it
- Account data: for as long as the account exists.
- Free-packet requests: the pasted denial and its draft are removed 90 days after the request. The packet in your console stays with its record.
- Paid packets, pilot records and purchase records: seven years, for tax and contract reasons, unless a pilot's Business Associate Agreement sets a shorter period.
- Server logs: for the period Cloudflare retains them.
The sealed record cannot be edited without breaking its seal, which is what lets you verify it. That is why it holds fingerprints instead of the text you send.
Your choices
Email support@strategic-innovations.ai from the address we hold to see, correct or delete what we hold about you. We answer within ten working days. Deleting an account does not delete a console bought with its email; ask for both if you want both.
Changes
If this page changes, the date at the top changes with it.