Privacy Policy
Last updated: October 1, 2026
Overview
Backwork LLC, a Grayhaven Industries company ("Backwork," "we," "us," or "our") operates this Privacy Policy, which describes how we collect, use, and share information when you use our coverage intelligence platform at backworkhealth.com (the "Service").
No PHI/ePHI in the Early Product
Backwork is currently designed for rule-level coverage intelligence, policy monitoring, and RCM workflow analysis. Do not submit protected health information or electronic protected health information ("PHI/ePHI") unless we have explicitly entered a PHI-enabled agreement with you.
This means you should not include patient names, dates of birth, member IDs, medical record numbers, claim IDs, chart notes, or uploaded patient documents in searches, Ask Backwork messages, benchmark forms, onboarding fields, or API requests. We may block inputs that appear to contain PHI/ePHI.
Information We Collect
Account Information: When you create an account, we collect your name, email address, and password. If you subscribe to a paid plan, we collect billing information through our payment processor.
Usage Data: We automatically collect information about how you use the Service, including pages visited, searches performed, features used, and interaction patterns.
Benchmark and Contact Information: When you request a coverage benchmark, we collect your work email, company, specialty or client type, common payers, monthly research-volume range, and the de-identified code-and-payer pairs you submit.
Device & Browser Data: We collect IP address, browser type, operating system, and device identifiers for security and analytics purposes.
API Usage Data: If you access our Service through the API, we log request metadata including endpoint, method, IP address, user agent, response time, and timestamps. This data is associated with your API key and used for rate limiting, abuse detection, and usage billing.
Cookies: We use essential cookies for authentication and session management, and analytics cookies to understand how the Service is used.
How We Use Your Information
- Provide, maintain, and improve the Service
- Authenticate your identity and manage your account
- Process payments and manage subscriptions
- Send service-related notifications (e.g., policy change alerts)
- Evaluate, perform, and respond to benchmark or contact requests
- Analyze usage patterns to improve product features
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
Connected AI Assistants (ChatGPT, Claude, Other MCP Clients)
You can connect an AI assistant such as ChatGPT, Claude, or another Model Context Protocol (MCP) client to Backwork. When you do, Backwork LLC, a Grayhaven Industries company receives the requests the assistant makes on your behalf. This section describes that data.
Sign-in and access: The assistant connects through OAuth. You sign in to Backwork and approve the connection on a consent screen. The connection gets a read-only scope: it can look up coverage information and read your organization's data, but it cannot change data in Backwork. Access tokens expire after 1 hour, and the connection must be approved again after 30 days.
What the assistant sends to Backwork: Only the fields a coverage question needs:
- Procedure, drug, and diagnosis codes (CPT, HCPCS, ICD-10, NDC) and code modifiers
- Payer, plan type, and line of business
- State and Medicare contractor (MAC) jurisdiction
- Site of service and provider specialty
- A date of service or as-of date for the policy
- Policy search text, such as a policy title or a treatment name
- Optionally, a coarse age band (pediatric, adult, or Medicare age) and sex, only when a policy's criteria depend on them
No patient identifiers: Backwork does not accept patient names, dates of birth, member IDs, medical record numbers, claim IDs, addresses, or other patient identifiers from an assistant. Endpoints that take claim or patient-context fields reject requests that appear to contain PHI/ePHI. Do not paste patient records into a conversation that uses Backwork.
Why we use it: We use these fields only to answer the coverage research question the assistant asked, to meter usage and enforce rate limits, and to detect abuse.
What Backwork returns: Public Medicare and commercial payer policy content, such as coverage criteria, prior authorization requirements, documentation requirements, policy changes, and links to the source documents. If you use the compliance or webhook tools, Backwork also returns your organization's own data: the review status of policy changes and the webhook endpoints your organization configured. Backwork does not return information about patients.
What we record: Each request is logged as API usage data (see "Information We Collect"): the endpoint, the request parameters listed above, the tool name, the assistant's OAuth client ID, your Backwork user ID and email address, your organization, the IP address, the user agent, and timestamps.
Retention: Request logs from a connected assistant follow the API usage log period: 90 days, after which they are purged or anonymized. Your account and the record that you approved a connection are kept while your account is active and removed within 30 days after you delete your account, as described in "Data Retention." The assistant's provider keeps your conversation under its own privacy policy, not this one.
Your controls:
- Disconnect Backwork in the assistant's connector or app settings. This revokes the tokens from that approval, and an access token already issued stops working within 1 hour.
- To revoke a connection from the Backwork side, contact support@backworkhealth.com. A connection also stops working when you leave the organization it was approved for.
- If you connected with an API key instead of signing in, revoke the key in API usage and keys.
- Delete your Backwork account to end every connection and remove your personal data as described in "Data Retention."
Third-Party Services
We use the following third-party services that may process your data:
- Clerk: Account sign-in, authentication, and organization membership
- Supabase: Database hosting
- Vercel: Application hosting, analytics, and product usage events
- Upstash: Rate limiting, which processes API key and network identifiers
- Pinecone: Semantic policy search, which processes the search text you enter
- TypeSafe: AI analysis of policy text and of the fields you submit to AI-assisted features
- Google Ads: Advertising and conversion tracking
- Stripe: Payment processing for subscriptions
Each of these services has its own privacy policy governing how they handle your data. We encourage you to review their policies.
Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS), encryption at rest, and secure access controls. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
Data Retention
We retain your account information for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention).
API usage logs, including IP addresses, are retained for 90 days for security and billing purposes, after which they are automatically purged or anonymized.
Benchmark and contact submissions may be retained in our business email systems for as long as reasonably necessary to evaluate and respond to the request, maintain business records, prevent abuse, and comply with legal obligations. You may request deletion using the contact information below.
Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Request data portability
- Withdraw consent at any time
To exercise any of these rights, please contact us at the address below.
Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at support@backworkhealth.com.