Privacy
Last updated October 3, 2026.
What Policy Radar receives
When an assistant calls Policy Radar, the server receives the tool parameters: a hospital name or CMS Certification Number, a place name, a payment model name, a policy topic, a procedure and location for a price lookup, one or two places for a surgery-market comparison, or public specialty, program-year, state, company and payment-category filters for Open Payments research. The tool does not request your full conversation or files. Public lookup does not require an account.
Optional member connection
When member connection is enabled and you choose to link your account, a Techy Surgeon server connects to the existing membership service to check whether you have Member or Founding access. Your assistant host receives a separate plugin access token, not your website sign-in credential. Only the access tier is included in tool results; website tokens, email addresses, purchase details and other account fields are excluded.
To maintain the connection, we store encrypted website access and refresh credentials on our server. Plugin token records use hashes rather than the plaintext token. Access tokens last up to five minutes, and a connection can be renewed for no more than 30 days before you must sign in again. Expiry stops further access; physical deletion of expired records is a separate maintenance process. We do not keep a separate copy of your account profile.
Disconnect the integration in your assistant host to stop it sending tokens. When the host sends a revocation request, we invalidate the connection and remove its active encrypted credentials. Records needed to prevent token reuse may remain. Logging out of a separate website session does not necessarily disconnect the integration. Supabase, our hosting provider and the existing membership service process authentication and connection data under their respective service policies. Contact us below for help disconnecting or requesting deletion.
What it never accepts
Policy Radar holds no patient data. Requests that appear to contain patient identifiers or clinical notes are refused before any processing, and the rejected text is not stored.
What is logged
For requests handled by the public-data tools, the server records the tool name, a timestamp, response time, result count, any recorded refusal and server version. Price Atlas, procedure discovery and the newer research tools also record a coarse outcome. Price Atlas records the access tier when checked and whether the request is for the first or a later page. A random event ID identifies each log entry; it does not identify a user or session. These records do not include query text, account identifiers, email addresses or credentials. Hosting-log retention follows the hosting configuration; we do not maintain a separate product-analytics event store.
How data is used
Logs are used to keep the service running and to count usage by tool. Data is not sold and is not used to train models. Links in results carry campaign tags so that visits to techysurgeon.com from the connector can be counted in aggregate.
Sources
Answers are drawn from public CMS data files, the Federal Register and Techy Surgeon data products built from public sources.
Contact
Questions or deletion requests: hello@techysurgeon.com.