Legal

Privacy Policy

Last updated June 30, 2026

Alcyoneus LLC ("Alcyoneus," "ARA," "we," "us," or "our") operates the ARA referral management platform (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to visitors, registered accounts, and to the organizations and end-users (such as patients or referral sources) who interact with forms created through the Service.

If you have questions about this policy, contact us at [email protected] or Alcyoneus LLC, 240 W. Willow St, Chicago, IL 60614.

1. Two roles: Customers and End-Users

ARA is used by organizations ("Customers," e.g. medical practices) to collect referral information from the people they interact with ("End-Users," e.g. patients or referring offices) through customizable forms, NFC cards, and QR codes. For data that Customers collect through their own custom forms, the Customer determines what is collected and why — Alcyoneus acts as a data processor on the Customer's behalf, not as the party controlling that data. If you are an End-User submitting a referral form and have privacy questions about that specific submission, please contact the organization that provided you the form or card.

The rest of this policy also describes data we collect directly, as the platform operator, from Customer accounts and from anyone who visits our website.

2. Information We Collect

Account information. When you create an ARA account we collect your username, email address, nickname, and a securely hashed password. We never store your password in plain text.

Organization information. When you create or join an organization, we store the organization name, its owner and member accounts, and organization-level settings (such as referral follow-up scheduling and saved sources).

Referral and form data. Organizations can build custom intake forms with arbitrary fields. When an End-User submits one of these forms — including via a tap of an NFC card or scan of a QR code — we store the responses submitted, along with an identifier for the referral source. Depending on how a Customer configures its forms, this may include health-related information about patients. We do not control or review the content of Customer-defined form fields.

Billing information. Subscription payments are processed entirely by our payment processor, Stripe. We do not receive or store full credit card numbers. We do store a Stripe customer ID and subscription status so we can manage your account and billing history.

Physical card orders. If you order physical NFC referral cards, we collect a shipping name, address, and phone number, which we use to fulfill the order and, via Stripe, to calculate applicable sales tax.

Referral program data. If you were referred to ARA by another user, or you refer others, we track that relationship (a referral code and the account that referred you) to apply applicable discounts.

Cookies and session data. We use an HTTP-only session cookie to keep you signed in, and a small non-sensitive cookie to remember your last-used organization. We do not use third-party advertising or analytics cookies.

Log and support data. We keep a limited, rolling log of account actions (such as sign-ins and organization changes) for security and troubleshooting purposes.

3. How We Use Information

  • To provide, maintain, and secure the Service, including authenticating accounts and delivering referral submissions to the correct organization.
  • To process payments, manage subscriptions, and calculate applicable taxes, through Stripe.
  • To fulfill physical card orders and communicate about their status.
  • To apply referral discounts you or your referrer are eligible for.
  • To detect, investigate, and prevent fraud, abuse, or violations of our Terms of Service.
  • To respond to support requests and communicate service-related updates.

We do not sell personal information, and we do not use Customer or End-User data for advertising.

4. Who We Share Information With

We share information only as necessary to operate the Service:

  • Stripe, Inc. — processes payments, manages subscriptions, and calculates tax on card orders. Stripe receives billing contact details and, for card orders, shipping addresses. Stripe's own privacy policy governs its handling of that data.
  • Authorized Alcyoneus personnel — a small internal administrative tool, restricted to our private network and protected by a separate access token, allows authorized staff to view account, organization, and referral records for support, billing, and security purposes.
  • Legal requirements — we may disclose information if required by law, subpoena, or to protect the rights, safety, or property of Alcyoneus, our users, or the public.
  • Business transfers — if Alcyoneus is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy or a successor policy.

We do not otherwise sell, rent, or share personal information with third parties for their own marketing purposes.

5. Health Information

Because Customers can configure their own intake forms, submissions may include health-related information about patients or other End-Users. Alcyoneus is not a healthcare provider and does not independently review form content. Customers are responsible for ensuring their use of custom forms complies with applicable health privacy laws (see our Terms of Service for details on HIPAA and Business Associate Agreements).

6. Data Retention

We retain account, organization, and referral data for as long as an account or organization remains active. When an organization is deleted, its associated forms, referrals, access codes, and card orders are deleted as well. Deleting a user account does not automatically delete organizations that account owns or belongs to. Rolling activity logs are limited to recent history and are periodically pruned. You may request deletion of your account or organization data by contacting [email protected], subject to any records we are required to retain for legal, billing, or security purposes.

7. Your Choices and Rights

You may access, correct, or request deletion of your account information at any time by contacting us or, where available, through your account settings. Depending on your location, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA), including the right to know what personal information we hold about you and to request its deletion. To exercise these rights, contact [email protected]. If you are an End-User who submitted a form through a Customer organization, please also contact that organization, as they control the content of their forms.

8. Security

We use industry-standard safeguards to protect information, including encrypted password storage (bcrypt hashing), HTTPS transport encryption, HTTP-only session cookies, and security headers (via Helmet/Content Security Policy). No system is completely secure, and we cannot guarantee absolute security of information transmitted to or stored by the Service.

9. Children's Privacy

The Service is intended for business use by adults and organizations, not for use directly by children. We do not knowingly collect account information from children under 13. Referral forms may incidentally include information about minors submitted by a Customer organization (e.g., a patient's guardian); such data is governed by the Customer's own obligations as described above.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date above when we do, and for material changes we will make reasonable efforts to notify account holders.

11. Contact Us

Alcyoneus LLC
240 W. Willow St
Chicago, IL 60614
[email protected]