Privacy Policy

Last updated: March 13, 2026

1. What We Collect

When you sign in with Google or Microsoft, we receive your name, email address, and profile picture. We use this information solely to create and manage your CitAlert account.

We also store data you provide through the app, including organization names, facility selections, and notification preferences.

2. How We Use Your Data

  • Authenticate your account and manage sessions
  • Display your profile within your organization
  • Send notifications about citation updates and facility changes
  • Generate compliance reports you request

3. Data Storage and Security

Your data is stored on Convex, our backend and database provider. All communication between your browser and our servers is encrypted via HTTPS. All data is isolated per organization, meaning members of one organization cannot access another organization's data.

Convex handles data storage, encryption at rest, and infrastructure security under their own Privacy Policy and Terms of Service.

4. Data Sharing

We do not sell, trade, or rent your personal information to third parties. We do not use your data for advertising, retargeting, or interest-based marketing. We do not transfer your data to data brokers or information resellers.

Your data may be shared only with infrastructure providers (such as our database and hosting services) strictly as needed to operate CitAlert.

5. Data Retention and Deletion

We retain your account data for as long as your account is active. If you delete your account or leave all organizations, your personal data will be removed within 30 days. Organization data (facilities, citations) is retained for the organization and is deleted when the organization is deleted by its admin.

6. CMS Data

CitAlert retrieves publicly available data from the Centers for Medicare & Medicaid Services (CMS). This includes facility ratings, inspection results, and health deficiency citations. This data is public record and is not considered personal information.

7. Cookies

We use essential cookies for authentication and session management. We do not use tracking or advertising cookies.

8. Your Rights

You can request a copy of your stored data, correct inaccurate information, or delete your account at any time. To delete your account, leave all organizations through the app. If you need assistance, contact us through the app.

9. Changes

We may update this policy from time to time. If we make significant changes, we will notify you through the app before the changes take effect. Continued use of CitAlert after changes constitutes acceptance of the updated policy. Changes will be posted on this page with an updated date.