Legal

Privacy Policy

Effective date: July 10, 2026  ·  Praxis EMS LLC, Maryland

Praxis EMS LLC ("PraxisEMS," "we," "us," or "our") operates the PraxisEMS platform at app.praxisems.com and the website at praxisems.com (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. By using the Service, you agree to the collection and use of information as described in this policy.

1. Who This Policy Applies To

This policy applies to all users of the Service, including Program Directors, Medical Directors, Faculty, Preceptors, and Students. It applies regardless of whether you are using a paid subscription, a free trial, or early access.

2. Information We Collect

We collect information in the following categories:

Account Information

When you register, we collect your name, email address, and password. Program Directors also provide a program name, state, and optionally a phone number.

Profile Information

Users may optionally upload a profile photo and add a phone number. Students may control whether their contact information is visible to other students in the People directory.

Clinical Activity Data

The Service records clinical shift information including dates, hours, clinical site, rotation specialty, and preceptor names. Patient contacts are recorded by type and category only (e.g., age group, chief complaint type, skill performed). We do not collect, request, or store any patient-identifying information such as names, dates of birth, medical record numbers, or any other Protected Health Information (PHI).

Accreditation Data

Program Directors and staff may enter accreditation-related documentation including advisory committee meeting records, survey responses, and resource assessment notes. This data is stored and accessible only to authorized users within the same program.

Payment Information

Payments are processed by Stripe. PraxisEMS does not store, process, or have access to your credit card or bank account numbers. Stripe's privacy policy governs the handling of your payment data.

Usage Data

We collect standard server logs including IP addresses, browser type, pages visited, and timestamps. This data is used for debugging, security, and service improvement and is not linked to individual user profiles for marketing purposes.

AI Feature Inputs

When you use AI-assisted features (such as Resource Assessment Matrix analysis), the input data and any context you provide is transmitted to a third-party AI provider to generate a response. See Section 6 for details on third-party service providers.

3. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve the Service
  • Authenticate users and enforce role-based access controls
  • Send transactional emails (enrollment approvals, rotation confirmations, survey invitations, password resets)
  • Process payments and manage subscriptions
  • Respond to support requests and feedback submitted through the Service
  • Monitor for security incidents and abuse
  • Generate aggregated, anonymized analytics to improve product features

We do not use your data to serve advertisements, build marketing profiles, or sell to third parties.

4. How We Share Your Information

We do not sell your personal information. We share information only in the following circumstances:

Within Your Program

Program Directors and authorized staff can see student activity data (shift submissions, progress, skill logs) for students enrolled in their program. This is the core function of the Service and is governed by your program's own policies.

Service Providers

We share data with the following third-party providers who help us operate the Service. Each is bound by their own privacy and security commitments:

ProviderPurpose
SupabaseDatabase hosting and authentication
VercelApplication hosting and deployment
StripePayment processing
ResendTransactional email delivery
AnthropicAI-assisted feature processing (RAM analysis)

Legal Requirements

We may disclose information if required to do so by law, court order, or government authority, or if we believe disclosure is necessary to protect the rights, property, or safety of PraxisEMS, our users, or the public.

Business Transfers

In the event of a merger, acquisition, or sale of assets, user information may be transferred as part of that transaction. We will notify affected users via email before their data is transferred and becomes subject to a different privacy policy.

5. HIPAA and Protected Health Information

PraxisEMS is not a HIPAA-covered entity and does not operate as a HIPAA Business Associate. The Service is designed to record clinical education activity — not patient records. Users must not enter Protected Health Information (PHI) into the Service.

If your program requires a Business Associate Agreement (BAA) for use of any software tool, PraxisEMS is not an appropriate tool for workflows that involve PHI, and you should not use it for that purpose.

6. FERPA

Student clinical logs and education records stored in PraxisEMS may be subject to the Family Educational Rights and Privacy Act (FERPA). The educational institution (program) is the FERPA-covered entity. PraxisEMS acts in the role of a "school official" with a legitimate educational interest as defined under FERPA, processing student records solely on behalf of and under the direction of the institution.

Program Directors are responsible for ensuring their use of the Service complies with FERPA and any applicable institutional policies.

7. Data Retention

  • Active program data is retained for the duration of the subscription.
  • Upon account termination, a 30-day data export window is provided.
  • After the export window closes, data is deleted from active systems within 30 days and from backup systems within 90 days.
  • Usage logs and anonymized analytics may be retained longer for security and product improvement purposes.

8. Security

We take reasonable technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS) and at rest
  • Row-level security ensuring users can only access data within their own program
  • Daily automated database backups
  • Access controls and authentication via Supabase Auth

No method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

9. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate information.
  • Deletion: Request deletion of your account and associated data, subject to the retention periods in Section 7.
  • Portability: Request an export of your data in a machine-readable format.
  • Opt-out: Opt out of non-transactional communications at any time.

California residents may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected and sold (we do not sell personal information), and the right to non-discrimination for exercising privacy rights.

To exercise any of these rights, contact us at info@praxisems.com.

10. Children's Privacy

The Service is intended for use by adults in professional educational settings. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have collected information from a minor, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you via email at least 30 days before the changes take effect. The updated policy will be posted at praxisems.com/privacy with a revised effective date.

12. Contact

For privacy-related questions, requests, or concerns, contact us at:

Praxis EMS LLC
Maryland
info@praxisems.com