Legal
Privacy Policy
Effective date: July 10, 2026 · Praxis EMS LLC, Maryland
Praxis EMS LLC ("PraxisEMS," "we," "us," or "our") operates the PraxisEMS platform at app.praxisems.com and the website at praxisems.com (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. By using the Service, you agree to the collection and use of information as described in this policy.
1. Who This Policy Applies To
This policy applies to all users of the Service, including Program Directors, Medical Directors, Faculty, Preceptors, and Students. It applies regardless of whether you are using a paid subscription, a free trial, or early access.
2. Information We Collect
We collect information in the following categories:
Account Information
When you register, we collect your name, email address, and password. Program Directors also provide a program name, state, and optionally a phone number.
Profile Information
Users may optionally upload a profile photo and add a phone number. Students may control whether their contact information is visible to other students in the People directory.
Clinical Activity Data
The Service records clinical shift information including dates, hours, clinical site, rotation specialty, and preceptor names. Patient contacts are recorded by type and category only (e.g., age group, chief complaint type, skill performed). We do not collect, request, or store any patient-identifying information such as names, dates of birth, medical record numbers, or any other Protected Health Information (PHI).
Accreditation Data
Program Directors and staff may enter accreditation-related documentation including advisory committee meeting records, survey responses, and resource assessment notes. This data is stored and accessible only to authorized users within the same program.
Payment Information
Payments are processed by Stripe. PraxisEMS does not store, process, or have access to your credit card or bank account numbers. Stripe's privacy policy governs the handling of your payment data.
Usage Data
We collect standard server logs including IP addresses, browser type, pages visited, and timestamps. This data is used for debugging, security, and service improvement and is not linked to individual user profiles for marketing purposes.
AI Feature Inputs
When you use AI-assisted features (such as Resource Assessment Matrix analysis), the input data and any context you provide is transmitted to a third-party AI provider to generate a response. See Section 6 for details on third-party service providers.
3. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the Service
- Authenticate users and enforce role-based access controls
- Send transactional emails (enrollment approvals, rotation confirmations, survey invitations, password resets)
- Process payments and manage subscriptions
- Respond to support requests and feedback submitted through the Service
- Monitor for security incidents and abuse
- Generate aggregated, anonymized analytics to improve product features
We do not use your data to serve advertisements, build marketing profiles, or sell to third parties.
4. How We Share Your Information
We do not sell your personal information. We share information only in the following circumstances:
Within Your Program
Program Directors and authorized staff can see student activity data (shift submissions, progress, skill logs) for students enrolled in their program. This is the core function of the Service and is governed by your program's own policies.
Service Providers
We share data with the following third-party providers who help us operate the Service. Each is bound by their own privacy and security commitments:
| Provider | Purpose |
|---|---|
| Supabase | Database hosting and authentication |
| Vercel | Application hosting and deployment |
| Stripe | Payment processing |
| Resend | Transactional email delivery |
| Anthropic | AI-assisted feature processing (RAM analysis) |
Legal Requirements
We may disclose information if required to do so by law, court order, or government authority, or if we believe disclosure is necessary to protect the rights, property, or safety of PraxisEMS, our users, or the public.
Business Transfers
In the event of a merger, acquisition, or sale of assets, user information may be transferred as part of that transaction. We will notify affected users via email before their data is transferred and becomes subject to a different privacy policy.
5. HIPAA and Protected Health Information
PraxisEMS is not a HIPAA-covered entity and does not operate as a HIPAA Business Associate. The Service is designed to record clinical education activity — not patient records. Users must not enter Protected Health Information (PHI) into the Service.
If your program requires a Business Associate Agreement (BAA) for use of any software tool, PraxisEMS is not an appropriate tool for workflows that involve PHI, and you should not use it for that purpose.
6. FERPA
Student clinical logs and education records stored in PraxisEMS may be subject to the Family Educational Rights and Privacy Act (FERPA). The educational institution (program) is the FERPA-covered entity. PraxisEMS acts in the role of a "school official" with a legitimate educational interest as defined under FERPA, processing student records solely on behalf of and under the direction of the institution.
Program Directors are responsible for ensuring their use of the Service complies with FERPA and any applicable institutional policies.
7. Data Retention
- Active program data is retained for the duration of the subscription.
- Upon account termination, a 30-day data export window is provided.
- After the export window closes, data is deleted from active systems within 30 days and from backup systems within 90 days.
- Usage logs and anonymized analytics may be retained longer for security and product improvement purposes.
8. Security
We take reasonable technical and organizational measures to protect your data, including:
- Encryption in transit (TLS) and at rest
- Row-level security ensuring users can only access data within their own program
- Daily automated database backups
- Access controls and authentication via Supabase Auth
No method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate information.
- Deletion: Request deletion of your account and associated data, subject to the retention periods in Section 7.
- Portability: Request an export of your data in a machine-readable format.
- Opt-out: Opt out of non-transactional communications at any time.
California residents may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected and sold (we do not sell personal information), and the right to non-discrimination for exercising privacy rights.
To exercise any of these rights, contact us at info@praxisems.com.
10. Children's Privacy
The Service is intended for use by adults in professional educational settings. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have collected information from a minor, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you via email at least 30 days before the changes take effect. The updated policy will be posted at praxisems.com/privacy with a revised effective date.
12. Contact
For privacy-related questions, requests, or concerns, contact us at:
Praxis EMS LLC
Maryland
info@praxisems.com