Legal

Privacy Policy

CodeReflex (codereflex.app)
Operated by MedRoute Technologies, LLC
San Antonio, Texas
Last Updated: June 10, 2026

This Privacy Policy describes how MedRoute Technologies, LLC ("Company," "we," "us," or "our") collects, uses, and shares information when you use the CodeReflex web application located at codereflex.app (the "Service"). This Privacy Policy is incorporated into and made part of our Terms of Use, available at codereflex.app/terms.

By creating an account or using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, do not create an account or use the Service.

The Service is intended for use by medical professionals located in the United States. We do not direct the Service to individuals outside the United States.

1. Information We Collect

1.1. Account Information.

When you create an account, we collect your email address and your subscription tier (free or paid plan). We do not collect your name, phone number, mailing address, specialty, institution, or any other profile information.

1.2. Payment Information.

If you subscribe to a paid plan, payment information (such as credit card number and billing details) is collected and processed directly by Stripe, Inc. We do not receive, access, or store your full payment card information. We may receive from Stripe a confirmation of your subscription status, transaction identifiers, and the last four digits of your payment method for account management purposes.

1.3. Clinical Text Input.

The Service allows you to enter de-identified clinical documentation text to receive E/M code suggestions and related educational output. Subject to the restrictions in Section 2, we do not store, retain, or log the clinical text you enter. Clinical text is processed in memory to generate output and is not intentionally retained after your session interaction is complete. The clinical text you enter is transmitted to our AI processing provider, Anthropic, solely to generate your output. Anthropic processes this text through its commercial API and does not use your inputs to train or improve its models. We do not warrant that transient caching inherent to standard internet and cloud infrastructure will never occur.

1.4. Support Communications.

If you contact us at info@codereflex.app, your email address and the content of your message are received and stored through Zoho, our email service provider. Subject to Section 3, do not include any protected health information, patient-identifiable information, or clinical text in any email you send to us.

1.5. Session Tokens and Tracking.

The Service uses Supabase session tokens solely to authenticate your account and maintain your logged-in session. These tokens are strictly functional and are not used for tracking, analytics, or advertising. The Service does not use cookies, pixels, web beacons, or any other tracking technologies. No third-party analytics platforms, error-tracking tools, advertising networks, or marketing tools operate on or through the Service. The only data logged in connection with your use of the Service is your email address for authentication and account management purposes. We do not collect or log IP addresses, device identifiers, browser type, operating system information, or location data.

2. Protected Health Information

2.1. PHI Prohibition.

You must not enter, upload, transmit, or otherwise submit any protected health information ("PHI") as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (45 C.F.R. Parts 160 and 164), or any patient-identifiable information, into the Service or into any communication with us (including emails to info@codereflex.app). You must de-identify all clinical text before entering it into the Service. We are not responsible for any PHI or patient-identifiable information you submit in violation of this prohibition.

2.2. Not a Business Associate.

Because the Service is designed not to receive, create, maintain, or transmit PHI, and because you are prohibited from submitting PHI under Section 2.1, we do not act as a "business associate" as defined by HIPAA. No Business Associate Agreement is offered or required under the standard use of the Service.

3. How We Use Your Information

We use the information we collect solely for the following purposes:

4. How We Share Your Information

4.1. No Selling or Renting.

We do not sell, rent, trade, or share your personal information for advertising, retargeting, or marketing purposes.

4.2. Service Providers.

We share limited information with the following third-party service providers solely as necessary to operate the Service. Each provider processes data only for the purposes described below and in accordance with its own privacy policy and terms of service.

Provider Purpose Data Shared
Supabase Authentication, database hosting Email address, subscription tier, session tokens
Netlify Web application hosting Minimal data necessary for hosting; no personal data logged
Stripe, Inc. Payment processing Payment and transaction information collected directly by Stripe
Anthropic (Claude API) AI processing to generate output De-identified clinical text entered by the user, processed in memory via Anthropic's commercial API, not stored and not used to train Anthropic's models.
Resend Transactional email delivery Email address, email content for transactional messages
Zoho Support email management Email address, content of support communications

4.3. Data Hosting.

All data processed by the Service and our core vendors is configured to remain within the United States.

4.4. Legal Requirements.

We may disclose your information if required by law, regulation, legal process, or governmental request, or if disclosure is necessary to protect the rights, property, or safety of the Company, our users, or the public, or to enforce our Terms of Use.

4.5. Business Transfers.

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you by email or by a prominent notice on the Service before your information becomes subject to a different privacy policy.

5. Data Retention and Account Deletion

5.1. Account Data.

We retain your email address and subscription tier for as long as your account is active. You may delete your account at any time from your Account page. Upon deletion, your account and all associated data under our control will be permanently removed, and any active subscription will be automatically canceled.

5.2. Stripe Transaction Records.

Stripe retains transaction records in accordance with its own privacy policy and applicable financial regulations. We do not control Stripe's retention practices. Please refer to Stripe's Privacy Policy at https://stripe.com/privacy for details.

5.3. Support Communications.

Emails you send to info@codereflex.app are stored in Zoho in accordance with Zoho's retention practices and our operational needs to resolve and document support inquiries.

6. Your Rights

6.1. Access, Correction, and Deletion.

You may request access to or correction of the personal information we hold about you by contacting us at info@codereflex.app. Because we collect only your email address and subscription tier, you may also update your email address directly through your account settings if that feature is available. Account deletion is available as described in Section 5.1. We will respond to requests within a reasonable timeframe.

6.2. State Privacy Rights.

Depending on your state of residence, you may have additional rights under applicable privacy laws, including the California Consumer Privacy Act (as amended) and the Texas Data Privacy and Security Act. These rights may include the right to know what personal information we collect, the right to access or correct it, the right to request its deletion, and the right not to be discriminated against for exercising your rights. Because we collect only your email address and subscription tier and do not sell or share personal information, the practical scope of these rights as applied to us is narrow. To exercise any of these rights, contact us at info@codereflex.app.

7. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal information from an individual under 18, we will delete that information promptly.

8. Security

We implement reasonable administrative and technical measures designed to protect the information we collect. No method of electronic transmission or storage is completely secure, and we cannot guarantee the absolute security of your information.

The Service may contain links to third-party websites or resources. This Privacy Policy applies only to the Service. We are not responsible for the privacy practices or policies of any third-party website or service.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The most current version will be posted at codereflex.app/privacy with the "Last Updated" date. If we make material changes, we will notify you by email or by posting a notice within the Service at least thirty (30) days before the effective date of the revised Privacy Policy. Your continued use of the Service after the effective date constitutes acceptance of the changes. If you do not agree, you must stop using the Service and delete your account.

11. Contact Information

If you have questions about this Privacy Policy or our data practices, please contact:

MedRoute Technologies, LLC
San Antonio, Texas
Email: info@codereflex.app

Back to top ↑