Privacy Policy

Effective Date: January 12, 2026 · Last Updated: September 25, 2026

1. Information We Collect

When you use Standing.io, we collect information you provide directly, including:

  • Account information (name, email address, password)
  • Clinic information (clinic name, medical director, state, and a phone number if you provide one)
  • Clinical protocol data (medication selections, dosing parameters, indications, contraindications)
  • Payment information (processed securely through our payment provider)
  • A record of your acceptance of our Terms of Service: the version accepted, the time, and the IP address it was accepted from
  • A record of each protocol-book download: the time, the account and book it was for, your IP address, your browser (the user-agent string it sends), and a fingerprint (a SHA-256 hash) of the PDF file delivered

2. How We Use Your Information

We use your information to:

  • Create and manage your account
  • Generate and format your protocol book documents
  • Process payments and deliver services
  • Keep delivery records of each download, so we can confirm what was delivered, when and to whom, and resolve disputes such as a contested charge
  • Communicate with you about your account and orders
  • Improve our services and develop new features

3. Clinical Data

Standing.io drafts standard organizational language around the clinical parameters your medical director enters, and does not provide medical advice. The clinical parameters (medication selections, dosages, routes, frequencies, indications, contraindications and discontinuation criteria) are provided by you and your medical director. Dose, route and frequency are not rewritten, except that unambiguous abbreviations on our list of error-prone abbreviations are spelled out and symbols the printed book cannot display (such as ≥, µ and arrows) are written out in words or plain characters; an abbreviation on that list that can mean more than one thing (such as MS) is flagged, never rewritten. Drafted sections may include administration and monitoring detail, such as infusion times, observation periods and monitoring intervals, that the Medical Director did not enter. The automated checks compare the drafted text only against the parameters the Medical Director entered; they do not evaluate added detail. The Medical Director must review every drafted section before adopting it.

To draft it, your clinical parameters, the medication and protocol names, and your medical director's name are sent through the Vercel AI Gateway to AI model providers under zero-data-retention routing, so the provider does not retain them, and they are not used to train AI models.

4. Data Storage & Security

Your data is stored securely using Supabase (PostgreSQL) with row-level security policies. We use industry-standard encryption for data in transit (TLS) and at rest. Access to your clinical data is restricted to your authenticated account and authorized administrators.

5. Cookies & Local Storage

We use only essential cookies: the session cookies our authentication provider (Supabase) sets to keep you signed in. We do not use advertising or analytics cookies. While you fill out the intake form, your unfinished entries (never your password) are saved in your browser's local storage on your device so a refresh doesn't lose them. Stripe sets its own cookies on its checkout pages.

6. Third-Party Services

We use the following third-party services to operate Standing.io:

  • Supabase for the database, authentication and the server functions that prepare your protocol drafts
  • Vercel for application hosting, and the Vercel AI Gateway, which routes protocol drafting to AI model providers (currently Anthropic's Claude models) under zero-data-retention routing; what it sends (your clinical parameters, the medication and protocol names, and your medical director's name) is not retained by the model provider or used to train models
  • Stripe for payment processing (when applicable)
  • Google Fonts for typefaces (your browser loads them from Google, which receives your IP address)

7. Data Retention

We retain your account and protocol data for as long as your account is active. To ask us to delete your account and its data, email privacy@getstanding.io from the email address on your account. We will confirm the request and tell you what was deleted and what was kept.

We may keep some records after a deletion request, for as long as the law requires or as we need them to establish or defend a legal claim: protocol-book revisions whose approval has been recorded, and the records of that approval; the delivery record of each download described in Section 1; payment records; and the record of your acceptance of our Terms of Service.

8. Your Rights

Each of these is handled by request: email privacy@getstanding.io from the email address on your account. You have the right to:

  • Access your personal data and receive a copy of it
  • Correct inaccurate data (you can also change your book's parameters yourself in your account)
  • Request deletion of your data, subject to the records kept as described in Section 7
  • Withdraw consent for data processing

9. Contact

For privacy inquiries or to exercise your data rights, contact us at privacy@getstanding.io.