Effective Date: January 12, 2026 · Last Updated: September 25, 2026
When you use Standing.io, we collect information you provide directly, including:
We use your information to:
Standing.io drafts standard organizational language around the clinical parameters your medical director enters, and does not provide medical advice. The clinical parameters (medication selections, dosages, routes, frequencies, indications, contraindications and discontinuation criteria) are provided by you and your medical director. Dose, route and frequency are not rewritten, except that unambiguous abbreviations on our list of error-prone abbreviations are spelled out and symbols the printed book cannot display (such as ≥, µ and arrows) are written out in words or plain characters; an abbreviation on that list that can mean more than one thing (such as MS) is flagged, never rewritten. Drafted sections may include administration and monitoring detail, such as infusion times, observation periods and monitoring intervals, that the Medical Director did not enter. The automated checks compare the drafted text only against the parameters the Medical Director entered; they do not evaluate added detail. The Medical Director must review every drafted section before adopting it.
To draft it, your clinical parameters, the medication and protocol names, and your medical director's name are sent through the Vercel AI Gateway to AI model providers under zero-data-retention routing, so the provider does not retain them, and they are not used to train AI models.
Your data is stored securely using Supabase (PostgreSQL) with row-level security policies. We use industry-standard encryption for data in transit (TLS) and at rest. Access to your clinical data is restricted to your authenticated account and authorized administrators.
We use only essential cookies: the session cookies our authentication provider (Supabase) sets to keep you signed in. We do not use advertising or analytics cookies. While you fill out the intake form, your unfinished entries (never your password) are saved in your browser's local storage on your device so a refresh doesn't lose them. Stripe sets its own cookies on its checkout pages.
We use the following third-party services to operate Standing.io:
We retain your account and protocol data for as long as your account is active. To ask us to delete your account and its data, email privacy@getstanding.io from the email address on your account. We will confirm the request and tell you what was deleted and what was kept.
We may keep some records after a deletion request, for as long as the law requires or as we need them to establish or defend a legal claim: protocol-book revisions whose approval has been recorded, and the records of that approval; the delivery record of each download described in Section 1; payment records; and the record of your acceptance of our Terms of Service.
Each of these is handled by request: email privacy@getstanding.io from the email address on your account. You have the right to:
For privacy inquiries or to exercise your data rights, contact us at privacy@getstanding.io.