Skip to main content
xcircl
Legal

Privacy policy

How xcircl LLC collects, uses, and protects personal information across xcircl.com and the xcircl API.

1. Who we are

xcircl.com and the xcircl API are operated by xcircl LLC (“xcircl”, “we”), a data-infrastructure company. We publish coverage statistics, documentation, and an API of verified, supply-side facts about regulated-care providers. This policy explains what personal information we collect from visitors and customers, how we use it, and the choices you have.

2. Provider (supply-side) data — not patient data

The dataset we hold and serve describes businesses and providers — names, locations, licensing, certification, and commercial details sourced from public records and provider submissions. We do not collect or hold patient records, health data, or protected health information (PHI), and xcircl is not a covered entity or business associate under HIPAA.

3. Information we collect

Contact and account information. When you contact us or request an API key, we collect what you submit — typically your name, email address, organization, and message — to respond and to provision the service.

API usage logs. When you call the API, we log request metadata — the API key used, endpoint, parameters, timestamp, response status, and originating IP address — to meter usage against your plan, enforce rate limits, secure the service, and bill correctly.

Site analytics. If analytics run on this site, they run in a privacy-preserving, aggregate mode. We do not build advertising profiles of visitors.

4. How we use information

To respond to inquiries, provision and operate API access, meter and bill subscriptions, secure the service against abuse, and improve the product. We do not sell personal information.

5. Service providers

We use a small number of infrastructure providers that process data on our behalf: Vercel (site and API hosting, including request logs), Supabase (database infrastructure), and — for paid subscriptions — Stripe (payment processing). Card details are collected and processed by Stripe directly; we never see or store full card numbers. Each provider processes data under its own security and privacy commitments.

6. Data retention

We keep contact correspondence and account records for as long as needed to provide the service and meet legal and accounting obligations. API usage logs are retained for billing, security, and capacity planning, then deleted or aggregated.

7. Your rights

You may request access to, correction of, or deletion of the personal information we hold about you, and you may object to or restrict certain processing. To exercise any of these rights, email info@xcircl.com; we respond to verified requests within the timelines required by applicable law.

8. Provider record corrections

Providers listed in the dataset can request corrections to their records. Regulatory and negative fields are attributed to their source and timestamp; they reflect the source, not an editorial judgment by xcircl.

9. Changes to this policy

When we change this policy, we will update it on this page and revise the date below. Material changes to how we handle API customer data are announced to affected customers by email.

10. Contact

Questions about this policy: info@xcircl.com.

Last updated: 2026-07-12