Legal
Privacy Policy
Last updated: June 5, 2026 — CLV Media, LLC
1. Introduction and Scope
CLV Media, LLC, a North Carolina limited liability company (“Company,” “we,” “us,” or “our”), operates CLV Intelligence at clvintelligence.com (“Platform” or “Service”). This Privacy Policy explains in precise, operational detail how we collect, process, store, disclose, and protect personal data in connection with your use of the Platform.
This Policy applies to all Users who access the Service from any jurisdiction. It is incorporated by reference into our Terms of Service. By using the Platform, you acknowledge that you have read and understood this Policy.
This Platform does not process Protected Health Information (PHI) as defined under the Health Insurance Portability and Accountability Act (HIPAA). No patient-identifiable data of any kind enters the Platform. The Platform is a professional intelligence tool used by healthcare revenue cycle professionals to monitor government-published reimbursement policy data.
2. Data Controller Information
The data controller responsible for personal data processed through the Platform is:
CLV Media, LLC
10850 Providence Rd #1325
Charlotte, NC 28277
privacy@clvintelligence.com
For data subject requests, data protection inquiries, or to contact our privacy function, use the email address above.
3. Data We Collect and How We Collect It
3.1 Account Registration Data. When you create an account, we collect your email address and a hashed password credential. Your password is hashed using industry-standard cryptographic functions by our authentication provider, Supabase, and is never stored in plaintext. We do not collect your name, employer, or specialty during registration unless you voluntarily provide them.
3.2 Subscription and Transaction Data. When you subscribe or purchase an Audit Pack, Stripe, Inc. (“Stripe”) collects and processes your payment card details in its PCI-DSS Level 1 compliant environment. The Company receives only a Stripe Customer ID (a non-sensitive tokenized reference), subscription status, tier, billing period dates, and transaction confirmation metadata. The Company does not receive, store, or have access to your full card number, CVV, or bank account information.
3.3 Platform Usage and Interaction Data. We collect interaction data to operate and improve the Service, including:
- Pages visited and navigation paths within the Platform;
- Alert records viewed, sorted, or filtered, and the filter parameters used;
- ICD-10 or HCPCS codes searched or added to your watchlist;
- Report and analytics features accessed;
- Email notifications opened and links clicked within such notifications (reported in aggregate by our email provider, Resend);
- Session duration and approximate geographic region (country/state level, derived from IP address; individual IP addresses are not persistently stored).
3.4 Technical and Device Metadata. We collect standard technical metadata associated with your sessions, including browser type and version, operating system, device category (desktop/mobile), referring URL, and Vercel-assigned request identifiers. This data is used exclusively for infrastructure performance monitoring, error diagnostics, and abuse detection. It is not used for behavioral profiling or advertising.
3.5 Referral Attribution Data. If you arrive at the Platform via a referral link containing a partner code (e.g., ?ref=CODE), that code is stored in a first-party cookie (“clv_ref”) for up to thirty (30) days. If you subscribe during that window, the referral code is passed to Stripe as subscription metadata to enable partner commission attribution. The Company validates referral codes against its partner database before attaching them to any subscription.
3.6 Voluntary Communications. If you contact us via email, submit a support request, or participate in any user research or feedback session, we retain the content of that communication and your email address for the purpose of responding to your inquiry and improving the Service.
3.7 Referral Partner Financial Data. Partners who enroll in the CLV Intelligence Partner Program and elect ACH disbursement provide banking information (account holder name, bank name, routing number, and account number) or a PayPal email address as an alternative. This data is collected solely for the purpose of disbursing earned commissions. Banking details are stored with field-level encryption and are accessible only to authorized Company personnel responsible for payment processing. Banking details are permanently deleted within thirty (30) days of a written partner account closure request submitted to partners@clvintelligence.com.
4. AI Data Routing and Processing Pipeline
This Section provides a precise technical disclosure of how the Platform’s artificial intelligence features interact with data.
4.1 What the AI Processes. The Platform employs large language models (“LLMs”) operated by OpenAI, L.L.C. (“OpenAI”) via its API to perform the following functions:
- Specialty classification of government-published policy documents (assigning a medical specialty category from a defined taxonomy);
- Signal score adjustment (refining a base algorithmic score based on contextual analysis of document text);
- Action recommendation generation (producing billing/coding action guidance based on document content);
- Public-facing editorial content generation, including specialty-specific blog posts and weekly digest summaries;
- Summary and teaser text generation for alert records.
4.2 What Is Sent to the AI. API calls to OpenAI contain exclusively the text of public-domain government documents (CMS publications, Federal Register notices, OIG alerts, MAC bulletins, etc.) and structured system prompts authored by the Company. No personally identifiable information about any User — including email addresses, usage history, watchlist codes, subscription data, or any other account data — is included in any API call to OpenAI or any other third-party AI service.
4.3 AI Data Retention and Caching. AI-generated outputs (signal score adjustments, specialty classifications, action recommendations, summaries) are computed once at the time of alert ingestion and stored as structured data fields in the Platform’s database. AI outputs are not recomputed on each User request; they are served from the database as static content. API calls to OpenAI are transient — no User data is queued, cached, or logged at the API boundary beyond what OpenAI’s own API infrastructure processes for the purpose of completing the request.
4.4 Training Data Prohibition. The Company has configured its OpenAI API integration pursuant to OpenAI’s API Data Usage Policy, which specifies that data submitted via the API is not used by OpenAI to train its foundation models. The Company does not consent to, and has not authorized, the use of any data processed through its OpenAI API calls — including government document text, system prompts, or AI-generated outputs — for the training, fine-tuning, or evaluation of any third-party AI model. Notwithstanding this configuration, Users are advised to review OpenAI’s current API Data Usage Policy at platform.openai.com for independent confirmation.
4.5 No User Prompts. The current version of the Platform does not include any feature by which Users submit free-form prompts, questions, or text inputs that are routed to an LLM. All AI processing is internal to the Platform’s data ingestion pipeline and operates on government-published document content. Should prompt-based features be introduced in the future, this Policy will be updated accordingly.
5. Proprietary Algorithmic Processing and Signal Scoring
5.1 Signal Scoring Engine. The Platform assigns each alert record a Signal Score between 0 and 100 using the Company’s proprietary multi-factor scoring algorithm. Scoring inputs include: document type and publication authority, keyword analysis of title and abstract text, presence and proximity of effective dates, document length as a proxy for regulatory significance, regulatory ID number presence, recency decay functions, and an AI-generated adjustment factor produced by the OpenAI API. The resulting score is a deterministic, rule-based output with an AI refinement component.
5.2 No User Profiling for Scoring. Signal Scores are assigned to alert records based entirely on properties of the underlying government documents. Signal Scores are not personalized to individual Users, do not incorporate User behavior data, and do not constitute a form of automated decision-making about any individual person within the meaning of GDPR Article 22 or CCPA/CPRA profiling provisions. No User-identifying data is used as an input to any scoring computation.
5.3 Specialty Classification. The Platform’s Specialty Classification Framework assigns each alert to one or more medical specialty categories from a defined, finite taxonomy. Classification is performed by the AI pipeline described in Section 4 and is applied to the government document content, not to User data.
6. Legal Basis for Processing (GDPR)
For Users located in the European Economic Area, United Kingdom, or other jurisdictions whose laws require identification of a lawful basis for processing personal data, the Company relies on the following bases:
| Processing Activity | Lawful Basis |
|---|---|
| Account creation and authentication | Contract performance (Art. 6(1)(b)) |
| Subscription billing and payment processing | Contract performance (Art. 6(1)(b)) |
| Delivering alert feeds, reports, and analytics | Contract performance (Art. 6(1)(b)) |
| Sending transactional emails (billing, account) | Contract performance (Art. 6(1)(b)) |
| Sending digest emails and newsletter content | Legitimate interests / Consent (Art. 6(1)(a)/(f)) |
| Platform usage analytics and error monitoring | Legitimate interests (Art. 6(1)(f)) |
| Fraud detection and security monitoring | Legitimate interests (Art. 6(1)(f)) |
| Referral attribution | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance and financial record retention | Legal obligation (Art. 6(1)(c)) |
7. How We Use Your Data
We use collected data for the following purposes:
- Provisioning and operating your account and subscription;
- Delivering alert feeds, analytics, reports, and other subscribed features;
- Processing payments and managing billing through Stripe;
- Sending transactional email communications, including account confirmations, subscription receipts, password resets, and billing notifications via Resend;
- Sending weekly digest emails and specialty-alert newsletters to subscribers who have not opted out;
- Detecting, investigating, and preventing fraud, abuse, and violations of our Terms of Service;
- Monitoring platform performance, diagnosing errors, and improving service reliability;
- Attributing referral commissions through our Partner Program;
- Complying with applicable legal obligations, including tax record-keeping requirements.
We do not use your data for advertising. We do not build advertising profiles. We do not sell, rent, lease, or trade personal data to any third party under any circumstances.
8. Third-Party Service Providers
The Company shares personal data with the following sub-processors and service providers, each acting under data processing obligations and their own published privacy policies:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase, Inc. | Database, authentication, and row-level security | Email address, hashed password, subscription metadata, watchlist data, usage records |
| Stripe, Inc. | Payment processing and subscription management | Email address, Stripe Customer ID; card details collected directly by Stripe |
| Resend, Inc. | Transactional and digest email delivery | Email address, first name if provided, subscription tier, email content |
| Vercel, Inc. | Platform hosting, edge network, and anonymized analytics | Anonymized request logs, page view events; no PII in analytics |
| OpenAI, L.L.C. | AI-assisted document analysis (internal pipeline only) | Public-domain government document text only; no User PII |
The Company does not share personal data with any other third parties except: (a) as required by valid legal process (court order, subpoena, or regulatory demand), in which case we will notify you to the extent permitted by law; or (b) in connection with a merger, acquisition, or sale of all or substantially all assets of the Company, in which case acquirer data handling will be disclosed in advance.
9. Cookies and Tracking Technologies
The Platform uses a minimal set of first-party cookies. No third-party advertising, tracking, or cross-site analytics cookies are deployed. A full description of each cookie, its purpose, and its duration is available in our Cookie Policy.
In summary, cookies are used for: (a) maintaining your authenticated session (Supabase); (b) referral attribution (clv_ref); (c) Stripe fraud prevention on checkout pages; and (d) theme preference storage. All session and authentication cookies are httpOnly and transmitted exclusively over HTTPS.
10. Data Retention and Account Deletion
10.1 Active Accounts. Personal data associated with active accounts is retained for the duration of your account’s existence and for a period of ninety (90) days following account closure or subscription cancellation, to enable account reinstatement and to resolve any post-termination billing disputes.
10.2 Account Deletion. You may request permanent deletion of your account and associated personal data by emailing privacy@clvintelligence.com. Upon verified receipt of a deletion request, the Company will:
- Permanently delete your email address, hashed password, watchlist, and usage records from the Supabase database within thirty (30) days;
- Request deletion of your data from Resend’s contact list;
- Retain only a Stripe Customer ID and transaction records as required for tax, accounting, and legal compliance purposes for a period of seven (7) years in accordance with applicable financial record-keeping laws. These retained records do not include payment card data.
10.3 Anonymized Aggregate Data. The Company retains anonymized, non-personally identifiable aggregate usage statistics (e.g., total alert views by specialty, subscription conversion rates, feature adoption metrics) indefinitely for service improvement and business analysis. These records cannot be used to identify any individual User.
10.4 AI-Generated Content. AI-generated alert summaries, signal scores, action recommendations, and editorial content are stored as properties of alert records — not User records — and are retained as part of the Platform’s content database. No User-identifying information is embedded in or linked to AI-generated content fields. These records persist following account deletion.
10.5 Legal Hold. Notwithstanding the foregoing, the Company reserves the right to retain data beyond the stated retention periods where such retention is necessary to comply with a legal obligation, enforce our Terms of Service, resolve disputes, or respond to valid legal process.
11. Data Security
11.1 Technical Safeguards. The Company implements the following security measures:
- Encryption in Transit: All data transmitted between your browser and the Platform is encrypted using TLS 1.2 or higher. All connections to Supabase, Stripe, Resend, and OpenAI APIs are encrypted in transit.
- Encryption at Rest: Data stored in the Supabase database is encrypted at rest using AES-256 by Supabase’s underlying cloud infrastructure (Amazon Web Services).
- Row-Level Security: The Platform’s database implements row-level security (RLS) policies that restrict each User’s access to their own data records. Service-role database access is restricted to authenticated server-side processes and is never exposed to client-side code.
- Authentication Security: Passwords are never stored in plaintext. Authentication is managed by Supabase Auth using industry-standard PKCE flow for secure token exchange.
- Access Controls: Production infrastructure credentials are stored exclusively as environment secrets in Vercel and GitHub Actions; they are never committed to source control or exposed in client-side bundles.
- API Authentication: All internal agent and cron job endpoints require a cryptographically random bearer token (CRON_SECRET). All external-facing routes require authenticated user sessions or valid Stripe webhook signatures.
11.2 Limitations. No security system is impenetrable. The Company cannot guarantee absolute security of data transmitted over the internet or stored in any system. In the event of a data breach that is reasonably likely to result in risk to your rights and freedoms, we will notify affected Users and, where required by applicable law, relevant supervisory authorities, within the timeframes required by law.
12. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data. To exercise any right, contact privacy@clvintelligence.com. We will respond within thirty (30) days of a verified request.
12.1 Rights Available to All Users:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete personal data.
- Deletion: Request deletion of your account and personal data as described in Section 10.2.
- Data Portability: Request your personal data in a structured, machine-readable format.
- Email Opt-Out: Unsubscribe from non-transactional emails (digests, newsletters, marketing) at any time via the unsubscribe link in any such email. Transactional emails (billing, account security) cannot be opted out of while your account is active.
12.2 Additional Rights Under GDPR (EEA/UK Users):
- Restriction of Processing: Request that we restrict processing of your data in certain circumstances.
- Object to Processing: Object to processing based on legitimate interests.
- Withdraw Consent: Where processing is based on consent, withdraw consent at any time without affecting the lawfulness of prior processing.
- Lodge a Complaint: Lodge a complaint with your local data protection supervisory authority.
12.3 Additional Rights Under CCPA/CPRA (California Residents):
- Right to Know: Request disclosure of the categories and specific pieces of personal information collected about you in the preceding twelve months.
- Right to Delete: Request deletion of personal information we have collected about you.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: The Company does not sell or share personal information for cross-context behavioral advertising. No opt-out is required, but you may contact us to confirm this.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
12.4 Other US State Privacy Laws. Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and other states with applicable data privacy legislation may have rights similar to those described above. Contact us to exercise your rights under applicable state law.
13. International Data Transfers
The Company is based in the United States. Personal data collected through the Platform is processed and stored on servers located in the United States (Supabase on AWS US East; Vercel US edge nodes). If you access the Service from outside the United States, your data will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
For Users in the European Economic Area or United Kingdom, such transfers are made on the basis of Standard Contractual Clauses (“SCCs”) or other appropriate transfer mechanisms as required by applicable law, pursuant to the data processing terms of our sub-processors (Supabase, Vercel, Resend, OpenAI, and Stripe), each of which maintains GDPR-compliant data transfer mechanisms.
14. Children’s Privacy
The Service is a professional B2B platform not directed at, and not intended for use by, individuals under the age of eighteen (18). We do not knowingly collect personal data from minors. If you believe that a minor has provided personal data to us, please contact privacy@clvintelligence.com and we will take prompt steps to delete such information.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, applicable law, or Platform features. The “Last updated” date at the top of this page reflects the most recent revision. Material changes — including any expansion of the categories of data collected, addition of new AI processing features, or changes to data retention periods — will be communicated to registered Users via email no fewer than fourteen (14) days before taking effect. Continued use of the Service following the effective date of a material change constitutes acceptance of the revised Policy.
16. Contact and Data Subject Requests
For all privacy inquiries, data subject access requests, deletion requests, or complaints:
CLV Media, LLC — Privacy
privacy@clvintelligence.com
We will acknowledge your request within seventy-two (72) hours and provide a substantive response within thirty (30) days. In cases of complexity or high volume, we may extend the response period by an additional thirty (30) days with notice.