← Back to WISeRly

Privacy Policy

Effective Date: August 26, 2026 | Last Updated: August 26, 2026

1. Introduction

WISeRly LLC ("WISeRly," "we," "us," or "our"), owned by the R.E. Salyer Family Revocable Living Trust, is committed to protecting the privacy and security of personal information. Clinical submission and PHI intake are currently disabled. This Privacy Policy describes our current practices regarding the information we collect through our website (wiserly.com) and our AI-powered prior authorization compliance platform (the "Service").

Current account, billing, and inquiry data remain subject to applicable privacy and security laws. If PHI services are activated after compliance approval, those services will also be governed by HIPAA, HITECH, executed BAAs, and applicable state health-data laws.

Independent status: WISeRly is not affiliated with or endorsed by CMS, is not an official WISeR participant, and provides preparation results rather than official determinations.

2. Our Role Under HIPAA

If WISeRly activates services that create, receive, maintain, or transmit PHI for a healthcare provider, WISeRly will act as a Business Associate as defined under 45 CFR §160.103 and will require an executed Business Associate Agreement ("BAA") before PHI is submitted. PHI intake remains disabled until the applicable customer and subcontractor agreements and technical safeguards are approved.

3. Information We Collect

3.1 Information You Provide

  • Account Information: Name, email, organization, job title, phone number, billing address
  • Authentication Data: Username and password stored using a salted PBKDF2 hash, never plaintext
  • Payment Information: Processed by Stripe; we do not store credit card numbers
  • Clinical Documentation: Not currently accepted; clinical upload and patient-data fields are disabled
  • Communications: Support tickets, demo requests, contact form submissions

3.2 Information Collected Automatically

  • IP address, browser type, device identifiers
  • Pages visited, features used, timestamps
  • Cookies and similar technologies (see Section 9)

3.3 Information from Third Parties

  • Stripe for account, subscription, and payment-status information

4. How We Use Information

We use information for:

  • Providing, maintaining, and improving the Service
  • Processing payments and managing subscriptions
  • Communicating about your account, security alerts, and service updates
  • Complying with legal obligations including breach notification
  • Detecting and preventing fraud, abuse, and security incidents

We do not sell personal information. PHI intake is currently disabled. If PHI services are activated, PHI will not be used for advertising or marketing.

5. How We Share Information

5.1 With Your Authorization

We share information when you direct us to, including with your designated team members and authorized integrations.

5.2 Service Providers (Subcontractors)

We engage service providers for the limited purposes described below. Clinical submission and PHI intake are currently disabled. A provider may not handle PHI unless its role is documented and any required BAA is executed and retained:

  • Replit: Current application origin and development hosting; PHI intake is disabled.
  • DigitalOcean: The owner reports traffic-routing services and a BAA request in progress. The executed BAA and complete production routing have not yet been verified in this project.
  • Stripe: Account, subscription, and payment processing. We do not send clinical documentation or patient identifiers to Stripe and do not store full payment-card numbers.

5.3 Legal Requirements

We may disclose information if required by law, court order, subpoena, or government request, or to protect the rights, property, or safety of WISeRly, our users, or others.

5.4 Business Transfers

In connection with a merger, acquisition, financing, or sale of assets, information may be transferred subject to standard confidentiality protections and continued application of this Privacy Policy or successor terms.

6. Data Retention

  • Account and billing metadata: Retained while the account is active and as reasonably needed for billing, security, dispute resolution, and legal obligations
  • Marketing and demo inquiries: Retained only as reasonably needed to respond and manage the business relationship and applicable retention requirements
  • Clinical documents and compliance scans: Not currently accepted or stored
  • Future BAA and HIPAA records: If PHI services are activated, retention will follow the executed BAA, approved retention schedule, and applicable law

7. Data Security

Current safeguards for account and billing functionality include:

  • Salted PBKDF2 password hashing
  • Hashed, expiring client and administrator sessions
  • Server-side authorization for protected billing and administrator APIs
  • Signed Stripe webhook verification and server-side subscription enforcement
  • Clinical upload, patient-name, and clinical-note submission controls disabled

No system is 100% secure. Formal HIPAA risk analysis, monitoring, incident response, vendor evidence, penetration testing, and backup validation remain pre-launch requirements before PHI intake is enabled. If PHI services are activated, breach response will follow the executed BAA and applicable law.

8. Your Rights

8.1 HIPAA Rights (Through Your Provider)

PHI intake is currently disabled. If PHI services are activated, HIPAA individual rights such as access, amendment, accounting of disclosures, restrictions, and confidential communications will generally be exercised through the healthcare provider acting as the Covered Entity, with WISeRly providing support as required by the BAA.

8.2 Account Holder Rights

  • Access and update your account information through your dashboard
  • Request a copy of personal information we hold about you
  • Request deletion of your account and associated data (subject to legal retention requirements)
  • Opt out of marketing communications via the unsubscribe link

8.3 State-Specific Rights

Residents of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with applicable privacy laws may have additional rights including the right to know, delete, correct, and opt out of certain processing. Contact us at privacy@wiserly.com to exercise these rights.

9. Cookies and Tracking

We use essential cookies for authentication and security. We do not represent that named third-party analytics products are active, and we do not use third-party advertising cookies on the platform. You can control cookies through your browser settings; disabling essential cookies will prevent the Service from functioning.

10. Children's Privacy

The Service is intended for healthcare professionals and is not directed to children under 13. We do not knowingly collect personal information directly from children. Clinical submission and PHI intake, including pediatric PHI, are currently disabled. If activated later, processing would require the applicable executed BAAs, approved safeguards, and a lawful basis established by the Covered Entity.

11. International Data Transfers

The Service is operated from the United States and is intended for US-based healthcare providers. If you access the Service from outside the US, you consent to the transfer of information to the United States.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-product notice at least 30 days before the effective date. Continued use of the Service after the effective date constitutes acceptance.

13. Contact Us

WISeRly LLC
Owned by the R.E. Salyer Family Revocable Living Trust
Developed, created, and designed by Rosemary Salyer
Privacy Officer: privacy@wiserly.com
HIPAA Compliance Officer: compliance@wiserly.com
General Inquiries: info@wiserly.com

© 2026 WISeRly LLC. All rights reserved. | Terms of Service | Disclaimers | Business Associate Agreement