Legal
Privacy policy
Effective August 13, 2026 · CuraDefend is operated by Psalm Wave LLC.
The short version
- We collect what the service needs: account details, organizational assessment answers, and application information you submit.
- We deliberately do not collect patient information, and our systems are designed to screen for and quarantine it.
- We do not sell personal information, run third-party advertising trackers, or send your assessment content to AI providers.
- Protection Check answers are processed in memory and are not stored unless you explicitly consent to share your result.
What we collect
Account data. Name, work email, hashed authentication credentials, optional two-factor enrollment, and session records (IP address and browser identifier) kept for security.
Organizational data. Your assessment intake, control answers, attestations, findings responses, and related records describe your organization’s practices. They never should — and by policy must not — contain patient information.
Application data. If you apply to the Founding Agency program, we store what you submit, with your consent, to evaluate and respond to the application.
Protection Check. Your twelve answers are scored in memory and shown to you. We store a summary only if you provide your email and check the consent box.
What we refuse to collect
CuraDefend is architected to operate without protected health information. Forms carry warnings, free-text inputs are screened for obvious patient identifiers, flagged content is quarantined and rejected, and staff are trained to refuse it during review. If we discover patient information in our systems, we will delete it and notify your organization’s administrator.
How we use information
- To provide the assessment, review, reporting, and Monitor services you request.
- To secure the platform: authentication, rate limiting, audit logging, and abuse prevention.
- To communicate with you about your account, assessment, and application.
- With consent, to send the follow-up you asked for (for example, an emailed Check result).
What we share
We do not sell personal information. We share information only with service providers necessary to run CuraDefend (such as hosting infrastructure), under contractual confidentiality; when required by law; or in a business transfer with equivalent protections. Your assessment content is never used to train AI models and is never sent to AI providers.
Retention and deletion
Issued reports are retained as immutable records for your organization. Audit logs are append-only and retained for accountability. You may request deletion of your account or organization data by contacting us; we will honor it except where retention is required for legal, security, or audit-integrity reasons, and we will tell you exactly what remains.
Your choices
- Access, correct, or export your organization’s data by request.
- Enable two-factor authentication on any account (we recommend it for all).
- Decline optional email follow-ups; consent boxes are never pre-checked.
Contact
Privacy questions: privacy@curadefend.com.