Our commitment: PathToApproval is designed from the ground up to collect the minimum data necessary to operate. We do not collect patient data. We do not sell user data. This policy explains exactly what we do and do not collect.

1. Who We Are

Auros AI LLC d/b/a PathToApproval ("Company," "we," "us," or "our") operates the PathToApproval platform at pathtoapproval.com — a prior authorization readiness and intelligence tool built for rare disease physician offices.

For privacy inquiries: contact@pathtoapproval.com

2. Scope of This Policy

This Privacy Policy applies to information collected through the PathToApproval platform, including any authenticated user accounts, usage analytics features, and communications with the Company. It does not apply to third-party websites linked from the Platform.

3. Information We Collect

3.1 Information You Provide

When you create an account, we may collect your name and professional title, practice or organization name, business email address, and state of practice. We do not collect Social Security numbers, financial account information, or payment card data.

3.2 Usage Data We Collect Automatically

We may automatically collect aggregate, de-identified usage data including which drug modules are accessed, which payer and state combinations are selected, which Platform tabs are viewed, and session frequency and duration. This data is collected at the practice level — it does not include any patient-level information.

3.3 What We Do NOT Collect

PathToApproval does not collect, store, or process any protected health information (PHI) as defined under HIPAA. Users must not enter patient names, dates of birth, insurance member IDs, diagnosis codes tied to specific patients, or any other patient-identifying information into the Platform.

We also do not collect patient medical records, insurance claim data, Social Security numbers, payment information, or precise geolocation data.

4. How We Use Your Information

We use information we collect to provide and maintain the Platform, authenticate users and manage accounts, analyze aggregate de-identified usage patterns to improve Platform content, communicate about updates and support, provide aggregate de-identified usage reports to pharmaceutical sponsor partners (no individual user data shared), and comply with legal obligations. We do not use your information for targeted advertising. We do not sell your personal information.

5. Pharmaceutical Sponsor Data Sharing

PathToApproval may share aggregate, de-identified usage data with pharmaceutical sponsor partners to demonstrate platform utilization. This data does not identify any individual user, practice, or patient. It is limited to drug module access counts, payer/state selection patterns, and session frequency at the aggregate level. No individual user data, practice-identifying data, or patient-related data is shared with sponsors under any circumstances.

6. HIPAA and Protected Health Information

PathToApproval is designed to operate as a stateless, PHI-free platform and does not function as a covered entity or business associate under HIPAA in its current architecture. Users are solely responsible for ensuring no PHI is entered. If you believe PHI has been inadvertently submitted, contact us immediately at contact@pathtoapproval.com. As features evolve, we will conduct formal HIPAA compliance assessments before implementing any features that could create PHI exposure.

7. Data Security

We implement reasonable administrative, technical, and physical safeguards including encrypted data transmission (HTTPS) and access controls limiting data access to authorized personnel. No method of internet transmission is 100% secure. We encourage users not to enter sensitive patient information into the Platform.

8. Data Retention

We retain account information for as long as your account is active or as needed to provide services. Aggregate usage analytics data is retained for up to 24 months. Upon request, we will delete your account information within 30 days, subject to legal retention obligations.

9. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or delete personal information we hold about you, and to opt out of non-essential communications. Contact us at contact@pathtoapproval.com — we will respond within 30 days.

10. Children's Privacy

The Platform is designed exclusively for licensed healthcare professionals and their authorized staff. We do not knowingly collect information from individuals under the age of 18.

11. Third-Party Links

The Platform links to third-party resources including payer websites, manufacturer hub sites, and CMS resources. This Privacy Policy does not apply to those third-party sites.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted with a revised effective date. Where appropriate, registered users will be notified by email. Continued use constitutes acceptance of the revised policy.

13. Contact Us

Email: contact@pathtoapproval.com
Auros AI LLC d/b/a PathToApproval · pathtoapproval.com