Seenward← Back to overview

Current as of August 13, 2026

Trust should be specific.

This page explains what Seenward collects, where it goes, how long it remains available, and what we deliberately refuse to process.

The boundary

  • We audit public business information, not patients.
  • We do not need clinical records, appointment details, portal access, website passwords, or payment-card numbers.
  • We do not use customer activity to build advertising profiles or sell personal information.
  • We do not promise rankings, revenue, clinical quality, legal compliance, or HIPAA certification.

Where information goes

  • Cloudflare: hosting, database storage, network protection, and Turnstile anti-bot verification.
  • Stripe: checkout, payment status, refunds, and receipts. Seenward does not store card numbers.
  • Resend: transactional messages and private report delivery.
  • Configured AI providers: OpenAI, Anthropic, Google, and xAI may receive public practice identifiers, service categories, and local benchmark questions. Contact email, payment details, and private notes are excluded from benchmark prompts.

Retention

  • Contact data is generally purged around 30 days after a terminal delivery or abandoned request.
  • Private report links expire around 30 days after delivery. Detailed prompt, response, evidence, and technical-check content is then scrubbed.
  • Security, webhook, and delivery events may remain for up to 180 days for fraud, dispute, and reliability investigation.
  • Short-lived rate-limit records are automatically removed.

Security controls

  • Private, unindexed report links with automatic expiry.
  • Signed Stripe and Resend webhooks with replay windows and duplicate-event protection.
  • Same-origin checks, anti-bot challenges, rate limits, constrained request bodies, and public-URL screening.
  • No-store responses for sensitive customer and operations endpoints.
  • Human approval before audit delivery.

These controls reduce risk; they do not make any internet service invulnerable.

Your controls

Use Manage order to cancel eligible work or request a refund. Use the contact in our Privacy Notice to request access, correction, or deletion.

Report a security concern

Email audits@seenward.com with a concise description and safe reproduction steps. Do not include patient data, passwords, or full payment information.

Seenward is operated by Civvy LLC.audits@seenward.com