This Privacy Policy sets out what information FillMap Technologies LLC (“FillMap”, “we”, “us”) collects through fillmap.app (the “Service”), the purposes for which it is used, the parties with whom it is shared, and the rights available to you.
1. Health information
FillMap performs lookups against insurance plans and medications, not against people. It does not request, collect, store, or log names, dates of birth, member or policy numbers, medical record numbers, diagnoses, or any other health information relating to you or to any other person. The Service provides no field in which such information can be entered.
FillMap does not retain the content of your searches. The number of lookups an account makes is counted, for rate limiting and abuse detection; what was looked up is not. That covers every input the Service accepts — the medication, the plan, and the ZIP code and pharmacies used to work out what a plan charges near you. The stored record of a lookup names the operation performed and nothing it was performed on. No profile of a user's medications, plans, pharmacies, location, or conditions exists.
2. Information we collect
- Account information. Email address and, where set, a password, stored as a salted hash by our authentication provider. An account contains no other data.
- Guest use. No email address or identifying information is held. A guest session is an anonymous identifier stored in the browser, used only for rate limiting and abuse protection. Clearing the browser ends the session permanently; it cannot be linked to a person or to any other session.
- Payment information. None. The Service is free; no card details are collected, no payment processor is used, and no billing records exist.
- Technical data. Authentication session records, used for security and to enforce one active session per account; per-account lookup counts, used for rate limiting and abuse detection; and standard server logs (IP address, browser type, timestamps) retained by our hosting providers for security and operations.
- Cookies. Only those necessary to maintain a signed-in session. No advertising or cross-site tracking cookies are used.
3. How we use information
- To provide, secure, and operate the Service, including authentication and the abuse controls described in these sections.
- To send account email, namely sign-in codes and password resets. Marketing email is not sent without consent.
- To troubleshoot faults, prevent abuse, and improve the Service.
4. Service providers
We share data only with the processors that run the Service:
- Supabase (database & authentication hosting, USA) — account and session data.
- Vercel (application hosting/CDN, USA) — serves the app; standard request logs.
- Brevo (transactional email, EU/USA) — your email address, to deliver verification and account emails.
We do not sell personal information, and we do not share it with advertisers or data brokers. We may disclose information if required by law, or to protect the rights, safety, and security of FillMap and its users.
5. Data retention and deletion
Account data is kept while your account is active. If you delete your account (or ask us to, from the support page in your account), we delete your account records within 30 days, except anything we must keep for legal or security reasons.
6. Security
Data is encrypted in transit (TLS) and at rest by our providers, and database access is governed by row-level security. No method of transmission or storage is entirely secure. The categories of data held are limited to those listed in Section 2; no health information and no payment details are held.
7. Your rights
You may request access to, correction of, export of, or deletion of your personal information through the support page in your account. We respond within 30 days. Additional statutory rights may apply depending on your jurisdiction, including Texas, California and the EU; verified requests are honored regardless of location.
8. Children
The Service is intended for adults aged 18 or over and is not directed at children. Information is not knowingly collected from children. An account believed to belong to a child will be removed on notice given through the support page.
9. Changes
This policy may be updated from time to time. Material changes will be notified by email or in-app notice before taking effect. The “last updated” date above reflects the current version.
10. Contact
Privacy enquiries and requests should be made through the support page in your account.