Privacy Policy

Last updated August 3, 2026 · Effective August 3, 2026

1. Who We Are and What This Policy Covers

Credivo LLC, a Delaware limited liability company (“Credivo,” “we,” “us,” or “our”), provides a web-based credentialing planning and tracking platform available at credivo.ai and any related subdomains, applications, and services (collectively, the “Service”).

This Privacy Policy explains what personal information we collect, how we use and disclose it, and the choices available to you. It applies to visitors to our website and to registered users of the Service. It does not apply to the practices of third parties we do not control, including your employer, hospital, health system, licensing board, payer, or any third-party service you connect to the Service.

By using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.

2. Important Notice Regarding Health Information

The Service is designed for clinicians and their administrative teams to organize professional licensure and credentialing tasks. The Service is not intended to receive, store, or process protected health information (“PHI”) as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”), and Credivo does not act as a covered entity or a business associate. Do not upload, enter, or transmit patient information through the Service. If you do so, you do so in violation of our Terms of Service and at your own risk.

3. Information We Collect

Information you provide directly.

  • Account information. Name, email address, password, and, if you choose to provide it, telephone number, employer, and job title.
  • Professional profile and credential information. Profession and role (for example, MD, DO, NP, or PA), state or states of practice, specialty, anticipated start date, prescribing status, Medicare and Medicaid billing status, license numbers, DEA and CDS registration numbers, National Provider Identifier, malpractice policy numbers, board certification details, education and training history, and issue and expiration dates for the foregoing.
  • Contacts and references. Names, titles, employers, email addresses, and telephone numbers of references, collaborating physicians, medical staff coordinators, insurance carriers, and similar contacts you enter into the Service.
  • Communications. Information you provide when you contact us for support, respond to a survey, or otherwise correspond with us.
  • Hospital-provided materials. If you send us a credentialing checklist or similar materials provided by your hospital or program so that we can customize your timeline, we collect the contents of those materials. You are responsible for ensuring you are permitted to share them with us.

The Service is currently offered to clinicians at no charge and is funded in part through sponsorships as described in Section 7. If we introduce paid features, payment information will be collected and processed by a third-party payment processor, we will not store full payment card numbers, and we will update this Policy before any charge is made.

Information collected automatically. IP address, browser and device type, operating system, referring and exit pages, pages viewed, features used, dates and times of access, and similar log and usage data. We and our service providers use cookies and similar technologies to collect this information. See Section 8.

Information from third parties. If you connect a third-party account to the Service, we receive information from that account as described in Section 6. We may also receive information from your employer or health system if it enrolls you in the Service.

Information about others. When you enter contact or reference information about another individual, you represent that you have the authority to provide that information to us for the purposes described in this Policy.

4. How We Use Information

We use personal information to:

  • create and administer your account and authenticate you;
  • generate, sequence, and personalize your credentialing checklist and timeline, including start-by dates and dependency mapping;
  • send deadline, renewal, and expiration reminders and other Service-related notifications;
  • provide customer support and respond to your inquiries;
  • operate, maintain, secure, troubleshoot, and improve the Service, including analyzing usage in aggregated or de-identified form;
  • detect, investigate, and prevent fraud, abuse, and violations of our Terms of Service;
  • send you product updates, newsletters, and marketing communications, subject to your right to opt out at any time; and
  • comply with legal obligations and establish, exercise, or defend legal claims.

We process this information as necessary to perform our contract with you, to pursue our legitimate business interests in operating and improving the Service, to comply with law, and, where required, with your consent.

5. Artificial Intelligence Features

Certain features of the Service, including the “Ask Credivo” assistant, may use large language models and other automated systems, including those operated by third-party providers, to generate responses and suggestions. Where they do, inputs you submit to these features, and information from your profile that is necessary to respond, may be transmitted to those providers for processing on our behalf.

Credivo does not use your credential information, documents, or assistant inputs to train its own generative artificial intelligence models. Outputs generated by these features may be inaccurate or incomplete and are provided for informational purposes only. See our Terms of Service for important limitations.

6. Third-Party Integrations and Google User Data

The Service allows you to connect your own Google Drive account so that the Service can reference and link to documents that remain stored in your Drive.

The Service requests only the drive.file scope, which limits our access to the specific files you open with or share with Credivo through the file picker. We do not request, and cannot obtain, access to the rest of your Drive. We do not store copies of your documents; we store only the links, file identifiers, and file names necessary to associate a document with a checklist item.

Credivo’s use and transfer of information received from Google APIs to any other application adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • we use Google user data only to provide and improve the user-facing features that you have requested, namely linking your credentialing checklist items to the corresponding files in your Drive;
  • we do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you;
  • we do not use Google user data for advertising; and
  • we do not allow humans to read Google user data unless we have your affirmative consent, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and de-identified.

Your files remain in your Google Drive. You may disconnect your Google account at any time through your account settings or through your Google security settings, which will revoke our access on a going-forward basis.

7. How We Disclose Information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We disclose personal information as follows:

  • Service providers. To vendors that perform services on our behalf, including our cloud hosting and database provider, email delivery, customer support, and error monitoring providers. These vendors are bound by contract to use the information only to provide services to us.
  • At your direction. To third parties you instruct us to share with, including through integrations you enable or documents you elect to share with a medical staff office or employer.
  • Sponsors. Hospitals, health systems, relocation providers, and similar partners that help fund the Service (“Sponsors”) may receive aggregated or de-identified information about use of the Service. We do not disclose your identifiable information to a Sponsor unless you enroll through that Sponsor or otherwise consent, and we will tell you at that time what will be shared. Sponsors do not receive the contents of files in your connected Google Drive.
  • Legal and safety. When we believe disclosure is required by law, subpoena, court order, or other legal process, or is reasonably necessary to protect the rights, property, or safety of Credivo, our users, or others.
  • Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of all or a portion of our assets, subject to the acquirer’s agreement to honor this Policy for information transferred.
  • Aggregated or de-identified information. We may create and disclose aggregated or de-identified information that cannot reasonably be used to identify you. We will not attempt to reidentify such information except as permitted by law.

8. Cookies and Analytics

We use cookies, local storage, and similar technologies to keep you signed in, remember your preferences, and secure the Service. Our Cookie Policy describes each cookie we use and your choices. Most browsers allow you to refuse or delete cookies, though some features of the Service may not function properly if you do.

We do not currently use third-party advertising or analytics trackers on the Service. If we adopt an analytics provider, we will update this Policy to identify it. Some browsers transmit a Global Privacy Control or similar opt-out preference signal. We treat such a signal as a valid request to opt out of any sale or sharing of personal information from that browser.

9. Retention

We retain personal information for as long as your account is active and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. Account and credential information is deleted or de-identified within 90 days following account closure, except where a longer retention period is required by law or is necessary to establish, exercise, or defend a legal claim. Backup copies are purged on our ordinary backup cycle.

10. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, access controls, and logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for all activity under your account.

11. Your Privacy Rights

All users. You may access, correct, download, or delete most of your information directly in your account settings. You may unsubscribe from marketing emails using the link in each message. You may not opt out of transactional and Service-related messages while your account is active.

California residents. Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, California residents have the right to know the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties to whom we disclose it; to request deletion; to request correction; to opt out of the sale or sharing of personal information; and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined by that statute, and we use sensitive personal information only for the purposes permitted without a right to limit. We will not discriminate against you for exercising these rights.

Other states. Residents of states with comprehensive consumer privacy statutes, including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana, have comparable rights, including a right to appeal a denial of a request. To appeal, reply to our decision or contact us at [email protected]. If your appeal is denied, you may contact your state attorney general.

How to exercise your rights. Submit a request at [email protected]. We will verify your identity using information associated with your account before fulfilling a request. An authorized agent may submit a request on your behalf with written authorization and proof of identity.

Categories of Personal Information Collected in the Preceding 12 Months

CCPA CategoryExamples CollectedBusiness PurposeDisclosed To
IdentifiersName, email, IP address, account ID, NPIAccount creation, authentication, Service deliveryService providers
Customer recordsTelephone number, employerSupport, notificationsService providers
Professional or employment informationProfession, specialty, license and DEA numbers, training history, start dateChecklist personalization and sequencingService providers
Internet or network activityPages viewed, features used, log dataAnalytics, security, product improvementService providers
Geolocation (coarse)IP-derived regionSecurity, fraud preventionService providers
InferencesDerived readiness status and timeline projectionsService deliveryNone

We do not knowingly collect biometric information, precise geolocation, or the contents of communications other than those you send us.

12. Children

The Service is intended for licensed and credentialing clinicians and their administrative teams and is not directed to individuals under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have done so, we will delete it.

13. United States Only

The Service is offered from and intended for users in the United States. We do not currently offer the Service in the European Economic Area, the United Kingdom, or Switzerland, and this Policy does not include the disclosures required by the General Data Protection Regulation.

14. Changes to This Policy

We may update this Policy. If we make material changes, we will notify you by email or through the Service before the changes take effect. The “Last Updated” date above indicates when this Policy was last revised. Your continued use of the Service after the effective date constitutes acceptance of the revised Policy.

15. Contact Us

Credivo LLC
8 The Green, Suite B
Dover, DE 19901
[email protected]

Credivo · Privacy Policy · Terms of Service · Cookie Policy · Accessibility Statement