Privacy Policy
Last updated September 18, 2026
Supply FlowQC helps healthcare procurement teams search a medical product catalog, compare distributor offers, and contact distributors about availability. This policy describes what we collect to do that, why we collect it, who it reaches, and how long we keep it. It covers our website, our API, and any AI assistant you connect to your account.
1. What we collect
We collect what the service needs to function, and we have tried to keep that list short enough to print in full.
| Account details | Your name, email address, and a one-way hash of your password. Optionally a phone number and time zone if you add them, and the organization your account belongs to. |
|---|---|
| Sign-in and security records | Session records, the time of your last sign-in, failed sign-in attempts, and the IP address a request arrives from. These exist to keep your account from being taken over and to enforce rate limits. |
| Connected applications | When you connect an AI assistant such as ChatGPT or Claude, we store which application you granted access to, the permissions you approved, and the access tokens issued to it. |
| Catalog searches | The search terms you send, so we can return results and diagnose failures. |
| Distributor inquiries | If you send an inquiry, we record the product, any part number and quantity, the message you wrote, the distributor it went to, and the delivery outcome. Your name and email appear in the message so the distributor can reply to you. |
2. What we do not collect
This is as important as the list above.
- We do not receive your AI conversations. When you connect an assistant, we see only the specific tool calls it makes on your behalf — a search term, or the contents of an inquiry you asked it to send. The surrounding conversation stays with your AI provider.
- We do not collect payment card numbers, government identification numbers, or health information about patients.
- We do not sell personal information, and we do not share it with advertisers or data brokers.
- We do not use your data to train machine learning models that serve other customers.
3. Why we use it
- To authenticate you and keep your account secure.
- To run catalog searches and return results.
- To transmit the inquiries you choose to send, and to keep a record of what was sent.
- To enforce rate limits and detect abuse, including limits on how many inquiries one account may send.
- To diagnose faults and keep the service running.
- To contact you about your account or a material change to this policy.
4. Who else sees it
We use a small number of service providers, each for one purpose, and none of them receives your data for their own use.
| Amazon Web Services | Hosting, databases, file storage, and delivery of outbound email. Data is processed in the United States. |
|---|---|
| Cloudflare | Turnstile, which distinguishes people from automated sign-up attempts on our registration form. |
| RoboSystems | The graph database service that stores the product catalog and executes your searches against it. |
| Distributors | Only when you send an inquiry, and only what that inquiry contains — including your name and email address, so they can reply to you directly. |
We may also disclose information where the law requires it, or where it is necessary to protect the rights and safety of our users. If our business is acquired, account data may transfer with it; we will say so before that happens.
5. How long we keep it
| Account details | Until you ask us to delete your account, after which they are removed within 30 days. |
|---|---|
| Sessions | A browser session expires after 7 days of inactivity, and no later than 30 days after you sign in. |
| Connected applications | An access token lasts one hour; the refresh token behind it lasts up to 90 days, or until you revoke the connection. Revoking takes effect immediately rather than waiting for expiry. |
| Distributor inquiries | Kept as a record of what was sent on your behalf, for as long as your account is open. A copy also exists in the recipient distributor’s inbox, which we cannot recall. |
| Security and diagnostic logs | Kept for a limited operational period and then discarded. |
6. Your choices
- Revoke a connected application at any time under Settings → Connected Apps. This immediately invalidates the tokens that application holds.
- Access, correct, or delete your account data by writing to privacy@supplyflowqc.com. We will respond within 30 days.
- Stop sending inquiries simply by not sending them. Nothing leaves our system on your behalf unless you ask for it; an assistant is instructed to confirm with you before sending, and sending requires a verified email address.
7. Security
Traffic is encrypted in transit. Passwords are stored only as one-way hashes and are never recoverable, by us or by anyone else. Access granted to an AI assistant is scoped and revocable, and each token is bound to the service that issued it, so a token taken from one connection cannot be replayed against another. No system is perfect; if a breach affects you, we will tell you.
8. Children
The service is built for procurement professionals and is not directed to children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, write to privacy@supplyflowqc.com and we will delete it.
9. Changes
If we change this policy in a way that materially affects what we collect or who sees it, we will update the date at the top of this page and notify account holders by email before the change takes effect.
10. Contact
Questions about this policy, or about data we hold on you, go to privacy@supplyflowqc.com.