Privacy
No patient data
Benefily takes a drug and a payer. It does not ask for, and you should not send, any patient identifier — no name, date of birth, member number or diagnosis. Nothing in this service requires protected health information, and we do not want it. We are not a HIPAA covered entity and do not act as a business associate.
What we store
- Your email address and password hash, held by our authentication provider.
- Your plan and Stripe customer reference, so entitlement can be applied.
- A SHA-256 hash of each API key. Never the key itself.
- A request log — endpoint, tool, status, timestamp — so you can inspect what your integration called, and so usage can be metered.
- For anonymous free-tier metering, a salted hash of your IP address and a daily count. The raw address is never written to storage.
Payments
Payments are processed by Stripe. Card details go directly to Stripe; we never see or store them.
Deletion
Email support@benefily.com to delete your account. We remove your profile, keys and request log. Anonymised daily counters may persist as aggregates that cannot be tied back to you.
Contact
support@benefily.com