For plan security and compliance teams
What we hold for health plans, and for how long
For the dashboard, your plan sends us nothing. If you sponsor outreach, you hand us one contact list, and we hold it briefly under strict rules. This page shows exactly how both work.
What we hold for health plans
For the dashboard, nothing. There is no file drop, no feed, and no link to your systems.
- For the dashboard, your plan sends Plainly nothing. No feed, no file, no link to your systems.
- A free account shows counts only. A count is a number of people, never a person.
- No data about one member ever reaches you. Counts only, with or without a contract.
- Each member chose to share, in writing, and can stop it at any time.
- If you sponsor outreach, you hand us one contact list, for delivery only. It sits under a business associate agreement. It is never matched to anything else. We delete it within 45 days.
- Sponsoring changes nothing about what we hold or show you. It turns tools on for members. It buys no data.
How the data moves
Member
She chooses to share
Plainly
Counts only, never names
Your plan
For the dashboard, no arrow points back at your plan. An outreach list moves one way, is used once, and is deleted. Money moves one way too, from your plan to us, and no member data moves back.
Our published rules for small numbers
A small number can point at one person. These rules stop that from happening.
Eleven is the floor
We hide any count from one to ten. Eleven is the smallest number we ever show.
No leftover math
If hiding one number would let you work it out from the rest, we hide a second number too.
A week behind, never live
Counts are a weekly picture. Each one is at least seven days old.
Ranges for small groups
Under about fifty, we show a range, like 11 to 25. Above that, we show the number.
No filters, no drill down
You read fixed panels by state and by week. There is no search box and no way to narrow a group.
Every number is logged
We record each number we show you, what it came from, and the rule we used.
Where the floor of eleven comes from
It follows the cell size rule that Medicare research files use. Counts of one to ten are never reported.
Read the cell size rule at ResDACWho else touches this
These companies help us run Plainly. Each one works under a contract with us.
| Company | What it does | Member data |
|---|---|---|
| Vercel | Runs the website and the servers behind it. | Yes |
| Supabase | Stores member data and keeps it encrypted. | Yes |
| Anthropic | Its model reads a member letter and puts it in plain words. | Yes |
| Vapi | Runs the phone line and the voice help in the app. | Yes |
| Porkbun | Sends our reminder emails and sign in codes. | Yes |
None of them get dashboard data from your plan, because the dashboard takes nothing from your plan.
Where we stand on SOC 2
Plainly has not completed a SOC 2 audit. We will complete SOC 2 Type I before handling any member-level data under a Business Associate Agreement.
We show no security seal on this page. We have not earned one yet.
The papers
- Our privacy policy, in plain words
- How Plainly for Plans works
- Free tier terms of use
We send these terms to your plan before a free account opens. Your plan agrees not to try to work out who sits inside a count.