Privacy Policy
A plain-English account of what data we collect, where it goes, and what rights you have over it. Each section starts with a summary.
The short version
- ✓We collect only what is needed to operate the directory — your account details, professional profile, and licenses.
- ✓We never sell your personal data to third parties.
- ✓Two features send data to external cloud services: Profile Auto-Fill and compatibility matching. We are transparent about exactly what is sent and to whom.
- ✓License numbers and names are checked against publicly accessible US government databases (NPI Registry, OIG LEIE).
- ✓Transactional emails are delivered via Proton Mail.
- ✓You can request access to, correction of, or deletion of your data at any time.
Who we are
KetCon is responsible for your data.
The data controller for personal data processed through this platform is KetCon, operated in the United States. Questions or requests regarding your data can be sent to privacy@ketcon.us.
If you are located in the European Economic Area (EEA) or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR, described below. If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA).
What data we collect and why
Account info, your professional profile, and license details — nothing more.
We collect and store the following categories of personal data:
- —Account data: Email address, hashed password, account role (doctor or therapist), email verification status, and account creation timestamp. Lawful basis: performance of a contract (providing access to the platform).
- —Professional profile: Name, professional bio, specialties, states of practice, collaboration style, session format, years of experience, profile photo, and website URL. Lawful basis: performance of a contract; you provide this voluntarily to appear in the directory.
- —License information: License type, license number, issuing state, and verification status. Lawful basis: legitimate interests (ensuring the directory lists only credentialled professionals; public safety).
- —Transactional records: Email delivery logs for account verification and license status notifications. Lawful basis: performance of a contract.
We do not collect browsing behaviour, click-stream data, IP addresses, device fingerprints, or any form of advertising identifiers. We do not use analytics trackers or third-party tracking scripts.
Third-party services that receive your data
Five external services are used. We list exactly what each receives and when.
KetCon does not share your data with advertisers, data brokers, or marketing platforms. The following operational services receive limited personal data as necessary to provide specific features. Each acts as a data processor on our behalf, except where noted.
Jina AI (r.jina.ai) — Jina AI GmbH, Germany
- Purpose
- Converts the professional website URL you provide into plain text so that your profile fields can be pre-populated.
- Data sent
- The URL you supply and the publicly accessible text content of that webpage and up to five of its subpages.
- When
- Only when you actively use the Profile Auto-Fill feature. Never used otherwise.
OpenRouter Inc. (openrouter.ai) — United States
- Purpose
- Routes structured text to a large language model for two purposes: (1) extracting profile fields from website content during Profile Auto-Fill, and (2) computing compatibility scores between professional profiles for the matching feature.
- Data sent
- Profile Auto-Fill: scraped website text. Matching: your professional profile fields (name excluded from matching prompts — only specialty, collaboration style, philosophy, states, and role are used).
- When
- Profile Auto-Fill: only when you initiate an extraction. Matching: periodically in the background once your profile is published, to keep match scores current.
Google LLC — Google Gemini 2.0 Flash model, United States
- Purpose
- The large language model that processes the text sent via OpenRouter. Google acts as a sub-processor.
- Data sent
- Same as OpenRouter above. Per Google's API data usage policies, data submitted via the API is not used to train Google's models by default.
- When
- Same as OpenRouter above.
CMS NPI Registry — U.S. Department of Health & Human Services
- Purpose
- Verifies that the NPI number and name on your profile match the publicly maintained National Provider Identifier registry.
- Data sent
- Your first name, last name, and NPI number. This is a public government database.
- When
- When you submit a license for verification and during periodic re-checks of already-verified licenses.
OIG LEIE — U.S. Office of Inspector General
- Purpose
- Confirms that a provider is not listed on the federal List of Excluded Individuals/Entities, which would prohibit them from participating in federally funded healthcare programmes.
- Data sent
- Your name and NPI number, checked against a publicly maintained exclusion list.
- When
- Same as NPI Registry above.
Proton AG — ProtonMail, Switzerland
- Purpose
- Delivery of transactional emails: account verification links and license status notifications.
- Data sent
- Your email address and the content of the notification (e.g. 'your license has been verified'). No profile or license data beyond what is stated in the email itself.
- When
- On account registration and when your license verification status changes.
We do not use any other third-party services. All other data processing is operated directly by KetCon.
Automated processing and matching
Compatibility scores are generated by an automated system, not a human. They are informational only.
The compatibility matching feature uses automated processing — specifically, a large language model accessed via OpenRouter — to compare professional profiles and generate a numeric compatibility score and a short explanatory summary. The factors considered include: stated specialties, collaboration style, therapeutic philosophy, states of practice, and professional role.
These scores are informational starting points, not clinical endorsements. No automated decision with legal or similarly significant effect is made about you. The matching output does not determine whether your profile is listed, removed, or restricted — those decisions, if they arise, involve human review.
Under GDPR Article 22, you have the right to object to automated processing that produces legal or significant effects. As described above, our automated matching does not meet that threshold, but you may contact us at any time to request that your profile be excluded from the matching feature.
International data transfers
KetCon operates in the United States. Data may be transferred between jurisdictions.
KetCon operates in the United States. If you are located in the European Economic Area, United Kingdom, or another jurisdiction with data transfer restrictions, please be aware that the following services process data in the United States:
- —OpenRouter Inc.
- —Google LLC (Gemini API)
- —CMS NPI Registry
- —OIG LEIE
Jina AI GmbH is headquartered in Germany and operates within the EEA. Proton AG is headquartered in Switzerland, which the European Commission has recognised as providing an level of data protection.
Where personal data is transferred to the United States, we rely on the necessity of the transfer for the performance of our contract with you, and on the use of service providers who maintain appropriate technical and organisational measures. If you have questions about specific transfer safeguards, contact us at privacy@ketcon.us.
Data retention
We keep your data while your account is active. Deletion is permanent.
We retain your personal data for as long as your account is active. If you delete your account, we will permanently remove your profile, license records, and account data within 30 days of your request. Transactional email logs may be retained for up to 90 days for operational purposes before deletion.
Data shared with third-party processors (Jina AI, OpenRouter, Google Gemini) during feature use is governed by those providers' own retention policies. We do not control retention on their systems, but we use only providers who offer no-training guarantees on API data by default.
Security
We take reasonable steps to protect your data.
Passwords are stored using industry-standard one-way hashing. Data is transmitted over encrypted connections (HTTPS/TLS). Access to production systems is restricted to authorised personnel.
No method of transmission or storage is 100% secure. If you become aware of a security concern involving your account or our platform, please contact us immediately at security@ketcon.us.
Your rights
You can access, correct, export, or delete your data. Just ask.
Depending on your location, you may have the following rights:
- —Access: Request a copy of the personal data we hold about you.
- —Rectification: Correct inaccurate or incomplete data. Most profile data can be updated directly in the app.
- —Erasure ("right to be forgotten"): Request deletion of your account and associated personal data.
- —Restriction: Request that we limit processing of your data in certain circumstances.
- —Data portability: Receive your data in a structured, machine-readable format.
- —Objection: Object to processing based on legitimate interests, including automated matching.
- —Withdraw consent: Where processing is based on your consent (e.g. Profile Auto-Fill), you may withdraw that consent at any time without affecting prior processing.
- —California residents (CCPA): You have the right to know what personal information is collected, to delete it, and to opt out of its sale. We do not sell personal information.
To exercise any of these rights, email privacy@ketcon.us from the address associated with your account. We will respond within 30 days. If you believe your rights have not been respected, you have the right to lodge a complaint with your local data protection authority.
Cookies and local storage
No tracking cookies. We only store what is needed to keep you logged in.
KetCon does not use cookies or third-party tracking technologies. We use your browser's localStorage for three strictly functional purposes:
- —Your authentication token, so you remain logged in between sessions.
- —Your display theme preference (light, dark, or system).
- —Whether you have dismissed the app install prompt.
None of this data is shared with third parties or used for tracking purposes.
Children's privacy
This platform is not for anyone under 18.
KetCon is a professional platform intended solely for licensed healthcare professionals. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has created an account, please contact us and we will delete it promptly.
Changes to this policy
We'll notify you of material changes before they take effect.
We may update this Privacy Policy from time to time. If we make a material change — one that significantly affects how we collect, use, or share your data — we will notify you by email at least 14 days before the change takes effect. Minor clarifications or corrections will be noted by updating the "Last updated" date at the top of this page.
Continuing to use KetCon after a material change takes effect constitutes acceptance of the revised policy. If you do not agree with a change, you may delete your account before it takes effect.
This Privacy Policy is governed by the laws of the United States. It is intended to be read alongside our Terms & Conditions.
Privacy questions or requests?
Email us from the address on your account and we'll respond within 30 days.
privacy@ketcon.us