Privacy Policy
Effective date: June 12, 2026 · Last updated: 2026-07-25
Willowcare LLC, 212 N. 2nd St., Ste 100, Richmond, KY 40475, operates TenorMD, software for anonymous, multi-source provider feedback. This policy explains what we collect, how we use it, and the choices you have. For data you and your reviewers submit through the Service ("Customer Data"), your organization is the data controller and Willowcare LLC acts as a processor under your instructions and any applicable data-processing addendum (DPA). This policy is incorporated into, and subject to, our Terms of Service, including its limitation of liability and dispute-resolution provisions.
1. Information we collect
- Account data — administrator names, email addresses, hashed passwords, role, and two-factor authentication settings.
- Program data — provider names/titles, questionnaires, review periods, coaching notes, and the email addresses or phone numbers you enter to invite reviewers.
- Responses — reviewers' band selections and free-text comments, stored without any stored link to the reviewer or to the invitation that produced them.
- Billing data — plan and subscription status, and customer/subscription identifiers. Card details are handled by our payment processor (Stripe); we do not store full card numbers.
- Contact & support data — information you submit through our contact form or support channels (name, email, organization, message).
- Technical & usage data — IP address, device/browser information, log and diagnostic data, and a single first-party session cookie used to keep you signed in.
2. How we use information
We use information to provide, secure, operate, and improve the Service; to authenticate users and prevent fraud and abuse; to deliver invitations and account emails (and SMS where enabled); to process payments; to respond to inquiries and provide support; to enforce our Terms and protect our legal rights; and to comply with law. We may create and use aggregated and/or de-identified data (data that does not identify you or any individual) for any lawful purpose, including benchmarks, statistics, and product improvement; such data is not personal information and our rights in it survive termination. We do not sell personal information, and we do not use Customer Data to train third-party advertising or unrelated machine-learning models.
3. How anonymity is protected
A submitted response is never associated with the invitation used to access the survey; the invitation is only marked "used" in a separate operation. Reports and exports show only aggregates and unattributed comments, and only after the organization's configured minimum number of responses is met. Anonymity also depends on factors outside our control (such as reviewer-pool size and what reviewers choose to write), and we do not guarantee non-identifiability.
4. Cookies
We use a single essential, first-party cookie to maintain your authenticated session. We do not use third-party advertising or cross-site tracking cookies.
5. Email & SMS
Invitation and account emails are transactional. Where you use SMS invitations, your organization is solely responsible for obtaining recipient consent; messages include opt-out instructions (reply STOP), consistent with applicable law (including CAN-SPAM and the TCPA in the United States). You must not use the Service to send messages to people who have not consented.
6. When we disclose information
We disclose personal information only: (a) to the subprocessors below, to operate the Service; (b) to comply with law, regulation, legal process, or a governmental request, or to establish or protect our legal rights; (c) to prevent fraud, abuse, or harm to any person or to the security of the Service; (d) in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case this policy will continue to apply to the transferred information; or (e) at the controller organization's instruction. We do not sell or rent personal information.
7. Subprocessors
We use a limited set of vendors to operate the Service. Each is bound by terms requiring appropriate security and limiting use to providing services to us. The current list:
| Subprocessor | Purpose | Region |
|---|---|---|
| Render | Application hosting & database | United States |
| Cloudflare | DNS, CDN, TLS, and object storage for backups | United States / global edge |
| Postmark | Transactional email delivery | United States |
| Stripe | Subscription billing & payments | United States |
| Twilio | SMS delivery (where SMS invitations are enabled) | United States |
We may update this list from time to time; the version posted here is current. A DPA is available to customers on request.
8. Healthcare data (HIPAA)
The Service is designed to collect feedback about providers, not information about identifiable patients, and instructs reviewers not to include patient identifiers. Willowcare LLC is not a HIPAA covered entity, does not intend to act as a Business Associate, and the Service is not intended or authorized to create, receive, maintain, or transmit Protected Health Information. You must not submit PHI through the Service; if your intended use would involve PHI, do not use the Service for that purpose unless we have signed a separate written agreement expressly permitting it. You are solely responsible for any PHI submitted in violation of this section.
9. Security
We use industry-standard safeguards, including encryption in transit (TLS), encryption of backups at rest, hashed passwords, mandatory administrator two-factor authentication, role-based access controls, tenant isolation, and continuous database backups. No method of transmission or storage is completely secure, and we do not warrant or guarantee security. You are responsible for safeguarding credentials and for the security of your own systems and networks.
10. Data retention
We retain Customer Data while your organization uses the Service and for up to 30 days after termination to allow recovery and export, unless you request earlier deletion, after which it is deleted from production systems. Backups are rotated on an approximately 7-day cycle, after which deleted data ages out of backups. We may retain limited records as needed for legal, tax, billing-dispute, audit, and security purposes, and may retain aggregated/de-identified data indefinitely.
11. Data location & international transfers
The Service is hosted in the United States and intended for use by U.S. organizations. If you access it from outside the U.S., you do so on your own initiative and understand your information will be transferred to and processed in the U.S., which may have different data-protection rules than your jurisdiction.
12. Your rights & choices
Organizations may access, export, correct, or request deletion of their data through the Service or by contacting us. Depending on where you live (for example, under the California Consumer Privacy Act or the GDPR), you may have rights to access, delete, correct, or port personal information, and to be free from discrimination for exercising them. We do not sell or "share" personal information for cross-context behavioral advertising. To exercise a right, contact [email protected]; we may need to verify your identity. For Customer Data, we will direct requests to the relevant organization (the controller), which is responsible for responding.
13. Children
The Service is intended for healthcare organizations and is not directed to children under 18. We do not knowingly collect personal information from children; if you believe a child has provided personal information, contact us and we will delete it.
14. Breach notification
If we become aware of a security incident affecting personal information, we will notify affected customers without undue delay as required by applicable law and will reasonably cooperate in the controller's own notification obligations. Notification will not be construed as an admission of fault or liability.
15. Changes to this policy
We may update this policy; we will post the new version with an updated effective date and, for material changes, provide additional notice. Your continued use after changes take effect constitutes acceptance.
16. Contact
Willowcare LLC · TenorMD
212 N. 2nd St., Ste 100, Richmond, KY 40475
Privacy requests: [email protected] · General: [email protected]