Privacy Policy
Version 1.0 · Updated 8/25/2026
This Privacy Policy explains how MeremAI LLC ("MeremAI," "we," "us," or "our") collects, uses, and shares information through HIPAA TrustGuard (the "Service"). By using the Service, you agree to the practices described here.
1. Information We Collect
We collect:
- Account information: name, email address, and password (handled by our authentication provider).
- Training data: module progress, quiz results, and issued certificates.
- Organization data: organization name, team memberships and roles, invitations, self-audit answers, uploaded compliance documents, and billing status.
- Badge and verification data: information shown on your public certificate or organization badge verification page, and activity related to those public pages.
- Usage and device data: log data, browser and device identifiers, and how you interact with the Service.
2. How We Use Information
We use information to provide and improve the Service, generate and verify certificates and trust badges, facilitate team management within your organization, communicate with you (including renewal and security notices), maintain an internal audit log for security and troubleshooting, and comply with legal obligations.
3. Certificates, Badges, and Public Verification
A certificate's credential ID and an organization's trust badge are designed to be publicly verifiable — anyone with the credential ID or a link to your organization's badge page can view limited information (such as name, status, issue and expiration dates) without signing in. Do not treat a credential ID as a secret.
4. Not a HIPAA Business Associate by Default
HIPAA TrustGuard is a workforce training and self-assessment tool. We are not a HIPAA covered entity or business associate with respect to your organization's own patient data unless we have separately executed a business associate agreement with you — this Service is not designed to receive, store, or process protected health information (PHI) about your patients, and you should not upload PHI into training responses, self-audit answers, or documents.
5. How We Share Information
We do not sell personal information. We may share information: with your organization's admins and owner, to the extent needed to operate team features; publicly, for the specific certificate or badge fields designed to be verifiable as described above; with service providers who help us operate the Service (hosting, email delivery); to comply with law or legal process; or in connection with a merger, acquisition, or asset sale, subject to confidentiality obligations.
6. Data Retention and Deletion
We retain account and organization data for as long as your account is active or as needed to provide the Service. You may deactivate or permanently delete your own account at any time from account settings; deletion is blocked while you are the sole owner of an organization. An organization owner may delete the organization, which removes team access, audits, documents, and the trust badge for that organization.
7. Security
We use administrative and technical safeguards designed to protect information, including row-level access controls, server-side re-verification of privileged actions, and an internal admin action log used for security monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Cookies
We use essential cookies required for the Service to function, such as keeping you signed in. We do not currently use non-essential advertising or cross-site tracking cookies.
9. Your Privacy Rights
Depending on your state of residence, you may have rights to access, correct, delete, or limit the use of your personal information. Most of these actions are available directly from your account settings; for anything else, an organization owner or admin can act on your organization's behalf, or contact us using the details below.
10. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from them.
11. International Users
The Service is hosted in the United States and intended primarily for U.S.-based individuals and organizations. If you access the Service from outside the United States, your information will be processed in the United States.
12. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will post the updated Policy with a new "Last Updated" date.
13. Contact
MeremAI LLC
2222 W. Grand River Ave Ste A
Okemos, MI 48864, USA
meremai.com
