Last updated June 30, 2026
Alcyoneus LLC ("Alcyoneus," "ARA," "we," "us," or "our") operates the ARA referral management platform (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to visitors, registered accounts, and to the organizations and end-users (such as patients or referral sources) who interact with forms created through the Service.
If you have questions about this policy, contact us at [email protected] or Alcyoneus LLC, 240 W. Willow St, Chicago, IL 60614.
ARA is used by organizations ("Customers," e.g. medical practices) to collect referral information from the people they interact with ("End-Users," e.g. patients or referring offices) through customizable forms, NFC cards, and QR codes. For data that Customers collect through their own custom forms, the Customer determines what is collected and why — Alcyoneus acts as a data processor on the Customer's behalf, not as the party controlling that data. If you are an End-User submitting a referral form and have privacy questions about that specific submission, please contact the organization that provided you the form or card.
The rest of this policy also describes data we collect directly, as the platform operator, from Customer accounts and from anyone who visits our website.
Account information. When you create an ARA account we collect your username, email address, nickname, and a securely hashed password. We never store your password in plain text.
Organization information. When you create or join an organization, we store the organization name, its owner and member accounts, and organization-level settings (such as referral follow-up scheduling and saved sources).
Referral and form data. Organizations can build custom intake forms with arbitrary fields. When an End-User submits one of these forms — including via a tap of an NFC card or scan of a QR code — we store the responses submitted, along with an identifier for the referral source. Depending on how a Customer configures its forms, this may include health-related information about patients. We do not control or review the content of Customer-defined form fields.
Billing information. Subscription payments are processed entirely by our payment processor, Stripe. We do not receive or store full credit card numbers. We do store a Stripe customer ID and subscription status so we can manage your account and billing history.
Physical card orders. If you order physical NFC referral cards, we collect a shipping name, address, and phone number, which we use to fulfill the order and, via Stripe, to calculate applicable sales tax.
Referral program data. If you were referred to ARA by another user, or you refer others, we track that relationship (a referral code and the account that referred you) to apply applicable discounts.
Cookies and session data. We use an HTTP-only session cookie to keep you signed in, and a small non-sensitive cookie to remember your last-used organization. We do not use third-party advertising or analytics cookies.
Log and support data. We keep a limited, rolling log of account actions (such as sign-ins and organization changes) for security and troubleshooting purposes.
We do not sell personal information, and we do not use Customer or End-User data for advertising.
We share information only as necessary to operate the Service:
We do not otherwise sell, rent, or share personal information with third parties for their own marketing purposes.
Because Customers can configure their own intake forms, submissions may include health-related information about patients or other End-Users. Alcyoneus is not a healthcare provider and does not independently review form content. Customers are responsible for ensuring their use of custom forms complies with applicable health privacy laws (see our Terms of Service for details on HIPAA and Business Associate Agreements).
We retain account, organization, and referral data for as long as an account or organization remains active. When an organization is deleted, its associated forms, referrals, access codes, and card orders are deleted as well. Deleting a user account does not automatically delete organizations that account owns or belongs to. Rolling activity logs are limited to recent history and are periodically pruned. You may request deletion of your account or organization data by contacting [email protected], subject to any records we are required to retain for legal, billing, or security purposes.
You may access, correct, or request deletion of your account information at any time by contacting us or, where available, through your account settings. Depending on your location, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA), including the right to know what personal information we hold about you and to request its deletion. To exercise these rights, contact [email protected]. If you are an End-User who submitted a form through a Customer organization, please also contact that organization, as they control the content of their forms.
We use industry-standard safeguards to protect information, including encrypted password storage (bcrypt hashing), HTTPS transport encryption, HTTP-only session cookies, and security headers (via Helmet/Content Security Policy). No system is completely secure, and we cannot guarantee absolute security of information transmitted to or stored by the Service.
The Service is intended for business use by adults and organizations, not for use directly by children. We do not knowingly collect account information from children under 13. Referral forms may incidentally include information about minors submitted by a Customer organization (e.g., a patient's guardian); such data is governed by the Customer's own obligations as described above.
We may update this Privacy Policy from time to time. We will update the "Last updated" date above when we do, and for material changes we will make reasonable efforts to notify account holders.
Alcyoneus LLC
240 W. Willow St
Chicago, IL 60614
[email protected]