COMPLIANCE // LEGAL

Privacy Policy

EFFECTIVE DATE: APRIL 8, 2026 // LAST REVISED: APRIL 8, 2026

1. Introduction

Shteg.ai, Inc. ("Shteg.ai," "we," "us," or "our") operates a healthcare revenue cycle management platform ("Platform") for licensed medical practices ("Customers"). This Privacy Policy describes how we collect, use, disclose, and protect information about our Customers, their authorized users ("Practice Staff"), and the financial data retrieved through our bank integration on behalf of Customers.

This policy does not govern the data practices of Customers with respect to their own patients (which is governed by each Customer's own HIPAA-compliant practices and our Business Associate Agreement).

2. Information We Collect

2.1 Customer Account Information

When a Customer registers, we collect:

  • Legal business name, EIN, and NPI
  • Authorized representative name, email address, and job title
  • State(s) of licensure and practice specialty
  • Signed agreement records and timestamps

2.2 Practice Staff Information

  • Name and email address
  • Role and access tier
  • Login timestamps and activity logs

2.3 Financial Account Data

When a Customer connects a bank account via the secure linking portal:

  • Account ownership identity (name on account, routing/account number last-4)
  • Account balance (used solely for settlement verification)
  • Secure access token (encrypted; never exposed to end users)

This data is collected exclusively to verify account ownership and initiate payment settlement on behalf of Customer. We do not use this data for credit scoring, marketing, or any purpose outside of settlement operations.

3. How We Use Information

Data TypePurpose
Account informationIdentity verification, contractual relationship management
Financial account dataAccount verification, RTP/ACH payment settlement
Practice Staff dataAuthentication, access control, audit trails
Usage dataProduct improvement, security monitoring, customer support

We do not sell, rent, or trade any Customer or financial data to third parties.

4. Open Banking Data Commitments

In compliance with open banking regulations, Shteg.ai commits to the following:

  • Minimal access: We request only the permissions necessary for the stated settlement use case.
  • No secondary use: Financial account data is used only to provide services to the Customer who authorized it.
  • Customer control: Customers may disconnect their bank accounts at any time. Upon disconnection, we revoke the secure access tokens and delete associated account data within 30 days.
  • No data aggregation: We do not aggregate or re-sell financial data across Customers.
  • No marketing use: Financial data is never used for advertising, profiling, or marketing purposes.

5. HIPAA & BAA

Where Shteg.ai processes Protected Health Information (PHI) on behalf of a Customer, it acts as a Business Associate under HIPAA. A separate Business Associate Agreement (BAA) governs PHI handling and is incorporated into the Customer's agreement with Shteg.ai.

6. Contact

Shteg.ai Privacy Officer
Email: privacy@shteg.ai
For security incidents: security@shteg.ai