Privacy Policy

Last updated: September 5, 2026

This Privacy Policy describes how Koru Industries Inc. (“Koru,” “we,” “us”) collects, uses, and shares information when you use Credentialed - the credentialed.health website, the Credentialed web platform, and the Credentialed iOS app (together, the “Service”).

In short: Credentialed is a professional credentialing tool. We collect the information needed to track and verify professional credentials - and nothing more. We do not sell your information, and we do not use it for advertising. The Service manages information about healthcare providers; it does not collect or store patient medical records.

Information we collect

Account information

  • Name, email address, and username
  • Password (stored only as a salted cryptographic hash - we cannot read it)
  • Role and organization affiliation

Professional credentialing information

  • Professional identifiers: NPI, state license numbers, DEA registration, board certifications, CAQH ID
  • Practice details: provider type, specialty, practice address, phone number
  • Verification and enrollment identifiers that licensing authorities and payer programs require: date of birth and, where a program such as Medicaid or Medicare requires it, a Social Security number
  • Documents you or your credentialing team upload (licenses, certificates, and verification evidence)
  • An optional profile photo, if you choose to add one (shown on your record so your credentialing team can identify you)

Device and usage information

  • If you use the iOS app: a device identifier and, if you enable notifications, a push notification token
  • Security and audit records: sign-in events, IP addresses, and actions taken on credentialing records (kept as a tamper-evident audit trail)
  • Messages you send to our support team

Where information comes from

  • You, when you create an account, complete your profile, or upload documents.
  • Your organization, if your account was created by a credentialing team you work with.
  • Public registries and primary sources, when we verify credentials: the NPPES NPI registry, state professional licensing boards, and federal exclusion lists (OIG LEIE and SAM.gov). This information is drawn from public records maintained by those authorities.

How we use information

  • To provide the Service: storing credentials, running primary-source verification against issuing authorities, and monitoring expirations and exclusion lists
  • To send the expiration reminders and alerts you configure (push and/or email, on the schedule you choose)
  • To secure the Service, prevent abuse, and maintain the audit trail that credentialing compliance requires
  • To respond when you contact support
  • To comply with legal obligations

We do not sell personal information, and we do not use it for advertising or share it for cross-context behavioral advertising.

How we share information

  • Your organization. If your account is affiliated with a client organization, that organization’s credentialing team can see the credentialing records it maintains about you.
  • Verification sources. Verifying a credential necessarily sends identifying details (such as your name and license number) to the issuing authority being checked.
  • Service providers that host and operate the Service on our behalf: cloud infrastructure (Railway), transactional email (SendGrid/Twilio), error monitoring (Sentry), and Apple’s push notification service. Each processes data only to provide its service to us.
  • Apple. iOS app subscriptions are purchased through, and billed by, Apple. We receive your subscription status from Apple; we never receive or store your payment card details.
  • Koru ID. Organization accounts may sign in through Koru ID, our single sign-on service; it processes your sign-in credentials and basic profile information.
  • Legal. When required by law, or to protect the rights, safety, or security of the Service and its users.

Data retention and deletion

You can delete your account at any time in the iOS app under Settings → Delete account, or by contacting support@credentialed.health. What deletion covers depends on the kind of account:

  • Independent (self-registered) accounts: your entire workspace is permanently deleted - profile, credentials, verification history, and uploaded documents, including the files themselves.
  • Organization-affiliated accounts: your sign-in identity, devices, and notification settings are deleted. Credentialing records maintained by your organization are retained by that organization - they are its compliance records, and requests about them should be directed to your credentialing team.

Security audit logs are retained in both cases, as required for compliance integrity. Residual copies in encrypted backups are removed as those backups age out.

Security

Data is encrypted in transit (TLS) and sensitive identifiers - such as license numbers, dates of birth, and Social Security numbers - are additionally encrypted at rest. A stored SSN is never displayed back in full; revealing one is a deliberate, logged action. Passwords are hashed, access is role-restricted, and account activity is logged. No security program can guarantee absolute security, but protecting this data is central to how the Service is built.

Your choices and rights

  • You can view and update your profile and credential information in the app or web platform.
  • You control notification methods and schedules in Settings, and can disable push notifications at the device level at any time.
  • You can request a copy of your data, corrections, or deletion by emailing support@credentialed.health. Depending on where you live, you may have additional rights under state privacy laws; we honor applicable requests regardless of state.

Children

The Service is a professional tool for licensed healthcare providers and credentialing teams. It is not directed to anyone under 18, and we do not knowingly collect information from children.

Changes to this policy

If we make material changes, we will update this page and revise the “Last updated” date above, and - for significant changes - notify you through the Service or by email.

Contact us

Questions about this policy or your data: support@credentialed.health