Privacy
Effective 2026-09-20. Plain language on purpose; we'll keep it that way as the product grows.
The short version
You can use Nevvi without an account, a signup, or an email address. We don't sell data about you, we don't run ads, and the medical data you see here contains no patient information — it is public, provider-level data published by CMS.
What we collect, and where it goes
- Searches. Code searches are processed on our servers. If you use the plain-English search box, your question text is sent to Anthropic (the Claude API, under their commercial API terms) to interpret it into procedure codes — the question text only, nothing else about you. All the numbers you see come from our own database of CMS data, never from the AI. We keep an anonymous log of questions and whether they resolved, to improve the product and find gaps in our code coverage. This log is never linked to your account — even when you're signed in, we do not record which searches you ran, or who ran them. When a search in the search bar finds nothing, we keep the words you typed for 90 days, without anything about who typed them, to improve the words Nevvi understands. Before we keep them, we remove anything shaped like an email address, a phone number, or a long number.
- Analytics. We use Google Analytics to understand usage. Page URLs are part of standard analytics, and since search terms appear in URLs, your search terms are included in what Google Analytics processes.
- Infrastructure. The site is served through Cloudflare (which sets a security cookie) and hosted on DigitalOcean. Web fonts load from Fontshare and Google Fonts — those requests carry your IP address and browser details, like any web request. Our servers keep standard request logs (IP address included) for rate limiting and abuse prevention.
- The request form. If you ask for a trial or a report, we collect what you type — name, work email, company, message — and use it to reply to you. Nothing else is done with it.
- Your location on a Brief request. When you ask for a Brief, we estimate a city and state from your connection's IP address and keep that estimate with the request, for licensing reports to the American Medical Association and to understand where readers are. We do not keep the IP address itself for this purpose.
- CSV by email. If you ask us to email you a CSV, we record your email address and the search you asked us to email you, and use them to deliver that file. If you tick the launch-updates box, we'll also send you one email when the analytics you asked about launches — and nothing else.
- Payments. Checkout is hosted by Stripe. Your card details go to Stripe directly and never touch Nevvi's servers; we receive payment status (paid / failed) and your billing contact from Stripe to provision your access.
About the physician data shown here
Nevvi displays provider-level statistics from public CMS releases: the Medicare Physician & Other Practitioners file, the Medicare Part D Prescribers file, and the Doctors & Clinicians file. CMS publishes all three. They describe medical practices, billing patterns, and prescribing volumes, not patients. Small counts are withheld before CMS publishes them: the Part B file withholds any figure based on fewer than 11 beneficiaries, and the Part D file has no row for a prescriber with 10 or fewer claims for a medication. If you are a clinician and want us to review what is shown about you, or believe a figure is inaccurate, contact us. The underlying record is CMS's, but we'll review how it renders here.
Contact
Questions about this page: use the contact form. If this policy changes materially, the effective date above changes with it.