Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · glowup.certainlyhealth.com

Certainly Health

Graded against 809 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-07-19
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

32 verified findings3 policy surfaces1/1 core docs verified

Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.

Risk triage

Watch: subprocessors data sharing

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
4
medium
0
low
1/1
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Certainly Health's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 32 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Terms not yet captured

AIRIN has not yet captured a gate-verified Terms of Service document for this platform.

Document status
  • Privacy Policy
    Verified - read in full - 32 citationsstaticLast captured 2026-07-19
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Defines what constitutes PHI in the context of the Services, identifies the conditions under which Certainly acts as a Business Associate under HIPAA, and delimits which user health information falls within that regulated category.

" Certain demographic, health and/or health-related information that Certainly collects about Users on behalf of our Healthcare Providers as part of providing the Services may be “protected health information” (“PHI”) governed by the Health ..."
📍 § 1 (HIPAA and PHI)Jump to exact text →
plan language
Privacy & data use

Defines the boundary between PHI (excluded from this Policy) and personally identifiable information (PII) collected when Certainly is not acting as a Business Associate, and provides examples of data collection activities that generate PII covered by this Policy.

"Personal data that a User provides to Certainly when Certainly is not acting as a Business Associate is not PHI and is therefore covered by this Privacy Policy. To provide just a few examples, we are collecting personally identifiable infor..."
📍 § 1 (HIPAA and PHI)Jump to exact text →
plan language
Privacy & data use

Disclaims any guarantee or promise of absolute security for user information or communications transmitted over the Internet or email, limiting the company's liability for security failures.

" Certainly implements technical, administrative, and physical safeguards to protect the information we collect from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. However, no Internet or email transmission is..."
📍 § 8 (Security)Jump to exact text →
plan language
Subprocessors & data sharing

Permits disclosure of user information to affiliates and to employees, consultants, and other vendors (subprocessors) performing services on Certainly's behalf, including data storage, payment, analytics, fraud prevention, and marketing, and notes affiliates must use information consistently with the Policy.

" Affiliates : We may disclose information to our affiliates, meaning an entity that controls, is controlled by, or is under common control with Certainly. Our affiliates may use the information we disclose in a manner consistent with this P..."
📍 § 4 (When We Disclose the Information We Collect)Jump to exact text →
Conflicting provisions (4)
  • Clause A explicitly states the Privacy Policy does not apply to PHI, while Clause B includes the disclosure of PHI via HIPAA authorization as an example of data that is 'not PHI' and 'therefore covered by this Privacy Policy'.

    "‍ This Privacy Policy does not apply to PHI, which is instead regulated by HIPAA. HIPAA provides specific protections for the privacy and security of PHI and restricts how PHI is used and disclosed. Please read the Notice of Privacy Practices of your Health Provider to understand how your PHI can be used and disclosed."
    "Personal data that a User provides to Certainly when Certainly is not acting as a Business Associate is not PHI and is therefore covered by this Privacy Policy. To provide just a few examples, we are collecting personally identifiable information (“PII”) when you (i) create an account, (ii) search for Healthcare Providers or available appointments with Healthcare Providers; (iii) post reviews; (iv) provide device/IP Information or Web Analytics information by browsing our websites (see below); or (v) authorize your Covered Entity health provider to disclose PHI to Certainly pursuant to a HIPAA Authorization form you have completed."
    Within one document
  • Clause A states that no mobile information (including text messaging data) will be shared with third parties for marketing/promotional purposes, while Clause B states that information may be disclosed to third parties based on user consent, creating a direct conflict if a user consents to share such data for those purposes.

    " No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. We may change this Policy to reflect changes in the law, our information practices or the features of the Services. We will indicate the date of the most recent update in this Policy. By continuing to use the Services, you are confirming that you have read and understood the latest version of this Policy. ‍"
    " Other Disclosures with Consent or at Your Direction . We may disclose your information to nonaffiliated third parties based on your consent to do so. For example, you may direct us to disclose information about you when you refer us or our Services to your friends or other acquaintances."
    Within one document
  • Clause A explicitly prohibits sharing mobile information with third parties/affiliates for marketing/promotional purposes, while Clause B states that information may be disclosed to affiliates and vendors (including those providing marketing services), creating a direct conflict regarding the sharing of user data for marketing.

    " No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. We may change this Policy to reflect changes in the law, our information practices or the features of the Services. We will indicate the date of the most recent update in this Policy. By continuing to use the Services, you are confirming that you have read and understood the latest version of this Policy. ‍"
    " Affiliates : We may disclose information to our affiliates, meaning an entity that controls, is controlled by, or is under common control with Certainly. Our affiliates may use the information we disclose in a manner consistent with this Policy. Vendors : We may disclose your information to employees, consultants, and other vendors who need access to such information to carry out work or perform services on our behalf, such as those who provide data storage, payment, technology support and services, customer service, analytics, fraud prevention, legal services, and marketing services. Safety and Protection of Certainly and Others : We may disclose certain information if we believe in good faith that doing so is necessary or appropriate to (i) protect or defend the Certainly or other parties, including to defend or enforce this Policy, our Terms of Service, or any other contractual arrangement; and/or (ii) protect the rights, property or personal safety of Certainly, our agents and affiliates, our employees, users and/or the public. Legal Requirements . We may disclose certain information if we believe in good faith that doing so is necessary or appropriate to comply with any law enforcement, legal, or regulatory process, such as to respond to a warrant, subpoena, court order, or other applicable laws and regulations. Business Transfers . We may disclose certain information, in connection with or during negotiations or closing of any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. "
    Within one document
  • Clause A states a general inability to guarantee the security of user information, while Clause B identifies Protected Health Information (PHI) as being governed by HIPAA, which legally mandates specific and robust security measures, creating conflicting expectations for users regarding PHI security.

    " Certainly implements technical, administrative, and physical safeguards to protect the information we collect from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. However, no Internet or email transmission is ever fully secure or error free. Therefore, we do not promise and cannot guarantee the security of your information or communications. ‍"
    " Certain demographic, health and/or health-related information that Certainly collects about Users on behalf of our Healthcare Providers as part of providing the Services may be “protected health information” (“PHI”) governed by the Health Insurance Portability and Accountability Act (“HIPAA”). Specifically, when (i) Certainly is providing administrative, operational, or other services to a Healthcare Provider that is a “Covered Entity” (as defined by HIPAA); and (ii) in order to provide those services, Certainly receives identifiable information about a User on behalf of the Healthcare Provider, where Certainly is acting as a “Business Associate” (as defined by HIPAA); and (iii) this identifiable information is regulated as PHI."
    Within one document

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 4
Tier-specific - 0
Total citations - 32
Severity
Surface
Document
Tier
Subprocessors & data sharing
High
" Affiliates : We may disclose information to our affiliates, meaning an entity that controls, is controlled by, or is under common control with Certainly. Our affiliates may use the information we disclose in a manner consistent with this Policy. Vendors : We may disclose your information to employees, consultants, and other vendors who need access to such information to carry out work or perform services on our behalf, such as those who provide data storage, payment, technology support and services, customer service, analytics, fraud prevention, legal services, and marketing services. Safety and Protection of Certainly and Others : We may disclose certain information if we believe in good faith that doing so is necessary or appropriate to (i) protect or defend the Certainly or other parties, including to defend or enforce this Policy, our Terms of Service, or any other contractual arrangement; and/or (ii) protect the rights, property or personal safety of Certainly, our agents and affiliates, our employees, users and/or the public. Legal Requirements . We may disclose certain information if we believe in good faith that doing so is necessary or appropriate to comply with any law enforcement, legal, or regulatory process, such as to respond to a warrant, subpoena, court order, or other applicable laws and regulations. Business Transfers . We may disclose certain information, in connection with or during negotiations or closing of any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. "
§ 4 (When We Disclose the Information We Collect)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Permits disclosure of user information to affiliates and to employees, consultants, and other vendors (subprocessors) performing services on Certainly's behalf, including data storage, payment, analytics, fraud prevention, and marketing, and notes affiliates must use information consistently with the Policy.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" Other Disclosures with Consent or at Your Direction . We may disclose your information to nonaffiliated third parties based on your consent to do so. For example, you may direct us to disclose information about you when you refer us or our Services to your friends or other acquaintances."
§ 4 (When We Disclose the Information We Collect)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Permits disclosure of user information to non-affiliated third parties based on user consent or at the user's direction, such as when a user refers the service to acquaintances.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" Analytics. We may use third-party web analytics services on the Services, such as those of Google Analytics. These vendors use the sort of technology described in the “Information We Collect Automatically” section above to help us analyze how users use the Services, including by noting the third-party website from which you arrive. The information collected by such technology will be disclosed to or collected directly by these vendors, who use the information to evaluate your use of the Services. To prevent Google Analytics from using your information for web analytics, you may install the Google Analytics Opt-Out Browser Add-on ."
§ 5 (Online Analytics)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Permits use of third-party web analytics services and discloses that usage information is shared with or collected directly by those vendors; also describes a user opt-out mechanism for one named analytics service, establishing the data-sharing arrangement and a user right to limit it.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" The Services may contain links to third-party websites or services. We are not responsible for the content or practices of those websites or services. The collection, use, and disclosure of your information by third parties will be subject to the privacy policies of the third-party websites or services, and not this Policy. We urge you to read the privacy and security policies of these third parties before providing information to them. ‍"
§ 11 (Links to Third Party Websites)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Disclaims responsibility for the content or privacy practices of linked third-party websites and clarifies that third-party collection, use, and disclosure of user information is governed by those third parties' own policies, not this Policy.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"‍ This Privacy Policy does not apply to PHI, which is instead regulated by HIPAA. HIPAA provides specific protections for the privacy and security of PHI and restricts how PHI is used and disclosed. Please read the Notice of Privacy Practices of your Health Provider to understand how your PHI can be used and disclosed."
§ 1 (HIPAA and PHI)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Restricts the application of this Privacy Policy to PHI, directing users to the Healthcare Provider's Notice of Privacy Practices instead, and notes that HIPAA governs PHI use and disclosure — user-favorable in that it acknowledges stronger statutory protections apply to PHI outside this Policy.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" While you can technically use Certainly if you are under 18, you must have a parent or guardian create and manage your account as you cannot book appointments on Certainly without adult supervision due to legal requirements regarding healthcare for minors; essentially, a parent or guardian needs to be involved in scheduling appointments for anyone under 18 ‍"
§ 7 (Children's Privacy)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Restricts minors under 18 from independently managing accounts or booking appointments, requiring parental or guardian involvement due to legal requirements for healthcare for minors, establishing an age-based access restriction.

AI-generated interpretation, not legal advice.

Data retention
High
"‍ Please note that certain information may be exempt from such requests under applicable law. For example, we may retain certain information for legal compliance and to secure our Services. We may need certain information in order to provide the Services to you; if you ask us to delete it, you may no longer be able to use the Services."
§ 6 (Your Choices)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Creates an exception to user deletion and access rights by permitting Certainly to retain certain information for legal compliance and service security purposes, and notes that deletion of necessary information may result in loss of Services.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"By using the Services, you are agreeing to the practices described in this Policy. If you do not agree to the practices described in this Policy, please do not access or use the Services."
Privacy Policy › “Last updated June 18, 2025”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Imposes an obligation on users by requiring agreement to the practices described in the Policy as a condition of using the Services, and restricts access to non-agreeing users.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"Any use of the Services is subject to the Agreement (as the term “Agreement” is defined in our Terms of Use , which incorporates this Privacy Policy). ‍ ‍"
Privacy Policy › “Last updated June 18, 2025”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Incorporates the Privacy Policy into the broader Agreement as defined in the Terms of Use, establishing that use of Services is subject to that Agreement and cross-referencing the governing terms.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Certain demographic, health and/or health-related information that Certainly collects about Users on behalf of our Healthcare Providers as part of providing the Services may be “protected health information” (“PHI”) governed by the Health Insurance Portability and Accountability Act (“HIPAA”). Specifically, when (i) Certainly is providing administrative, operational, or other services to a Healthcare Provider that is a “Covered Entity” (as defined by HIPAA); and (ii) in order to provide those services, Certainly receives identifiable information about a User on behalf of the Healthcare Provider, where Certainly is acting as a “Business Associate” (as defined by HIPAA); and (iii) this identifiable information is regulated as PHI."
§ 1 (HIPAA and PHI)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines what constitutes PHI in the context of the Services, identifies the conditions under which Certainly acts as a Business Associate under HIPAA, and delimits which user health information falls within that regulated category.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We may disclose your information in any of the following circumstances:"
§ 4 (When We Disclose the Information We Collect)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Introduces the circumstances under which Certainly may disclose user information, establishing the general permissive framework for data sharing.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"‍ This Privacy Policy (the “Privacy Policy” or “Policy”) describes the types of information Certainly Health and its affiliates (“Certainly,” “we,” “our,” or “us”) collect and process from and about you."
Privacy Policy › “Last updated June 18, 2025”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines the scope of the Privacy Policy by identifying the entity ('Certainly Health and its affiliates') and characterizing the document as describing types of information collected and processed from users, establishing foundational definitional terms used throughout.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"Except as described in this Privacy Policy, the Policy applies to any and all websites, mobile applications, and any other electronic and/or digital products and/or other services that are made available by Certainly and that link to this Policy, and our offline services (collectively, the “Services”)."
Privacy Policy › “Last updated June 18, 2025”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines the scope of services to which the Policy applies, including websites, mobile applications, digital products, and offline services collectively termed 'Services,' establishing which activities are governed by the Policy.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"Personal data that a User provides to Certainly when Certainly is not acting as a Business Associate is not PHI and is therefore covered by this Privacy Policy. To provide just a few examples, we are collecting personally identifiable information (“PII”) when you (i) create an account, (ii) search for Healthcare Providers or available appointments with Healthcare Providers; (iii) post reviews; (iv) provide device/IP Information or Web Analytics information by browsing our websites (see below); or (v) authorize your Covered Entity health provider to disclose PHI to Certainly pursuant to a HIPAA Authorization form you have completed."
§ 1 (HIPAA and PHI)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines the boundary between PHI (excluded from this Policy) and personally identifiable information (PII) collected when Certainly is not acting as a Business Associate, and provides examples of data collection activities that generate PII covered by this Policy.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" When you access or otherwise use our Services, we may collect information from you. The types of information we collect depend on how you use our Services. Please note that we need certain types of information to provide the Services to you. If you do not provide us with such information, or if you ask us to delete that information, you may no longer be able to access or use certain Services. The information we collect may include data you directly provide to us, data we obtain automatically from your interactions with our Services, and data we obtain from other sources."
§ 2 (Information We Collect)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Describes the general obligation on users to provide certain information as a condition of accessing Services, and notes that failure to provide or deletion of such information may result in loss of access, establishing the data provision requirement.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"‍ Information you provide directly to us. We may collect information directly from you. For example, you may provide us with information when you use the Services, communicate with us, create an account, subscribe to newsletters, or participate in a promotion. Information you provide directly to us may concern you and others and may include, but is not limited to: ‍ Email address; User name; Date of birth; Sex; Health insurance information; Payment information (e.g. through our payment processing vendors); Your User Content (as defined in the Terms of Service), such as chat communication and posted images; and"
§ 2 (Information We Collect)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines categories of information directly provided by users, enumerating specific data types (email, username, date of birth, sex, health insurance information, payment information, user content, communications) that Certainly may collect.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" You are not required to provide us with such information, but certain features of the Services may not be accessible or available absent the provision of the requested information."
Privacy Policy › “Contents of communications with us”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Disclaims any requirement for users to provide information while noting that certain Service features may be inaccessible without the requested information, limiting the obligatory nature of data provision.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"‍ Information we collect automatically. We and our third-party vendors, which include ad networks and analytics companies such as Google Analytics, may use cookies and other tracking technologies to collect information about the computers or devices (including mobile devices) you use to access the Services. As described further below, we may collect and analyze information including but not limited to (a) browser type; (b) ISP or operating system; (c) domain name; (d) access time; (e) referring or exit pages; (f) page views; (g) IP address; (h) unique device identifiers; (i) version of our Services you’re using; and (j) the type of device that you use. We may also track when and how frequently you access or use the Services, including how you engage with or navigate our site or mobile application. We may use this information (including the information collected by our third-party vendors) for analytics (including to determine which portions of the Services are used most frequently and what our users like/do not like), to evaluate the success of any advertising campaigns, and as otherwise described in this Policy."
Privacy Policy › “Contents of communications with us”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Grants permission for Certainly and third-party vendors (including ad networks and analytics companies) to use cookies and tracking technologies to automatically collect device and usage information, establishing the basis for automated data collection.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Certainly Health's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Certainly Health's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Certainly Health's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Certainly Health requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Certainly Health's published policies yet.

What the policies actually cover

0 topics

None of Certainly Health's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

34
clauses
7
patterns
7
stances
privacy sharing · 6training use · 1
privacy sharingMEDIUMPrivacy Policy › “Contents of communications with us”

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

‍ Information we collect automatically. We and our third-party vendors, which include ad networks and analytics companies such as Google Analytics, may use cookies and other tracking technologies to collect information about the computers or devices (including mobile devices) you use to access the Services. As described further below, we may collect and analyze information including but not limited to (a) browser ...
Open source citation
privacy sharingMEDIUM§ 3 (How We Use the Information We Collect)

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

We may use your information for any of the following purposes: ‍ Provide and administer the Services; Personalize the Services; Communicate with you, including to inform you about features or aspects of the Services we believe might be of interest to you, or to communicate with you about changes to our terms, conditions, or policies; Engage in other communications with you, such as to respond to your inquiries, co...
Open source citation
privacy sharingMEDIUM§ 4 (When We Disclose the Information We Collect)

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

Affiliates : We may disclose information to our affiliates, meaning an entity that controls, is controlled by, or is under common control with Certainly. Our affiliates may use the information we disclose in a manner consistent with this Policy. Vendors : We may disclose your information to employees, consultants, and other vendors who need access to such information to carry out work or perform services on our be...
Open source citation
privacy sharingMEDIUM§ 4 (When We Disclose the Information We Collect)

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

Other Disclosures with Consent or at Your Direction . We may disclose your information to nonaffiliated third parties based on your consent to do so. For example, you may direct us to disclose information about you when you refer us or our Services to your friends or other acquaintances.
Open source citation
privacy sharingMEDIUM§ 5 (Online Analytics)

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

Analytics. We may use third-party web analytics services on the Services, such as those of Google Analytics. These vendors use the sort of technology described in the “Information We Collect Automatically” section above to help us analyze how users use the Services, including by noting the third-party website from which you arrive. The information collected by such technology will be disclosed to or collected dire...
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersprivacy data useconditionalMEDIUM1
All applicable tierssubprocessors data sharingconditionalMEDIUM3
All applicable tierstraining useconditionalMEDIUM2
Team / Businesssubprocessors data sharingconditionalMEDIUM1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

‍ Information we collect automatically. We and our third-party vendors, which include ad networks and analytics companies such as Google Analytics, may use cookies and other tracking technologies to collect information about the computers or devices (including mobile devices) you use to access the Services. As described further below, we may collect and analyze information including but not limited to (a) browser type; (b) ISP or operating system; (c) domain name; (d) access time; (e) referring or exit pages; (f) page views; (g) IP address; (h) unique device identifiers; (i) version of our Services you’re using; and (j) the type of device that you use. We may also track when and how frequently you access or use the Services, including how you engage with or navigate our site or mobile application. We may use this information (including the information collected by our third-party vendors) for analytics (including to determine which portions of the Services are used most frequently and what our users like/do not like), to evaluate the success of any advertising campaigns, and as otherwise described in this Policy.
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

The Services may contain links to third-party websites or services. We are not responsible for the content or practices of those websites or services. The collection, use, and disclosure of your information by third parties will be subject to the privacy policies of the third-party websites or services, and not this Policy. We urge you to read the privacy and security policies of these third parties before providing information to them. ‍
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on training use

We may use your information for any of the following purposes: ‍ Provide and administer the Services; Personalize the Services; Communicate with you, including to inform you about features or aspects of the Services we believe might be of interest to you, or to communicate with you about changes to our terms, conditions, or policies; Engage in other communications with you, such as to respond to your inquiries, comments, feedback, or questions; Analyze, maintain, improve, modify, customize, and measure the Services, including to train our artificial intelligence/machine learning models;Develop new programs and services; Detect and prevent fraud, criminal activity, or misuses of our Service, and to ensure the security of our IT systems, architecture, and networks; Comply with legal obligations and legal process and to protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or other parties, including to enforce our Terms of Service and any other agreements; and Carry out any other purpose for which the information was collected. We may combine information that we collect from you through the Services with information that we obtain from other sources. We may also aggregate and/or de-identify information collected through the Services. We may use and disclose de-identified or aggregated data for any purpose, including without limitation for research and marketing purposes. ‍
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

Affiliates : We may disclose information to our affiliates, meaning an entity that controls, is controlled by, or is under common control with Certainly. Our affiliates may use the information we disclose in a manner consistent with this Policy. Vendors : We may disclose your information to employees, consultants, and other vendors who need access to such information to carry out work or perform services on our behalf, such as those who provide data storage, payment, technology support and services, customer service, analytics, fraud prevention, legal services, and marketing services. Safety and Protection of Certainly and Others : We may disclose certain information if we believe in good faith that doing so is necessary or appropriate to (i) protect or defend the Certainly or other parties, including to defend or enforce this Policy, our Terms of Service, or any other contractual arrangement; and/or (ii) protect the rights, property or personal safety of Certainly, our agents and affiliates, our employees, users and/or the public. Legal Requirements . We may disclose certain information if we believe in good faith that doing so is necessary or appropriate to comply with any law enforcement, legal, or regulatory process, such as to respond to a warrant, subpoena, court order, or other applicable laws and regulations. Business Transfers . We may disclose certain information, in connection with or during negotiations or closing of any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

Other Disclosures with Consent or at Your Direction . We may disclose your information to nonaffiliated third parties based on your consent to do so. For example, you may direct us to disclose information about you when you refer us or our Services to your friends or other acquaintances.
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

Analytics. We may use third-party web analytics services on the Services, such as those of Google Analytics. These vendors use the sort of technology described in the “Information We Collect Automatically” section above to help us analyze how users use the Services, including by noting the third-party website from which you arrive. The information collected by such technology will be disclosed to or collected directly by these vendors, who use the information to evaluate your use of the Services. To prevent Google Analytics from using your information for web analytics, you may install the Google Analytics Opt-Out Browser Add-on .
Open timeline citation
Jul 20, 2026model trainingHIGH

Latest stance: training permitted on training use

We may use your information for any of the following purposes: ‍ Provide and administer the Services; Personalize the Services; Communicate with you, including to inform you about features or aspects of the Services we believe might be of interest to you, or to communicate with you about changes to our terms, conditions, or policies; Engage in other communications with you, such as to respond to your inquiries, comments, feedback, or questions; Analyze, maintain, improve, modify, customize, and measure the Services, including to train our artificial intelligence/machine learning models;Develop new programs and services; Detect and prevent fraud, criminal activity, or misuses of our Service, and to ensure the security of our IT systems, architecture, and networks; Comply with legal obligations and legal process and to protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or other parties, including to enforce our Terms of Service and any other agreements; and Carry out any other purpose for which the information was collected. We may combine information that we collect from you through the Services with information that we obtain from other sources. We may also aggregate and/or de-identify information collected through the Services. We may use and disclose de-identified or aggregated data for any purpose, including without limitation for research and marketing purposes. ‍
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-07-19· verified 2026-07-19verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

34 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Certainly Health's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Certainly Health's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Certainly Health's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.