Terms of Service

Privacy Policy

Effective June 23, 2026 · Version 2026-06-23

1. Our approach

Your credentials belong to you. We collect the minimum needed to run your passport, we encrypt sensitive identifiers, we never sell your data, and we share it only with the sub-processors needed to provide the service or with recipients you explicitly choose. Rōvn is HIPAA-aligned, BAA available. Rōvn is not "HIPAA certified". No authority issues such a certification.

2. What we collect

  • Account: your name, email and/or phone, and profession.
  • Credentials you add: license details, certifications, immunizations, test/clearance records, the documents you upload, and work history, education, and references you choose to enter.
  • Sensitive identifiers, only when you request a license verification: the last four digits of your SSN and your date of birth (encrypted), used solely to match your record, and never displayed back or shared for any other purpose.
  • Limited technical data needed for security and to operate the service (for example, IP address and timestamps in our audit log).

3. How we use it

  • To build and display your credential passport.
  • To read and structure your uploaded documents using AI (you confirm every field; AI never decides).
  • To run a primary-source license verification when you request one.
  • To remind you about upcoming credential expirations, if you opt in.
  • To secure the service, prevent abuse, and maintain an audit trail.

4. Who we share it with

We share data only as needed to provide the service, under contract, and never for their own marketing:

  • Amazon Web Services, hosting, encrypted storage, AI processing (Amazon Bedrock), and email delivery (Amazon SES), under a BAA.
  • Anthropic, AI document extraction of credential metadata, under a BAA.
  • NCSBN / Nursys, to verify a nursing license when you request it.
  • Recipients you choose, a facility or other party sees only the passport or share link you send them, and only for as long as you allow it. You can revoke a share at any time.

5. AI processing

Only credential metadata (not clinical or patient information) is processed by AI, and only to read and organize your documents. AI assists; you confirm; source systems prove the facts; humans make every regulated decision. AI processing runs under Business Associate Agreements with our AI providers.

6. Storage, security, and retention

Data is encrypted in transit and at rest. Sensitive identifiers are additionally encrypted at the field level and are never returned to your device. Verification activity is recorded in an append-only, hash-chained audit log. We keep your data while your account is active and for as long as needed to provide the service and meet legal obligations; you can request deletion at any time, after which we remove your personal data except records we are required to retain (without the underlying sensitive identifiers).

7. Your rights and choices

  • Access, correct, or update your information in the app at any time.
  • Export or share your passport, and revoke any share you have created.
  • Withdraw consent for verification, and request deletion of your account and data.
  • Contact us about any privacy request at privacy@rovn.to.

8. Children and changes

Rōvn is not intended for anyone under 18. We may update this Policy; material changes will carry a new version and effective date. Questions or requests: privacy@rovn.to.