Payer enrollmentPricing
Log inStart free trial
Payer enrollmentPricing

Privacy Policy

In effect since September 22, 2026

In short

We collect what we need to run Sokndall: who you are, the provider and payer data you enter, and basic technical records.

We do not sell personal data, and we never use what you enter to advertise anything.

A handful of companies process data for us — Supabase, Vercel, Polar, Resend, and Google if you sign in with it — and they are all listed below.

You can export everything at any time, and deleting your account deletes it. Questions: privacy@sokndall.com.

Who we are and what this covers

Sokndall makes credentialing and payer enrollment tracking software. This policy covers the marketing site at sokndall.com and the application you sign in to.

For the data you enter about your providers, you are the controller and we are the processor: it is your data, and we handle it on your instructions. For your own account and billing details, we are the controller.

Write to privacy@sokndall.com about anything in this policy.

What we collect

  • Account: your first and last name, your work email address and a password, which is stored hashed by Supabase Auth and never in a form we can read. If you sign in with Google instead, we receive your name, email address and profile picture from Google. A profile photo of your own is optional.
  • What you enter: your practice or client details, your providers' names, NPIs, CAQH IDs, licence and registration numbers with their dates, payer applications and their history, the notes and phone logs you write, and the documents you upload. No patient data belongs here, and the Terms forbid it.
  • Billing: your plan, subscription status and the name and email on the subscription, which come back to us from Polar. Card numbers go to Polar and never reach us.
  • Technical: IP address, browser and basic request logs, kept for security and abuse prevention, and a record that an alert or digest email was sent to a given address, so the same email is not sent twice.

How we use it

To run the service: show you your data, work out what expires and what has gone quiet, send the alert and digest emails on the schedule you choose, and keep the account working.

To bill you, through Polar.

To support you when you write in, which sometimes means looking at your account to answer the question you asked.

To keep the service safe: spotting abuse, debugging, and meeting a legal obligation when one applies.

We do not sell personal data. We do not use what you enter for advertising, and we do not use it to train machine-learning models.

Who processes data for us

  • Supabase — database, sign-in and file storage. Your data sits in Supabase's US East (Ohio) region.
  • Vercel — hosting for the site and the application.
  • Polar — payments and merchant of record: it charges the card, handles tax and issues invoices.
  • Resend — delivery of the emails we send you: alerts, the weekly digest, password resets and invitations.
  • Google — only if you choose to sign in with Google.
  • Cloudflare — the bot check on the sign-in and sign-up forms, where it is switched on.
  • Centers for Medicare & Medicaid Services — when you look up an NPI, that number is sent to the public NPI Registry (NPPES) to fetch the public record.

These companies are in the United States, and so are we. If you are in the EEA or the UK, that means your data is transferred to the United States, and we rely on the standard contractual clauses our processors offer for those transfers.

We do not add processors quietly. If this list changes, this page changes with it.

Cookies and tracking

The application sets three cookies, all of them necessary: the Supabase session cookie that keeps you signed in, one that remembers which client you have open, and one that remembers whether the sidebar is folded. There are no advertising cookies inside the application, and no analytics or session-recording tool in it.

The marketing pages at sokndall.com carry no analytics today. When we start advertising we will add the Reddit and Google advertising tags to the marketing pages only, so we can tell which campaign a sign-up came from. They will never be added to the application, and they will never see what you keep in it. We will update this section, and offer the opt-out those tags require, on the day they go in.

We honour the Global Privacy Control signal for the advertising tags described above.

Keeping and deleting

Your content is kept while your account exists. Deleting a client deletes its records and files, leaving only a line saying a client of that name was deleted, when and by whom. Deleting the account ends the subscription, removes the stored files and deletes everything under the organization. Neither can be undone, so export first.

If an account ends without being deleted, it stays read-only for 30 days so you can export, and we may delete it after that.

Server and security logs are kept for up to 90 days. The record that an email was sent lives with the account and goes when it goes. Billing records are kept by Polar, and by us where the law requires, for as long as tax rules demand.

How it is protected

Every account is separated from every other account in the database itself, with row-level security, and on Billing Co each client is separated from the rest the same way. There is no path in the application that steps around it.

Uploaded documents live in private storage. A download link is made when you click and expires in a minute; an export's links expire in ten. Nothing is publicly addressable.

Connections are encrypted in transit, passwords must be at least twelve characters and are stored hashed, and sign-in can require a bot check.

The strongest protection is the one in the Terms: there is no patient data here to lose.

If we ever have a breach that affects your data, we tell the account owner by email without undue delay, and describe what happened and what we are doing about it.

Your rights

You can see everything we hold about your account inside the application, correct it there, export it as CSV or ZIP, and delete it by deleting the client or the account.

Depending on where you live, you may also have the right to ask for a copy of your personal data, to have it corrected or deleted, to object to or restrict how we use it, and not to be treated differently for asking. Write to privacy@sokndall.com and we answer within 30 days. We may need to check that you are who you say you are first.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other state privacy laws. If that ever changes because of the advertising tags described above, this policy will say so before it happens.

If you are a provider whose details sit in someone's account, that account belongs to the practice or billing company that entered them. Ask them first; we will pass a request on to them and help them answer it.

Children

Sokndall is a business tool and is not directed to anyone under 18. We do not knowingly collect data from children, and if we learn that we have, we delete it.

Changes and contact

When this policy changes we update the date at the top, and we email the account owner before a material change takes effect.

Privacy questions and requests: privacy@sokndall.com. Anything else about the product: support@sokndall.com.

Adapted from the Basecamp open-source policies, used under CC BY 4.0.

Sokndall tracks provider credentials and payer enrollment applications for small practices and billing companies. No PHI.

Start free trial

Questions? support@sokndall.com. Written support only.

Product

Payer enrollmentPricingFor billing companies

Compare

Best credentialing softwaresymplr pricingModio Health pricingMedTrainer pricing

Guides

Credentialing for therapistsBehavioral health credentialingCAQH reattestationCAQH Provider Data PortalCredentialing checklistCredentialing servicesFree spreadsheet template

Company

AboutSecuritySign in
© 2026 Sokndall. All rights reserved.TermsPrivacyNo patient data. No PHI. No BAA to negotiate.