Privacy Policy
Effective September 29, 2026
- We don’t sell or rent your data, and we don’t use it for advertising.
- We keep your account, a hash of each API key, and a usage record for every request: what was called and what it cost you, not what you searched for.
- Server access logs include request URLs and IP addresses and are deleted after 30 days.
- Card details stay with Stripe. The prices we serve are public data, not data about you.
Who we are
TiC Explorer runs ticexplorer.com, its developer console and the API at api.ticexplorer.com. This policy covers all three. Questions: privacy@ticexplorer.com.
What we collect
- Account. Sign-in is handled by Clerk. We receive your Clerk user ID and email address, and Clerk stores your name and sign-in details.
- API keys. We store a one-way hash of each key, its name and a short prefix. The full key is shown once and never stored.
- MCP connections. When you authorize an AI app, we store hashed OAuth tokens. Access tokens expire after one hour and refresh tokens after 30 days without use.
- Usage records. For each request: the time, the operation (for example, a rate lookup), the result status, the key or connection used, and the price. Usage records do not contain your search terms.
- Access logs. Our servers and Google Cloud’s load balancer log requests, including the full URL (with any query parameters you send), your IP address and user agent. Request bodies are not logged.
- Billing. Stripe processes payments. We keep your Stripe customer ID, card brand, last four digits and expiry, your plan, and your invoices. Full card numbers never reach us.
Health-related searches
Searches such as a billing code or a provider’s name can relate to health care. They are not stored with your usage records, but they can appear in access logs for up to 30 days. Please don’t put names, member IDs or other personal details in queries. TiC Explorer is not designed to receive protected health information.
How we use it
To run the service, sign you in, meter and bill usage, prevent abuse, fix problems, and contact you about your account or billing.
Who we share it with
- Clerk, for sign-in.
- Stripe, for payments and invoices.
- Google Cloud, which hosts the service, its logs and backups in the United States.
- To answer some searches we send the search text, without your account details, to outside services: a language-model API for billing-code searches and the US Census Bureau geocoder for addresses.
- Authorities, when the law requires it.
Cookies
Clerk sets session cookies so you stay signed in. The console remembers whether its sidebar is open (a cookie, 7 days) and your theme (browser storage). Stripe may set cookies on the billing page. We use no analytics, advertising or tracking cookies.
How long we keep it
- Account, key and billing records: while your account is open, and afterwards as long as tax and accounting rules require.
- Usage records: for the life of your account.
- Access logs: 30 days.
- Database backups: daily, kept up to 180 days.
The data we serve
The prices come from files that health plans and hospitals must publish under federal price-transparency rules, and from public Medicare data. They describe plans and providers, not individual people.
Your choices
You can revoke keys in the console at any time. To see, correct or delete your data, or to close your account, email privacy@ticexplorer.com. We’ll respond within 30 days.
Security
Traffic is encrypted in transit, keys and tokens are stored only as hashes, and access to production systems is limited.
Children
The service is for developers and businesses, not for children under 16.
Changes
We’ll post changes here with a new effective date, and email you about material changes.