Skip to content

LEGAL

Privacy Policy

Your privacy matters. This policy explains what data we collect, how we use it, and your rights as a user of RegenCompliance.

Last Updated: May 5, 2026

1. Introduction

Dibb Enterprises LLC ("Company," "we," "us," or "our"), operating as RegenCompliance, provides an FDA/FTC compliance scanning platform for healthcare practices at app.regencompliance.ai. This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our website and services (collectively, the "Service"). By using the Service, you agree to the practices described in this policy.

2. Information We Collect

We collect the following categories of information:

Account Information

Email address, password (hashed), clinic name, and treatment types offered. This information is collected during account registration and is required to provide the Service.

Scan Content

Marketing text you submit for compliance scanning, along with scan results, compliance scores, flagged violations, and AI-generated rewrites. This content is stored as part of your audit trail.

Billing Information

Payment details are collected and processed by Stripe. We do not store your full credit card number, CVC, or other sensitive payment details on our servers. We receive only a payment confirmation, last four digits of your card, and billing address from Stripe.

Usage Data

Information about how you interact with the Service, including pages visited, features used, scan frequency, and timestamps. This data helps us improve the platform.

Support Communications

If you contact us for support, we collect the content of your support tickets, including any attachments or screenshots you provide, along with your email address and communication history. This data is used solely to resolve your support request.

3. Information We Do NOT Collect

RegenCompliance is a marketing compliance tool. We do not collect, access, process, or store any of the following:

  • Protected Health Information (PHI) as defined by HIPAA
  • Patient data, medical records, or clinical records
  • Treatment histories or patient outcomes
  • Any data from your EMR, practice management software, or patient databases

HIPAA DISCLAIMER

RegenCompliance is NOT HIPAA compliant and is not designed or intended to process, store, or transmit Protected Health Information (PHI). You must not submit any content containing patient names, medical records, treatment histories, health conditions tied to identifiable individuals, or any other PHI through the Service. The Service is designed exclusively for analyzing marketing and advertising content. If you inadvertently submit PHI, contact us immediately at support@regencompliance.com so we can delete it from our systems.

4. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing and operating the Service, including running compliance scans, generating rewrites, and maintaining your audit trail
  • Processing payments and managing your subscription through Stripe
  • Improving our compliance rules database and scanning accuracy based on aggregated, anonymized scan patterns
  • Communicating with you about your account, service updates, and new features
  • Responding to support requests and providing customer service
  • Enforcing our Terms of Service and protecting against misuse

5. Third-Party Services

We use the following third-party service providers to operate the platform:

Supabase

- Database and Authentication

Stores your account data, scan history, and compliance records. Handles user authentication and session management. Data is encrypted at rest.

Stripe

- Payment Processing

Processes all subscription payments and billing. Stripe is PCI-DSS Level 1 certified. We never store your full payment details on our servers.

Anthropic (Claude API)

- AI Analysis

Scan content you submit is sent to the Anthropic Claude API for compliance analysis and rewrite generation. Anthropic processes this data according to their API data usage policy and does not use API inputs to train their models.

Vercel

- Hosting and Deployment

Hosts the RegenCompliance web application. Vercel provides edge network delivery, serverless function execution, and aggregate Web Analytics (Speed Insights and basic page-view counts collected without third-party cookies).

Resend

- Transactional Email (when activated)

Delivers transactional emails such as account confirmations, password resets, and billing notifications. Currently inactive; transactional email may be routed through GoHighLevel instead. Activated by the operator when configured.

GoHighLevel (GHL)

- CRM and Marketing Automation (when activated)

Receives contact records and pipeline events (signup, application, subscription lifecycle, account deletion) for sales follow-up and marketing sequences. Each event is opt-in via webhook configuration; missing webhook config means no data is sent.

Sentry

- Error Monitoring (optional)

Infrastructure is in place for error and performance monitoring. PII (email, IP, request bodies on auth/payment paths) is scrubbed before events reach Sentry. Currently disabled; enabled only when the operator configures the Sentry DSN.

Have I Been Pwned (HIBP)

- Password Breach Check

During signup and password reset, the SHA-1 prefix of the candidate password (first 5 characters) is sent to HIBP's k-anonymity API to check whether that password appears in a known breach. The full password and full hash never leave our server.

6. Cookies

We use a minimal number of cookies to operate the Service:

CookiePurposeDuration
regen_demoDemo session tracking for free compliance scans90 days
sb-*Supabase authentication and session managementSession / persistent
cookie_consentRecords your cookie consent preference1 year
__stripe_*Set by Stripe.js when you visit a checkout page or open the Customer Portal. Used for payment-fraud detection.Session / 1 year
_vercel_*Vercel infrastructure cookies (deployment routing, Speed Insights aggregation). No personal identifiers.Session

We do not use third-party advertising cookies, tracking pixels, or behavioral analytics cookies that share identifiable data with external parties.

7. Data Retention

Your scan history, compliance reports, and account data are retained for the duration of your active subscription. If you cancel your account, we retain your data for 30 days to allow for reactivation. After 30 days, your scan history, account data, and all associated records are permanently deleted from our systems. Anonymized, aggregated data that cannot be linked back to your account may be retained indefinitely for the purpose of improving our compliance rules.

8. Your Rights Under GDPR

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete personal data
  • Right to Erasure: Request deletion of your personal data
  • Right to Data Portability: Request your data in a structured, machine-readable format. You can also use our built-in data export feature in your account settings to download your scan history and compliance reports at any time
  • Right to Restriction: Request that we restrict processing of your personal data
  • Right to Object: Object to processing of your personal data for certain purposes

To exercise any of these rights, contact us at support@regencompliance.com. We will respond within 30 days.

9. Your Rights Under CCPA

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you
  • Right to Delete: Request deletion of personal information we have collected from you
  • Right to Opt-Out of Sale: We do not sell your personal information to third parties. There is nothing to opt out of
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights

To exercise your CCPA rights, contact us at support@regencompliance.com.

10. Data Security

We take the security of your data seriously. All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). Data stored in our database is encrypted at rest through Supabase's built-in encryption. Access to production systems is restricted to authorized personnel and protected by multi-factor authentication. While no system is 100% secure, we implement industry-standard security practices to protect your information.

11. Children's Privacy

The Service is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at support@regencompliance.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by email and/or through an in-app notification at least 14 days before the changes take effect. The "Effective Date" at the top of this policy indicates when it was last updated. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

13. Contact Us

For any questions about this Privacy Policy, to exercise your data rights, or to submit a data-related request, contact us at:

Dibb Enterprises LLC

Operating as RegenCompliance

Email: support@regencompliance.com

Website: app.regencompliance.ai