Privacy Policy
Last updated October 10, 2026
EdPortus ("we", "us") runs edportus.com, learn.edportus.com and admin.edportus.com. EdPortus is EdPortus Medical Education, LLC, a Florida limited liability company in formation, based in Florida, USA. This policy explains what we collect, why, who we share it with, and your choices.
The short version
- We collect what we need to run your courses, certificates, tracking and reminders.
- We never sell your personal information and never share it for cross-context behavioral advertising. We use no third-party advertising trackers.
- We hold no patient information. Course cases are fictional. Do not upload any patient information.
- You can download your data from "My data" in your account (or ask us at support@edportus.com), and ask us to correct or delete it.
What we collect
Information you give us:
- Account: name, email, password (stored only as a one-way hash), degree and specialty, your National Provider Identifier (NPI), and, if you give them at sign-up or on your profile, your license state, number and expiration date. When you create an account we look up your NPI in the public national NPI registry (NPPES) and keep the result (the name, credential and status the registry lists, and any reason your account needed a manual review), plus when you agreed to the Terms of Use and this Privacy Policy and which versions. A resident without an NPI yet can still sign up; the account is then reviewed by our team.
- Founding 1,000 reservations: if you reserve a founding spot, your name, email, NPI, license state and specialty, whether you opted in to marketing email, and when you accepted the Terms. We look up your NPI in the public national NPI registry (NPPES, run by the federal Centers for Medicare & Medicaid Services) and keep the name the registry lists and any reason your reservation needed a manual review. We also keep your place in line or on the waitlist, your referral code and who referred you, when you confirmed your email address, and an administrator's decision if one was needed.
- Licenses and credentials: license numbers and dates, DEA number, board certification and other items you choose to track.
- Documents you upload to your vault, such as certificates and cards.
- Certificates you send to your certificate inbox: if you use your personal inbox address, we receive the email you send or forward to it, including the sender, subject, text and attachments, and read the certificate details from it (provider, title, date, hours, credit type and topics) for you to confirm before anything is added. See "Certificate reading" below.
- Learning records: courses started and finished, time spent, answers, test scores, evaluations, credits and certificates.
- Purchases: what you bought, when and for how much. Card details go straight to Stripe; we never see your full card number.
- Messages you send us.
- Office manager access: if you invite someone to help manage your licenses and credentials, their email address, whether they may only view or also edit, whether they may see full license and DEA numbers, when access was granted, renewed or ended, and what they did with it. You see that activity in your account. The person you invite needs their own EdPortus account, which does not have to belong to a physician.
- Reporting choices: whether you agreed to let us report your completions to CE Broker, and when. That is a separate choice from any other reporting.
- Notifications on your phone or computer: if you turn them on, the address your browser's push service gives us for that device, its encryption keys, a short device label (for example "Chrome on Mac") and when we last sent to it.
- Referrals: if you invite a colleague, or sign up through a colleague's invite link, the invited email address, who invited whom, when the colleague signed up and paid, and the free months given. To stop abuse we compare the card fingerprint Stripe gives us for each side (never the card number) and the email domains.
- Expense records you add for your yearly expense report: date, category, amount, note and any receipt.
- Questions you ask Ask EdPortus, if it is offered: we keep the question after removing your name and your license and NPI numbers, with your license state, degree and plan and the answer, but not your account, so we can check the answers.
- Wallet passes: which licenses and credentials you added to Apple Wallet or Google Wallet, so we can update or void the pass.
- Community posts and verification: if you post in Community, the videos and captions you post, and the National Provider Identifier you give us with the name, credential and specialty the public NPI registry lists for it. Your posts, display name, credential and specialty are shown publicly with your posts. Likes, reports and views of Community posts are kept as usage records. We may also ask you to confirm your identity before you can post, and we keep a record that you did.
Information we create automatically:
- Usage records: first-party records of what you open and answer in the Service, used to run and improve it. When you open a link in one of our emails, the link may pass through our own address first so we can count the click; no tracking pixels are used.
- Server logs: standard technical logs, which may briefly include your IP address, kept for security and troubleshooting and deleted within 30 days.
- Viewer ID for Community videos: when you watch a Community post, your browser keeps a random ID in its local storage (
edportus-viewer) so that a view is counted only once a day. It contains nothing about you, is sent only to us, and you can clear it with your browser's site data. - State guess: when you visit, our own server looks up your IP address in a downloaded table to guess your US state, so the home page opens on it. The address is not stored by this lookup and is not sent to anyone.
How we use it
- To create your account, deliver courses and issue certificates.
- To track your licenses and credentials and send the reminders you set up.
- To report completions when a state requires it or you ask us to. We report to CE Broker only after you agree to it separately; to withdraw that agreement, write to support@edportus.com. A report contains only what CE Broker needs: your name, your license state, profession and number, and the course, completion date and hours.
- To check that a person who creates an account, reserves a founding spot or posts in Community is a physician, using the public national NPI registry.
- To keep credit and activity records that accreditation rules require.
- To take payment, send receipts and prevent fraud.
- To keep the Service secure, fix problems and improve courses.
- To send marketing email, only if you opted in.
Certificate reading
When you upload a certificate or send one to your certificate inbox, our own software reads it first. We may also switch on an optional reading step by Anthropic, an AI company, which then receives the certificate's text or image for this one purpose and returns the details it finds. That step is switched off unless we turn it on. Either way, nothing is added to your records until you confirm it, and details read by AI are marked as such on the screen. Do not send anything with patient information to your inbox.
- Service emails, such as receipts, certificates, password resets, renewal notices and the reminders you turned on, are part of the Service.
- Marketing emails go only to people who opted in. Every one has a one-click unsubscribe link.
- Travel CE news is a separate opt-in. If you choose it, we use your renewal dates, the hours you still need, your state, the classes and trips you have bought from us before and, if your profile says you own or run a practice, that role (for group and seat offers) to choose which trips and classes to tell you about. We never put license numbers or credit details in emails. You can unsubscribe in one click without affecting other emails.
Who we share it with
We do not sell personal information or share it for cross-context behavioral advertising. We share only:
- Service providers that process data for us under contract:
- Stripe for payments;
- Amazon Web Services for hosting in the United States, document and video storage, and email through Amazon SES (sending, and receiving your certificate inbox);
- Resend, a backup email provider, if we switch email to it;
- Anthropic, only when the optional certificate reading described above is switched on, and, if Ask EdPortus is offered, for each question you ask: the question with your name and your license and NPI numbers removed, your license state and degree, and the rule facts we found for it.
- Push services: when you turn on notifications, we send each one to the push service your browser uses (Google for Chrome and Edge, Apple for Safari, Mozilla for Firefox, or Microsoft). The notification is encrypted so that the push service cannot read it.
- Google, if you add a license or credential to Google Wallet: the pass's label, type, state, masked number (last digits only), expiration date and status. Apple Wallet passes go from our server straight to your device; Apple's push service only tells the device that a pass changed.
- The national NPI registry: we send an NPI to the public NPPES registry to look it up. We send only the number.
- Video players: some course sections show a video from YouTube (in its privacy-enhanced mode, youtube-nocookie.com) or Vimeo (with its "do not track" setting). When such a section loads, your browser connects to that company, which receives your IP address and browser details under its own privacy policy. Our own videos and Community posts are served from our storage.
- Reporting systems, accreditors and course partners, when a state or accreditation rule requires it or you ask us to report. We send only what the report needs.
- Your organization, if you join one or it bought your seat: staff with access to that organization's account see your name and email as a member, and your completion status for any seat they bought. They see your requirement status only as totals across members, and only if you choose to share it. We log every time they view or download the member list.
- People you give office manager access to: the licenses, credentials and documents you let them see. License and DEA numbers stay masked for them unless you choose to show the full numbers. You can end their access at any time.
- Anyone you choose, for example when you share a link or send your records.
- The public, for Community posts you publish and the name, credential and specialty shown with them.
- For legal reasons: to comply with law or a valid legal request, to protect rights and safety, or as part of a merger or sale of the business, where the buyer would be bound by this policy.
Cookies
We use only the cookies we need:
- Sign-in session, to keep you signed in.
- State choice, to remember the state you picked.
- Appearance, to remember System, Light or Dark.
- Referral link, if you open a colleague's invite link: a first-party cookie (
ep_ref) keeps the invite code for 30 days so the free month can be applied when you sign up. It holds only the code and is never shared. - Campaign tags, if you arrive from a link that carries them (for example from an email or a partner site): we keep the tags and the date in a first-party cookie for 90 days so we can tell which links bring people to sign up. It holds no personal information and is never shared.
Stripe sets its own cookies on its checkout pages for payment and fraud prevention. YouTube and Vimeo may set their own cookies or similar storage when you play one of their videos in a course. We use no advertising cookies.
Besides cookies, your browser's local storage keeps the Community viewer ID described above, and the installed app keeps only the app's own files, never your account pages or documents.
Do Not Track: we do not track you across other sites, so a Do Not Track signal changes nothing about what we do.
How long we keep it
- Course records, such as completions, test answers, certificates and evaluations, with orders and receipts, are kept for at least six years because accreditation rules require it.
- Other account data, such as licenses, credentials, documents and their files, credit you recorded from other providers and imports, expense records, share links and settings, is removed from your account at once when you delete it and permanently deleted 90 days later. We keep your name and degree with your course records, certificates, receipts and our audit log, as described above, and the unsubscribe record for your old address.
- Messages to support: the text of a message is erased 180 days after it was written; the ticket and its dates stay.
- Server logs are deleted within 30 days.
- Founding reservations are kept while the founding offer runs and for as long as you hold a founding price; if you never join, you can ask us to delete yours.
- Notification addresses are deleted when you turn notifications off for a device or delete your account.
- Unsubscribe records are kept so we can keep honoring your choice.
Security
- All traffic is encrypted in transit.
- License numbers are encrypted at rest, and DEA numbers are shown masked.
- Passwords are stored only as one-way hashes, and documents are kept in private storage.
- Course videos, narration and Community videos are streamed through short-lived links rather than offered for download.
- Watermark: when you are signed in, course screens, quick learn items and videos show a faint watermark with your name and the last four digits of your NPI (or your email if you have not given an NPI). Only you, and anyone looking at your screen, see it. It is there to discourage copying and to trace copies that are shared.
No method is perfect. If a breach affects your personal information, we will notify you as required by law, including Florida's Information Protection Act (Florida Statutes section 501.171) and the laws of other states.
Your rights
Everyone can use these rights, whatever state you live in:
- Access and download your data any time from "My data" in your account, or by writing to support@edportus.com.
- Correct your information in your account, or ask us to.
- Delete your account and data, except records we must keep for accreditation, legal or tax reasons. Those are kept only for that purpose.
- Opt out of marketing at any time.
Email support@edportus.com for anything you cannot do in your account. We answer within 30 days and may need to confirm your identity first. We will not treat you differently for using these rights.
California residents may ask whether we shared personal information with others for their direct marketing. We do not.
Children
The Service is not directed to anyone under 18, and we do not knowingly collect information from children. If you believe a child has given us information, write to us and we will delete it.
Where data is stored
Your data is stored and processed in the United States.
Changes to this policy
We will post any change here with a new date. For material changes, we will email you before they take effect.
Contact
Email support@edportus.com. We answer within five business days.
IP geolocation by DB-IP (db-ip.com), licensed under Creative Commons Attribution 4.0.