Privacy and data handling, in plain language.
Trust is the whole product. This page describes exactly how Reeve treats data today, what we do not do, and where we are honest about the paper still being drafted. If anything here changes, this page changes first. Last revised 2026-09-08, taken from the commit history of the page rather than typed in by hand. Effective 2026-07-27. Last reviewed against the database as it stands on 2026-09-09.
How the Margin Review actually handles your file
Your file is processed in your browser. Names, member identifiers and addresses are removed and replaced with coded references before any arithmetic runs, and no name is written into any output. Dates of service are kept, because the filing deadlines cannot be computed without them. This is not HIPAA Safe Harbor de-identification and Reeve does not claim it is. It is pseudonymization with dates retained, and it is why Reeve will have a signed business associate agreement in place before it processes a real client record.
Being complete about it: alongside the coded references, a run still holds service dates, the county or ZIP used to pick the right rate, a coded caregiver reference used for the shared-visit and long-day checks, service codes and modifiers, and rate and paid amounts. On a small book any of those can narrow a row toward a person. All of it stays on your machine for the length of the browser session, and none of it is transmitted.
A formal expert determination and a written data-use paper are gated before the first paying customer. That plan has not changed. Until they are signed, the description above is the accurate one.
Reeve is read-only
Reeve does not write to an EMR. It does not create, edit, or delete a record in any upstream system. It does not file a claim, does not touch a clearinghouse, and does not move money. The mechanism is plain rather than clever: no write path exists in the product.
That posture is deliberate. A tool with no write path has no way to cause a billing incident.
Where we are still honest about the paper
A formal Data Use Agreement and Business Associate Agreement are being drafted by a healthcare attorney. They are not yet in place. Until that paper is finalized and signed, Reeve will not process a real named record for your agency on any surface other than the in-browser Margin Review.
We would rather say this plainly than imply a legal footing we do not have. When the agreements are ready, this page and any paid-tier onboarding will reflect it.
What the marketing site itself collects
- ›Contact details you give us on purpose. If you book a call or email hello@get-reeve.com, we keep your name and email so we can reply.
- ›One page view counter, and not ours. Reeve runs no analytics script, no tag manager and no pixel of its own. The hosting platform injects a page view counter (Tinybird web analytics, loaded from /~flock.js on this origin) that records the page path and address, the referring page, the browser's user agent and language and a country derived from its time zone, sets a thirty minute cookie named session-id, and reports to /~api/analytics on this origin. Reeve does not read that data, does not join it to anything, and does not send it a single field from a review. It is the platform's counter, and the switch for it is in the platform, not in this code. The hosting layer keeps ordinary web server request logs, which is how any website works, and we do not join them to anything.
- ›No selling of data, ever. Reeve does not sell, rent, or share visitor data with third parties for marketing.
- ›No tracking cookies. The site sets no advertising cookie and no cross-site identifier. Signing in to the workspace sets a session cookie, which is the only cookie Reeve sets, and it exists so you stay signed in. The hosting platform's page view counter sets a second cookie, session-id, for thirty minutes; Reeve sets none of its own on the marketing site.
What Reeve will not do
- ›Will not upload your billing export from the Margin Review to a Reeve server.
- ›Will not store identified client data from the review after your browser session ends.
- ›Will not write to your EMR, file a claim, or move money on your behalf.
- ›Will not quote a recoverable dollar figure for a state whose Medicaid fee schedule Reeve has not verified.
The workspace, and what it enforces
The paid workspace is an account layer around the same review. These sentences are printed from a table in the code, and each one is tied to the control that backs it, so a claim here cannot outlive the mechanism it describes.
- ›A session on this machine ends after thirty minutes without activity, and you are warned one minute before it does.
- ›A session ends thirty days after it began, however active you have been.
- ›Every change to people, roles, invitations, settings and runs is recorded in a trail an owner or an admin can read and nobody can edit or delete.
- ›Findings stay in the browser that ran the review. What reaches us is the fact that a run happened, over how many rows, and the totals if you keep them.
- ›A run can be sealed into an encrypted file for a colleague in the same workspace; the file opens only inside that workspace and only with a passphrase, and no server is involved in either direction.
- ›A run covering fewer than five clients records no totals at all, whatever the keep totals setting says.
- ›Only an owner can grant or remove the owner role, and the last owner of a workspace cannot be removed. The database refuses it, not the screen.
- ›An export carries a handling sentence on its first row, because the file holds dates of service and claim numbers.
Contact
Questions about how Reeve handles data, or a specific request about your own information, go to privacy@get-reeve.com. That inbox is read by a person.
A security report, or a question from a security review, goes to security@get-reeve.com.
Collect is money you never captured. Cover is money a payer can still take back.
Reeve reports the two separately and never adds them together, because only one of them is yours to go and get. The Margin Review reads both on your own export and costs nothing.
One pass over your own export, in your browser. The findings are yours to keep, with no obligation.
The recovery lane. Care you delivered and never billed, units short of what was authorized, lines paid under the published rate.
Everything in Collect, plus the exposure lane. Retired codes, authorizations at the end of their period, care delivered past what was approved.
Month to month, no annual contract. Read-only in every tier. Run the free review.
See it work on your own book.
The Margin Review runs on your machine. Load a closed-period export, watch names get replaced with a coded reference locally, and keep the findings.