AXIONIA
Privacy & data use

Your numbers stay yours. The patterns are what we learn from.

We ask employers for information most of them consider proprietary, so we owe a plain answer about what happens to it. This page describes what the system actually does, not what a template says.

Last updated 6 August 2026

The commitment that matters most

No data about a specific company is ever disclosed, named, or referenced in any external material that isn’t for that company. Not in a benchmark report shown to someone else, not in a sales deck, not in a case study, not in conversation with a broker, carrier or vendor.

We do use what we learn for research and benchmarking. That work is aggregate: patterns across many employers, never a row you could trace back to one. Where a group is small enough that an aggregate figure would effectively identify a participant, we don’t publish the figure.

What we deliberately don't collect

Worth stating first, because it’s unusual and it’s enforced in the database rather than in a policy.

No member-level health data. Our intake accepts aggregate, de-identified information only — counts, bands, program names. We don’t ask for a census containing names, dates of birth or identifiers, and we don’t want one. This keeps Axionia outside HIPAA scope by design rather than by promise. If you send member-level data anyway, we will tell you and delete it.

No IP addresses. Our analytics and view-logging tables have no column for one. Location, where we show it, comes from our hosting provider already resolved to country or city, so the address itself is never written down.

No advertising trackers. Our analytics are first-party. Nothing you do here is sold, shared with an ad network, or used to follow you elsewhere.

Identifying the organisation you work for. On the pages where we share documents with prospective clients and investors, we try to work out which organisation a reader belongs to, so that we know whether the people we sent something to have read it. We do this in three ways, and where we can we use the first: the document link we sent you already records who we sent it to; the email address you give us tells us your employer’s domain; and for readers we know nothing else about, we may ask a third-party service which organisation an internet connection belongs to. That last method sends your IP address to that service. It is often wrong, and we record how we reached each conclusion so we know not to rely on it. We keep only the answer — the organisation’s name — and never the address it was derived from.

What we do collect

Account information — name, work email, company, and the role you tell us. Needed to give you an account and send you your report.

What you tell us about your programs — your benefit mix, vendors, carriers, states of operation, covered lives, and anything you ask us to look into. Some of this is optional; where it is, the form says so and says what it buys you.

Documents you send us — vendor decks, renewal packets, benefit summaries. Held for the work and deleted on request.

First-party usage — which pages were viewed, and whether a report was opened or printed. Tied to a session cookie and, once you submit a form, to your account.

How your data becomes a benchmark

The benchmark is the point of the product, so it’s worth being precise about how it’s built.

Your portfolio is reduced to structured attributes — industry, workforce shape, size band, which program categories you run, region. Those attributes join a pool. When we tell another employer how their portfolio compares, they see a distribution, never a list of companies, and never a company name.

The company-level record stays attached to you, and is used for your own analysis, your own year-over-year comparison, and nothing else.

Who else sees it

Our people. Analysts and subject-matter reviewers contracted by Axionia, under confidentiality terms, and only for the work in front of them.

The infrastructure we run on. Supabase (database and authentication), Vercel (hosting), Anthropic (the models behind our analysis), Resend (transactional email) and Cloudflare (DNS). They process data to provide those services and for no purpose of their own.

Nobody else. We take no compensation from any vendor, broker or carrier, and we don’t give them your data either. There is no arrangement under which your information reaches a party selling to you.

Keeping it, and getting rid of it

Account and report data is kept while your account is open and for as long as we may reasonably need it afterwards. Uploaded documents are deleted on request.

You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. Email privacy@axionia.com and a person will answer.

One limit worth stating honestly: aggregate benchmark statistics already computed cannot be unwound for one participant, because they no longer contain a participant. Deleting your data stops it contributing to anything future.

Changes

If this page changes in a way that affects what we do with data already collected, we’ll tell account holders directly rather than quietly updating the date at the top.

Axionia is operated by CareVisory LLC. Questions about anything here go to privacy@axionia.com.