Credentialing Autofill · Last updated September 8, 2026
Privacy policy
This policy describes the Credentialing Autofill MVP extension and its product pages on richbirds.net. The extension and the website handle different kinds of information.
1. Who provides this product
Credentialing Autofill is provided by richbirds. Privacy and support inquiries can be sent to richbirds3930@gmail.com. Please do not include sensitive provider or patient information in an initial message.
2. Provider profiles stay on your device
You may enter provider names, contact details, practice locations, NPI and taxonomy identifiers, licenses, education, malpractice insurance, hospital affiliations and other credentialing fields. You may also store PDFs and their metadata. These are stored in the browser’s local extension storage, encrypted with a key derived from your vault password.
The extension does not upload provider profiles, document contents or portal-page contents to a custom server, to richbirds.net, or to an analytics service. The MVP has no provider cloud synchronization and no extension analytics or error telemetry.
3. Local scanning and filling
When you scan a page, the extension processes form labels, attributes, existing field values and nearby context locally to propose mappings. The preview is temporary. Only values you select and approve for filling are sent into the destination page. The payer portal then handles those values according to its own practices, including any automatic saving it performs.
Site access is used to scan and fill permitted pages and frames. Closed shadow roots and inaccessible frames may require manual entry. The extension does not submit forms automatically.
4. Passwords, encryption and backups
Your vault password is not sent to us. Provider data and PDF contents are encrypted with AES-256-GCM; the key is derived from your password using PBKDF2-SHA256. The working vault key is kept in background-service memory and cleared on lock or restart. A forgotten password cannot be recovered by us.
JSON exports are password-encrypted and include profiles and stored PDFs. Import replaces the local vault after successful decryption and validation. You control where you save and share backups. Files that you download or export remain on your device until you remove them.
Encryption does not protect data from every threat, including a compromised operating system, an unlocked browser session or a malicious destination portal. Use a strong password and follow your organization’s device-security requirements.
5. Purchases and license validation
Lemon Squeezy processes paid subscriptions and checkout. It may collect purchaser and billing information according to its own privacy policy. We may access purchase or subscription records made available through the merchant dashboard for billing and support.
The extension sends your license key and a randomly generated device-instance name or ID directly to Lemon Squeezy to activate, validate or deactivate Pro access. It does not send provider profiles with those requests. As with ordinary internet requests, the receiving service can receive your network IP address and request metadata.
The extension encrypts the locally stored license key, status, expiration, instance ID and verification timestamp using a device key stored in IndexedDB. This device key supports background checks independently of your vault password. License responses may contain customer metadata, but the extension does not retain customer name or email in its license cache.
A successful license check is cached for less than 24 hours. When a new check cannot be completed after that period, Pro features pause. Existing provider data remains available locally for reading and encrypted backup.
6. Copying, documents and sharing
Copying a value or filename puts it on your system clipboard. Downloading a PDF creates an ordinary local file that is no longer protected by the vault’s encryption. Other software may access clipboard content or files according to your device settings. You decide where to paste values, upload documents or share backups.
The document helper does not automatically assign files to a portal or transmit PDFs. No background upload is performed.
7. Website visits
Visiting richbirds.net makes ordinary requests to our web server. Server access and error logs can contain IP addresses, request times, requested URLs, status codes, browser information and referrers for operation, troubleshooting and security. These website logs are separate from extension provider data.
The Credentialing Autofill product and legal pages do not add advertising trackers, analytics scripts or a provider-data collection form. The shared showcase may store a language preference locally. Checkout and support links take you to services with their own data-handling practices.
8. Retention, deletion and your choices
Local profiles and documents remain in your browser until you delete them, replace the vault, clear extension storage or uninstall the extension. Deleting a profile also deletes its associated vault documents. Exported backups and downloaded PDFs are separate copies and must be deleted wherever you saved them.
Deactivate a license in the extension to release its device activation. Uninstalling the extension does not cancel a paid subscription. Use the subscription-management options provided with your purchase or contact support for billing assistance.
Website logs and support correspondence are retained as needed for operations, security and handling your request. Purchase records are handled through Lemon Squeezy. Contact us about access or deletion of information you supplied to us; we cannot retrieve or delete a vault that exists only on your device.
9. No sale or advertising use of provider data
We do not sell provider data or use it for advertising, data brokerage, credit decisions or unrelated profiling. The extension is an administrative data-entry assistant; it is not intended for patient records or clinical decision-making.
10. Changes and contact
We may update this policy as the product changes. The date at the top identifies the current version. Any future cloud or telemetry feature would require a corresponding update to the disclosed practices.
Questions: richbirds3930@gmail.com. Also read the disclaimer and human-review requirements.