Privacy Policy

Stellar Inc. — SENTINEL · Effective 2026-08-11 · Last updated 2026-08-11

Stellar Inc. ("Stellar," "we," "us") provides SENTINEL, a documentation-integrity software product for skilled nursing and post-acute providers. This Privacy Policy explains how we handle information for our website and our product. SENTINEL is in active development; some capabilities described in our materials are not yet generally available.

1. Scope

This policy covers (a) visitors to our website and (b) the data our product processes when a provider authorizes SENTINEL to connect to its systems. It does not change any Business Associate Agreement (BAA) or customer contract, which govern in the event of a conflict.

2. Information we collect

Website visitors. If you contact us or join an interest list, we collect the information you provide (e.g., name, work email, organization, role) and standard technical data (e.g., IP address, browser type) via essential cookies. Please do not submit any patient information through our website forms.

Product data (provider-authorized). When a provider authorizes SENTINEL, the product accesses current clinical documentation on a read-only basis through the provider's authorized data connection to evaluate documentation completeness and timeliness at the point of care. SENTINEL is observe-only — it does not write back to the record and makes no clinical decision.

3. Protected Health Information (PHI)

Where SENTINEL processes PHI on a provider's behalf, we act as a Business Associate under a BAA and handle PHI only as that BAA and HIPAA permit. SENTINEL is designed to minimize and not retain identifiable PHI: identifiable data remains in the provider's environment, and our processing is designed so that identifiable PHI is not stored at rest by Stellar. We retain only non-identifiable operational data.

4. How we use information

To operate, secure, and improve the product and website; to communicate with prospective and current customers; and to meet legal and contractual obligations. We use provider-authorized clinical data solely to perform the documentation-integrity service for that provider.

5. We do not sell your data

We do not sell personal information or PHI, and we do not use provider clinical data to train models for other customers or purposes.

6. Sharing

We share information only with service providers/subprocessors acting on our behalf under appropriate agreements, a provider's own authorized systems, and as required by law. A current subprocessor list is available to customers on request.

7. Security

We use administrative, technical, and physical safeguards appropriate to the data, including access controls, encryption in transit, and a minimize-and-don't-retain design for PHI. No method is completely secure.

8. Retention

Website contact data is kept only as long as needed for the purpose collected. Product operational data follows our retention standard (short-rolling for detail; PHI not retained at rest). Records required by law are kept for the required period.

9. Your choices

You may request access to, correction of, or deletion of personal information you provided to us, subject to legal and contractual limits. For PHI, requests are handled through the provider (the covered entity) under HIPAA.

10. Children

Our website and product are not directed to children.

11. Changes

We may update this policy; we will post the new effective date here.

12. Contact

Stellar Inc., New Martinsville, West Virginia · toni@stellarclinical.com