PRIVACY POLICY
Together4Cancer® · NeedleSpotter Inc.
Effective date: April 27, 2026 · Last updated: April 27, 2026
This Privacy Policy is divided into two sections:
Section A covers patients and caregivers using together4cancer.com and Before Treatment Starts™.
Section B covers healthcare professionals subscribing to the Together4Cancer® Compass newsletter at together4cancer.org.
Please read the section that applies to you.
For all privacy questions: contact@together4cancer.com
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SECTION A — PATIENTS AND CAREGIVERS
together4cancer.com · navigator.together4cancer.com · Before Treatment Starts
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
This section governs the collection, use, and protection of information from patients, caregivers, and family members using together4cancer.com and the Before Treatment Starts™ pre-treatment navigation platform at navigator.together4cancer.com.
—
A1. WHO WE ARE
NeedleSpotter Inc. is a New Jersey-based company operating the Together4Cancer® patient education platform and the Before Treatment Starts™ pre-treatment navigation tool. Our mission is to help newly diagnosed cancer patients and their caregivers make informed decisions before treatment begins.
—
A2. WHAT INFORMATION WE COLLECT
Information you provide directly
Name and email address — collected when you purchase access to Before Treatment Starts™ or any Together4Cancer® product through our checkout process.
ZIP code — collected at purchase, used to provide location-relevant resources and for aggregate geographic analysis.
Clinical context — information you share during your Before Treatment Starts™ navigation session, including cancer type, stage, proposed treatment, testing status, and questions for your care team. This information is used solely to personalize your navigation experience and generate your Decision Readiness Record™ and Pre-Appointment Patient Brief.
Information collected automatically
Session behavior (PostHog) — The Before Treatment Starts™ platform uses PostHog analytics to track session behavior, including which stages of the navigation tool you complete, how many messages you exchange, and whether you generate your documents. Your email address is used to associate these events with your account. PostHog data is used to improve the platform and understand how patients use the tool.
Website analytics (Google Analytics) — Standard web analytics data including pages visited, time on site, device type, and referral source, collected on together4cancer.com.
Advertising attribution (Facebook Pixel) — If you arrived at our site through a social media advertisement, Facebook Pixel may collect standard advertising attribution data including page views and purchase events, in accordance with Meta’s data use policies.
Supabase session data — Your session progress, stage completion, and document generation status are stored in our Supabase database, associated with your email address. This data is used to allow you to return to your navigation session and to generate aggregate platform insights.
Technical data — IP address, browser type, device type, and operating system, collected automatically as part of standard web server operation.
Future tracking — educational grant sponsor pixels
In the future, Together4Cancer® may partner with pharmaceutical companies through unrestricted educational grants. Sponsor-provided pixels may be placed on the platform for the purpose of measuring the reach of educational content. We will update this Privacy Policy before implementing any sponsor tracking and will disclose the specific nature of any such tracking at that time.
Future products
Additional tools and products may be added under the Together4Cancer® umbrella over time, including ChairSide™ and other patient and caregiver resources. Each new product will be covered by this Privacy Policy. Where a new product involves meaningfully different data practices, we will update this Privacy Policy and notify users accordingly.
What we do not collect
We do not collect your Social Security number, insurance information, medical record numbers, date of birth, or any other identifier that constitutes Protected Health Information (PHI) under HIPAA. We do not sell your personal information. We do not share your individual clinical information with any third party.
—
A3. HOW WE USE YOUR INFORMATION
To provide and personalize the platform
We use your email to grant you access to Before Treatment Starts™ and send your access link. We use your clinical context to generate your personalized Decision Readiness Record™ and Pre-Appointment Patient Brief. This clinical information is processed in real time through Anthropic’s Claude AI via a secure server-side proxy and is not stored in a way that links your full identity to your complete clinical narrative.
To improve the platform
We use aggregate, de-identified session behavior data to understand how patients use the tool, which stages generate the most engagement, and where the navigation experience can be improved. This analysis is conducted at the population level, never at the individual level.
To communicate with you
We use your email address to send your access link, important platform updates, and — if you have opted in — educational content from Together4Cancer®. You can unsubscribe from marketing communications at any time by clicking the unsubscribe link in any email or by contacting us at contact@together4cancer.com.
Aggregate patient insights shared with educational grant sponsors
De-identified, aggregate data about patient decision patterns may be shared with pharmaceutical companies and other organizations that support Together4Cancer® through unrestricted educational grants. This data is always aggregate — for example: “40% of lung cancer patients using the platform had not had comprehensive biomarker testing ordered before their first treatment appointment.” No individual patient is ever identified in any data shared with sponsors. Your name, email, and clinical details are never disclosed to any third party.
—
A4. HOW WE STORE AND PROTECT YOUR INFORMATION
Before Treatment Starts™ and all Together4Cancer® patient platforms are built on HIPAA-grade security architecture. Specifically:
· All data is encrypted at rest using AES-256 encryption in our Supabase database.
· All data is encrypted in transit using SSL/TLS.
· Your clinical session data is never exposed to the browser — all AI processing occurs server-side through a secure proxy.
· Row Level Security is enforced on all database tables.
· Access to your account requires authentication via a time-limited secure token sent to your email address.
· We do not log or store your clinical conversation content in plain text in any location accessible to unauthorized parties.
We have initiated the Business Associate Agreement (BAA) process with our AI infrastructure provider, Anthropic, as part of our commitment to maintaining HIPAA-grade data handling practices.
—
A5. THIRD-PARTY SERVICES
We use the following third-party services to operate our patient platforms:
Anthropic — AI processing for Before Treatment Starts™. anthropic.com/privacy
Supabase — Database and authentication. supabase.com/privacy
PostHog — Session analytics. posthog.com/privacy
Google Analytics — Website analytics. policies.google.com/privacy
Meta (Facebook Pixel) — Advertising attribution. facebook.com/privacy/explanation
Resend — Transactional email delivery. resend.com/privacy
Vercel — Platform hosting. vercel.com/legal/privacy-policy
Voyage AI — Clinical content retrieval. voyageai.com/privacy
—
A6. YOUR RIGHTS AND CHOICES
Access and correction — email contact@together4cancer.com to request access to or correction of your personal information.
Deletion — email contact@together4cancer.com to request deletion of your account and associated data. We will delete your information within 30 days except where required by law.
Unsubscribe — click the unsubscribe link in any email or email contact@together4cancer.com.
Cookie and tracking opt-out — install the Google Analytics Opt-out Browser Add-on to opt out of Google Analytics. Manage Facebook ad preferences through your Meta Ad Preferences settings.
—
A7. CHILDREN’S PRIVACY
Our patient platforms are not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. Contact contact@together4cancer.com if you believe a child under 13 has provided us with personal information.
—
A8. CALIFORNIA PRIVACY RIGHTS (CCPA)
If you are a California resident, you have the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of your personal information. We do not sell personal information. Contact contact@together4cancer.com to exercise your rights.
—
A9. CHANGES TO THIS SECTION
We will update the “Last updated” date at the top of this page when we make material changes and notify you by email where appropriate.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SECTION B — HEALTHCARE PROFESSIONALS
together4cancer.org · Together4Cancer® Compass Newsletter
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
This section governs the collection, use, and sharing of information from healthcare professionals who subscribe to or interact with the Together4Cancer® Compass newsletter at together4cancer.org. This section is also relevant to pharmaceutical companies and healthcare organizations considering commercial arrangements with NeedleSpotter Inc. in connection with Compass.
—
B1. WHO WE ARE
NeedleSpotter Inc. operates the Together4Cancer® Compass, a clinician-facing oncology newsletter delivering clinical decision gap content, patient communication tools, and actionable guidance to community oncologists, nurse practitioners, and other healthcare professionals across the United States.
NeedleSpotter Inc. also operates NeedleSpotter, a B2B oncology marketing agency that partners with pharmaceutical companies on HCP-targeted educational programs. Compass is one channel through which these programs are delivered.
—
B2. WHAT INFORMATION WE COLLECT FROM COMPASS SUBSCRIBERS
Professional email address — collected when you subscribe to Compass, either through a direct subscription form or through outreach communications you have responded to or not opted out of.
Engagement data — we automatically collect data about your interactions with Compass emails, including whether you opened a specific issue, which links you clicked, the date and time of your interactions, your email client type, and approximate geographic location based on IP address at time of open. This engagement data is associated with your professional email address and, where applicable, your National Provider Identifier (NPI).
NPI association — where your NPI number can be matched to your professional email address through commercially available HCP data sources, we may associate your engagement data with your NPI for the purposes described in Section B3. You may opt out of NPI association at any time by emailing contact@together4cancer.com.
What we do not collect — we do not collect patient information through Compass. We do not collect your personal home address, Social Security number, or financial information through the Compass newsletter.
—
B3. HOW WE USE COMPASS SUBSCRIBER INFORMATION
Newsletter delivery
We use your professional email address to deliver Compass issues, including non-promotional educational content, disease state updates, patient communication tools, and — where applicable and clearly marked — promotional communications that have completed Medical, Legal, and Regulatory (MLR) review.
Platform improvement
We use aggregate engagement data to understand which content topics generate the most interest, inform our editorial calendar, and improve the quality and relevance of Compass content.
NPI-matched engagement reporting to pharmaceutical partners
Compass subscriber engagement data may be matched against National Provider Identifier (NPI) lists provided by pharmaceutical company partners for the purpose of measuring educational content reach among their target HCP audiences.
This process works as follows: a pharmaceutical partner provides us with an NPI list of healthcare professionals they seek to reach. We match that list against our Compass subscriber engagement data and report back which NPIs on their list engaged with specific Compass content and at what level.
What is shared with partners: matched engagement metrics only — open events, click events, and content interaction data associated with matched NPIs.
What is never shared with partners: subscriber email addresses, personal contact information, home addresses, or any individually identifiable information beyond NPI-matched engagement metrics.
Subscribers may opt out of NPI matching at any time by emailing contact@together4cancer.com with the subject line “Opt out of NPI matching.”
Sponsored email tracking tags and pixels
Individual Compass issues may include tracking tags, pixels, or identifiers added at the request of commercial partners for engagement measurement purposes. These tags collect open and click metrics only and do not transmit subscriber personal information to partners beyond NPI-matched engagement data described above. The presence of any sponsor tracking will be disclosed within the relevant Compass issue. Subscribers may opt out of all sponsor tracking by emailing contact@together4cancer.com with the subject line “Opt out of sponsor tracking.”
Promotional communications
Together4Cancer® may deliver MLR-reviewed promotional email communications to Compass subscribers on behalf of pharmaceutical company partners. All promotional communications will be clearly marked as promotional at the top of the email, identified by sponsoring company name, and compliant with applicable FDA promotional guidelines and PhRMA codes of conduct. Subscribers may opt out of promotional communications while remaining subscribed to non-promotional Compass content by emailing contact@together4cancer.com with the subject line “Opt out of promotional emails.”
—
B4. EDITORIAL INDEPENDENCE
Non-promotional Compass editorial content is produced independently by NeedleSpotter Inc. Commercial arrangements of any kind do not influence the editorial content, clinical positions, or therapy references in non-promotional Compass issues. All sponsored, promotional, or commercially supported content will be explicitly identified at the point of delivery in accordance with applicable FDA guidelines and PhRMA codes of conduct. NeedleSpotter Inc. reserves the right to enter into any lawful pharmaceutical or healthcare industry commercial arrangement in connection with Compass, provided editorial independence is maintained and all commercial relationships are disclosed to subscribers.
—
B5. THIRD-PARTY SERVICES
Email delivery platform — newsletter and transactional email delivery.
Google Analytics — website analytics on together4cancer.org.
Commercially available HCP data sources — used for NPI matching and professional email verification.
We will update this section as specific vendor relationships are established or changed.
—
B6. DATA RETENTION
We retain Compass subscriber engagement data for as long as you remain subscribed and for a reasonable period thereafter to fulfill obligations to commercial partners with whom engagement data has been shared. You may request deletion of your engagement data at any time by emailing contact@together4cancer.com.
—
B7. YOUR RIGHTS AS A COMPASS SUBSCRIBER
Unsubscribe — click the unsubscribe link in any Compass issue or email contact@together4cancer.com. Unsubscribing removes you from all future Compass communications.
Opt out of NPI matching — email contact@together4cancer.com with the subject line “Opt out of NPI matching.”
Opt out of sponsor tracking — email contact@together4cancer.com with the subject line “Opt out of sponsor tracking.”
Opt out of promotional communications — email contact@together4cancer.com with the subject line “Opt out of promotional emails.” You will continue to receive non-promotional Compass content.
Access and deletion — email contact@together4cancer.com to request access to or deletion of your engagement data. We will respond within 5 business days.
—
B8. CHANGES TO THIS SECTION
When we make material changes to Section B — particularly changes affecting how subscriber data is shared with commercial partners — we will notify subscribers by email before those changes take effect and provide a reasonable opt-out period.
—
CONTACT US
NeedleSpotter Inc.
Operating as Together4Cancer® · NeedleSpotter
New Jersey, USA
contact@together4cancer.com
We respond to all privacy requests within 5 business days.
—
© 2026 NeedleSpotter Inc. · Together4Cancer®
together4cancer.com/privacy





