Privacy · Spectre Spaces

Policies

Privacy

Spectre Software Solutions LLC ("S2olutions") operates this page, s2olutions.com, and the Spectre Spaces desk. This is what that desk does with information. It is not legal advice, and it does not replace the data retention page.

This page

Effective September 22, 2026.

Spectre Spaces™ is a product of Spectre Software Solutions LLC. A licensed agency's name on a desk is a tenant label. It does not make that agency the owner of this page.

The request-access form on s2olutions.com asks for your name, email, the product you want access to, and an optional note. S2olutions uses that to answer the request. This form is not an insurance application.

This page does not ask you to buy a plan, and it does not give personal legal advice.

What Spectre Spaces is

Spectre Spaces is an agency workspace. A signed-in agent keeps a book of clients, notes, tasks, documents, and meetings for their own agency. It is software for that desk. It is not a Medicare plan, not a carrier, and not a way for an agent to look up someone else's Medicare history.

This covers agents and agency staff who sign in to a Spectre Spaces workspace, people whose information an agency records on that desk, and a Medicare beneficiary who chooses to authorize Spectre Spaces, through CMS, to receive their Blue Button data.

Information on the desk

The agency decides what to type into the book. That can include a client's name, contact details, household, policy notes, appointments, and documents the agency uploads. Social Security numbers and Medicare Beneficiary Identifiers are not a search key in Spectre Spaces. Where the desk stores a last-four or an identifier slot, that slot is a pointer for the agency, not a pull against Medicare.

Sign-in uses a session for the agent's account: name, email, role, and agency. We use that session to show the right book and to keep one agency from reading another.

Medicare data, only after the beneficiary authorizes it

CMS Blue Button 2.0 is a beneficiary-authorized API. Spectre Spaces uses Version 2 (FHIR R4 and OAuth 2.0). The beneficiary signs in with Medicare and chooses what this application may read. Access is for that person and this application. It is not a general Medicare database, and it is not a carrier enrollment API.

When the beneficiary allows it, Spectre Spaces may store coverage information, Medicare Part A and Part B claim explanations, Medicare Part D prescription claim information (including Part D events that CMS includes for a Medicare Advantage enrollee who has Part D), Explanation of Benefits resources, dates, and claim information returned by Blue Button, and beneficiary demographics only if the beneficiary allows the Patient read. They can deny that and still allow coverage and claim explanations.

Blue Button does not provide Medicare Part C claims. Spectre Spaces does not present Part C claims as if they came from this connection.

Those Medicare resources are stored on a Medicare Data record for that client, separate from the ordinary book row. The connection can be revoked. Revocation clears the tokens and the stored claim payloads and keeps an audit line of the action. Tokens are encrypted at rest and are not shown to the browser.

CMS operates the Medicare.gov authorization screen and the Blue Button API. Their own notices apply to that step. Spectre Spaces receives only what the beneficiary's authorization and the approved scopes return.

What we do not do

Who can see a record

An agent sees the clients on their own desk. An agency owner can see the agency's book. A person at another agency cannot. Medicare payloads are shown inside that same boundary. Support access, if we ever need it to fix an account, is limited to what the agency asks us to look at.

How long we keep it

Desk records stay until the agency deletes them or closes the workspace. A revoked Medicare connection drops the claim payloads and tokens. Audit lines that say an authorization started, completed, or was revoked can remain so the agency has a history of the connection. They do not keep the claim body.

Those sentences are about the workspace book. This host's own timers are the ones on the data retention page, and this page does not set a different period. A session record and its cookie expire after 12 hours. A CSRF cookie lasts 1 hour. After a contact note is mailed, this host keeps a copy for 30 days. A failed-send note lasts 1 hour. An activation link lasts 48 hours. Approved seats and analytics outcomes have no expiry timer. A destruction schedule for seats and analytics outcomes is not automated yet.

Security

Workspaces are separated by agency. Sessions are required for the book and for Medicare Data. Blue Button tokens and the PKCE verifier used during sign-in are encrypted with a server key and are not returned to the page. No method of storage is perfect. The agency still has to protect its own logins.

Health information

A book of insurance clients, and Medicare claims in particular, can be health information. Spectre Spaces is built so that information stays inside the agency workspace and so Medicare claims are not copied onto the ordinary client row. The agency remains responsible for its own legal duties, including HIPAA where HIPAA applies to that agency. This policy does not make S2olutions the beneficiary's doctor, plan, or insurer.

Children

Spectre Spaces is a tool for agencies. It is not directed at children under 13.

Changes

If this policy changes, the date at the top changes with it. A beneficiary can disconnect Medicare data at any time, including after a change.

This host and the pixel

Public pages on this host load a Meta Pixel, id 3752929798220720, and send a PageView only. They do not send email or phone. The data retention page does not load that pixel. The signed-in desk and analytics do not load it either. How long Facebook keeps a PageView is not set here.

Contact

Spectre Software Solutions LLC
Privacy questions: privacy@s2olutions.com
Site: s2olutions.com

The privacy statement for the S2olutions website, consulting, and the other house products is a separate page. This page is the Spectre Spaces desk.

Terms · Data retention