Skip to main content

Privacy Policy

Last updated: 2026-05-11

The OEP-decoder runs in your browser

When you use MedigapWindow.com’s federal Medigap OEP decoder, you enter your date of birth, your Medicare Part B effective date, your state of residence, and whether you’re currently enrolled in Medicaid. These values never leave your device. The calculation runs in your browser using JavaScript that executes locally; no values are transmitted to our servers, logged, or sent to any third party.

We track only aggregate, non-identifying counts for product analytics — for example, what percent of overall sessions result in an “OEP open” output versus “OEP closed” versus “dual eligible.” No DOB, no Part B date, no state, no Medicaid status is ever logged.

What analytics we do run

We use Google Analytics 4 in a privacy-restricted configuration:

  • Consent Mode v2: by default, we deny all tracking categories. You may opt in to anonymous analytics via the cookie banner; analytics_storage is granted only after your explicit opt-in.
  • ad_storage is hard-coded denied. There is no opt-in path for advertising cookies on this property. You cannot enable advertising tracking even if you wanted to.
  • ad_personalization is hard-coded denied.
  • Google Signals (cross-device tracking) is disabled at the property level.
  • Granular location/device data collection is disabled at the property level.
  • IP anonymization is enabled.

We do not run any Google Ads remarketing tag, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, or other advertising tracker on this site. We do not run any session-replay tools (Hotjar, FullStory, etc.).

Why this matters for the Medicare-beneficiary audience

Medicare beneficiaries are classified as a Sensitive Audience under Google’s Personalised Advertising Policy. Our policy goes beyond the platform-required restrictions: we do not run advertising trackers at all on this content. The Medicare-broker industry has a scam-adjacent reputation in some quarters, and the audience reasonably treats sites that retarget them as a red flag. We earn trust by not retargeting at all.

Cookies

We use a single first-party preference cookie (mw-consent-v1) to remember your analytics opt-in / opt-out choice. If you opt in to analytics, Google Analytics 4 may set its own first-party cookies (_ga, _ga_*) on your device for measurement only.

Server logs

Our hosting infrastructure logs HTTP requests (URL, status code, IP address, user-agent string, request timestamp) for security and operational purposes. These logs are not used for advertising or behavioral profiling. They are retained for a limited period and then deleted.

Third-party links

This site links to medicare.gov, cms.gov, state insurance department websites, the federal SHIP locator, and other authoritative sources. When you follow a link, you are subject to the privacy policy of the destination site. We have no control over those sites’ privacy practices.

Your rights

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete it, and the right to opt out of any sale. We do not sell or share personal information for advertising. To exercise any of these rights, contact us using the address on our About page.

Contact

For privacy questions, contact us using the address on our About page.