Data Protection & HIPAA-Conscious Design

Privacy Policy

Effective Date: September 13, 2026 • Version 2.2

Zero-Health-Data Model Training Guarantee

ClaimAppeal AI strictly prohibits the use of your uploaded denial notices, Explanation of Benefits (EOBs), clinical charts, or generated appeal letters to train public or commercial artificial intelligence models. Your clinical and financial data is processed transiently and isolated to your private account.

1. Introduction

At ClaimAppeal AI (“we”, “our”, or “us”), we respect the deeply sensitive nature of healthcare coverage, medical billing, and clinical diagnoses. This Privacy Policy details how we collect, store, isolate, and safeguard your data when you access our platform and utilize our statutory appeal letter generator.

By using the Service, you consent to the data practices described in this policy. If you do not agree, please do not use the Platform or upload documents.

2. Information We Collect

We collect information only to the extent necessary to deliver high-fidelity appeal drafting:

Account & Auth Information

Email address, hashed authentication credentials managed through Supabase Auth, account role, and subscription status (e.g. Free 1-appeal allowance vs. Pro).

Denial Documents & Claim Inputs

Uploaded denial letters, EOB statements, insurer names, claim numbers, CARC/RARC codes, service dates, procedure descriptions, and relevant physician clinical notes.

Technical Metadata: We collect standard operational telemetry including browser user agent, IP address for fraud prevention and rate limiting, timestamps, and error diagnostics.

3. How We Use Your Data

  • Statutory Appeal Generation: To parse denial reasons, match them against federal statutory standards (ERISA § 503, ACA § 2719), and synthesize formal rebuttal correspondence.
  • Account & Quota Enforcement: To verify active access, track single-use free allowances (1 lifetime appeal), and manage premium subscriptions.
  • Security & Abuse Mitigation: To detect malicious bot activity, brute-force attempts, and unauthorized bulk scanning.

We do NOT sell, rent, or monetize personal health data or contact lists to pharmaceutical marketers, brokers, data brokers, or advertising networks.

4. HIPAA-Conscious Architectural Security

While ClaimAppeal AI directly serves consumers as an assistive drafting tool, our technology architecture incorporates safeguards aligned with the Health Insurance Portability and Accountability Act (HIPAA) Security Rule:

  • Cryptographic Encryption: All data is encrypted in transit using Transport Layer Security (TLS 1.3) and at rest utilizing Advanced Encryption Standard (AES-256).
  • Row-Level Security (RLS): Database tables enforcing Postgres Row-Level Security ensure that users can strictly query and access only records linked directly to their authenticated user identifier (`auth.uid() = user_id`).
  • Ephemeral Document OCR: When you upload a denial document or image for scanning, optical character recognition and parsing are processed securely, and files can be purged upon request.

5. AI Sub-Processors & Data Transmission

To generate legal and medical appeal rebuttals, sanitized text excerpts are transmitted to enterprise AI API providers (such as OpenAI Enterprise / Anthropic / Google Cloud Vertex). Under our enterprise service agreements:

  • Data sent via enterprise APIs is never retained for model training or RLHF tuning.
  • Payloads are processed under strict zero-data-retention or ephemeral logging policies.
  • Data transmissions are secured under TLS 1.3 point-to-point encryption.

6. Data Retention & User Deletion Rights

You retain complete authority over your claim history. At any time, you can:

  • Delete Specific Appeals: Remove individual appeal drafts from your dashboard, which cascades immediately across database records.
  • Account Termination: Request a complete account wipe by emailing privacy@claimappeal.ai or using the Settings menu. Upon account deletion, all associated health inputs, generated letters, and auth credentials are permanently expunged within 30 days.

7. Cookies & Local Storage

We maintain a minimal cookie footprint. We do not use third-party tracking pixels (such as Meta Pixel or Google Analytics advertising trackers) that monitor health-related searches.

Our cookies and local storage tokens are strictly functional:

  • Session State: Supabase authentication tokens stored in secure, HTTP-only cookie headers.
  • UI Preferences: Local storage key storing your preferred theme (Dark vs. Light mode).

8. Privacy Officer & Inquiries

If you have questions regarding this Privacy Policy, wish to exercise GDPR/CCPA consumer rights, or require information on data handling practices:

ClaimAppeal AI Data Privacy & Security Office

Email: privacy@claimappeal.ai

Support Ticket: claimappeal.ai/contact