Draft — pending legal review

Privacy policy

What we collect when you use Patient Bill, why, and the choices you have over your data.

Last updated: September 3, 2026

The short version

We collect the information needed to run your AI medical-bill audit, explain possible billing issues, generate self-help call scripts, secure your private workspace, and operate the Service. We don't sell your data, we don't share it for cross-context behavioral advertising, we don't use it to train third-party AI models, and you can ask us to delete your workspace and bills at any time.

1. Medical information and HIPAA status

Patient Bill is not a healthcare provider, health plan, or healthcare clearinghouse, so we are not a HIPAA "covered entity."New self-help workspaces do not require a HIPAA authorization. We receive the medical-billing information that you choose to upload or enter and use it to audit the bill and generate explanations and call scripts for your use. We do not request records from, contact, or act as your representative with providers or insurers.

We are not a "business associate" of your provider or insurer unless we sign a separate Business Associate Agreement with that entity. Your HIPAA rights (access, amendment, accounting of disclosures, etc.) run against your providers and insurers, not against us; we will, however, honor the access, correction, and deletion rights described below for the data we hold.

2. Categories of personal information we collect

Information you give us

  • Identifiers: any name, email address, phone number, or postal address you choose to provide. Email is optional.
  • Health information (sensitive PI): the bills, EOBs, itemized statements, medical records, diagnoses, procedure codes, dates of service, providers, and insurance details you upload or enter.
  • Patient details for non-self cases: name, date of birth, and contact info of the patient on the bill if that person is not you.
  • Community information: the pseudonymous display name, posts, replies, votes, saves, and reports you choose to submit in the public Community.
  • Historical signature data: legacy cases may retain typed or drawn authorization records and signing metadata.
  • Support correspondence: messages you send us.

Information collected automatically

  • Usage data: pages visited, features used, and rough timing — used to fix bugs and improve the product.
  • Device and log data: browser type, operating system, IP address, and security logs.
  • Cookies and similar technologies: see Section 11.

3. Sources, purposes, and recipients

The table below summarizes the categories of personal information we collect, where they come from, why we use them, and the categories of recipients we may share them with.

CategorySourceBusiness purposeRecipients
Identifiers, account infoYouSecure your private workspace; send an optional return linkHosting, email, error-monitoring vendors
Health information / sensitive PIYouAudit the bill and generate explanations and phone call scripts for you to useAI sub-processor and hosting vendors
Usage, device, log dataAutomaticSecurity, fraud prevention, debugging, product improvementHosting, analytics, error-monitoring vendors
Community posts, replies, and pseudonymYouPublish and moderate the patient-to-patient CommunityThe public, search engines, moderators, and hosting vendors
Historical signature and correspondence dataYou and legacy service vendorsMaintain authorization and mailing records for legacy casesHosting, record-retention, and legacy mail vendors

4. Sensitive personal information

Health information about you, and any non-self patient you authorize, is "sensitive personal information" under the California Consumer Privacy Act (as amended by the CPRA) and similar laws. We use it only to provide the Service you requested (and the supporting purposes listed in Section 3 above). We do not use sensitive PI to infer characteristics about you and do not use it for any purpose that triggers the right-to-limit under CPRA § 1798.121.

4A. Public Community content

Community posts and replies are public and may be copied, quoted, cached, or indexed by search engines. Your Community display name is a pseudonym and is kept separate from your private account email, workspace, uploaded bills, audit results, and assistant history. We do not intentionally publish those private records in the Community.

Do not post names, contact details, dates of birth, account or member numbers, medical-record numbers, or other information that identifies you or another person. We use automated screening to flag likely personal or health information before publication, but screening is not perfect. Community members may report content, and moderators may review, hide, restore, lock, or remove content and restrict accounts. Moderation records may be retained to enforce our rules and protect the Service.

5. Legal bases for processing (users outside the US)

Patient Bill is intended for users in the United States. If you access the Service from outside the US, your information will be transferred to, stored, and processed in the United States. Where the EU/UK GDPR or similar laws apply, we rely on the following legal bases: contract(to provide the Service you requested), consent (for marketing texts and non-essential cookies), legitimate interests (security, fraud prevention, product improvement, and direct service correspondence), and legal obligation (tax, recordkeeping, and responding to lawful requests).

6. What we don't do

  • We don't sell or rent your personal information for money.
  • We don't "share" your personal information for cross-context behavioral advertising (as those terms are defined under California law).
  • We don't share your bills with advertisers.
  • We don't use your bills to train third-party AI models. Our AI sub-processor is contractually prohibited from training on your content.

We have not sold or shared personal information for cross-context behavioral advertising in the prior 12 months, and we have no actual knowledge of selling or sharing the personal information of consumers under 16.

7. California privacy rights (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and (if applicable) sell or share.
  • Access a copy of your personal information in a portable format.
  • Correct inaccurate personal information we maintain about you.
  • Delete personal information we collected from you, subject to legal exceptions.
  • Opt out of sale or sharing — we do not sell or share, but you may still submit a request.
  • Limit the use of sensitive PI to the purposes identified in Section 4 above.
  • Non-discrimination for exercising any of these rights.

Submit a request by emailing hello@patientbill.orgfrom an email associated with your workspace, or by writing to the postal address in Section 16. We will verify your identity using information already associated with your request. You may use an authorized agent; we will require written permission and may verify your identity directly. We will respond within 45 days (extendable by another 45 days where allowed). We honor the Global Privacy Control (GPC) signal as an opt-out preference signal where required.

8. Other US state privacy rights

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have similar rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale, and certain profiling. We do not engage in targeted advertising, sale, or profiling that produces legal or similarly significant effects. To exercise these rights, contact us at hello@patientbill.org. You may appeal a denial by replying to our response.

9. Security

We use commercially reasonable technical, administrative, and physical safeguards designed to protect personal information, including encryption in transit (TLS) and at rest, role-based access controls and least-privilege permissions for employees, secure managed-hosting infrastructure, regular backups, and vendor due-diligence on our sub-processors. No system is perfectly secure; we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and applicable regulators as required by law.

10. Data retention

We keep personal information only as long as needed for the purposes described in this policy:

  • Workspace contact information: while your workspace is active, plus up to 12 months after deletion to handle disputes and legal obligations.
  • Case files (bills, EOBs, records, audit results): for the life of the case plus 7 years to support our records and applicable statutes of limitations.
  • Community content: while published and for a reasonable period after deletion or moderation for safety, abuse prevention, legal compliance, and backup rotation. Public copies or search-engine caches may remain outside our control.
  • Community reports and moderation records: as reasonably needed to enforce our rules, investigate abuse, and document moderator actions.
  • Historical signatures and mailed correspondence: legacy authorization records, PDFs, and mail-vendor metadata may be retained for 7 years.
  • Security and access logs: typically 12–24 months.
  • Anonymous draft bills that are never claimed are cleaned up automatically after a short window.
  • Backups: deleted records may persist in encrypted backups for up to 90 days before being overwritten.

11. Cookies and tracking technologies

We use a small number of first-party cookies and local-storage entries for private draft access, session management, and remembering your preferences. We use limited analytics and error-monitoring tooling to understand how the Service is used and to diagnose problems; these may set first-party or third-party cookies. We do not use advertising cookies, retargeting pixels, or cross-site tracking. You can block or delete cookies via your browser settings, and we honor the Global Privacy Control (GPC) signal where required by law.

12. Sub-processors and service providers

We share personal information with vendors who help us run the Service under written contracts that restrict their use of the data to providing their service to us. Current categories include:

  • Cloud hosting and database — to run the application and store your data.
  • Legacy mail vendor (Lob) — to retain or process historical correspondence and mailing records for legacy cases.
  • AI provider — to extract line items from uploaded bills and draft explanations and call scripts, under terms that prohibit training on your content.
  • Transactional email provider — to send optional private return links and service updates.
  • Error monitoring and analytics — to detect crashes and improve reliability.

We may also disclose personal information to professional advisors and to comply with law, respond to lawful requests, enforce our Terms, or protect our or others' rights. In a merger, acquisition, financing, or sale of assets, information may be transferred to a successor under equivalent protections.

13. Marketing communications

We send transactional messages only when you request a return link or when necessary for a workspace you chose to save; you cannot opt out of these while the workspace is active. Any non-essential marketing email includes an unsubscribe link; you can also opt out by emailing hello@patientbill.org.

14. Automated decision-making

Audit results and recommended call scripts are generated with the help of AI and other automated tooling. These outputs do not produce legal or similarly significant effects on you. You decide whether to use any output, and you can request a human review of any audit by emailing hello@patientbill.org.

15. Workspace deletion

To delete a saved workspace, email hello@patientbill.orgfrom the address associated with it and include the private return link if available. We will confirm the request, delete active workspace data within 30 days, and overwrite remaining copies from backups within 90 days. We may retain limited records where required by law, needed for security or fraud prevention, or necessary to enforce our Terms.

A workspace-deletion request does not automatically remove Community content. If you also want Community posts or replies reviewed for deletion, identify them in your request. We may preserve a minimal record where necessary for safety, abuse prevention, legal obligations, or enforcement of our Terms.

16. Children's privacy

Patient Bill is not intended for, and we do not knowingly collect personal information from, children under 13. A parent or guardian may use the Service to review a bill issued for a minor child; in that case the adult is responsible for the workspace and must have authority to provide the information. If we learn that we have collected personal information from a child under 13 without a parent's consent, we will delete it. Parents or guardians may contact us at hello@patientbill.orgto review or request deletion of a child's information.

17. International data transfers

Personal information is processed and stored in the United States. By using the Service, you understand that your information may be transferred to and processed in a country whose data-protection laws may differ from those of your country of residence.

18. Changes to this policy

If we make material changes, we'll update the "Last updated" date above and, where appropriate, email you or post an in-product notice at least 14 days before the change takes effect (or sooner if required by law). Continued use after a change means you accept the updated policy.

19. Contact

Questions, requests, or complaints about privacy:

Patient Bill, Inc. — Privacy
2261 Market St #4501
San Francisco, CA 94114
Email: hello@patientbill.org

California residents may submit CCPA requests to the email address above; we maintain it as our designated CCPA request channel.

This page is provided for transparency, is a plain-language draft, has not been reviewed by counsel, and is not a substitute for legal advice. You are encouraged to consult an attorney before relying on it.