Privacy Policy
Effective Date: July 1, 2026
1. Scope
This Privacy Policy explains how BillSurgeon LLC (BillSurgeon, we, us, our) collects, uses, and discloses information through billsurgeon.com and the audit service (the Service). It does not cover information you send directly to your provider, insurer, or anyone outside the Service.
2. No Accounts
The Service has no account or login. Each audit runs in a single session and, after payment, a job record as described below.
3. What We Collect
- Bill documents you upload: may include your name, address, birth date, insurance details, provider and facility names, and procedure and diagnosis codes
- Info you give us directly: state of residence, insurance status, and, for a dispute letter, the patient, provider, and account details you confirm
- Payment info: handled directly by Stripe; we get confirmation of payment and limited metadata, never your full card number
- Technical data: standard web request data such as IP address, collected by Cloudflare for security and performance
- Anonymous analytics: aggregate stats like error counts, estimated amounts, common error categories, and bill type, structured so none of it identifies you
4. How We Use It
To generate your free verdict and, after payment, your full findings and letter; to process payment; to run, secure, and improve the Service; and to produce the anonymous analytics above. We never use your bill data to train third party AI models or for advertising.
5. How Long We Keep It
Once your audit is complete and your report is generated, we delete the uploaded bill files and your identifiable job record, including verdict, findings, and letter details. After that, only the anonymous aggregate statistics in Section 3 remain, and they cannot be linked back to you. Download your report and letter promptly, we do not keep an identifiable copy for later retrieval. Payment records are kept by Stripe and by us as required for accounting, tax, and fraud prevention.
6. Anthropic and Zero Data Retention
Your audit uses Anthropic's Claude models to read and analyze your bill, under Anthropic's zero data retention API terms: the content sent for your audit is not kept by Anthropic or used to train its models after your request finishes.
7. Who We Share Information With
We never sell your personal information or your consumer health data. We only share information with the providers who help run the Service, each limited by contract to using it only for us:
- Stripe: payments
- Anthropic: AI analysis, zero data retention
- Supabase (Lovable Cloud): infrastructure
- Inngest: background job processing
- Cloudflare: hosting
- Zoho: business email for support and privacy requests
We may also disclose information if the law requires it, to protect our rights or others' safety, or as part of a merger or sale, with notice as required by law.
8. Your Choices and Rights
Since there are no accounts, email privacy@billsurgeon.com from your checkout email, or with your order details, to exercise these rights. Depending on your state, you may be able to:
- Know what personal information we have collected, used, and shared
- Access a copy of it
- Request deletion, including from backups, with limited legal exceptions
- Withdraw any consent you gave
- Not be discriminated against for asking
We will respond within the time the law requires, and tell you how to appeal a denied request.
9. Consumer Health Data (Washington, Nevada, Connecticut)
Because bill documents can reveal health information, we publish a separate Consumer Health Data Privacy Notice covering Washington's My Health My Data Act, Nevada's consumer health data law, and Connecticut's data privacy act. Read it here: Consumer Health Data Privacy Notice.
10. California Privacy Rights
We are below the CCPA's thresholds (over $26.625 million in yearly revenue, personal information of 100,000 or more California consumers a year, or 50% or more of revenue from selling or sharing personal information), but we extend CCPA style rights to know, delete, correct, and limit use of sensitive personal information to everyone, everywhere, as described above. We do not sell or share personal information for cross context advertising, and we do not use precise geolocation, biometric identifiers, or automated decisions that have a legal or similarly significant effect on you.
11. HIPAA
BillSurgeon is not a HIPAA covered entity (not a provider, health plan, or clearinghouse) and not a business associate of one, since you engage us directly rather than through a covered entity. HIPAA's Privacy and Security Rules do not directly apply to us as a result. If we ever have a breach of unsecured, identifiable health information, we will notify as required by the FTC's Health Breach Notification Rule and applicable state law.
12. Data Security
We use safeguards including encryption in transit, access controls on identifiable bill content, and a policy of keeping health information out of application logs and any shareable content, including the optional share card, which is built entirely on your device and contains no name, provider, date, or line item detail. No system is perfectly secure, and we cannot guarantee absolute security.
13. Children
The Service is not for anyone under 18, and we do not knowingly collect information from children. If we learn we have, we delete it.
14. International Use
The Service is built for U.S. medical bills and U.S. residents. If you access it from elsewhere, that is your choice and your responsibility for local law compliance; we make no claim the Service fits outside the U.S.
15. Changes to This Policy
We may update this policy. Material changes update the Effective Date above and, where Washington law requires, come with notice before they apply to data already collected.