Consumer Health Data Privacy Notice
Effective August 2, 2026 · Last reviewed August 2, 2026
A medical bill or EOB can reveal health care, diagnoses, services, providers, insurance details, and financial information. Medical Bill Reader uses a document only to provide the analysis you request. We do not sell consumer health data, use it for advertising, or intentionally save the document or report in our own database.
Scope of this notice
This notice supplements our Privacy Policy and describes consumer health data practices for the bill analyzer. Medical Bill Reader is a direct-to-consumer information service. It is not a health care provider, health plan, HIPAA covered entity, or HIPAA business associate, and it does not offer a business associate agreement for this public service.
Data, sources, and purposes
| Category and source | Purpose |
|---|---|
| The bill or EOB you choose to upload, including visible health, provider, insurance, identity, and charge details | Generate the plain-language report you request |
| The AI-generated report derived from that document | Display the requested report in your active browser session |
| Request metadata and pseudonymous security or entitlement tokens generated by the service | Prevent abuse, enforce usage limits, and confirm paid access |
| Payment and subscription information you provide directly to Stripe | Process payment and provide or manage purchased access |
Processors and sharing
- Anthropic:receives the complete supported file through its commercial API and returns the report. Anthropic says standard API inputs and outputs are automatically deleted from its backend within 30 days, except when a service has longer customer-controlled retention, different agreed terms apply, or retention is needed for policy enforcement or law. Anthropic's published policy says inputs and outputs flagged by its automated trust and safety systems may be retained for up to two years and associated classification scores for up to seven years. Medical Bill Reader does not claim a zero-data-retention agreement or Business Associate Agreement. See Anthropic's published retention policy.
- Vercel: hosts the application and routes requests. It may process IP addresses, request metadata, and operational logs under the active account configuration and its terms. Our application code is designed not to log bill content, base64 file data, filenames, or report text.
- Upstash: stores HMAC-protected rate-limit, entitlement, and webhook-deduplication keys. It does not receive the uploaded document or AI report from our application.
- Stripe: receives payment details directly through Stripe-hosted Checkout and stores payment, customer, subscription, and limited entitlement records under its terms. Medical Bill Reader does not receive or store full card numbers.
Third-party analytics is disabled site-wide. Medical Bill Reader does not load Google Analytics or send public-page usage, document content, report text, filenames, upload activity, analysis activity, payment state, or conversion events to Google. Consumer health data is not disclosed to advertising systems.
Retention and deletion
- Medical Bill Reader database: the document and report are not intentionally written to one. They pass through application memory for the request.
- Your browser: the preview and report remain in the active page state until you remove them, refresh, navigate away, or close the page. A single-analysis access cookie can remain for up to 24 hours; a verified subscription access cookie can remain for up to 400 days and is renewed after successful use. These cookies contain opaque entitlement identifiers, not bill content.
- Anthropic: standard commercial API retention is up to 30 days, with the longer exceptions described above. Policy-flagged inputs and outputs may be retained for up to two years and associated classification scores for up to seven years.
- Security and access keys:temporary reservations expire after about 10 minutes; most rate-limit and monthly usage keys expire between one minute and 40 days. A pseudonymous pay-per-use replay-prevention key may be retained for up to 370 days. Stripe records follow Stripe's and our applicable payment, accounting, dispute, and legal retention requirements.
A privacy request can cover data we control. Provider records may be subject to provider-side deletion procedures, contractual limits, fraud-prevention needs, or legal retention obligations.
Your choices and rights
- Remove names, addresses, dates of birth, member IDs, account numbers, barcodes, and other identifiers that are not needed for the explanation before uploading.
- Do not select Explain My Bill if you do not want the document transmitted to Anthropic and infrastructure providers.
- Depending on applicable law, you may request access, confirmation, correction, deletion, or withdrawal of consent for future processing of consumer health data, and may appeal a denied request.
Email privacy@medicalbillreader.com with the subject “Consumer Health Data Request.” Describe the request and the email or payment reference needed to locate any record. Do not email a medical bill or diagnosis. We may need to verify your identity before acting. To appeal a decision, reply with the subject “Privacy Request Appeal.”
Legal reference
Washington's My Health My Data Act requires a prominent consumer health data privacy notice and provides rights that may apply to Washington consumers. Read the official Chapter 19.373 RCW. This notice is informational and is not legal advice.