UseClaimRight ("we," "us") helps you review medical bills and pursue insurance appeals. We know these documents are deeply personal. This policy explains what we collect, how we use it, and the control you keep. By using our service you agree to the practices described here.
Only what you choose to upload: your itemized medical bills, insurance Explanation of Benefits (EOB) statements, insurance policy documents such as a Summary of Benefits, and the email address you sign in with. These documents normally carry your name, member and account numbers, dates of service, and the medical services you were billed for. We do not need your Social Security number, and we ask you not to upload it.
We use your documents solely to analyze your bill, identify overcharges and errors, prepare appeal and dispute materials, and communicate with you about your case. We process this information using automated tools, including AI models, under our direction to perform the analysis you requested.
We use Google Analytics to understand site usage — pages visited and general product events (for example, that an audit was completed). Analytics uses cookies and similar identifiers. We never send your documents, their contents, audit findings, or any health information to analytics — it sees page and event names only, never what's in your bill.
We never sell your information. We never share it for advertising or marketing. We do not use your health information to target ads. We share it only with parties necessary to carry out the service you asked for (for example, submitting an appeal to your insurer on your instruction) or when required by law.
You authorize every document before it is filed. You can ask us to delete your data at any time by emailing privacy@useclaimright.com, and we will remove it promptly except where we must retain records to comply with law. We keep your information only as long as needed to provide the service and meet legal obligations.
To analyze a bill we send its text, and the text of any EOB or plan document you upload, to Google's Gemini models on Vertex AI, part of Google Cloud. That text includes the personal details printed on the documents — your name, member and account numbers, dates of service, and what you were treated for. We do not remove them first. Google states that customer data sent to Vertex AI is not used to train its models, and Vertex AI is a service Google covers under its Cloud data protection terms; their terms govern what they do with it. Google may retain the data briefly for abuse monitoring and to meet legal obligations — “not used for training” is not the same as “not stored”.
We show you the exact text before it is sent, so nothing goes out that you have not seen.
We store that text and the audit findings in your account so you can re-open an audit later. We do not store the uploaded file itself. You can delete any audit, or your entire account and everything in it, at any time — deletion is immediate and permanent.
This changed in August 2026. Earlier versions removed personal details in your browser before sending anything. That step has been removed, and this policy describes what the product does now.
Every page of the app runs Google's reCAPTCHA Enterprise in invisible mode, through Firebase App Check. It never shows you a puzzle or a checkbox. To decide whether a request is coming from a real browser rather than a script, it sends Google signals about your device and browser — things like your IP address, user agent, screen and timezone settings, and how the page is being interacted with. This happens on every page load, whether or not you upload anything, and it is separate from the document analysis described above. Google's Privacy Policy and Terms of Service govern that data. We use it only to keep automated scripts from running up the bill on a free service; we never see a score for an individual person, and it plays no part in your audit results.
We encrypt your documents in transit and at rest, limit who can access them, and minimize what we store. No method of storage or transmission is perfectly secure, but we take reasonable measures to protect your information.
Because you direct us to handle your own records, our handling of your health information is governed by this policy and applicable consumer-privacy law, including the FTC Health Breach Notification Rule, rather than HIPAA. If a breach of your identifiable health information occurs, we will notify you as required by law. Depending on where you live, you may have additional rights to access, correct, or delete your data.
Questions? Email privacy@useclaimright.com.