Privacy Policy
Last updated 2026-07-15 · v1.0
Provided for general information only and is not legal advice. IsMyBillWrong is not a law firm.
Privacy Policy
Effective date: July 15, 2026 · Version 1.0
This is a first draft pending attorney review. It describes our intended practices and is published for development and internal review only.
[[ENTITYLEGALNAME]] ("IsMyBillWrong," "we," "us," or "our") operates IsMyBillWrong.com. IsMyBillWrong is an AI service that audits medical bills for errors and generates dispute letters for a flat fee. Your medical bills are sensitive, and this policy explains — in plain English — exactly what we collect, how we use it, who we share it with, how long we keep it, and the choices and rights you have. We describe only what the system actually does.
A note on HIPAA: We are generally not a HIPAA "covered entity" or "business associate," so we do not claim to be "HIPAA compliant." Instead, this policy describes the concrete protections we actually apply — encryption, data minimization, no use of your data to train AI, and a fixed purge schedule.
1. Information we collect
We collect only what we need to run the Service:
- Documents you upload. Itemized hospital bills, insurance Explanations of
Benefits (EOBs), collections letters, and similar documents. These often contain health information — dates of service, procedure and diagnosis codes, provider names, and amounts. This is the core of what we process to audit your bill and prepare your letters.
- Information extracted from those documents. Structured data our extraction
step pulls out of your uploads (line items, codes, amounts, dates), stored so the audit can run.
- Account information. Your email address, used for sign-in (email magic-link
or Google sign-in — we do not store passwords) and for transactional messages about your case.
- Payment metadata from Stripe. When you pay, our payment processor Stripe
handles your card. We receive and store payment metadata only — for example a charge ID, the amount, the last four digits and card brand, and success/failure status. We never receive or store your full card number.
- Basic technical and usage data. Limited security and reliability data such as
your IP address (used for sign-in security, rate limiting, and abuse prevention) and privacy-friendly, aggregate analytics (see Section 4).
We do not ask for information we don't need, and we instruct you not to upload documents that are not yours.
2. How your documents are analyzed by AI
To audit your bill, your documents are analyzed by Google Cloud AI services:
- Google Document AI extracts the text and line items from your uploaded
documents.
- Google's Gemini models, via Vertex AI, perform the audit reasoning — spotting
patterns like unbundling and upcoding and drafting the narrative parts of your letters.
We use these under Google Cloud's enterprise terms, which prohibit using your data to train Google's models. In plain terms: your documents and their contents are not used to train any AI model — not ours, not Google's. They are used only to process your case. We also limit what we send: uploaded document text is treated as untrusted data, and personal health information is kept out of our application logs, error reports, and analytics.
3. How we use your information
We use your information only to:
- run the free scan and the paid audit, and generate your dispute letters;
- process your payment (via Stripe);
- send you transactional email about your case and deadlines (via Postmark);
- secure the Service, prevent abuse, and enforce our Terms; and
- comply with law.
We do not use your information for advertising or profiling, and we do not make automated decisions that produce legal effects about you without your involvement — you review and send every letter yourself.
4. We do not sell your data, advertise to you, or use ad trackers
- No sale of data. We do not sell or "share" (as defined by California law)
your personal information or health information, and we never will.
- No advertising use. We do not use your data for targeted advertising, and we
do not allow third parties to use it for their advertising.
- No third-party ad trackers. We do not embed third-party advertising or
social-media tracking pixels, and we do not use third-party analytics services such as Google Analytics. No outside company receives your browsing data from our site.
5. Who we share information with
We share information only with the service providers that make the Service work, and only as needed:
| Provider | Purpose | What it receives | |---|---|---| | Google Cloud (Document AI + Gemini via Vertex AI) | Document extraction and audit reasoning | Your uploaded documents and their extracted contents, under enterprise no-training terms | | Stripe | Payment processing | Payment details you enter at checkout; we receive only payment metadata back | | Postmark | Transactional email delivery | Your email address and message contents (case/deadline notices) |
These are the only external service providers that receive your information. We do not use third-party analytics or advertising services, so no other outside company receives your data.
We may also disclose information if required by law, to respond to lawful requests, to protect our rights or the safety of others, or in connection with a merger or acquisition (in which case this policy continues to apply to the transferred data). We do not share your data with data brokers or advertisers.
6. How we protect your information
- Encryption at rest. Uploaded documents are encrypted at rest
(application-layer AES-256-GCM). Traffic is encrypted in transit with TLS.
- Data minimization. We collect only what we need and keep health information
out of logs, error monitoring, and analytics by design.
- Access limits. Access to case data is restricted; our administrative tools
are not publicly exposed.
- No training on your data. As described above, your documents are never used
to train AI models.
- Malware scanning and upload validation protect the Service and other users.
No system is perfectly secure, but these are the concrete measures we apply.
7. How long we keep your information (retention schedule)
We keep your information only as long as we need it, then permanently purge it on a fixed schedule. These are the exact windows implemented in our system:
| Data | Retention | |---|---| | Uploaded documents (bills, EOBs, letters) | Permanently purged 90 days after your case is resolved or abandoned | | Extractions (data pulled from your documents) | Permanently purged 90 days after your case is resolved or abandoned | | Rendered dispute-package PDFs | Permanently purged 90 days after your case is resolved or abandoned | | Account records | Kept until you delete your account; an account inactive for 730 days becomes eligible for deletion after notice |
We purge data on this schedule. We keep a metadata-only record that a deletion happened (for example, a timestamp and record identifier — never the contents of your bill) as part of our internal audit trail. Payment records may be retained longer where we are legally required to keep them (for tax and accounting). These retention windows come from a single machine-readable configuration, and an automated check prevents this policy from drifting out of sync with it.
8. Your choices and deletion rights
You can:
- Access and update your account information from your account.
- Delete your account and case data. You may delete your account at any time
from your account settings, or by emailing [[CONTACT_EMAIL]]. When you delete your account, we purge your uploaded documents, extractions, and rendered PDFs, and delete your account record (subject to the metadata-only deletion log and any records we must keep by law).
- Withdraw consent to health-data processing at any time (see Section 9); doing
so ends our ability to continue auditing that case.
To exercise any right in this policy, email [[CONTACT_EMAIL]]. We will verify your request (usually by confirming control of your account email) and respond within the timeframes required by applicable law. We will not discriminate against you for exercising your privacy rights.
9. Washington My Health My Data Act — consumer health data
Because we process health information, we apply the standards of the Washington My Health My Data Act (MHMDA) to all users, regardless of where you live:
- Consent. We collect and process the consumer health data in your uploaded
documents only with your separate, affirmative, unbundled consent, obtained at upload (see our [Consumer Health Data Consent](./consumer-health-data-consent.md)), and we use it only for the purposes you consented to.
- No sale. We do not sell your consumer health data, and we will not,
without the separate valid authorization the Act requires (which we do not seek).
- Your rights. You have the right to confirm whether we are processing your
consumer health data, to access it, to withdraw consent, and to have it deleted. To exercise these rights, email [[CONTACT_EMAIL]].
- Authorized agents. You may designate an authorized agent to make a
consumer-health-data request on your behalf; we will require proof of your authorization before acting.
- Access controls. We restrict access to consumer health data to the people and
processes that need it to provide the Service.
10. California (CCPA/CPRA) rights
If you are a California resident, you have the right to: know/access the personal information we collect and how we use and disclose it; delete your personal information; correct inaccurate personal information; and opt out of sale/sharing and of targeted advertising — noting that we do not sell or share your personal information and do not use it for targeted advertising, so there is nothing to opt out of. We do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit. We will not discriminate against you for exercising these rights. To exercise them, email [[CONTACT_EMAIL]]; you may use an authorized agent, and you may appeal a denial by replying to our response.
11. Florida Digital Bill of Rights
If you are a Florida resident covered by the Florida Digital Bill of Rights, you have the right to confirm and access your personal data, correct it, delete it, obtain a portable copy, and opt out of the sale of personal data and of targeted advertising and profiling. As stated above, we do not sell your personal data and do not use it for targeted advertising or profiling. To exercise these rights, email [[CONTACT_EMAIL]].
12. Breach notification
We maintain safeguards to protect your information, but if a breach of unsecured, individually identifiable health information does occur, we commit to notifying affected users (and, where applicable, the U.S. Federal Trade Commission and the media) consistent with the FTC Health Breach Notification Rule — including notifying affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. Our internal breach-response process follows those timelines.
13. Children
The Service is for adults (18+) and is not directed to children. We do not knowingly collect personal information from children under 13. If you believe a child provided us information, email [[CONTACT_EMAIL]] and we will delete it.
14. Changes to this policy
We may update this policy prospectively. Material changes will be reflected in the version and effective date above and, where appropriate, communicated to you.
15. Contact us
[[ENTITYLEGALNAME]] [[ENTITYADDRESS]] Email: [[CONTACTEMAIL]]
Related documents: [Terms of Service](./terms-of-service.md) · [Refund Policy](./refund-policy.md) · [UPL Disclaimer](./upl-disclaimer.md) · [Consumer Health Data Consent](./consumer-health-data-consent.md)