Privacy policy

Effective May 14, 2026.

This is a working privacy policy and is intended to be reviewed by counsel before launch. Read it carefully and ask any questions via privacy@insuredefense.com before uploading any documents.

What we collect

  • Account information — email address, optional name, payment information (processed by Stripe; we do not store full card numbers).
  • Denial documents — files you upload, which may contain protected health information (PHI) such as member IDs, diagnoses, treatment codes, dates of service, and provider names.
  • Triage answers — your responses to our questions about your treatment, plan type, and urgency.
  • Generated outputs — the appeal package and supporting documents we prepare.
  • Server logs — IP address, browser type, request timestamps. We redact identifiers like member ID and patient name from logs.

How we use it

We use your information to provide the service: read your denial, categorize it, prepare your appeal, deliver it to you, and send you follow-up reminders related to your case. We do not sell your information, do not share it with advertisers, and do not use it to train AI models.

Third-party processors

  • Anthropic — we send the contents of your denial document and your triage answers to Anthropic’s Claude models to generate structured data and your appeal. Anthropic processes this under their API data-use terms and does not train on customer API content.
  • Amazon Web Services — we store your uploaded files in encrypted S3 buckets within AWS’s US-East region.
  • Stripe — we use Stripe to process payments. Stripe is PCI-DSS compliant. We do not store full card numbers.
  • Email delivery — we use a transactional email provider (Resend / Postmark) to deliver appeal documents and follow-up reminders. We minimize PHI in email subject lines and bodies.

Retention

Uploaded denial documents auto-delete from our storage after 90 days. Generated appeal packages are retained for 12 months so that you can re-download them. You can request earlier deletion at any time by emailing privacy@insuredefense.com.

Marketing tracking

We deliberately do not run third-party marketing pixels (Meta, TikTok, Google Ads, etc.) or session-replay tools on any page that handles your medical documents. Marketing tags run only on our public marketing site (pages like the homepage, /pricing, /how-it-works), never on the upload, triage, or checkout pages inside the app subdomain.

Your rights

You have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your information (subject to limited exceptions for our legal and financial recordkeeping).
  • Withdraw consent for processing at any time (which may end the service).

Breach notification

InsureDefense is subject to the FTC Health Breach Notification Rule (16 CFR Part 318) as a vendor of personal health records. In the event of a breach affecting unsecured PHR-identifiable health information, we will notify each affected individual, the FTC, and (where required) prominent media outlets within 60 days of discovery.

Contact

privacy@insuredefense.com