Privacy policy
Effective May 14, 2026.
This is a working privacy policy and is intended to be reviewed by counsel before launch. Read it carefully and ask any questions via privacy@insuredefense.com before uploading any documents.
What we collect
- Account information — email address, optional name, payment information (processed by Stripe; we do not store full card numbers).
- Denial documents — files you upload, which may contain protected health information (PHI) such as member IDs, diagnoses, treatment codes, dates of service, and provider names.
- Triage answers — your responses to our questions about your treatment, plan type, and urgency.
- Generated outputs — the appeal package and supporting documents we prepare.
- Server logs — IP address, browser type, request timestamps. We redact identifiers like member ID and patient name from logs.
How we use it
We use your information to provide the service: read your denial, categorize it, prepare your appeal, deliver it to you, and send you follow-up reminders related to your case. We do not sell your information, do not share it with advertisers, and do not use it to train AI models.
Third-party processors
- Anthropic — we send the contents of your denial document and your triage answers to Anthropic’s Claude models to generate structured data and your appeal. Anthropic processes this under their API data-use terms and does not train on customer API content.
- Amazon Web Services — we store your uploaded files in encrypted S3 buckets within AWS’s US-East region.
- Stripe — we use Stripe to process payments. Stripe is PCI-DSS compliant. We do not store full card numbers.
- Email delivery — we use a transactional email provider (Resend / Postmark) to deliver appeal documents and follow-up reminders. We minimize PHI in email subject lines and bodies.
Retention
Uploaded denial documents auto-delete from our storage after 90 days. Generated appeal packages are retained for 12 months so that you can re-download them. You can request earlier deletion at any time by emailing privacy@insuredefense.com.
Marketing tracking
We deliberately do not run third-party marketing pixels (Meta, TikTok, Google Ads, etc.) or session-replay tools on any page that handles your medical documents. Marketing tags run only on our public marketing site (pages like the homepage, /pricing, /how-it-works), never on the upload, triage, or checkout pages inside the app subdomain.
Your rights
You have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your information (subject to limited exceptions for our legal and financial recordkeeping).
- Withdraw consent for processing at any time (which may end the service).
Breach notification
InsureDefense is subject to the FTC Health Breach Notification Rule (16 CFR Part 318) as a vendor of personal health records. In the event of a breach affecting unsecured PHR-identifiable health information, we will notify each affected individual, the FTC, and (where required) prominent media outlets within 60 days of discovery.