Privacy Policy

Last updated: April 22, 2026  ·  Effective immediately upon acceptance

AiMyClaims (“we,” “our,” or “us”) operates the website aimyclaims.com and the related services described herein (collectively, the “Service”). This Privacy Policy explains how we collect, use, store, and protect information you provide when you use our Service, including any Protected Health Information (“PHI”) you voluntarily submit as part of medical bill analysis.

Please read this policy carefully. By using AiMyClaims you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.


1Who We Are and What We Do

AiMyClaims is a consumer financial advocacy tool, not a health-care provider, health plan, or healthcare clearinghouse. We are therefore not a HIPAA Covered Entity as defined under 45 CFR § 160.103, and we are not a Business Associate acting on behalf of a Covered Entity.

Despite this, we voluntarily follow HIPAA security best practices for protecting PHI because your medical information is highly sensitive and you deserve the same level of care. Nothing in this policy creates or implies a Business Associate Agreement or any HIPAA-regulated relationship.

Our Service allows you to:

  • Upload photos or PDFs of medical bills for AI-powered error analysis.
  • Receive a detailed breakdown identifying potential billing errors, duplicate charges, and upcoded procedures.
  • Purchase a professionally drafted negotiation letter based on the analysis.
  • Optionally engage our AI voice agent (AIMY) to negotiate directly with hospital billing departments on your behalf.

We provide bill-analysis and advocacy assistance only. We do not provide medical advice, legal advice, or any guarantee of a particular negotiation outcome.


2Information We Collect

2.1 Information You Provide Directly

When you create an account or use the Service, you may provide:

  • Account information — your name and email address (via Google SSO through Clerk).
  • Bill documents — images (PNG, JPG) or PDF files of medical bills. These documents typically contain PHI such as patient name, date of birth, provider name, diagnosis codes, procedure (CPT) codes, itemized service descriptions, insurance information, and billed amounts.
  • Extracted billing data — text and structured data our AI extracts from your uploaded documents, including CPT codes, billed amounts, provider names, and service dates.
  • Email address for marketing communications — if you opt in via our landing page email form.
  • PHI consent acknowledgment — a record that you consented to PHI processing before uploading.

2.2 Payment Information

All payment processing is handled by Stripe. We do not store your credit card number, CVV, or full payment card details. We retain a Stripe Customer ID linked to your account for receipt and refund purposes. Stripe's privacy practices are described at stripe.com/privacy.

2.3 Automatically Collected Information

When you use the Service, we automatically collect limited technical data:

  • Log data — IP address, browser type, operating system, pages visited, and timestamps.
  • Usage metadata — actions such as when a negotiation letter was viewed, copied, or printed; outcome status you self-report; and whether you engaged the voice agent.

We do not use third-party advertising trackers, pixels, or behavioral ad networks. We do not use cookies beyond what is strictly necessary for authentication and session management.

2.4 Voice Call Data

If you use the AIMY voice negotiation service, we collect and store:

  • A full transcript of the call (text only — no audio recording is retained by AiMyClaims).
  • Call metadata: duration, outcome (e.g., agreed amount), hospital billing representative name and extension (if provided).
  • Any settlement PDF generated as a result of a successful negotiation.

Audio is processed in real time by Deepgram (transcription) and Cartesia (text-to-speech) and is not retained by either service beyond the duration of the call under their standard data handling terms. Twilio retains call metadata per their own retention policies.


3How We Use Your Information

We use the information we collect for the following purposes:

3.1 Providing the Service

  • Processing your uploaded bill documents through our AI analysis pipeline to identify billing errors, upcoded procedures, duplicate charges, and statistical anomalies compared to Medicare/Medicaid benchmark rates.
  • Generating a customized negotiation letter based on the specific errors found in your bill.
  • Conducting AI-powered phone negotiations with hospital billing departments when you activate the voice agent.
  • Storing your analysis results and letter so you can access them within 90 days of upload.

3.2 Account and Payment Management

  • Authenticating your identity via Clerk (Google SSO).
  • Processing one-time payments via Stripe and maintaining a record of your purchase history.
  • Sending transactional emails (purchase confirmations, analysis ready notifications, outcome follow-ups) via Resend.

3.3 Service Improvement

  • Improving the accuracy of our AI billing-error detection models using aggregated, de-identified data patterns (never individual identified records).
  • Monitoring system performance and debugging technical errors.

3.4 Legal Compliance

  • Complying with applicable laws and regulations.
  • Responding to lawful requests from courts or government authorities.
  • Protecting our rights, your rights, and the safety of users.

We do not use your PHI or bill data to train external AI models or share identified health data with any third party for any marketing, research, or commercial purpose not described in this policy.


4Data Retention

We retain your bill data — including uploaded images, extracted text, analysis results, negotiation letters, and voice call transcripts — for 90 days from the date of upload or call completion. After 90 days, this data is permanently deleted from our systems unless you have an active support request or legal hold in place.

Account information (name, email, purchase history) is retained for as long as your account remains active and for up to 3 years thereafter for tax and legal compliance purposes, unless you request deletion sooner (see Section 6).

Email subscribers who have not used the Service may unsubscribe at any time using the link in any email we send. On unsubscribe, your email address is removed from active mailing lists within 10 business days.


5Data Security

We take the security of your data seriously, particularly given that your bills contain sensitive PHI. Our security measures include:

  • Encryption in transit — all data transmitted between your browser and our servers uses TLS 1.2 or higher (HTTPS).
  • Encryption at rest — bill files and extracted data stored in Supabase (PostgreSQL) are encrypted at rest using AES-256.
  • Access controls — database row-level security ensures you can only access your own bills. Administrative access is restricted by Clerk user ID.
  • Third-party security — we use Supabase Pro, which provides SOC 2 Type II compliant infrastructure on AWS.
  • No local storage of PHI — bill documents and extracted PHI are never written to client-side local storage or cookies.

While we implement strong safeguards, no internet transmission or electronic storage system is 100% secure. If you discover a security vulnerability, please report it immediately to privacy@aimyclaims.com.


6Your Rights and Choices

You have the following rights regarding your personal data:

6.1 Access

You may request a copy of the personal information and bill data we hold about you by contacting privacy@aimyclaims.com. We will respond within 30 days.

6.2 Deletion

You may request deletion of your account and all associated data at any time. To do so, email privacy@aimyclaims.com with subject line “Delete My Account.” We will permanently delete your data within 30 days, except where retention is required by law or for an open dispute.

6.3 Correction

If any account information we hold is inaccurate, you may update it via your account settings or by contacting us.

6.4 Portability

You may request an export of your bill analyses and negotiation letters in JSON or PDF format.

6.5 Opt-Out of Marketing Email

You may unsubscribe from marketing emails at any time using the unsubscribe link in any email or by contacting us. Transactional emails related to active service purchases cannot be suppressed until the service engagement is complete.

6.6 California Residents (CCPA)

California residents have the right to know what personal information is collected, to request deletion, to opt out of the “sale” of personal information (we do not sell personal information), and to non-discrimination for exercising these rights. To exercise your California privacy rights, contact privacy@aimyclaims.com.


7Third-Party Service Providers

We share your data with third-party service providers only to the extent necessary to operate the Service. We do not sell, rent, or trade your personal information or PHI to any third party for marketing purposes. Our current sub-processors are:

Anthropic Privacy Policy ↗

AI analysis of bill data and generation of negotiation letters; AI voice agent conversation logic

Data shared: Extracted bill text, CPT codes, billed amounts, provider names, diagnosis context

Supabase Privacy Policy ↗

Hosted PostgreSQL database and file storage for bill documents, analysis results, and user profiles

Data shared: All structured data and uploaded bill files; encrypted at rest on AWS

Clerk Privacy Policy ↗

Authentication and user identity management (Google SSO)

Data shared: Name, email address, authentication tokens; no PHI

Stripe Privacy Policy ↗

Payment processing for one-time service purchases

Data shared: Payment card data (held by Stripe only), purchase amounts, Stripe Customer ID; no PHI

Resend Privacy Policy ↗

Transactional and marketing email delivery

Data shared: Email address, name, email content; no PHI

Twilio Privacy Policy ↗

Outbound telephone calls for the AI voice negotiation agent

Data shared: Phone numbers of hospital billing departments (not patient phone numbers), call metadata

Deepgram Privacy Policy ↗

Real-time speech-to-text transcription during voice calls

Data shared: Live audio stream during voice calls; not retained beyond call duration under standard terms

Cartesia Privacy Policy ↗

Text-to-speech voice synthesis for the AI voice agent

Data shared: Text to be spoken (negotiation script context); not retained

Railway Privacy Policy ↗

Cloud hosting for the voice agent microservice

Data shared: Application logs; PHI in logs is minimized by design

Vercel Privacy Policy ↗

Hosting for the main web application (Next.js)

Data shared: Web server logs, edge function execution logs; no PHI

All sub-processors are contractually required to process data only as directed by us and to maintain appropriate security measures. We review sub-processors periodically and will update this list when our service providers change.


8HIPAA and PHI — Our Voluntary Compliance Posture

The Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations apply to Covered Entities (health plans, healthcare clearinghouses, and most healthcare providers) and their Business Associates. AiMyClaims is not a Covered Entity under HIPAA because we are not a healthcare provider, health plan, or healthcare clearinghouse. We are a consumer financial advocacy service.

However, because our users voluntarily submit documents containing PHI (such as medical bills with diagnosis codes, CPT codes, dates of service, and provider names), we voluntarily adhere to the following HIPAA-inspired principles:

  • Minimum necessary use — we access and process only the PHI required to analyze your bill and generate your negotiation letter.
  • No unauthorized disclosure — we never disclose your PHI to third parties except our listed sub-processors for the sole purpose of providing the Service.
  • No research or commercial secondary use — we never use your identifiable PHI to train AI models, for research publications, or for any commercial purpose beyond the Service you requested.
  • Technical safeguards — AES-256 at rest, TLS in transit, row-level access controls.
  • Breach notification — in the event of a data breach that may have exposed your PHI, we will notify you at your registered email address within 72 hours of discovering the breach.

Important: By uploading a medical bill to AiMyClaims, you are voluntarily and knowingly sharing PHI with a non-HIPAA-regulated service. You have the right to redact information from your bill before uploading (e.g., removing your Social Security number or birth date) if the full document contains more PHI than necessary for bill analysis.


9Children's Privacy

The Service is not directed to children under 18 years of age. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@aimyclaims.com and we will delete that information promptly.

Adults may upload bills on behalf of minor dependents. In that case, the account holder takes responsibility for consenting to the processing of the dependent's PHI.


10International Users

AiMyClaims is operated in the United States and is intended for users in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer.


11We Do Not Sell Your Data

We do not sell, rent, license, or otherwise transfer your personal information or PHI to any third party for monetary or other valuable consideration. This includes data brokers, insurance companies, healthcare providers, pharmaceutical companies, and advertisers.

We do not share personal information with third parties for their own marketing purposes.


12Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the “Last updated” date at the top of this page.
  • Send an email notification to registered users at their account email address.

Your continued use of the Service after a policy update constitutes your acceptance of the revised policy. If you object to any change, you may close your account and request data deletion before the change takes effect.


13Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal information, please contact us:

AiMyClaims Privacy Team

Email: privacy@aimyclaims.com

Website: aimyclaims.com

We aim to respond to all privacy inquiries within 5 business days and to fulfill access or deletion requests within 30 days.