Last updated: April 22, 2026 · Effective immediately upon acceptance
AiMyClaims (“we,” “our,” or “us”) operates the website aimyclaims.com and the related services described herein (collectively, the “Service”). This Privacy Policy explains how we collect, use, store, and protect information you provide when you use our Service, including any Protected Health Information (“PHI”) you voluntarily submit as part of medical bill analysis.
Please read this policy carefully. By using AiMyClaims you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.
AiMyClaims is a consumer financial advocacy tool, not a health-care provider, health plan, or healthcare clearinghouse. We are therefore not a HIPAA Covered Entity as defined under 45 CFR § 160.103, and we are not a Business Associate acting on behalf of a Covered Entity.
Despite this, we voluntarily follow HIPAA security best practices for protecting PHI because your medical information is highly sensitive and you deserve the same level of care. Nothing in this policy creates or implies a Business Associate Agreement or any HIPAA-regulated relationship.
Our Service allows you to:
We provide bill-analysis and advocacy assistance only. We do not provide medical advice, legal advice, or any guarantee of a particular negotiation outcome.
When you create an account or use the Service, you may provide:
All payment processing is handled by Stripe. We do not store your credit card number, CVV, or full payment card details. We retain a Stripe Customer ID linked to your account for receipt and refund purposes. Stripe's privacy practices are described at stripe.com/privacy.
When you use the Service, we automatically collect limited technical data:
We do not use third-party advertising trackers, pixels, or behavioral ad networks. We do not use cookies beyond what is strictly necessary for authentication and session management.
If you use the AIMY voice negotiation service, we collect and store:
Audio is processed in real time by Deepgram (transcription) and Cartesia (text-to-speech) and is not retained by either service beyond the duration of the call under their standard data handling terms. Twilio retains call metadata per their own retention policies.
We use the information we collect for the following purposes:
We do not use your PHI or bill data to train external AI models or share identified health data with any third party for any marketing, research, or commercial purpose not described in this policy.
We retain your bill data — including uploaded images, extracted text, analysis results, negotiation letters, and voice call transcripts — for 90 days from the date of upload or call completion. After 90 days, this data is permanently deleted from our systems unless you have an active support request or legal hold in place.
Account information (name, email, purchase history) is retained for as long as your account remains active and for up to 3 years thereafter for tax and legal compliance purposes, unless you request deletion sooner (see Section 6).
Email subscribers who have not used the Service may unsubscribe at any time using the link in any email we send. On unsubscribe, your email address is removed from active mailing lists within 10 business days.
We take the security of your data seriously, particularly given that your bills contain sensitive PHI. Our security measures include:
While we implement strong safeguards, no internet transmission or electronic storage system is 100% secure. If you discover a security vulnerability, please report it immediately to privacy@aimyclaims.com.
You have the following rights regarding your personal data:
You may request a copy of the personal information and bill data we hold about you by contacting privacy@aimyclaims.com. We will respond within 30 days.
You may request deletion of your account and all associated data at any time. To do so, email privacy@aimyclaims.com with subject line “Delete My Account.” We will permanently delete your data within 30 days, except where retention is required by law or for an open dispute.
If any account information we hold is inaccurate, you may update it via your account settings or by contacting us.
You may request an export of your bill analyses and negotiation letters in JSON or PDF format.
You may unsubscribe from marketing emails at any time using the unsubscribe link in any email or by contacting us. Transactional emails related to active service purchases cannot be suppressed until the service engagement is complete.
California residents have the right to know what personal information is collected, to request deletion, to opt out of the “sale” of personal information (we do not sell personal information), and to non-discrimination for exercising these rights. To exercise your California privacy rights, contact privacy@aimyclaims.com.
We share your data with third-party service providers only to the extent necessary to operate the Service. We do not sell, rent, or trade your personal information or PHI to any third party for marketing purposes. Our current sub-processors are:
Anthropic Privacy Policy ↗
AI analysis of bill data and generation of negotiation letters; AI voice agent conversation logic
Data shared: Extracted bill text, CPT codes, billed amounts, provider names, diagnosis context
Supabase Privacy Policy ↗
Hosted PostgreSQL database and file storage for bill documents, analysis results, and user profiles
Data shared: All structured data and uploaded bill files; encrypted at rest on AWS
Clerk Privacy Policy ↗
Authentication and user identity management (Google SSO)
Data shared: Name, email address, authentication tokens; no PHI
Stripe Privacy Policy ↗
Payment processing for one-time service purchases
Data shared: Payment card data (held by Stripe only), purchase amounts, Stripe Customer ID; no PHI
Resend Privacy Policy ↗
Transactional and marketing email delivery
Data shared: Email address, name, email content; no PHI
Twilio Privacy Policy ↗
Outbound telephone calls for the AI voice negotiation agent
Data shared: Phone numbers of hospital billing departments (not patient phone numbers), call metadata
Deepgram Privacy Policy ↗
Real-time speech-to-text transcription during voice calls
Data shared: Live audio stream during voice calls; not retained beyond call duration under standard terms
Cartesia Privacy Policy ↗
Text-to-speech voice synthesis for the AI voice agent
Data shared: Text to be spoken (negotiation script context); not retained
Railway Privacy Policy ↗
Cloud hosting for the voice agent microservice
Data shared: Application logs; PHI in logs is minimized by design
Vercel Privacy Policy ↗
Hosting for the main web application (Next.js)
Data shared: Web server logs, edge function execution logs; no PHI
All sub-processors are contractually required to process data only as directed by us and to maintain appropriate security measures. We review sub-processors periodically and will update this list when our service providers change.
The Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations apply to Covered Entities (health plans, healthcare clearinghouses, and most healthcare providers) and their Business Associates. AiMyClaims is not a Covered Entity under HIPAA because we are not a healthcare provider, health plan, or healthcare clearinghouse. We are a consumer financial advocacy service.
However, because our users voluntarily submit documents containing PHI (such as medical bills with diagnosis codes, CPT codes, dates of service, and provider names), we voluntarily adhere to the following HIPAA-inspired principles:
Important: By uploading a medical bill to AiMyClaims, you are voluntarily and knowingly sharing PHI with a non-HIPAA-regulated service. You have the right to redact information from your bill before uploading (e.g., removing your Social Security number or birth date) if the full document contains more PHI than necessary for bill analysis.
The Service is not directed to children under 18 years of age. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@aimyclaims.com and we will delete that information promptly.
Adults may upload bills on behalf of minor dependents. In that case, the account holder takes responsibility for consenting to the processing of the dependent's PHI.
AiMyClaims is operated in the United States and is intended for users in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer.
We do not sell, rent, license, or otherwise transfer your personal information or PHI to any third party for monetary or other valuable consideration. This includes data brokers, insurance companies, healthcare providers, pharmaceutical companies, and advertisers.
We do not share personal information with third parties for their own marketing purposes.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
Your continued use of the Service after a policy update constitutes your acceptance of the revised policy. If you object to any change, you may close your account and request data deletion before the change takes effect.
If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal information, please contact us:
We aim to respond to all privacy inquiries within 5 business days and to fulfill access or deletion requests within 30 days.