Privacy Policy

Last updated: May 12, 2026

Our Commitment to Your Privacy

TrueMedBills is built with privacy as the foundation. We are an informational tool, not a healthcare provider, and we handle your data accordingly.

What We Collect

When you upload a medical bill, we process it to extract billing data for analysis. We never store: patient names, dates of birth, Social Security numbers, addresses, member IDs, or phone numbers. We store only anonymized billing data (provider names, CPT codes, charge amounts, date of service in month/year format only) in our encrypted database for analytics purposes.

How We Use Your Data

Your uploaded bill is processed by AI to identify errors and compare charges against CMS fair market rates. We do not sell, share, or monetize your data in any form. Aggregated, anonymized analytics data may be used to improve our service.

Data Retention

Uploaded files are automatically deleted from our storage after 30 days. Anonymized analytics data (no PII) may be retained indefinitely. You may request deletion of your session's data at any time by emailing privacy@fairmеdbill.com.

Security

All data is transmitted using TLS 1.3 encryption. Files are stored in Cloudflare R2 with 256-bit AES encryption at rest. We follow industry best practices for security.

HIPAA Notice

TrueMedBills is not a HIPAA Covered Entity or Business Associate. We are a consumer informational tool, not a healthcare provider, health plan, or clearinghouse. As such, HIPAA does not apply to our service.

Our AI analysis is powered by third-party providers (including Anthropic) who do not have Business Associate Agreements (BAAs) in place. We strongly recommend redacting your name, address, date of birth, Social Security number, and member ID before uploading any document. Our AI only needs CPT codes, procedure descriptions, and charge amounts to perform a full analysis.

By using TrueMedBills, you acknowledge that you are voluntarily submitting your own billing documents and that this service is not subject to HIPAA protections.

What Data the AI Sees

When you upload a bill, the document contents are sent to Anthropic's Claude API for analysis. Anthropic's standard data usage policies apply. We instruct the AI to focus solely on billing codes and charges, and to disregard any personal identifiers in the document. We do not store AI conversation logs.

Contact

Questions? Email privacy@truemedbills.com.