Privacy & Data Security
Your medical data is sensitive. We treat it with enterprise-grade security, strict confidentiality, and radical transparency.
Our Commitment to You
At VetoBill, we understand that medical bills contain sensitive personal information. Your trust is our most valuable asset. This Privacy Policy explains exactly how we collect, use, store, and protect your data when you use our AI-powered medical bill analysis platform.
Our Core Promise: We do not sell your data. We do not share your data with third parties for marketing. We do not retain your documents longer than necessary. Our business model is aligned with your success—we only earn when you save money on your bills.
Information We Collect
We collect only the minimum information necessary to provide our analysis services.
1. Information You Provide
- Account Information: Name, email address, and password when you create an account.
- Medical Bills: Documents you upload (PDF, JPG, PNG) containing billing codes, dates of service, provider names, and charged amounts.
- Communication Data: Information you provide when contacting our support team.
2. Information Collected Automatically
- Usage Data: Pages visited, time spent on site, and features used (to improve our service).
- Device Information: IP address, browser type, and operating system (for security and fraud prevention).
We do not actively collect your full medical history, diagnosis codes (unless present on the bill you upload), insurance policy numbers beyond what is needed for billing identification, or social security numbers. We advise users to redact sensitive non-billing information before uploading.
How We Use Your Information
Your data is used solely for the purpose of providing and improving our services:
- Bill Analysis: To extract CPT/HCPCS codes, compare charges against benchmarks, and identify potential anomalies using AI.
- Service Delivery: To generate reports, dispute letters, and provide advocacy support.
- Security: To detect and prevent fraud, unauthorized access, and technical issues.
- Communication: To send you analysis results, service updates, and respond to inquiries.
- Improvement: To train and refine our AI models (using anonymized, aggregated data only).
Enterprise-Grade Security
We employ industry-leading security measures to protect your data:
AES-256 Encryption
All documents are encrypted at rest and in transit using bank-grade AES-256 encryption standards.
Automatic Deletion
Uploaded documents are automatically deleted from our servers 24 hours after analysis is complete. You can also request immediate deletion.
Secure Infrastructure
Hosted on secure cloud infrastructure (Supabase/Vercel) with regular security audits and compliance monitoring.
No Data Selling
We strictly prohibit the sale or rental of your personal data to third parties, advertisers, or data brokers.
Data Sharing & Disclosure
We do not sell your data. We only share information in the following limited circumstances:
- Service Providers: We engage trusted third-party vendors (e.g., OCR providers, cloud hosting) who process data solely on our behalf under strict confidentiality agreements.
- Legal Requirements: If required by law, subpoena, or government regulation.
- With Your Consent: If you explicitly authorize us to share data with a specific party (e.g., a healthcare advocate you hire).
VetoBill is not a “Covered Entity” under the Health Insurance Portability and Accountability Act (HIPAA). We are a technology platform providing data analysis tools. While we implement HIPAA-aware security protocols (encryption, access controls, audit logs), our services do not constitute medical advice or healthcare treatment.
Users are responsible for ensuring they have the right to upload any documents they submit. Do not upload documents containing sensitive information about other individuals without their consent.
Your Rights & Choices
Depending on your location, you may have the following rights regarding your data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your account and associated data (“Right to be Forgotten”).
- Opt-Out: Opt-out of non-essential communications (marketing emails).
To exercise these rights, please contact us at hello@vetobill.com.
Cookies & Tracking
We use essential cookies to ensure our platform functions correctly (e.g., keeping you logged in). We may use analytics cookies to understand how users interact with our site to improve performance. We do not use tracking cookies for advertising purposes.
You can control cookie settings through your browser preferences.