Privacy Policy

Effective date: October 3, 2026

[LEGAL NAME], LLC ("we") runs BillerKiller at billerkiller.com and medicalbillbuster.com. This policy explains what we collect, why, who we share it with, how long we keep it, and your rights. We are not a health care provider or health plan, so HIPAA generally doesn't apply to the data you give us directly. We protect medical bills as sensitive health information anyway.

What we collect

  • Identifiers and contact details: name, email, mailing address, phone number, IP address, and the account or reference numbers on your bills.
  • Your documents: the bills, notices, fines, statements, Explanations of Benefits, receipts and denial letters you upload or paste, and your answers to our audit questions. Medical bills can include procedure and diagnosis codes, dates of service and provider names.
  • Gmail receipts (only if you connect Gmail): we use read-only access to find receipts from the last two years and keep only receipt details (merchant, item, date, price, order number). We don't keep the emails, and our access is dropped when the scan ends.
  • Your case: the letters we draft, your edits and typed signature, who we sent them to, replies the company sends to your case address, and the outcome you report.
  • Phone calls (only if you ask us to call): the number called and a transcript of what was said. We don't record audio.
  • Payment information: handled by Stripe. We store only references (such as a customer or invoice ID), never your full card number.
  • Consent records: what you agreed to, when, and from which IP address.

Your browser also keeps some of this (for example, your scanned bill and dashboard) in its own storage until you clear it.

How we use it

To read and audit your bill, draft your letters, send them when you ask us to, follow up, track the outcome, calculate and collect our fee, send you reminders about your case and deadlines, answer you, keep records we're legally required to keep, and protect against fraud. We do not sell your information, and we do not use it for advertising. Our use of data from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements: Gmail data is used only to find your receipts, isn't transferred except to provide that feature, and is never used for advertising or to train AI models.

Consumer health data (Nevada, Washington and similar laws)

Medical bills are consumer health data. We collect it only to provide the service you asked for, after you agree on the upload form. We share it only with the service providers listed below, under contracts that limit their use to providing our service. We will ask for your separate consent before sharing it with anyone else. We never sell it, and we don't use location-based targeting around health care facilities. You can withdraw consent or ask us to delete your data at any time. Nevada's consumer health data law (NRS 603A.400 to 603A.550) is enforced by the Nevada Attorney General.

Who we share it with

  • The company you're disputing with, when you sign a letter and ask us to send it, or ask us to call.
  • Payment processing: Stripe.
  • Hosting and database: Vercel (website) and Supabase (case records).
  • Reading documents and drafting: Anthropic (Claude), which processes your documents to read them and draft letters. It doesn't use them to train its models.
  • Email: Resend (sending) and Postmark (receiving replies to your case).
  • Mail: Lob, when you choose certified mail.
  • Phone calls: Bland AI or Twilio, when you ask us to call.
  • Gmail: Google, when you connect Gmail.
  • Legal requirements: when required by law or to protect our rights.

How long we keep it

  • Uploaded images and PDFs: read, then not stored as files; the text we read from them stays with your case.
  • Medical audits you never unlock: deleted after 7 days.
  • Cases: kept while your case is open, then deleted 24 months after it closes, unless you ask us to delete them sooner.
  • Fee and payment records: kept for up to 7 years for tax and accounting purposes.

Security

Data is encrypted in transit, and our database and hosting providers encrypt it at rest. Case pages are reached only through a long random link; keep yours private. If a breach affects your information, we will notify you and the authorities as required by law, including under the FTC Health Breach Notification Rule (16 C.F.R. Part 318) and state breach laws.

Your rights

Wherever you live in the United States, you can ask us to:

  • tell you what personal information we have about you and how we use it;
  • delete it;
  • correct it;
  • confirm that we don't sell or share it (we don't);
  • limit our use of your sensitive information to what's needed to provide the service;
  • withdraw your consent.

We won't treat you differently for using these rights. We honor Global Privacy Control browser signals as an opt-out of sale or sharing.

California residents have these rights under the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.). Nevada residents may submit a verified request that we not sell their covered information (NRS Chapter 603A); we don't sell it.

How to ask: use the form below or email privacy@billerkiller.com. We'll verify your identity by email, confirm receipt within 10 business days, and respond within 45 days. We may need 45 more days in complex cases and will tell you if so. An authorized agent may make a request for you with your signed permission.

If you live outside the United States

We process your data in the United States. When you upload a bill from outside the US, we ask for your consent to that transfer.

If the EU or UK GDPR applies to you, we rely on your consent and on the need to perform our contract with you. You have the right to access, correct, delete, restrict or object to processing of your data, to data portability, to withdraw consent, and to complain to your data protection authority (in the UK, the Information Commissioner's Office). Where required, we notify the authority of a personal data breach within 72 hours. Transfers use the EU Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum. Data protection contact: privacy@billerkiller.com.

Children

The service is for adults. We don't knowingly collect information from children under 13. A parent or guardian may upload a child's bill for them.

Changes

If we make material changes, we'll post the new policy here with a new effective date and email you if you have an open case.

Contact

[LEGAL NAME], LLC. [ADDRESS]. privacy@billerkiller.com

Make a privacy request

We’ll verify your identity by email before acting on the request.