1. Overview
overcharged. is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard information when you use our service.
Key Principle: We are designed to NOT store your medical bills or personal health information. All processing happens in-memory during your session only.
2. What Information We Collect
Information You Provide
- • Medical bills or EOB documents: Uploaded as PDF, JPEG, or PNG files for analysis
- • Context information: Annual income range, state of residence, insurance status, household size
Automatically Collected Information
- • IP address (for rate limiting and abuse prevention)
- • Browser type and device type
- • Access timestamps
- • Error logs (technical errors only, no bill contents)
3. How We Use Your Information
We use your uploaded documents and context information to:
- • Extract bill details (charges, codes, dates)
- • Identify potential billing errors
- • Provide state-specific guidance
- • Generate personalized action plans and templates
- • Assess eligibility for financial assistance programs
4. How Long We Keep Your Information
Medical Bills and Analysis Results
Retention: ZERO. Deleted immediately after processing.
Our architecture is designed for stateless processing. Uploaded bills are processed in-memory only (RAM), not written to disk or databases. When your analysis is complete, all data is cleared from memory.
Technical Logs
We retain minimal technical logs (IP addresses, timestamps, error messages) for up to 30 days for security and debugging purposes. These logs do NOT contain bill contents or personal health information.
5. Third-Party Services
Anthropic (AI Processing)
We use Anthropic's AI API to analyze your uploaded documents:
- • Your bill and context information are transmitted to Anthropic via encrypted connection (HTTPS)
- • Anthropic processes the data according to their Privacy Policy
- • Anthropic does not train models on user data submitted via API
Your Choice: By using our service, you consent to this processing by Anthropic. If you are not comfortable with this, please do not upload your bills.
Cloudflare (Hosting)
Our service is hosted on Cloudflare. See Cloudflare's Privacy Policy for details.
6. Data Security
We implement security measures to protect your information:
- • Encryption in transit: All data uses HTTPS/TLS
- • No encryption at rest needed: We don't store bills
- • Rate limiting: Prevents abuse
- • Input validation: Validates file types and sizes
7. HIPAA Compliance
We are NOT a HIPAA-covered entity or business associate.
We do not act as your healthcare provider, store protected health information (PHI), or have business associate agreements with healthcare providers. You use this service at your own discretion and are responsible for removing identifying information from bills before upload.
8. Your Rights
You have complete control:
- • What you upload: You decide what bills to upload
- • PII removal: You are responsible for removing personal information before upload
- • Exit anytime: Close your browser to end your session immediately
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last Updated" date at the top. Your continued use of the service after changes are posted constitutes acceptance of the updated Privacy Policy.
Privacy Summary:- • We collect: uploaded bills + context (income, state)
- • We use it for: AI-powered bill analysis via Anthropic
- • We store it for: ZERO time (deleted immediately)
- • Third parties: Anthropic (AI), Cloudflare (hosting)