Privacy Policy

Last Updated: November 12, 2025

Healtheja, Inc. ('we', 'us', or 'our') is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you use the CareRoute mobile application, our website (including web forms such as Bill Defense intake), and our related services, including our Bill Defense bill negotiation service.

1. Information We Collect

1.1 Account Information

  • Email address (users signing in with Apple ID may use a private relay email)
  • Nickname (optional)
  • Authentication tokens
  • User locale and timezone

1.2 Health Information

  • Health profiles including medical conditions, allergies, and health goals
  • Chat conversations with our AI health assistant
  • Health-related queries and interactions
  • If you choose to upload medical bills or Explanation of Benefits (EOBs), we process them to provide bill‑savings features
  • If you ask us to contact providers or insurers on your behalf about a specific bill (for example through our Bill Defense bill negotiation service), we may collect limited identifying information needed to perform that service (e.g., full name, date of birth, address, phone, relevant account or statement numbers) and your signed authorizations (e.g., HIPAA authorization or representative letter)
  • For Bill Defense, we may also collect information such as your household size and approximate income range to screen for financial assistance or discount eligibility.

1.3 Usage Information

  • App usage patterns and frequency
  • Feature interactions
  • Token consumption metrics
  • Database and storage usage
  • Device information (type, operating system version)
  • Error logs and performance data

1.4 Notification Preferences

  • Health notification settings and preferences
  • Maximum daily notification limit (user-configured)
  • Notification interaction history

1.5 Sensitive Identifiers We Don't Collect

  • Social Security numbers
  • Insurance member IDs or insurer portal passwords
  • Payment card numbers (purchases handled by Apple/Google; we receive no card data)

2. How We Store Your Information

2.1 Server-Side Storage

The following data is stored on our secure servers:

  • User account information (email, nickname, locale, timezone)
  • Health profiles and related data
  • Chat conversations
  • Usage metadata and analytics
  • Notification preferences and history
  • For Bill Defense and other on-your-behalf bill negotiations, signed authorizations, related correspondence, and structured case data stored in secure internal tools (for example, Google Sheets within our Google Workspace)

2.2 Data Security

  • All data is encrypted in transit using TLS/SSL
  • Data is encrypted at rest using industry-standard encryption
  • Access controls and authentication mechanisms protect your data
  • Regular security audits and monitoring
  • Secure infrastructure hosted on Google Cloud Platform
  • Primary infrastructure hosted in the United States (Google Cloud Platform)
  • We use secure Google Workspace tools (such as Google Sheets) for structured Bill Defense case tracking, with access restricted to authorized team members

3. How We Use Your Information

We use your information to:

  • Provide personalized health information and advisory services
  • Generate AI-powered responses to your health queries
  • Send health notifications based on expected utility and your preferences
  • Respect your configured maximum daily notification limit
  • Improve our services through aggregated usage analysis
  • Use de‑identified and aggregated information to understand the impact of our services and to share general statistics or case examples about our results (for example, that we helped save a certain amount on a type of bill), without naming you or disclosing details that could reasonably identify you
  • Ensure platform security and prevent fraud
  • Comply with legal obligations
  • Provide customer support
  • Provide bill‑savings and provider‑finder features. For self‑guided use, we avoid identity‑based queries and do not transmit your personal identity to providers/insurers; if you authorize us to contact them on your behalf, we may use and disclose the minimum necessary identifying information to perform that service

4. Data Retention and Deletion

4.1 Automatic Data Expiration

  • Chat conversations automatically expire and are permanently deleted after 6 months
  • Expired data is completely removed from our servers and cannot be recovered
  • Documents you upload (e.g., medical bills or EOBs) for self-guided features in the app are retained only as long as needed to provide that feature and can be deleted by you in the app; once deleted, we remove them from servers within 10 days.
  • Documents and case materials used for Bill Defense (including files received via web intake, email, and secure internal tools such as Google Sheets) cannot be deleted through in-app controls; you may request deletion by contacting us, and once deletion is approved and consistent with the Bill Defense retention rules below, we remove them from our systems within 10 days.
  • If you ask us to contact providers/insurers on your behalf about a bill, we retain your signed authorizations and related correspondence for the duration of the engagement and up to 24 months thereafter for audit and dispute resolution (unless a longer period is required by law); you may request earlier deletion where permitted

4.2 User-Initiated Deletion

  • Delete individual chats through the app (removed from servers within 10 days)
  • Modify or delete health profiles at any time
  • Update notification preferences and settings
  • Delete your entire account via the 'Delete Account' option in settings

4.3 Account Deletion

When you delete your account:

  • All app data is immediately removed from your device
  • Server data is marked for deletion and removed within 10 days
  • Some anonymized usage metadata may be retained for analytics and fraud prevention
  • You cannot create a new account with the same credentials for 10 days

5. Data Sharing and Third Parties

5.1 We Do Not Sell Your Data

We never sell, rent, or trade your personal information to third parties for their marketing purposes.

5.2 Service Providers

We work with trusted service providers who help us operate our services:

  • Anthropic Claude and OpenAI APIs to generate responses; we configure providers not to use your data for model training, and providers may retain logs for a limited period per their policies
  • Google Cloud Platform for hosting and infrastructure
  • RevenueCat for subscription management (only receives anonymized user IDs)
  • Apple/Google for authentication services
  • Google Maps/Places or similar directory services for provider search; queries use generalized parameters (e.g., specialty and location) without your personal identity
  • Cost‑estimation partners and public datasets; when feasible we use de‑identified or aggregated data

5.3 Legal Requirements

We may disclose information if required by law, court order, or governmental authority, or to protect our rights and safety.

5.4 Do Not Sell or Share

We do not sell your personal information or share it for cross‑context behavioral advertising. We do not use your information for targeted advertising.

5.5 De‑identified & Aggregated Information

We may use or share de‑identified and aggregated information for research, benchmarking, and to explain or promote our services.

  • De‑identified means we have removed direct identifiers (such as name, address, email, phone, and medical record numbers) and taken reasonable steps to reduce the risk that a specific individual could be re‑identified
  • Examples include statistics about average savings for certain types of bills or anonymized case summaries (for example, that we helped save a certain amount on a hospital MRI bill)
  • When we use or share de‑identified or aggregated information, we do not name you or disclose details that could reasonably be used to identify you

5A. LLM Processing & Safeguards

When we use third‑party AI APIs to generate responses:

  • We minimize personal health information in prompts and mask identifiers when possible
  • We configure providers not to use your data to train their models
  • Providers may retain logs for a limited period for abuse monitoring per their policies; we do not control those retention windows
  • We do not permit providers to contact you or use your information for marketing

5B. Feature‑Specific Privacy Disclosures (Provider Finder & Bill Savings)

  • Self‑guided provider finder and bill review: we do not transmit your personal identity to insurers or providers, and we do not log in to insurer portals on your behalf
  • If you ask us to contact providers or insurers on your behalf: we may disclose only the minimum necessary identifying information to carry out your request; we do not store or use your insurer portal credentials without your explicit consent
  • Provider Finder uses generalized inputs such as specialty, location, plan category, and state; we avoid identity‑based queries for network or price lookups unless you explicitly authorize otherwise
  • Bill‑savings suggestions are generated from the information you provide and publicly available or partner data; you choose what to share

5C. Research & De‑identified Sharing (PriceCheck)

With your per‑bill consent, we may support healthcare price‑transparency research by sharing a de‑identified version of a bill with academic partners such as Rice University's Baker Institute PriceCheck.

  • Participation is optional and off by default; we ask for consent in‑context (after we present results for that bill). Declining will not affect your CareRoute experience
  • What we share: line items (e.g., CPT/HCPCS), billed, allowed, patient‑responsibility, and payer adjudication fields; dates are generalized (e.g., month/year); internal IDs are hashed
  • What we do not share: names, addresses, medical record numbers, claim IDs, exact dates of birth, phone numbers, email addresses
  • De‑identification standard: we remove identifiers consistent with HIPAA de‑identification (45 CFR §164.514(b)(2)) and may apply additional safeguards such as date generalization and small‑cell suppression
  • Withdrawals stop future sharing; previously shared de‑identified data may not be retractable from research datasets
  • When research is conducted under an IRB protocol, we follow that protocol’s consent requirements (e.g., Rice/Baker Institute PriceCheck)

5D. Bill Defense (Bill Negotiation Service)

If you enroll in our Bill Defense service (where we help negotiate or reduce a specific bill on your behalf):

  • We collect the information needed to work on your case, which may include your name, contact details, date of birth, address, relevant account or statement numbers, household size and approximate income range, and copies of bills, EOBs, and related correspondence.
  • We use this information only to evaluate options for your bill (for example, discounts, financial assistance, payment plans, or coding reviews), negotiate with providers or their billing partners, and calculate any savings‑based fee owed to us.
  • When contacting providers or insurers, we disclose only the minimum necessary identifying information and may share signed authorizations (such as a HIPAA authorization or representative letter) to document our authority to speak on your behalf.
  • Bill Defense communication may occur through email as well as in‑app or via our website; we secure email using reputable providers (for example, Google Workspace), but you should be aware that standard email is not end‑to‑end encrypted.
  • We retain Bill Defense materials and authorizations for the duration of your case and for a limited period thereafter (generally up to 24 months) for audit, dispute resolution, and regulatory requirements, after which we delete or de‑identify them unless longer retention is legally required. You may request earlier deletion where permitted by law and consistent with our contractual obligations.

6. Your Privacy Rights

You have the right to:

  • Access your personal information through the app or by contacting us.
  • Correct or update your health profiles, Bill Defense details, and account information.
  • Request deletion of specific data (including Bill Defense documents where allowed) or your entire account.
  • Export your health profile data where technically feasible.
  • Request information about how we use your data, including in Bill Defense.

7. Data Security Measures

We implement comprehensive security measures:

  • Encryption in transit (TLS) and at rest
  • Secure authentication via Apple Sign-In and Google Authentication
  • Regular security assessments and penetration testing
  • Employee access controls and confidentiality agreements
  • Incident response procedures
  • Compliance with healthcare data protection standards
  • Data minimization and role‑based access controls (pseudonymization where feasible)

8. Children's Privacy

CareRoute is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately. Parents or guardians who believe a child has provided information may contact privacy@careroute.ai to request deletion.

9. International Data Transfers

Your information may be processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information in accordance with this privacy policy. Where required, we rely on Standard Contractual Clauses or comparable safeguards for transfers.

10. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes through the app or via email. Your continued use of CareRoute after changes indicates acceptance of the updated policy.

11. Contact Information

For privacy-related questions, concerns, or to exercise your rights, please contact us at:

  • Email: privacy@careroute.ai

12. Regulatory Compliance

We strive to comply with applicable privacy laws and regulations, including GDPR, CCPA, and other regional privacy requirements. Specific rights may vary based on your location. We are generally not a HIPAA covered entity or business associate; if we enter into a Business Associate Agreement (BAA) with a partner, workflows under that BAA follow its terms.

© 2025 CareRoute by Healtheja, Inc. All rights reserved.

This privacy policy is effective as of November 12, 2025