Unbill LLC
Privacy Policy
Effective September 20, 2026 · Applies to the Unbill private beta
Unbill LLC (“Unbill”) is building an advocacy platform for navigating high-friction systems. Unbill is currently an invitation-only private beta. This policy describes what information we collect, how we use it, and the choices you have. We will update this policy before practices change, including before any public launch.
Information we collect
- Contact information: your email address when you apply for the private beta, join the waitlist, or contact us.
- Account information: the name and email address associated with your sign-in, provided through our authentication provider.
- Information you provide in the product: you may upload healthcare, insurance, billing, financial, and other records that you have the right to provide, along with questions, profile details, and other content you choose to submit. We use this information to organize and review your records, answer your questions, identify billing or coverage issues, prepare materials you request, and operate and secure the service. Health records are also subject to the additional limits described below.
- Consumer-directed health-plan and clinical records: if this feature is enabled and you choose to connect a supported insurer, health plan, provider, or record source, Unbill may receive the read-only records you authorize. Depending on the source, these may include coverage information, claims and Explanations of Benefits, providers, service dates, billing or procedure codes, submitted and allowed amounts, plan payments, member responsibility, notes, procedures, conditions, and other health-record files. Unbill does not request permission to alter payer or provider records.
- Technical information: basic log and device information generated by operating the service, such as timestamps and request data.
How we use information
- To provide the beta service: organizing the records you upload or connect, analyzing them, answering your questions, and preparing administrative materials you have requested.
- To operate, secure, and improve the product, and to fix problems.
- To communicate with you about your account, the beta, and things you have asked us about.
We do not sell your personal information.
Consumer-directed health-plan and clinical records have a narrower rule: Unbill uses them only to provide the record organization, billing review, answers, plan-specific research, administrative materials, deletion, support, or security function you requested. Unbill does not use those records, including de-identified content derived from them, for advertising, general research, model training, product analytics, or product improvement.
Optional product analytics and session replay
In the signed-in product, Unbill asks permission before using Mixpanel product analytics, privacy-masked session replay, and heatmaps. These tools help us understand feature use, where people click or stop, and where the beta is confusing. The public marketing site is not included in Mixpanel session replay.
All page text and form values are masked before replay data leaves your device. We exclude case-detail and advocacy screens, case-scoped questions, account-management screens, documents, media, tables, dates, downloads, external links, console output, network traffic, and internal Case, Document, and Finding identifiers. Mixpanel retains session replays for 30 days. You may decline or later turn this collection off under Profile → Privacy and data.
Consumer-directed health-record connections
A connection starts only when you choose to connect a supported source, review the requested read-only access, and complete that source’s authorization and consent flow. Unbill uses Flexpa as a service provider to facilitate supported insurer, health-plan, and other patient-authorized record connections. Flexpa and the connected source may present their own privacy notices and terms during authorization.
Imported records are assigned to the healthcare profile for the person receiving care. A coverage record or plan document may be used across that person’s Cases when its plan and effective dates apply; it is not made available to a different person’s profile merely because both profiles are in the same household. If more than one plan may apply, Unbill may ask you to select or confirm the plan for a Case. Health-record evidence is context for an administrative billing review; it is not a diagnosis, medical advice, or proof that a billed service was or was not performed.
Connection tokens, raw imported health records, and the normalized health-record projections Unbill retains for product features are encrypted with application-level AES-256-GCM before they reach our database. Minimal lifecycle and provenance metadata, such as record type, content fingerprint, synchronization status, and timestamps, remains separately queryable so Unbill can operate and verify the connection. Health-record and customer-document AI inference is routed through Anthropic Claude on Amazon Bedrock under Unbill’s AWS Business Associate Agreement; the clinical path does not use a direct Anthropic API endpoint.
Unbill currently offers this beta directly to consumers and designs these connections to act at your direction; it is not your insurer, healthcare provider, Flexpa, or a payer or provider portal. Legal obligations can depend on the parties, contracts, and purpose of a particular data flow. Unbill protects the records under this policy, its terms, its applicable contractual commitments, and applicable consumer privacy and security law.
How information is shared
We share information only with the service providers needed to operate Unbill, for example authentication, cloud hosting and database infrastructure, document processing, and AI analysis providers, and only so they can provide those services to us. Providers involved in the connected-record path include Flexpa, which facilitates patient-authorized health-record connections; Amazon Web Services, which provides bounded AI processing through Bedrock; Vercel, which hosts the secure callback and application runtime; and Neon, which stores application-encrypted imported record content without Unbill’s decryption key, together with the minimal account, lifecycle, provenance, and product data needed to operate the service. Information may also be available to people you authorize for the healthcare profile and to authorized Unbill security personnel through an exceptional, logged procedure for support, deletion, or a security incident. We may also disclose information when required by law, or to protect the rights, safety, or security of Unbill, our users, or others. We do not sell personal information, and we do not share it with third parties for their own marketing.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.
Text messages
If you voluntarily enroll in Unbill Transactional SMS Updates, we collect your mobile phone number and a record of your consent. We use that information to send content-minimized transactional case updates and dispute checklists. Consent is not a condition of purchase. Message frequency varies, and message and data rates may apply. Reply STOP to cancel or HELP for support. We do not use this enrollment for marketing messages.
Data retention and deletion
We retain general account information while your account is active or as needed to operate the service and meet legal obligations. You can request access to or deletion of your information at any time by emailing privacy@unbill.ai, and we will respond to verified requests. You may also use that address to request a copy of your information or ask us to correct information that is inaccurate or out of date.
Signed-in customers can download a structured copy of their account data from Settings. Requests that cannot be completed automatically receive an internal reference and may be submitted for another review. A complete portable copy that includes original uploaded files can be requested through the privacy address above. Applicable rights and response procedures may vary based on where you live.
Ask Unbill conversations are stored under your authorized healthcare profile so history remains available across sessions and can stay attached to the Case you selected. Archiving removes a conversation from the active interface. Verified access or export requests use the contact above, and deleting your account removes the corresponding conversation rows through the ordered account-deletion process, subject to applicable legal obligations and backup aging.
Imported health-plan and clinical records are retained for the life of the applicable connection or healthcare profile, not indefinitely. They may remain available across the Cases for that person until you disconnect the source, delete the healthcare profile or account, request verified deletion, or Unbill performs a documented security purge. Disconnecting ends future Unbill synchronization, asks Flexpa to revoke the connection where its interface supports that action, and starts deletion of stored connection credentials, imported snapshots, and related derived health-record text, subject to legal requirements, operational completion, and backup aging. Content-free security, consent, and data-rights audit events may remain, along with the limited insurance information described in the next paragraph.
When you disconnect an insurance account, Unbill stops accessing it and removes the insurance records received through that connection. We may keep limited information that was already used in a Care Plan, Case, or action so your Unbill history remains understandable. This can include the insurer, dates of service, provider name, claim status, and relevant billed, allowed, paid, or member-responsibility amounts. We don’t keep the underlying insurance records, claim-line details, diagnosis or procedure codes, or member identifiers solely for this purpose. Saved Ask answers that quoted records from the disconnected account are removed. Information retained after disconnect is included in your data export and is deleted if you delete your Unbill account.
A payer or provider may maintain its own authorization or connected-app record even after Unbill asks Flexpa to revoke access. Where applicable, you can also revoke the connection through the source’s connected-app settings or through Flexpa at privacy.flexpa.com. You may email privacy@unbill.ai for help. Backup copies age out under the applicable infrastructure retention schedule, and a restored copy must be subjected to the deletion procedure again.
For supported direct clinical-record connections, Unbill keeps a content-free, tamper-evident history of access for the life of the authorized healthcare profile. That history records the actor category, purpose, time, result, and number of encrypted records involved; it does not store what was read. Payer-connection consent, synchronization, and revocation use separate content-free lifecycle evidence. You may request a verified export covering all Cases by emailing the address above.
Security
Access to your information is restricted to your authenticated account. We use administrative, technical, and organizational safeguards designed to protect personal information. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
Invite-beta availability
Some live health-data features are released only in selected states during the private beta. Unbill asks for your current state and records when you attest to it so those features can fail closed outside the configured beta area. This is an operational release control, not identity verification or a representation that every legal requirement has been finally determined.
Children
Unbill is for adults. Individuals under 18 may not create accounts or submit information directly. A parent, legal guardian, or other legally authorized representative may provide information about a minor when using Unbill on the minor’s behalf. If you believe a minor has provided information directly to Unbill, please contact us.
Changes and contact
We will post updates to this policy on this page with a new effective date and communicate material changes to active participants. Where required, we will obtain renewed consent before using connected health information in a materially different way. Questions and privacy requests: privacy@unbill.ai.