ClaroBill

Privacy Policy

Effective date: April 7, 2026. Last updated: April 7, 2026. Last reviewed: May 2026.

ClaroBill (“we,” “our,” or “us”) is committed to protecting your privacy. This policy explains what data we collect when you use ClaroBill, how we use it, and your rights regarding that data. Because ClaroBill processes medical bills, we treat all uploaded content as sensitive and apply strict handling controls throughout our systems.

1. Data We Collect

Account data: When you create an account: your email address and an authentication credential. If you sign in with a third-party identity provider, we receive only your email and display name from that provider.
Medical bill files: Files you upload (PDFs, images) are stored encrypted at rest in private storage. Only you and our processing systems can access them. We do not share uploaded files with any third party other than as described in Section 3.
Extracted bill data: Text and line items extracted from your bill (such as procedure codes, charge amounts, and dates of service) are stored in our database and used to generate your report. We do not store patient names or dates of birth beyond what you include in the uploaded file itself.
Payment data: We do not store credit card numbers. Payment processing is handled by an external payment service. We retain a customer identifier and transaction identifier from that service to support refunds and order history.
Usage data: Anonymized page views and feature interactions. Bill identifiers and other personal identifiers are stripped before any analytics event is recorded. We do not use session recording or keystroke logging.
Error and performance data: Anonymized error reports and stack traces. Request body contents are redacted before transmission to prevent leakage of sensitive information.

2. How We Use Your Data

  • To extract text and line items from your uploaded bill
  • To run automated billing checks against the line items on your bill
  • To generate an analysis report and a personalized dispute letter draft
  • To deliver your report and dispute letter via email
  • To process your payment and support refund requests
  • To monitor service reliability and fix errors
  • To understand aggregate usage patterns and improve the product

We do not use your medical bill data to train AI models. That includes our own models and those of any service provider we work with. Every service we use that processes your data is contractually prohibited from using submitted content for model training or any purpose other than performing the service for us.

3. Categories of Service Providers

To deliver the Service, we engage a small number of service providers to handle specific operational functions. We do not publish the names of these providers on this page in order to limit the value of the disclosure to bad actors and competitors. We share only the minimum data necessary for each provider to perform its function. The categories are:

Cloud infrastructureDatabase, encrypted file storage, and authentication
Document processingText extraction from uploaded bill images and PDFs
AI servicesBill summarization and dispute letter drafting. Contractually prohibited from using submitted content for model training.
Payment processingCard processing, refund support, and transaction history
Email deliveryDelivery of transactional emails (account, reports, receipts)
Operational telemetryAnonymized error reporting and aggregate usage analytics, with personal identifiers stripped before transmission

All service providers operate in the United States. A current list of named sub-processors is available to enterprise customers and regulators on written request to privacy@clarobill.com.

We do not sell your data to advertisers, data brokers, or any other third party. We do not share your data for advertising or marketing purposes.

4. Data Retention

  • Uploaded bill files: retained for 90 days after upload, then automatically deleted
  • Extracted line item data and reports: retained for 12 months, then deleted
  • Account data: retained until you delete your account
  • Payment records: retained for 7 years as required by financial regulations
  • Anonymized analytics: retained indefinitely in aggregate, with no link to your identity

5. HIPAA Notice

Clarobill is not a Covered Entity or Business Associate as defined by the Health Insurance Portability and Accountability Act (HIPAA). Medical bills you upload are not “protected health information” (PHI) under HIPAA in the context of this Service because Clarobill is not a healthcare provider, health plan, or healthcare clearinghouse.

However, because your bill may contain sensitive health information, we apply strong technical and organizational controls (encryption at rest and in transit, strict access controls, and data minimization) consistent with the spirit of HIPAA and industry best practices.

6. Your Rights

You have the right to:

  • Access the data we hold about you
  • Correct inaccurate data
  • Delete your account and associated data (within 30 days of request)
  • Export your data in a portable format
  • Opt out of analytics by using a browser with tracking protection enabled

To exercise any of these rights, email privacy@clarobill.com. We will respond within 30 days.

7. Cookies and Tracking

We store a randomly generated analytics session identifier in your browser. This identifier is not linked to your account or personal information. We do not use third-party advertising cookies and we do not allow advertising networks to track you through our Service.

Your authentication session is stored in a secure, httpOnly cookie.

8. Security

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Uploaded files are stored in private storage with no public access. Access to production systems is restricted to authorized personnel via multi-factor authentication.

If you discover a security vulnerability, please report it responsibly to security@clarobill.com.

9. Children

The Service is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has submitted data to Clarobill, contact us at privacy@clarobill.com and we will delete it promptly.

10. Changes to This Policy

We will notify you of material changes to this policy by email at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.

11. Contact

Privacy questions or requests: privacy@clarobill.com