This U.S.-market policy separately governs consumer health data. Health-denial documents are transferred to server and AI processors for the requested review, are not sold or used for advertising, and are scheduled for deletion from DenialFight active servers within 10 days.
1. Scope
This policy supplements the general Privacy Policy and applies to “consumer health data” as defined by laws such as the Washington My Health My Data Act and Nevada consumer health data law. It covers data linked or reasonably linkable to a consumer that identifies or can be used to infer health status, treatment, diagnosis, insurance claims, benefits, medication, bodily functions or efforts to obtain health services.
2. Categories that may be collected
- Health-insurance coverage, claim, denial, prior-authorization and appeal information.
- Diagnosis, symptoms, condition, treatment, procedure, provider, prescription, test, disability or medical-necessity information appearing in a user-provided document.
- Identifiers and contact details needed to associate a requested review with the consumer.
- Information about payment for health services and an insurer’s stated reason for nonpayment.
- User statements and inferences created solely to organize the requested denial review.
3. Sources
We collect health data directly from you or from a representative you authorize. We may extract it from documents you choose to provide. We do not purchase health data from data brokers, infer health status for advertising or collect precise location to identify a visit to a health facility.
4. Purposes
- Perform the specific U.S.-market multi-document review and drafting task you request.
- Safely extract ZIP contents, organize evidence, explain a denial reason and generate a free preview plus complete case package.
- Locate generic public procedures, regulators, provider directories and resources without intentionally placing personal identifiers or sensitive claim details in search queries.
- Provide support, prevent fraud, secure the Service and comply with law.
- Maintain a limited record of consent, delivery and privacy requests.
- Improve systems only with properly de-identified data; identifiable uploaded health documents and answers are not intentionally contributed for model training or targeted advertising.
5. Consent
Where applicable law requires consent, we request a separate, specific affirmative action before collecting or processing consumer health data. Acceptance of general Terms alone is not treated as health-data consent. Consent may be withdrawn for future processing. We will request separate written authorization before any sale; DenialFight does not currently sell consumer health data.
6. Sharing and AI recipients
Consumer health data may be disclosed to processors necessary for hosting, security, document extraction, AI-assisted generation, support or storage; to a recipient you direct; or when law requires. Current AI analysis uses OpenAI AI/API technologies. Reviewed paid or enterprise Google Gemini services or another provider listed on the Subprocessors page may be used for availability or specialized processing. We do not use unpaid consumer AI tiers for uploaded health documents. Processors must be restricted to the service purpose. We do not share health data with advertising networks, data brokers or social-media platforms for profiling.
7. Your rights
- Confirm whether consumer health data is collected, shared or sold.
- Access the data and receive information about recipients where applicable.
- Withdraw consent for future collection or sharing.
- Request deletion from DenialFight and, where required, processors and affiliates.
- Appeal a refusal by replying to the decision or emailing privacy@denialfight.com with “Health Data Appeal.”
- Complain to the Washington or Nevada Attorney General or another competent regulator.
8. How to exercise rights
Email privacy@denialfight.com with “Consumer Health Data Request,” identify your state, describe the request and provide the minimum information needed to locate your record. We may verify identity and authority using proportionate methods and will not use verification data for another purpose. Authorized agents must provide proof of authority where allowed.
9. Retention and deletion
Claim and health documents, extracted text, page images, user descriptions and generated answers are scheduled for deletion from DenialFight active servers no later than 10 days after upload, unless you delete the review sooner or law requires preservation. Limited transaction, security, consent and compliance records may be retained separately and should not contain document contents.
The 10-day commitment applies to DenialFight active servers. AI and infrastructure processors may maintain limited security, abuse-monitoring or legally required records under their applicable business terms. We request processor deletion where required by law and available under our configuration, but do not represent that every processor offers zero data retention.
10. HIPAA status and FTC rule
DenialFight is not automatically regulated by HIPAA because it is not a health plan, covered provider or clearinghouse and may not be a business associate. Unless a signed Business Associate Agreement applies, do not assume HIPAA protections. The FTC Health Breach Notification Rule and state laws may nevertheless require safeguards and notices after certain unauthorized acquisitions or disclosures of identifiable health information.
11. Security and incident response
We apply safeguards appropriate to sensitive health information and maintain an incident-response process. If a legally reportable incident occurs, notice will be provided to affected people, regulators and others within the legally required period and with the required content. No security program eliminates all risk.
12. Changes and contact
Material changes to collection, purpose, sharing or sale will be disclosed and new consent obtained when required. Contact privacy@denialfight.com. Effective July 31, 2026; last updated July 31, 2026.
Questions or requests?
Use the dedicated address so your message reaches the correct review queue. Email is not an emergency service and does not extend an insurance or legal deadline.
privacy@denialfight.com