Skip to content
DenialFight
Appeal guidesCase analysesLetter samples
Review my denial
U.S. privacy and data protection

Privacy Policy

How the U.S.-market DenialFight service collects, uses, protects, retains and discloses personal information, claim documents and consumer health data.

Effective July 31, 2026 Last updated July 31, 2026
On this page1. Scope and who is responsible2. Information we may collect3. Information we ask you not to provide4. Sources of information5. Why we use information6. Legal bases under GDPR and UK GDPR7. Automated tools and human responsibility8. When information may be disclosed9. No sale, targeted advertising or unrelated use of health data10. Retention and deletion11. Security12. International transfers13. U.S. state privacy rights14. California notice at collection15. EEA, UK and Swiss rights16. Children17. HIPAA and consumer health laws18. Changes and contact

DenialFight uploads the files or ZIP archive you select to its server, safely extracts supported archive contents, and transfers document content to artificial-intelligence processors to perform the review you request. Remove unnecessary identifiers first. Original uploads, extracted archive contents and text, your description, generated answers and the complete package are scheduled for deletion from DenialFight active servers within 10 days.

1. Scope and who is responsible

This Privacy Policy applies to DenialFight.com, related pages, forms, document tools, emails and support interactions (collectively, the “Service”). DenialFight.com is the service operator and, where applicable, the controller of personal data. Contact the privacy team at privacy@denialfight.com. This policy does not govern an insurer, employer, health plan, medical provider, attorney, regulator, payment processor or external website that maintains its own privacy practices.

The Service is designed and marketed only for adults in the United States and all content is provided only in English. A U.S. user may submit a denial issued by a European or other non-U.S. company; the tool may identify potentially relevant foreign rules, but the Service remains U.S.-directed and is not localized legal advice for another country. Visitors whose data is protected by the GDPR, UK GDPR or Swiss law retain applicable mandatory rights described below.

2. Information we may collect

  • Identifiers and contact data, such as name, email address, mailing address, telephone number and claim or account reference supplied by you.
  • Claim and policy data, including insurer, policy type, denial reason, coverage terms, claim number, dates, amounts, adjuster communications, evidence and your description of events.
  • Consumer health and medical information that may appear in a health-insurance denial, explanation of benefits, medical-necessity notice, clinical record, diagnosis, treatment history, prescription record or supporting document.
  • Uploaded content and document metadata, including every direct file or ZIP archive name, size and format; safely extracted archive contents; extracted text and page images; and the text or images contained in each submitted document.
  • Transaction data if paid features are offered, such as product selected, amount, currency, payment status and invoice data. Full payment-card numbers should be handled by a payment processor and not stored by DenialFight.
  • Device and usage data, such as IP address, browser, device type, operating system, referring page, requested URL, timestamps, security events and consent preferences.
  • Communications and support records, including emails, privacy requests, feedback and records needed to resolve a complaint.
  • Inferences generated by the tool, such as document classifications, extracted issues, missing-information flags or suggested next steps. These are educational outputs, not legal or insurance decisions.

3. Information we ask you not to provide

Unless a field expressly requests it and the production Service confirms secure processing, do not provide Social Security numbers, complete financial-account credentials, passwords, biometric identifiers, information about another person without authority, unredacted records unrelated to the denial, or any material you are legally prohibited from disclosing. Redact unnecessary identifiers before uploading.

4. Sources of information

  • Directly from you when you complete a form, upload a document, purchase a product or contact support.
  • From a person you authorize, such as a family member, representative or attorney. That person must have lawful authority to provide the information.
  • Automatically from your browser and hosting/security infrastructure when you request a page.
  • From service providers acting on our instructions, such as payment, hosting, email, security or document-processing providers.
  • From public or official sources you ask the tool to consider. DenialFight does not promise that third-party information is complete or current.

5. Why we use information

  • Provide the self-service review, organize documents, generate educational explanations, create user-requested drafts and deliver purchased files.
  • Authenticate requests, maintain security, prevent fraud, troubleshoot errors and preserve service integrity.
  • Respond to support, privacy and legal requests and communicate material service or policy changes.
  • Process payments, refunds, accounting and tax records when paid services are enabled.
  • Measure and improve the Service only where permitted and, when required, only after consent.
  • Comply with law, valid legal process, regulatory obligations and enforceable requests; establish, exercise or defend legal claims.
  • Protect users, DenialFight and others from abuse, unlawful conduct or imminent harm.

6. Legal bases under GDPR and UK GDPR

  • Contract or steps requested before a contract: to provide the tool, requested document and support.
  • Explicit consent: where you voluntarily ask us to process health or other special-category data and no other Article 9 condition is appropriate. You may withdraw consent, but prior lawful processing remains valid.
  • Legitimate interests: service security, fraud prevention, limited product improvement, support and protection of legal rights, balanced against your rights.
  • Legal obligation: tax, accounting, consumer-protection, sanctions, security-incident and lawful-process requirements.
  • Legal claims: processing necessary to establish, exercise or defend claims, where applicable.

7. Automated tools and human responsibility

The Service uses document extraction, controlled public-resource research and generative AI, currently through a separately isolated and authorized OpenAI processing service, to produce a preview and complete case package. A package may include a draft appeal, complete report, action plan, evidence and independent-support directions, destination and resource list, and supporting files. Depending on availability and the task, DenialFight may also use reviewed paid or enterprise services from Google Gemini or another disclosed provider. We do not use unpaid consumer AI tiers for uploaded claim documents. DenialFight does not make a legally binding decision about you, determine coverage, practice law or guarantee an outcome. Outputs can be incomplete, outdated, inaccurate or unsuitable for your facts.

DenialFight does not intentionally opt in to provider training or feedback sharing for user documents. AI jobs are run in ephemeral mode so the processing service does not persist a job session history. OpenAI data use is governed by the authorized account’s plan, Data Controls and applicable terms; the application does not provide a separate training-disable control that overrides those account controls. A processor may retain limited safety, abuse-monitoring or security records, and DenialFight cannot promise deletion from a processor sooner than that binding period.

You are responsible for reviewing every output against your policy, denial letter, deadline, evidence and applicable law. Do not submit an output without checking names, dates, addresses, claim numbers, citations and factual statements. Seek a licensed attorney, regulator, benefits adviser or other qualified professional when consequences are significant.

8. When information may be disclosed

  • Vendors that provide hosting, storage, cybersecurity, email delivery, customer support, document processing, artificial-intelligence processing, payment and professional services under contractual restrictions. AI recipients may include OpenAI (ChatGPT, API and related AI technologies), Google (paid Gemini API or enterprise technologies) and functionally similar reviewed providers listed on the Subprocessors page.
  • A recipient you direct us to contact or a platform you choose to use. We do not submit an appeal to an insurer unless a separate feature clearly says so and you authorize it.
  • Government, courts, regulators, law enforcement or other parties when disclosure is legally required or reasonably necessary to protect rights, safety and security.
  • A successor or transaction counterparty in a merger, financing, reorganization, insolvency or sale, subject to confidentiality and applicable notice requirements.
  • Other parties with your specific direction or consent.

9. No sale, targeted advertising or unrelated use of health data

DenialFight does not sell personal information or consumer health data for money. DenialFight does not share personal information for cross-context behavioral advertising and does not use claim or health information for targeted advertising. We do not permit advertising pixels on pages where a person enters or uploads claim or health information. If these practices change, we will update the policy, provide any required notice and choice, and obtain consent where required.

10. Retention and deletion

  • Uploaded claim documents, rendered page images and extracted document text: scheduled for deletion from DenialFight active servers no later than 10 days after upload, unless you delete the review sooner or preservation is legally required.
  • User descriptions and generated answers or drafts: scheduled for deletion from DenialFight active servers no later than 10 days after upload. Download anything you need before that date.
  • Support correspondence: generally up to 24 months after closure.
  • Payment, tax and transaction records: up to seven years or the period required by law; these records should not contain claim-document contents.
  • Security logs: generally up to 12 months, extended when reasonably necessary to investigate an incident.
  • Consent, Terms acceptance and privacy-request records: generally up to six years to demonstrate compliance and resolve disputes.
  • Document-review directories are excluded from ordinary application releases and are not intentionally copied to DenialFight backups. If an exceptional infrastructure backup contains them, it is isolated, access-restricted and expires on the provider’s secure rotation schedule.
  • Third-party processor retention: DenialFight’s 10-day period governs its own active servers. OpenAI or another processor may retain limited logs or content for abuse monitoring, legal compliance or security under the applicable business terms; approved zero-data-retention configurations may be used when available but are not promised unless stated at upload.

11. Security

We use safeguards appropriate to the sensitivity of information, which may include encrypted transmission, access controls, least-privilege permissions, logging, vendor review, secure development practices, retention limits and incident response. No internet transmission, storage system or AI service is completely secure. You accept the inherent risk of transmitting information online and should retain your own copies of important documents.

12. International transfers

The Service is directed to the United States, and data may be processed in the United States or another country where a provider operates. Those countries may have different privacy laws. Where GDPR, UK GDPR or Swiss law requires a transfer mechanism, we rely as applicable on adequacy decisions, the EU Standard Contractual Clauses, the UK Addendum, contractual and technical safeguards, or another lawful mechanism. Contact privacy@denialfight.com for information about the relevant safeguard.

13. U.S. state privacy rights

Depending on your state and whether statutory thresholds and exemptions apply, you may have rights to know, access, correct, delete or obtain a portable copy of personal data; opt out of sale, targeted advertising or certain profiling; limit specified uses of sensitive personal information; withdraw consent; and appeal a denied request. We will not discriminate against you for exercising a right. DenialFight does not sell or share personal information for behavioral advertising. Instructions are provided on the Your Privacy Choices page.

14. California notice at collection

At or before collection, California residents are informed that the Service may collect identifiers, customer records, protected classification information included in a claim, commercial information, internet activity, geolocation at an approximate IP-derived level, audio/electronic communications, professional information, sensitive personal information, consumer health information and inferences. These categories are used for the purposes in Section 5 and retained under Section 10. We do not sell or share these categories for cross-context behavioral advertising. We use sensitive information only to provide the requested service, maintain security, comply with law and other permitted purposes. See Your Privacy Choices for requests and authorized-agent instructions.

15. EEA, UK and Swiss rights

Where applicable, you may request access, correction, erasure, restriction, portability and objection; withdraw consent; and complain to your local supervisory authority. You also may request information about international-transfer safeguards. Rights are subject to legal conditions and exemptions. We may need to verify identity and authority before acting. You are not required to provide information, but we cannot provide a document-specific tool without the information needed for that request.

16. Children

The Service is not directed to children and may be used only by people at least 18 years old. Do not provide information about a minor unless you are the parent or legal guardian and the information is necessary for an adult-directed insurance matter. We do not knowingly collect personal information directly from children under 13. Contact us to request deletion if you believe a child submitted information.

17. HIPAA and consumer health laws

DenialFight is not a health plan, health care provider or clearinghouse and is not automatically a HIPAA covered entity or business associate. Unless we sign a valid Business Associate Agreement, do not assume HIPAA applies. Other laws may protect consumer health data, including the FTC Health Breach Notification Rule and state consumer health statutes. See the separate Consumer Health Data Privacy Policy.

18. Changes and contact

We may update this policy to reflect the Service, vendors or law. Material changes will be posted with a new date and additional notice where required. Effective July 31, 2026; last updated July 31, 2026. Privacy requests and questions: privacy@denialfight.com. Legal notices: legal@denialfight.com. Support: support@denialfight.com.

Questions or requests?

Use the dedicated address so your message reaches the correct review queue. Email is not an emergency service and does not extend an insurance or legal deadline.

privacy@denialfight.com
DenialFight

U.S.-market self-service tools for understanding insurance denials and preparing your own appeal. U.S. users may submit denials from European companies, but foreign-law points require independent verification. Not a law firm, insurer, medical provider or claims representative.

ResourcesAppeal guidesCase analysesLetter samplesStart a review
LegalPrivacy PolicyTerms of UseCookie PolicyImportant DisclaimersSecurity & Retention
Privacy rightsConsumer Health Data PolicyYour Privacy ChoicesAI Providers & SubprocessorsAccessibility
Contactprivacy@denialfight.comlegal@denialfight.comsupport@denialfight.com
© 2026 DenialFight.com · Last legal update: July 31, 2026United States market only. Use at your own risk. No result, deadline, coverage decision or recovery is guaranteed.