Skip to content
DenialFight
Appeal guidesCase analysesLetter samples
Review my denial
Who may receive uploaded content

Subprocessors & AI Providers

Current and potential service providers that may process U.S. DenialFight documents, generated answers, transaction data or operational records.

Effective July 31, 2026 Last updated July 31, 2026
On this page1. OpenAI — active AI document processor2. Google Gemini — planned/conditional AI processor3. Other artificial-intelligence providers4. Hosting and infrastructure — active5. Lemon Squeezy — configured payment processor and intended merchant of record6. Support, email and professional providers7. Government and user-directed recipients8. International processing9. Provider changes and objection10. Questions

Submitting a document authorizes transfer to the active providers necessary for the requested review. OpenAI AI processing through an isolated, server-authorized shared worker is active. Lemon Squeezy is configured for payment testing and will receive checkout data only when a user starts its checkout; live payment acceptance remains conditional on store activation. Google Gemini is identified for planned or conditional use and does not receive review content unless its feature is activated.

1. OpenAI — active AI document processor

Provider and technology: an OpenAI AI service in a separately isolated shared server worker, authenticated through a server-managed authorization. Purpose: multi-document extraction-assisted review, limited public-resource research, issue identification, complete case-report generation, appeal drafting and creation of the paid ZIP package from which the free preview is derived. Data: uploaded document text or page images, safely extracted archive contents, user description, category and a constrained server-generated instruction. Location: processing may occur in the United States and other locations permitted by OpenAI’s terms.

Configuration: credentials remain only in the shared worker; DenialFight does not intentionally opt in to training or feedback sharing; each review uses ephemeral AI execution and read-only sandbox settings. Public web searches are instructed to exclude user identifiers and sensitive claim details. Actual provider data use depends on the authorized account’s plan and Data Controls. OpenAI may retain safety or abuse-monitoring data under its applicable policy unless an approved zero-data-retention arrangement applies.

2. Google Gemini — planned/conditional AI processor

Provider and technology: Google paid Gemini API or an enterprise Google Cloud/Vertex AI configuration. Purpose if activated: fallback availability, document understanding or quality comparison. Data may include the same document content and instructions sent to the primary AI processor. DenialFight will not use unpaid Gemini API, unpaid AI Studio or a consumer Gemini account for uploaded claim documents because their data-use terms differ.

Status: not active in the current review path. Before activation, DenialFight will validate the paid or enterprise account, contractual data controls, retention, security and lawful transfer basis and update this page if the material processing changes.

3. Other artificial-intelligence providers

DenialFight may add a functionally similar provider—for example Anthropic, Microsoft Azure-hosted AI, Amazon Bedrock or another enterprise document/AI service—only after reviewing its business terms, no-training controls, security, retention and transfer mechanisms. If such a provider will receive identifiable review content, this page and the upload disclosure will identify it before or at the time required by law. DenialFight does not grant permission for a processor to use user documents for its own advertising.

4. Hosting and infrastructure — active

Server, container, networking, TLS, storage, monitoring and backup providers process uploaded files, extracted text, generated answers, IP addresses and operational logs as needed to host and secure the Service. Review data is segregated from application releases and scheduled for active-server deletion within 10 days. Infrastructure providers may maintain limited system or security records under contract.

5. Lemon Squeezy — configured payment processor and intended merchant of record

Purpose: hosted checkout, tax calculation, order administration, payment status, receipts, refunds and fraud prevention. Data when checkout is started: name, email, billing details, order identifiers, review-specific opaque identifiers, IP/device signals and payment information supplied directly to Lemon Squeezy. Uploaded denial documents and generated package contents are not sent to Lemon Squeezy. DenialFight receives order metadata rather than full payment-card numbers. Status: Lemon Squeezy Test Mode is configured for development verification and transfers no real funds; a separately labeled local simulation may also be used when provider test credentials are unavailable. Live checkout remains disabled until Lemon Squeezy enables the store and live credentials. Live access will require a Lemon Squeezy checkout URL, review-specific custom data and a signature-verified paid-order webhook before the package is unlocked.

6. Support, email and professional providers

Email, support, legal, accounting, security and incident-response providers may process contact details, correspondence or a limited record needed for the assigned task. Do not email a claim document unless support expressly provides a suitable secure method. Professional advisers are bound by contractual, ethical or legal duties as applicable.

7. Government and user-directed recipients

A court, regulator, law-enforcement agency or other recipient may receive information when disclosure is legally required, necessary to protect rights or safety, or directed by you. These recipients are not ordinary subprocessors and may have independent legal authority. DenialFight does not send an appeal to an insurer through the current review flow.

8. International processing

The Service is directed only to the United States, but providers may operate globally and a U.S. user may submit a European-company denial. Where the GDPR, UK GDPR or Swiss law applies, DenialFight uses an available lawful transfer mechanism such as adequacy, Standard Contractual Clauses, the UK Addendum or another valid safeguard. Foreign-law content in a review does not change the Service’s U.S. market positioning.

9. Provider changes and objection

Providers can change for availability, security, performance or product development. Material new use of identifiable document content will be disclosed through this page, the Privacy Policy and, where required, a new consent prompt. If you do not accept a listed processor, do not upload a document. You may request deletion of an existing DenialFight review, subject to lawful exceptions and processor capabilities.

10. Questions

Questions about a provider, processing location, contract category or retention control may be sent to privacy@denialfight.com. Security questions may be sent to security@denialfight.com. Last updated July 31, 2026.

Questions or requests?

Use the dedicated address so your message reaches the correct review queue. Email is not an emergency service and does not extend an insurance or legal deadline.

privacy@denialfight.com
DenialFight

U.S.-market self-service tools for understanding insurance denials and preparing your own appeal. U.S. users may submit denials from European companies, but foreign-law points require independent verification. Not a law firm, insurer, medical provider or claims representative.

ResourcesAppeal guidesCase analysesLetter samplesStart a review
LegalPrivacy PolicyTerms of UseCookie PolicyImportant DisclaimersSecurity & Retention
Privacy rightsConsumer Health Data PolicyYour Privacy ChoicesAI Providers & SubprocessorsAccessibility
Contactprivacy@denialfight.comlegal@denialfight.comsupport@denialfight.com
© 2026 DenialFight.com · Last legal update: July 31, 2026United States market only. Use at your own risk. No result, deadline, coverage decision or recovery is guaranteed.