Privacy Policy

Effective date: July 31, 2026

Denial Appeal Pro ("DAP," "we," "us," or "our") provides software that helps healthcare billing professionals and provider offices generate administrative appeal letters from denial letters and remittance data. This Privacy Policy describes how we collect, use, store, and protect information when you use our website and services.

1. Information we collect

We may collect the following categories of information:

  • Account information: name, email address, password (stored via our authentication provider), and billing-related identifiers linked to your account.
  • Payment information: payment method and transaction details are processed by Stripe. We do not store full payment card numbers on our servers.
  • Uploaded documents and pasted text: denial letters, explanations of benefits (EOBs), remittance advice, and related billing documents you submit for extraction and appeal generation.
  • Protected health information (PHI): documents you upload may contain PHI, including patient names, member/subscriber IDs, dates of birth, dates of service, diagnosis and procedure codes, and other identifiers appearing on payer correspondence.
  • Generated content: extracted claim data, appeal letters, and export files you create through the service.
  • Technical data: IP address, browser type, device information, and usage logs necessary to operate and secure the service.

2. How we use information

We use collected information solely to:

  • Provide denial extraction, review, and appeal letter generation;
  • Maintain your account, authenticate access, and enforce plan limits;
  • Process payments and send transactional communications;
  • Improve reliability, security, and product performance;
  • Comply with legal obligations.

We do not sell your personal information or PHI. We do not use uploaded denial documents to train public AI models for unrelated purposes. Document content is processed only to deliver the appeal-generation service you request.

3. Third-party processors

We use trusted subprocessors to operate the service. Each receives only the data necessary for its function:

  • Supabase — authentication, database storage, and access-controlled user data.
  • OpenAI — AI-assisted extraction and appeal letter generation from content you submit.
  • Stripe — payment processing and subscription billing.
  • Netlify — application hosting and serverless function execution.
  • Resend (when configured) — transactional email delivery.

These providers are contractually required to protect data and may only process it according to our instructions and applicable law.

4. Data retention

Uploaded source documents and raw extraction inputs are retained for up to 30 days to support appeal generation, account recovery, and dispute resolution, then deleted or anonymized unless a longer retention period is required by law or you have an active paid subscription with saved appeal history you choose to maintain.

Account, billing, and audit records may be retained longer as needed for legal, tax, and security purposes.

5. Security

We implement administrative, technical, and organizational safeguards including encryption in transit (TLS), encryption at rest via our cloud providers, role-based access controls, and authenticated API access. No method of transmission or storage is completely secure; you use the service at your own risk within these limits.

6. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access personal information we hold about you;
  • Request correction of inaccurate information;
  • Request deletion of your account and associated data;
  • Object to or restrict certain processing.

To exercise these rights, email privacy@denialappealpro.com. We will respond within a reasonable timeframe and may verify your identity before fulfilling requests.

7. HIPAA notice

Denial Appeal Pro is a software tool provider, not a covered entity under HIPAA. When provider offices use DAP to process patient information from denial documents, the provider office typically acts as the covered entity and DAP may act as a business associate depending on the nature of the relationship and data flow.

You are responsible for your own HIPAA compliance, including determining whether a Business Associate Agreement (BAA) is required, executing BAAs with us and our subprocessors where applicable, and ensuring you have a lawful basis to upload PHI into the service. See our HIPAA Notice for subprocessors and BAA request information.

8. Children

The service is intended for healthcare billing professionals and is not directed to individuals under 18. We do not knowingly collect information from children.

9. Changes

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated effective date.

10. Contact

Privacy inquiries: privacy@denialappealpro.com