MedBillCheckup

Privacy Policy

What stays on your device, the one moment figures from your bill are sent to us and exactly what is and is not in that request, what we keep (nothing), who else is involved, and the rights you have.

Version 2.4 · Effective 2026-09-26

This policy describes how MedBillCheckup handles your information. It is written to match what the software actually does. Where a statement depends on how this deployment is configured, the configured value is shown.

The short version: your bill never leaves your device. It is read by your own browser and kept there. The only time anything about a bill reaches us is when you ask for the findings, and then only the figures read from it (never the file, never the patient's name), processed in memory and not stored. We run no database and hold no copy of anything about your bills. The only thing we keep is a message, if you choose to send us one from the Support page.

Who is responsible for your data

Controller: Rémi Toumi Address: Calle de Lezama, Madrid, 28034, Spain Registration: Individual sole trader (Spain), no company registration number Privacy contact: billcheck.businessacc@proton.me General support: billcheck.businessacc@proton.me

We have not appointed a Data Protection Officer. Whether one is required depends on the scale of processing, and we keep that under review as the service grows.

What stays on your device

The application runs in your browser. Everything it produces about a bill is held in your browser's own storage (an IndexedDB database named billcheck) on the device you used, and nowhere else:

The documents you open. Medical bills, Explanations of Benefits and Good Faith Estimates, as files. These contain health information. They are never uploaded. There is no server that receives them and no copy outside your device.

What your browser reads from them. Provider, dates, line items, billing codes and amounts, together with the page each value came from and how confidently it was read. A PDF with a text layer is read directly; a scan or a photograph is read by text recognition that runs on your device.

Patient identifiers found in your documents. A patient name, account number, date of birth or insurance member ID may appear on a bill. After a document is read these are separated from everything else on your device. They are never included in anything sent to us.

Your corrections, the findings, the questions, the letter and the PDF report, once you have asked for the findings.

Proof of payment. If you pay for a bill, a signed receipt for that bill; if you subscribe, a signed pass. These are what let you open your findings again without paying twice.

Your choices. The country you told us the bill is from, and your consent choices with the version of the document you consented to.

You can download all of this as a single file, import it on another device, or erase it, from Settings.

What reaches us, and when

We operate no database and store nothing about your bills. Three things can reach our servers, each transient (a message you choose to send us is the one thing that is kept; see Messages you send us):

1. The request that runs the checks. When you ask for the findings on a bill, your browser sends one request to a function we host. It contains exactly:

  • the line items, amounts, dates, billing codes and provider name your browser read from the bill, with the corrections you made;
  • the country you chose;
  • a measure of how legible the document was;
  • for subscribers only, the same figures from an Explanation of Benefits or a Good Faith Estimate if you chose to compare them;
  • your receipt or pass, so the function can confirm the bill has been paid for.

It does not contain the file, any page image, any text outside those figures, the patient's name, account number, date of birth or insurance member ID, your email address, or anything identifying your device beyond what any web request carries. The function runs the checks in memory, returns the findings to your browser, and keeps nothing. The request body is not logged and is not written anywhere. This is the only processing of health information that happens on our side, and it lasts for the seconds the request takes.

2. A sign-in request, subscribers only. If you subscribe and want to use another device, you enter the email address you used at checkout. We look it up with our payment provider and, if it belongs to an active subscriber, email you a link. The request is processed in memory and not stored; the email is delivered by the provider named below.

3. Ordinary web-server records. Our hosting provider records requests as any web server does. Our own functions log a request identifier, timestamps and error codes only. We derive short-lived rate-limit counters from the network address a request arrives from; they live in memory and are discarded when the function instance ends. We do not keep raw IP addresses.

Payment. If you pay, our payment provider collects your email address and payment details on its own pages and keeps the record of what you bought. For a single-bill purchase it also holds a fingerprint (a cryptographic hash) of the figures you paid to have checked, so that your receipt can be tied to that bill. The fingerprint cannot be turned back into the figures. We never see or store card numbers.

We do not collect precise location, we set no cookies, we do not use tracking of any kind, and we do not build advertising profiles. There are no analytics.

Messages you send us {#messages}

The Support page has a message box for problems, payment questions, complaints and ideas. If you use it, we receive the topic you chose, what you wrote, and the version of the app you were using. For a payment question or a complaint you may also give the email address you paid with; it is optional and used only to find your payment with our payment provider.

The message is delivered by our email provider to our support mailbox, which only the operator can read; nothing is stored on our side or by our host. You get an automatic reply on screen; we do not correspond by email. Please do not include anything from your bill: no names, account numbers or medical details. We keep messages for as long as they are useful to deal with what you raised and to improve MedBillCheckup. You can ask us to delete yours at any time by writing to billcheck.businessacc@proton.me.

Why we process it, and on what legal basis

Reading a bill in your browser is done by software running on your device under your control; no data is disclosed to us by it. The table covers what is processed on our side.

What Why Legal basis (GDPR)
Running the checks on the figures you send To produce the findings you paid for Article 6(1)(b), performance of a contract
The health information inside those figures Same Article 9(2)(a), your explicit consent
Subscriber sign-in by email link To let a subscriber use another device Article 6(1)(b)
Payments and subscription state (held by the payment provider) To take and manage a purchase Article 6(1)(b)
Rate limiting and abuse prevention To keep the service working and safe Article 6(1)(f), legitimate interests
A message you send from the Support page To deal with the problem, payment question, complaint or idea it describes Article 6(1)(b) where it concerns your purchase; otherwise Article 6(1)(f), legitimate interests in running and improving the service

Health information is special-category data. We rely on your explicit consent under Article 9(2)(a) for the one request that carries it. That consent is asked for separately, is never pre-ticked, is never bundled with anything else, and can be withdrawn at any time in Settings. Withdrawing it means the app will not send the figures of a bill to us for checking; it does not affect a request that already ran, and it does not affect anything on your device.

If you are in the United States, several state laws treat health information as sensitive data requiring opt-in consent, and the Washington My Health My Data Act requires separate consent for collecting and for sharing consumer health data. We apply the same explicit-consent approach everywhere, and we share consumer health data with no one.

Automated processing

The checks that produce your findings are ordinary arithmetic and comparison rules written in code. They compare amounts, dates and descriptions in the figures your browser sent.

MedBillCheckup does not make automated decisions that produce legal or similarly significant effects about you. It does not decide what you owe, what your insurance covers, whether a charge is correct, or whether you have a legal claim. It produces information and questions; every decision remains yours.

Who else processes your data

Recipient What they receive Why
Hosting Cloudflare carries every request to our functions, including the one that runs the checks, and serves the application To run the service
Payments Stripe, which hosts checkout, takes the payment and keeps the payment record; we never see or store card numbers To take a purchase or a subscription
Email Brevo, which receives a subscriber’s email address in order to deliver a sign-in link; it also delivers the messages you send from the Support page to our support mailbox To send sign-in links to subscribers and deliver your messages
Error tracking no third-party error tracker; errors go to the server log only, without request bodies To find and fix faults
Support mailbox Each message you send from the Support page, and any email you write to us, is kept in our support mailbox To read your message

No recipient ever receives your bill, a page of it, or the patient's name. No document is sent to an AI provider; there is none.

The current list, with locations and transfer mechanisms, is published at https://medbillcheckup.com/subprocessors.

We do not sell your personal information. We do not share it for cross-context behavioural advertising. We do not disclose it to data brokers.

International transfers

The operator is established in Spain. Hosting and payments may involve processing outside the European Economic Area, principally in the United States. Where that is the case we rely on the European Commission's Standard Contractual Clauses together with the provider's own safeguards.

Because the bill itself never leaves your device, the only health-related data that can cross a border is the redacted figures of a bill, in transit, for the seconds it takes to run the checks. The subprocessor page states, for each provider, where processing takes place and on what transfer mechanism we rely.

How long we keep it

Data Kept for
Your bills, what was read from them, your results, letters, receipts, pass and choices On your device only, until you erase them. We hold no copy
The figures sent when you run the checks In memory for the duration of the request, then gone. Not stored, not logged
A subscriber's sign-in request In memory for the duration of the request; the link expires after 15 minutes
Function logs (request ids, timestamps, error codes) Per the hosting provider's log retention; they contain no bill contents
Payment records Held by the payment provider under its own retention policy, as required for accounting
A message you send from the Support page (kept in our support mailbox) As long as it is useful to deal with what you raised and to improve MedBillCheckup; deleted if you ask

Apart from a message you chose to send us, there is nothing to delete on our side because nothing is written. Erasing your data is something you do on your device, and it is complete.

Erasing your data

In the app: Settings → Erase everything on this device deletes every bill, result, letter, receipt, pass and consent choice the app holds in that browser. Do this before lending or disposing of a device. Settings → Download my data first if you want to keep a copy.

In the browser: clearing site data for https://medbillcheckup.com in your browser's settings has the same effect, as does uninstalling the app if you installed it.

Erasing your device data does not cancel a subscription; manage that from the billing page, which opens the payment provider's portal. It also does not remove the payment provider's records; see Your rights.

Security

The strongest protection is that the bill never leaves your device: there is no server-side store of bills to breach. Requests travel over an encrypted connection. The request that runs the checks is verified by a signed token and rate-limited, processed in memory, and never logged. Full detail is on the security page.

Keeping the bill on your device also means its safety depends on your device. Anyone who can open your browser profile can open your bills. On a shared computer, use the erase control when you are done.

Your rights

If you are in the EEA you have the rights to access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time. You may lodge a complaint with your national supervisory authority; for a Spain-established operator that is the Agencia Española de Protección de Datos (https://www.aepd.es/).

If you are in the United States, depending on your state you may have rights to access, correct, delete and obtain a copy of your data, to opt out of sale or sharing, and to appeal a refused request. We do not sell or share your data, so there is nothing to opt out of.

For everything about your bills, you exercise these rights yourself, immediately, in Settings, because the data exists only on your device: download everything (access and portability), correct what was read (rectification), withdraw consent, or erase everything (erasure). There is no account to delete, and we could not act on a request about a bill even if asked, because we do not have it and cannot identify you from it.

For a message you sent us, write to billcheck.businessacc@proton.me and we will give you a copy or delete it.

For payment records, write to billcheck.businessacc@proton.me from the email address you used at checkout. We can ask the payment provider to give you a copy of, correct, or delete what it holds, subject to the retention it is required to keep for accounting. We respond within one month for EEA requests and within 45 days otherwise.

Children

MedBillCheckup is for adults. You must be at least 18 to use it, and we ask you to confirm this before any document is processed. We do not knowingly process information from children. If you believe a child has used the service, erase the data on that device; if a payment was made, write to billcheck.businessacc@proton.me and we will have the payment record deleted.

Changes

If we change this policy materially we will publish the new version with a new version number and effective date, and the app will show you the new version and ask you to review the permissions you gave before it sends anything to us again. Your consent choice is stored on your device together with the version you accepted, so you can always see what you agreed to.

Version 2.4, effective 2026-09-26