Scope
This policy applies to the ClaimDoula website, authenticated application, Direct Connect insurer integrations, and ClaimDoula Browser Connect. ClaimDoula is an invitation-only consumer health application in private alpha.
ClaimDoula is not your insurer, health care provider, employer, or insurance agent. When you direct an insurer to send information to a consumer application that is not acting for a covered entity, HIPAA may no longer govern the application’s later handling of that information. We treat the information as sensitive regardless and follow this policy and other applicable privacy and breach-notification requirements.
Information we handle
- Account and household information: your name, email address, authentication identifiers, household roles, invitations, and consent records.
- Insurance and health information: claims, explanations of benefits, coverage, plan information, providers, clinical records returned by an authorized insurer API, and plan settings you enter.
- Connection information: encrypted insurer authorization tokens, connection status, consent and refresh timestamps, and a local Browser Connect session kept on your enrolled computer.
- Security and operations information: bounded audit events, device status, sync counts, error categories, and technical logs needed to secure and operate the service.
- Communications: information you choose to send when requesting support, access, correction, or deletion.
We receive information from you, members you are authorized to represent, authentication providers, insurers you explicitly connect, and your enrolled Browser Connect application. We do not collect insurer passwords in ClaimDoula or upload them from Browser Connect.
How we use information
We use information to authenticate you; connect sources you authorize; capture, preserve, organize, reconcile, and explain insurance records; show your household’s information; keep sources current; provide support; prevent abuse; investigate errors and security incidents; and improve the reliability and clarity of ClaimDoula.
We do not sell personal or health information. We do not use it for targeted advertising, data-broker profiles, or marketing third-party products. We do not place advertising pixels or session-replay tools inside the authenticated app. We do not use identifiable claim evidence to train external AI models.
We do not create de-identified or anonymized claim datasets for sale, advertising, third-party marketing, external model training, or research. If we create de-identified information for bounded security or reliability work, we prohibit re-identifying it and require service providers handling it for us to do the same.
ClaimDoula does not currently market third-party goods or services or disclose information to enable that marketing. We would require a separate, affirmative opt-in before introducing either practice.
When information is disclosed
We disclose information only as needed to:
- service providers that perform authentication, hosting, storage, security, email delivery, or other essential operations for ClaimDoula;
- an insurer or connected service when you initiate or refresh that connection;
- another household member whom the household owner invites and authorizes;
- comply with law, protect a person, investigate fraud or abuse, or defend legal rights; or
- complete a business transfer, subject to this policy and notice of a material change.
Service providers may use information only to perform their contracted function for ClaimDoula. We do not authorize them to advertise with it or sell it. ClaimDoula is intended for people in the United States. Essential providers may operate infrastructure in more than one country; we do not represent that every transient processing location is inside the United States.
If ClaimDoula changes ownership, we will provide notice before a new owner materially expands the uses or disclosures described here and will obtain renewed consent when appropriate. You may request deletion instead of continuing. If ClaimDoula stops operating, we will stop new collection and schedule information we control for deletion, subject to the limited exceptions below.
Your choices and rights
- You choose each insurer connection and each person whose information is authorized.
- You can disconnect Direct Connect or Browser Connect without deleting previously verified claims. You may also revoke ClaimDoula in the insurer’s own connected-app settings. Reaffirming consent allows collection to continue under your current choices; withdrawing consent stops new collection, while previously verified information remains until you separately request deletion.
- You may ask for access to, correction of, or a portable copy of information ClaimDoula maintains about you. Source claim corrections must be made by the insurer or provider that issued the record.
- You may close your account and request deletion as described on the data deletion page.
To exercise a request, email josh@claimdoula.com from your account email. We will verify the request before acting so another person cannot obtain or erase your records.
Retention and deletion
Current evidence is kept while your alpha account is active. Superseded browser captures are generally deleted after 14 days, superseded API snapshots after 30 days, diagnostic logs after 7 days, and noncurrent object versions after 7 days.
After a verified account-deletion request, primary account evidence is scheduled for deletion within one day and remaining backup copies within 30 days. We may retain narrowly limited information when required by law or reasonably necessary to investigate abuse, enforce these terms, or respond to a security incident.
Security and incidents
ClaimDoula uses safeguards designed for sensitive health and financial information, including encrypted transport and storage, server-side authorization, dataset isolation, least-privilege access, bounded logs, audit events, and fail-closed evidence checks. No system can guarantee absolute security.
If an incident affects your information, we will investigate and provide notices required by applicable law. Health applications may be subject to the Federal Trade Commission’s Health Breach Notification Rule even when they are not covered by HIPAA.
Children’s information
ClaimDoula accounts are for adults. A parent, guardian, or other legally authorized adult may connect a child’s insurance information only when authorized to do so. We do not knowingly invite children under 13 to create accounts.
Changes and contact
We will update the effective date when this policy changes. If a change materially expands how alpha health information is collected, used, or disclosed, we will provide notice and obtain renewed consent when appropriate before applying it to new activity.
Privacy questions
Email josh@claimdoula.com. Please do not include claim numbers, diagnoses, member IDs, or other sensitive details in ordinary email.