Privacy Policy
Last updated: June 5, 2026
What we collect
Account details (email, name), documents and audio you upload (denial letters, contracts, provider responses, call recordings and transcripts), claim metadata (provider, plan, state), security data (MFA settings, active sessions with device and IP), newsletter consent records (timestamp, source, IP), and usage analytics including UTM parameters.
How we use it
To analyze your documents, generate your reports and letters, run your case deadlines and reminders, secure your account, send transactional emails and (with consent) our product newsletter, operate the anonymized document library, and improve the service.
Document and audio handling
Uploaded document text and files are encrypted at rest. We send document text to a large-language-model provider solely to perform your analysis. Call recordings and transcripts you attach to a case are stored privately with that case, are used only to transcribe and extract call details for you, and are never added to the shared contract library.
The anonymized contract library
With your explicit consent, a contract you upload may be contributed to a shared library so other customers of the same provider can compare documents faster. Before storage, an automated PII-redaction pass (pattern matching plus AI review) removes names, addresses, phone numbers, emails, policy/contract/claim/account numbers, property addresses, and signatures, and we keep a redaction log. Library entries store only provider, plan, year, and sanitized text, with no link back to you or your account — so deleting your account never touches the library.
Newsletter and marketing email
With your consent (a pre-checked box at signup you can uncheck, the footer form, or Settings), we send product updates and new claim-type announcements — a few emails a month. Every newsletter email includes a one-click unsubscribe link and our physical mailing address, and we honor unsubscribes immediately. Transactional emails (receipts, deadline reminders, security alerts) are part of the service and can’t be turned off while your account is active.
Advertising and analytics
We use Google Analytics 4 and the Meta Pixel, and we send server-side conversion events to Meta’s Conversions API (deduplicated by event ID). We capture UTM parameters on your first visit, store them on your account, and attach them to purchase events so we can measure which campaigns work.
Cookies and tracking consent
Non-essential trackers (Google Analytics 4 and the Meta Pixel) load only after you give consent through our cookie banner, where you can accept all, reject non-essential, or manage categories individually. We honor Global Privacy Control (GPC) signals by automatically rejecting non-essential trackers. Server-side Conversions API events are sent only for users who consented to marketing cookies. You can change your choice anytime via the "Cookie settings" link in the footer. Essential storage (sign-in session, security) does not require consent.
Security data
If you enable multi-factor authentication, we store your TOTP secret encrypted and one-way hashes of your recovery codes. We keep a list of your active sessions (device, IP, timestamps) so you can review and revoke them, and we email you about new-device sign-ins and security changes.
Sharing
We do not sell your personal information. We share data only with service providers needed to operate the app: payment processing (Stripe), email delivery (Resend), analytics (Google, Meta), AI analysis and transcription (OpenAI), and — only when you use Mail-it-for-me — our print-and-mail provider (PostGrid), which receives your letter content and the sender/recipient addresses needed to print and deliver it.
Your rights and account deletion
You can delete your account yourself anytime in Settings → Delete my account, after confirming with your password or MFA code. Deletion permanently removes your profile, uploads, letters, call logs, recordings, transcripts, case files, sessions, analytics identifiers, and newsletter list entries, and cancels any subscription. Only payment transaction records we are legally required to retain are kept, anonymized, by our payment processor. You may also request access or correction of your data at support@decodemydenial.com.