Legal

Privacy Policy

Effective date: April 6, 2026  ·  Last updated: October 5, 2026

Plain English first: Your uploaded dental document is sent over an encrypted connection for one-time AI processing and is not retained by MyBillRX. If you separately opt in, we may retain de-identified procedure, price, payor, provider, and geography data to improve dental price benchmarks. Patient and member identifiers are not retained in that benchmarking dataset.

1. Who We Are

MyBillRX (“we,” “us,” “our”) is a direct-to-consumer dental billing education service operated at mybillrx.com. We help patients understand their dental bills and explanations of benefits (EOBs) by generating plain-English analyses of uploaded documents.

MyBillRX is not a healthcare provider, dental practice, insurance company, or health plan. We are not a “covered entity” or “business associate” as defined under the Health Insurance Portability and Accountability Act (HIPAA). We voluntarily hold our data practices to a standard that exceeds what HIPAA would require.

2. What Happens to Your Upload

We do not retain the original treatment plan, bill, or EOB you upload. The file is transmitted over an encrypted connection to our AI processing provider so we can extract the dental codes and pricing fields needed for your analysis.

When you upload a document:

  • Your file is transmitted over an encrypted (HTTPS/TLS) connection for processing.
  • The document is analyzed in real time by an AI model to generate structured dental pricing data.
  • The original file is not written to MyBillRX persistent storage.
  • Our extraction instructions exclude patient/member names, dates of birth, IDs, claim/account numbers, addresses, phone numbers, and emails.
  • Your final price analysis is based on the confirmed dental line items you review before continuing.

No human review of your uploaded document is required for the standard automated workflow.

3. What We Do Collect

We collect only the minimum data necessary to operate the service:

  • Session data: Standard server logs may capture your IP address, browser type, and the pages you visit for security and abuse prevention. These logs are not tied to any document you upload.
  • Cookies: We use functional cookies to maintain your session. We do not use advertising trackers or behavioral profiling cookies.
  • Analytics: Aggregate, anonymized page view data (e.g., number of visits) may be collected. No personally identifiable information is included.
  • Optional benchmarking contribution: If you opt in, we retain de-identified dental procedure and pricing fields such as CDT code, billed/allowed amount, plan-paid amount, patient-responsibility amount, payor, provider/practice information, geography, and service month. We also retain a one-way document hash for duplicate detection; the original document is not retained.

4. How We Use Your Information

The limited data we collect is used solely to:

  • Generate and deliver your report
  • Maintain the security and performance of the service
  • Comply with legal obligations
  • If you opt in, improve de-identified dental price and reimbursement benchmarks

We do not use your data for advertising, marketing profiling, or sale to third parties.

5. Third-Party Services

We use the following third-party service providers in the operation of MyBillRX. Each is governed by its own privacy policy:

  • Anthropic — AI analysis of uploaded documents. Documents are transmitted to Anthropic's API for processing under their data processing terms. Anthropic does not use API-submitted data to train models by default.
  • Netlify / Vercel — hosting and CDN infrastructure

If you opt in to benchmarking, the de-identified fields described above may also be stored in our reimbursement intelligence systems, including PayorMap, for aggregate pricing and reimbursement analysis. The original uploaded document is not included.

6. Data Retention

Your original uploaded document is used for transient processing and is not retained by MyBillRX. If you do not opt in to benchmarking, MyBillRX does not intentionally retain the extracted dental pricing fields for benchmarking after your session.

If you opt in, the de-identified benchmarking fields described in Section 3 may be retained to improve pricing and reimbursement intelligence. Those records are separated from the original document and do not include patient/member identifiers.

Server access logs may be retained for up to 90 days for security purposes and do not contain the uploaded document itself.

7. Children's Privacy

MyBillRX is intended for adults (18+). We do not knowingly collect information from children under 13. If you believe a child has submitted information through our service, contact us at the address below and we will take appropriate action.

8. Security

All data transmitted to and from MyBillRX is encrypted using TLS (HTTPS). We do not store your documents, so there is no database of health records that could be breached. We implement standard security controls to protect the infrastructure and service.

9. Your Rights

We do not intentionally retain patient/member identifiers from your uploaded dental document. If you opted in to de-identified benchmarking and have a question about our data practices, contact us and we will respond within 30 days. Because benchmarking records are intentionally de-identified, we may not be able to link a specific retained record back to you.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date at the top of this page. Continued use of MyBillRX after changes are posted constitutes acceptance of the updated policy.

11. Contact

Questions about this Privacy Policy? Email us at hello@mybillrx.com.