Legal
Privacy Policy
Effective date: April 6, 2026 · Last updated: October 5, 2026
Plain English first: Your uploaded dental document is sent over an encrypted connection for one-time AI processing and is not retained by MyBillRX. If you separately opt in, we may retain de-identified procedure, price, payor, provider, and geography data to improve dental price benchmarks. Patient and member identifiers are not retained in that benchmarking dataset.
1. Who We Are
MyBillRX (“we,” “us,” “our”) is a direct-to-consumer dental billing education service operated at mybillrx.com. We help patients understand their dental bills and explanations of benefits (EOBs) by generating plain-English analyses of uploaded documents.
MyBillRX is not a healthcare provider, dental practice, insurance company, or health plan. We are not a “covered entity” or “business associate” as defined under the Health Insurance Portability and Accountability Act (HIPAA). We voluntarily hold our data practices to a standard that exceeds what HIPAA would require.
2. What Happens to Your Upload
We do not retain the original treatment plan, bill, or EOB you upload. The file is transmitted over an encrypted connection to our AI processing provider so we can extract the dental codes and pricing fields needed for your analysis.
When you upload a document:
- Your file is transmitted over an encrypted (HTTPS/TLS) connection for processing.
- The document is analyzed in real time by an AI model to generate structured dental pricing data.
- The original file is not written to MyBillRX persistent storage.
- Our extraction instructions exclude patient/member names, dates of birth, IDs, claim/account numbers, addresses, phone numbers, and emails.
- Your final price analysis is based on the confirmed dental line items you review before continuing.
No human review of your uploaded document is required for the standard automated workflow.
3. What We Do Collect
We collect only the minimum data necessary to operate the service:
- Session data: Standard server logs may capture your IP address, browser type, and the pages you visit for security and abuse prevention. These logs are not tied to any document you upload.
- Cookies: We use functional cookies to maintain your session. We do not use advertising trackers or behavioral profiling cookies.
- Analytics: Aggregate, anonymized page view data (e.g., number of visits) may be collected. No personally identifiable information is included.
- Optional benchmarking contribution: If you opt in, we retain de-identified dental procedure and pricing fields such as CDT code, billed/allowed amount, plan-paid amount, patient-responsibility amount, payor, provider/practice information, geography, and service month. We also retain a one-way document hash for duplicate detection; the original document is not retained.
4. How We Use Your Information
The limited data we collect is used solely to:
- Generate and deliver your report
- Maintain the security and performance of the service
- Comply with legal obligations
- If you opt in, improve de-identified dental price and reimbursement benchmarks
We do not use your data for advertising, marketing profiling, or sale to third parties.
5. Third-Party Services
We use the following third-party service providers in the operation of MyBillRX. Each is governed by its own privacy policy:
- Anthropic — AI analysis of uploaded documents. Documents are transmitted to Anthropic's API for processing under their data processing terms. Anthropic does not use API-submitted data to train models by default.
- Netlify / Vercel — hosting and CDN infrastructure
If you opt in to benchmarking, the de-identified fields described above may also be stored in our reimbursement intelligence systems, including PayorMap, for aggregate pricing and reimbursement analysis. The original uploaded document is not included.
6. Data Retention
Your original uploaded document is used for transient processing and is not retained by MyBillRX. If you do not opt in to benchmarking, MyBillRX does not intentionally retain the extracted dental pricing fields for benchmarking after your session.
If you opt in, the de-identified benchmarking fields described in Section 3 may be retained to improve pricing and reimbursement intelligence. Those records are separated from the original document and do not include patient/member identifiers.
Server access logs may be retained for up to 90 days for security purposes and do not contain the uploaded document itself.
7. Children's Privacy
MyBillRX is intended for adults (18+). We do not knowingly collect information from children under 13. If you believe a child has submitted information through our service, contact us at the address below and we will take appropriate action.
8. Security
All data transmitted to and from MyBillRX is encrypted using TLS (HTTPS). We do not store your documents, so there is no database of health records that could be breached. We implement standard security controls to protect the infrastructure and service.
9. Your Rights
We do not intentionally retain patient/member identifiers from your uploaded dental document. If you opted in to de-identified benchmarking and have a question about our data practices, contact us and we will respond within 30 days. Because benchmarking records are intentionally de-identified, we may not be able to link a specific retained record back to you.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date at the top of this page. Continued use of MyBillRX after changes are posted constitutes acceptance of the updated policy.
11. Contact
Questions about this Privacy Policy? Email us at hello@mybillrx.com.