Privacy Policy
Last updated: July 13, 2026
1. Overview
TestMyBill.com is owned and operated by Westenders LLC, a North Carolina limited liability company doing business as TestMyBill ("TestMyBill," "we," "our," or "us"). TestMyBill provides an AI-enabled software tool that helps patients and their authorized representatives understand and respond to medical bills. This Privacy Policy explains how we collect, use, disclose, retain, and protect information in connection with the Service. Capitalized terms not defined in this Privacy Policy have the meanings given in our Terms of Service. For consumer health data specifically, see also our Consumer Health Data Privacy Policy.
2. Information We Collect
Bill documents and related information you upload
When you upload an image, PDF, or other supported document, or manually enter billing information, we process that information to extract and organize relevant fields, such as provider names and addresses, patient names, account or claim numbers, service dates, billing codes, itemized charges, payment amounts, insurance information, and other information contained in or derived from the document. The AI component is designed to act as a narrow document processor that extracts information and generates available letter types; it is not intended to operate as a general-purpose assistant or to follow instructions contained inside uploaded documents. Uploaded files, extracted data, and generated letters are stored temporarily and automatically deleted as described in Section 4.
Questionnaire responses
Depending on the letter type you select, we may ask for financial information, such as monthly income, household size, or offer amounts; insurance information, such as insurer name, claim or denial numbers, denial reasons, or coverage details; collection-related information; and additional context you choose to provide. We use this information to generate and support the requested letter and related Service functionality.
Email address — transactional
After a completed purchase, we may send a receipt, confirmation, or secure download link to the email address you provided at checkout. These transactional emails are sent regardless of marketing preferences. By default, letter content is not included in transactional emails. If you separately and voluntarily choose the optional “email me a copy” feature, the generated letter content will be emailed to the address you enter and may transit our email delivery provider outside any HIPAA business-associate chain (see Section 5); you should use the secure download option if you do not want the letter content sent by email.
Email address — optional marketing communications
During the letter-generation process, you may optionally check an unchecked box to receive occasional TestMyBill product updates, medical-billing tips, and tool announcements. If you do, we store your email address and, if provided, your name in a separate contact list for that purpose. This marketing list is maintained separately from your medical-billing activity. We do not intentionally record your letter type, bill amount, provider, uploaded documents, or other health-financial context in that marketing contact list. You can unsubscribe at any time by clicking the link in any marketing email or by emailing hello@testmybill.com. Not checking the box has no effect on your letter.
Payment information
Payment processing is handled by Stripe, Inc. or another third-party payment processor. TestMyBill does not store full credit card numbers, bank account information, or payment credentials. We receive limited payment metadata, such as transaction identifiers, payment status, amount, date, and information needed to provide receipts, refunds, credits, tax, accounting, fraud-prevention, and customer-support functions.
Technical information
Our servers and service providers collect standard technical and usage information, such as IP address, device and browser type, pages or features used, referring URLs, timestamps, and diagnostic events. Error reports may be transmitted to Sentry or similar application-monitoring providers for debugging and reliability; we configure these tools to avoid intentionally transmitting health-related billing content.
Cookies and similar technologies
We use cookies for essential site functionality (such as accessing your own letter), and, only with your consent, a functional cookie that remembers a referral discount between visits. Where required by law, we obtain consent or provide opt-out controls before using non-essential cookies. See our Privacy Preference Center to review or change your choice at any time.
Support communications
If you contact us for support, deletion requests, privacy requests, refunds, or other questions, we collect the information you provide in that communication and any information reasonably necessary to respond, authenticate the request, investigate the issue, and maintain records of our response.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Extract and organize billing information from your uploaded documents or manually entered information
- Generate a personalized negotiation, appeal, hardship, dispute, verification, or related letter based on your situation
- Send receipts, confirmations, secure download links, support communications, and, if requested, a copy of your letter
- Process your payment through Stripe or another third-party payment processor
- Monitor, secure, debug, troubleshoot, and improve Service reliability and performance
- If — and only if — you opt in, contribute de-identified or anonymized metadata to aggregate billing-trends research (see Section 5a)
- If — and only if — you separately opt in, send you occasional product updates and medical-billing tips by email (see “Email address — optional marketing communications” above)
- Comply with applicable legal obligations, enforce our Terms, prevent fraud or misuse, and protect the rights, privacy, safety, and security of TestMyBill, users, and others
We do not sell your personal information or health-related information. We do not use your health-related billing information for third-party advertising, cross-context behavioral advertising, or building unrelated user profiles. We disclose information only as described in this Privacy Policy, with your direction or consent, or as otherwise permitted or required by law.
4. Data Retention and Deletion
We follow a minimum-retention policy for health-related billing information, subject to legal, security, fraud-prevention, dispute-resolution, tax, accounting, and backup requirements:
| Data type | Retention period |
|---|---|
| Uploaded bill files (images / PDFs) | Automatically deleted within 24 hours after letter generation or service completion |
| Extracted bill data (text fields) | Automatically deleted within 24 hours after letter generation or service completion |
| Generated letters | Automatically deleted within 24 hours after letter generation or service completion |
| Email addresses (transactional delivery) | Retained only as needed for delivery, receipts, support, security, fraud prevention, and legal or accounting records |
| Email addresses (optional marketing opt-in) | Retained until you unsubscribe or request deletion |
| De-identified or anonymized billing metadata (opt-in only) | Retained long-term in de-identified or aggregate form (see Section 5a) |
| Payment transaction records | Retained as needed for tax, accounting, chargeback, fraud-prevention, legal, and recordkeeping purposes |
| Server / request logs | Retained as needed for security, debugging, fraud prevention, analytics, legal, and operational purposes |
You may request deletion of data associated with your session at any time by contacting us at hello@testmybill.com. We will honor deletion requests as required by applicable law, but we may retain information where necessary for legal, security, fraud-prevention, dispute-resolution, tax, accounting, backup, or compliance purposes, and we may be unable to identify or delete information that has already been de-identified, anonymized, or aggregated.
5. Third-Party Service Providers and Other Disclosures
To deliver, secure, support, and improve the Service, we disclose information to service providers and processors that act on our behalf under contractual data-protection obligations. The categories below describe the providers we currently use or may use for similar functions:
Microsoft Azure OpenAI
Processes bill text, images, questionnaire responses, and related inputs to extract data and generate letters. Microsoft is subject to contractual privacy and security commitments for this processing, including Business Associate Agreement terms where applicable.
Supabase, Inc.
Provides database and file storage for temporary retention of uploaded documents, extracted data, generated letters, and related Service records. Supabase is subject to contractual privacy and security commitments for this processing, including Business Associate Agreement terms where applicable.
Stripe, Inc.
Processes payments, receipts, refunds, chargebacks, fraud screening, and related payment functions. Stripe operates under its own privacy policy and compliance program. We do not intentionally send uploaded bills, generated letters, or health-related billing content to Stripe.
Vercel, Inc.
Hosts and serves the application and may process standard request logs, network information, and deployment data. We do not intentionally store uploaded bills or generated letters in Vercel logs.
Resend, Inc.
Delivers email. By default, purchase receipts and download-link emails contain no letter content. Resend is not currently covered by a Business Associate Agreement, so we deliberately keep generated letter content out of default transactional emails. If you choose the optional “email me a copy” feature, the generated letter content, which may include health-related billing information, will transit Resend outside any BAA-protected chain. To reduce that risk, use the secure download link instead.
Sentry, Inc.
Receives technical error reports and diagnostic information for application monitoring and reliability. We configure monitoring tools to avoid intentionally transmitting uploaded bills, generated letters, or health-related billing content.
Other disclosures
We may also disclose information if you direct us to do so, if needed to comply with law or legal process, to enforce our Terms, to protect rights, privacy, safety, or security, to prevent fraud or misuse, in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, or with your consent.
5a. De-Identified Billing-Trends Research (Opt-In Only)
We may maintain an aggregate research dataset that helps us understand medical-billing trends and improve the Service. Contribution to this dataset is strictly opt-in: nothing is added unless you actively check the consent box when generating a letter. The box is off by default, and declining has no effect on your letter, price, or ability to use the Service.
If you opt in, we record only coarse fields intended to exclude direct identifiers and reduce re-identification risk, such as:
- State — a 2-letter U.S. state code only, derived from the bill or user input, not a street address, city, or ZIP code
- Bill-amount range — a broad bucket (e.g., "$2.5k–$5k"), not the exact amount
- Letter type — the workflow you selected (e.g., hardship, appeal, surprise-bill)
- Denial type — for appeals, a categorized enum (e.g., "prior_authorization"), never the raw denial text
- Intent context — a coarse category describing your goal (e.g., affordability, accuracy review, collections)
- Timestamp — when the anonymized record was created (your platform-usage time, not a clinical date)
We never include any of the following in this dataset:
- Patient names, account numbers, claim numbers, or medical record numbers
- Addresses, phone numbers, email addresses, or insurance member IDs
- Uploaded bill images or PDFs, or any raw document text
- Exact dollar amounts or any free-text you entered
Because these records are designed to exclude direct identifiers and be maintained in de-identified or aggregate form, they are retained on a long-term basis and are not subject to the 24-hour deletion schedule that governs uploaded documents, extracted bill data, and generated letters.
We record the exact timestamp of each contribution internally. We use that internal timestamp for administration, security, deduplication, quality control, and to build aggregate trend reports (for example, grouping contributions by day, month, or quarter). We do not display or export exact, individual-record timestamps in any public or customer-facing report. Any report we publish or share outside the company is built from aggregate, bucketed data only — it groups records together and does not expose any single contribution on its own. A trend is not displayed at all unless at least 25 records exist for that category. You may ask us to delete a contribution by contacting hello@testmybill.com, but we may be unable to locate or delete information once it has been de-identified, anonymized, or aggregated.
5b. Promotional Credits, Referrals, and Follow-Up Emails
After a completed purchase we may issue a one-time promotional credit and a shareable referral link. These systems are deliberately designed to remain separate from your health information:
What we store. Credit and referral records contain randomly generated codes, references to payment transactions, issuance and expiration dates, redemption status, and related non-sensitive operational data. They are not intended to store your uploaded bill, generated letter, provider, exact bill amount, medical issue, or other health-related billing content.
Referral privacy. A referral link is designed not to reveal health-related billing information about the person who shared it. Visitors who use a referral link see only a generic welcome message; we do not disclose the referrer's bill, provider, letter, or reason for using TestMyBill. Referral analytics record only non-sensitive events, such as that a link was clicked or a discount was applied.
Referral reward emails. If someone purchases through your referral link, we may send you a one-time transactional email containing your reward code. This email uses the email address from your original checkout or account record, does not add you to a marketing list, and contains no information about the referred customer's bill, letter, or health-related context.
Post-purchase check-in emails. We may send post-purchase check-in or reminder emails only where permitted by law and, for marketing content, only if you separately and explicitly opted in to marketing emails. Consent is verified at the time of sending, and each marketing email contains an unsubscribe link. Scheduling records are designed to contain only information needed to send the message, such as email address, credit code, and send date, and not health-related billing content.
6. HIPAA Notice
TestMyBill.com is a direct-to-consumer software tool, not a healthcare provider, health plan, health insurer, or healthcare clearinghouse as those terms are defined under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Unless TestMyBill separately agrees in writing, TestMyBill is not acting as a HIPAA covered entity or business associate for you, and your use of TestMyBill does not create a covered-entity, business-associate, provider-patient, or insurer-insured relationship.
Even where HIPAA does not directly apply to TestMyBill's relationship with you, we use privacy and security safeguards designed to protect health-related billing information, including minimum-necessary access principles, encryption in transit and at rest, contractual data-protection obligations for processors, and automated deletion schedules for uploaded documents, extracted bill data, and generated letters.
Business Associate Agreement terms or similar contractual protections are in place with certain processors that handle health-related information on our behalf where applicable, including Microsoft Azure OpenAI and Supabase for relevant processing and storage functions.
7. Security
We implement administrative, technical, and organizational safeguards designed to protect information submitted to the Service, which may include:
- Encryption of data in transit using industry-standard transport security protocols
- Encryption of data at rest for supported storage systems
- Private, access-controlled cloud storage for uploaded bill files and generated letters
- Randomized session identifiers and access controls designed to limit unauthorized access
- Design choices intended to avoid storing uploaded bills, extracted bill data, or generated letters in client-side browser storage
No internet-based service, storage system, AI tool, or electronic transmission is completely secure. We cannot guarantee that unauthorized access, disclosure, loss, or misuse will never occur. You should provide only the minimum information necessary to use the Service and may use manual entry options where available if you prefer not to upload an original document.
8. Your Rights
Depending on where you live and the nature of the information involved, applicable law may give you rights to request access to, deletion of, correction of, or information about certain personal information we maintain, as well as rights to opt out of certain uses or disclosures. Because we generally use anonymous sessions rather than user accounts, we may need the approximate date and time of your session, email address used for checkout or delivery, transaction information, or other details to locate and verify your information. We may deny or limit requests where permitted by law, including where information cannot reasonably be linked to you, has been deleted, has been de-identified or aggregated, or must be retained for legal, security, fraud-prevention, dispute-resolution, tax, accounting, or compliance purposes. To submit a request, email hello@testmybill.com.
9. Children's Privacy
TestMyBill.com is not directed to children under 18 years of age, and children may not use the Service directly. An adult may use the Service on behalf of a minor only if legally authorized to do so. We do not knowingly collect information directly from children. If you believe a minor has submitted information through the Service without appropriate authorization, contact us and we will take appropriate steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technologies, service providers, legal requirements, or business operations. We will post the updated policy on this page with a revised "Last updated" date. Changes are effective when posted unless the updated policy states otherwise. Continued use of the Service after any update constitutes acceptance of the revised policy.
11. Contact
For privacy questions, data deletion requests, or concerns:
Westenders LLC (doing business as TestMyBill)
Email: hello@testmybill.com