Privacy Policy

Last updated: July 2026

Placeholder template for the MVP — this is not legal advice, and the final text will be reviewed by counsel before launch.

This Privacy Policy explains how Heimdall (“Heimdall,” “we,” “us”) handles information when a practice uses the service.

1. Information we collect

  • Account information — the email and practice details used to sign in.
  • Claim documents — the denial, claim, and clinical documents your practice uploads to process an appeal.
  • Usage data — basic logs needed to operate and secure the service (never document contents).

2. How we use information

We use uploaded documents solely to extract claim data, analyze the denial, and draft the appeal letter for your practice. We do not sell your data.

3. Protected health information (PHI)

Heimdall is built to handle healthcare data carefully: documents are encrypted in transit and at rest, identifiers such as member IDs are minimized, and logs never contain document text or patient content. Handling of PHI is governed by the agreement between your practice and Heimdall.

4. Sharing & subprocessors

We use trusted infrastructure and AI subprocessors to run the service. We share only what is necessary to provide it, under appropriate confidentiality and data-protection terms.

5. Security

We use industry-standard safeguards including encryption, access controls, and audit logging. No system is perfectly secure, but we work to protect your data.

6. Retention

We retain documents and case data for as long as needed to provide the service and meet legal obligations, then delete or de-identify them.

7. Your choices

Your practice may request access to, correction of, or deletion of its data, subject to legal and contractual requirements.

8. Changes

We may update this policy; material changes will be communicated to your practice.

9. Contact

Questions about privacy? Email hello@heimdallclaims.com.