Privacy Policy
Last updated: July 2026
This Privacy Policy explains how Heimdall (“Heimdall,” “we,” “us”) handles information when a practice uses the service.
1. Information we collect
- Account information — the email and practice details used to sign in.
- Claim documents — the denial, claim, and clinical documents your practice uploads to process an appeal.
- Usage data — basic logs needed to operate and secure the service (never document contents).
2. How we use information
We use uploaded documents solely to extract claim data, analyze the denial, and draft the appeal letter for your practice. We do not sell your data.
3. Protected health information (PHI)
Heimdall is built to handle healthcare data carefully: documents are encrypted in transit and at rest, identifiers such as member IDs are minimized, and logs never contain document text or patient content. Handling of PHI is governed by the agreement between your practice and Heimdall.
4. Sharing & subprocessors
We use trusted infrastructure and AI subprocessors to run the service. We share only what is necessary to provide it, under appropriate confidentiality and data-protection terms.
5. Security
We use industry-standard safeguards including encryption, access controls, and audit logging. No system is perfectly secure, but we work to protect your data.
6. Retention
We retain documents and case data for as long as needed to provide the service and meet legal obligations, then delete or de-identify them.
7. Your choices
Your practice may request access to, correction of, or deletion of its data, subject to legal and contractual requirements.
8. Changes
We may update this policy; material changes will be communicated to your practice.
9. Contact
Questions about privacy? Email hello@heimdallclaims.com.