Third Party Index

Snapshot 50935

Document
Privacy policy
URL
https://www.ezappeal.com/privacy
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
25475 bytes
SHA-256 (raw)
f9ffefea0bfb3173c85895060fe925aaef9183e239cafc43c466e0663bb72719
SHA-256 (normalized text)
f1e721df9153fe9a007f56d5ac0d97cd885d2f3bbd88a91c7d972b3fb59984f5

Normalized text

Scripts and page chrome removed; this is what change detection compares.

EZAppeal
Privacy Policy
Last Updated: October 5, 2026
1. Information We Collect
Account Information: When you register, we collect your email address, password (stored as a bcrypt hash), and optionally your practice name, NPI, physician name, specialty, and contact information. If you tell us how you heard about EZAppeal, we keep your answer, and we record where your first visit came from: the campaign tags in the link you followed (utm_source, utm_medium and utm_campaign), the page you landed on, and the name of the website that sent you. We use these only to learn which channels bring us customers.
Clinical Documents: When you use our appeal or prior authorization tools, you upload denial letters and clinical notes. This data is processed transiently to generate your documents and is not stored permanently on our servers.
Activity Record: For each document drafted we keep a short record: the payer, procedure code and name, denial code, billed amount, criteria-match counts, document type and time, plus the date you mark it sent and the payer's decision and any paid amount you record. It never holds a patient name, member ID, date of service or any document text.
Usage Data: On our public pages and inside the app we collect anonymized analytics, such as pages visited and features used, that carry no account identifier. Inside your account we also keep a usage record tied to your account: when you sign up, sign in or come back, that a remittance was triaged and how many denials and appeal rows it held, which kind of document was drafted, when you mark a letter sent, the decision you record for a letter (paid, denied again or still waiting) and whether you recorded it in the app or from an email, and when a step failed and why, by category. The usage record never includes clinical content, patient or claim details, payer names, codes, claim amounts, or letter text.
Payment Information: Payment processing is handled entirely by Stripe. We never see, store, or have access to your credit card numbers or bank details.
2. Cookies & Tracking Technologies
We use the following cookies and tracking technologies:
Technology	Purpose
Google Analytics	Website traffic analysis and usage patterns on our public pages (two Analytics properties, both ours)
Google Ads	Measures whether a click on one of our Google ads leads to a signup, and lets us show our ads on Google to people who visited our public pages (remarketing)
Microsoft Clarity	Session recording and heatmaps on our public pages, to improve usability. Never on the free 835 denial worklist page
Microsoft Advertising (UET)	Measures whether a click on one of our Microsoft ads leads to a signup or demo on our public pages. Never on the free 835 denial worklist page
localStorage and sessionStorage	Your sign-in token, your cookie choice, a partner referral code if you arrived through a partner link (kept up to 90 days), a random per-tab ID for our own page-visit counts, and, if you sign up right after running the free denial audit, a note in that tab so your dashboard can offer to pick up where you left off
Never inside your account. None of these analytics or advertising tools load on any page you see while signed in, where clinical documents are handled. Nothing you paste or upload is ever sent to them.
How to opt out: Click Decline in the cookie notice, or use the button below. Either one turns off Google Analytics, Google Ads remarketing and Clarity right away, stops Microsoft Advertising from using cookies right away, deletes the cookies these tools set on this site, and keeps them all from loading on your later visits in this browser. You can also block cookies in your browser settings.
We do not sell your data to advertisers or third parties.
3. How We Use Your Information
To provide appeal letter and prior authorization services
To process payments and manage your account
To send account emails: verification codes and password resets, a copy of your Business Associate Agreement when you accept it, and short notes about your own account, such as a reminder to finish setting up, a monthly summary, or a question about whether the payer has decided on a letter you drafted. These notes carry no clinical content or patient details, and each one has an unsubscribe link. The answer links in a decision question record that letter's outcome without signing in.
To improve our service, through anonymized analytics on our public pages and inside the app, and the usage record described in section 1
To comply with legal obligations (HIPAA, tax reporting)
We do not sell your information or use clinical data for AI model training. Clinical data never reaches any analytics or advertising service.
4. Data Sharing
We share data only with service providers necessary to operate EZAppeal:
AWS Bedrock: AI processing of clinical content, under our Business Associate Agreement with AWS. Data is not used for training.
Anthropic: coverage-criteria research using payer names, procedure codes and drug names only. No clinical text and no patient data.
Stripe: payment processing (PCI DSS Level 1)
Supabase: database hosting for account data, the activity record and the usage record (no document text)
Vercel / Railway: application hosting (SOC 2)
Resend: transactional and account email
ipapi.co: approximate location for the IP address of a login or registration, shown in your login history
DocuSeal: e-signature, only if a Business Associate Agreement is signed through the e-signature path
Google Analytics, Google Ads, Microsoft Clarity and Microsoft Advertising: public marketing pages only, as described in section 2
5. Data Retention
Clinical documents: processed in memory to produce your document, then discarded. Denial letters, clinical notes and generated letters are never written to our database.
Account data, activity record, usage record, login history and payment records: kept until you ask us to delete them. We do not delete these on a schedule. Deletion is done by us on request (see section 6).
Google Analytics and Google Ads data: governed by Google's retention settings, on public-page visits only.
Sign-in sessions: renew while you are active. After 30 minutes without activity in any open tab, the dashboard locks until your password is entered again. A session ends about a day after your last activity, and always 7 days after you signed in. Changing or resetting your password stops your other sessions from renewing, so they end within a day.
6. Your Rights
You may request at any time:
Access: A copy of all data we hold about you
Correction: Update inaccurate information via Account Settings
Deletion: Removal of your account and associated data
Opt-out: Disable analytics cookies at any time
Email contact@ezappeal.com to exercise these rights. We respond within 30 days.
7. HIPAA Compliance
EZAppeal maintains HIPAA-compliant practices. Clinical data is processed transiently and never stored permanently. AWS, which performs all AI processing of clinical content, is our Business Associate under a signed BAA. Our API server processes documents in memory only and stores none of them. See our Compliance page for details.
8. Changes to This Policy
We may update this policy from time to time. Registered users will be notified of material changes via email.
9. Contact
Questions? Email contact@ezappeal.com.
Our public pages use Google Analytics, Google Ads, Microsoft Clarity, and Microsoft Advertising cookies to measure visits and ad clicks and to show our ads to past visitors. None of them load inside your account. Privacy Policy