1. The short version
The public website is in concierge mode. Selecting a bill or EOB on the site keeps it on your device; it is not uploaded for an instant online audit. Contact us without medical documents to request secure intake instructions once an approved channel is available. We retain documents and case records only when needed for the service you request. We never sell your data or share it with advertisers, and you can request deletion of information we hold.
2. What we collect
- Documents you submit through an approved secure intake channel for an audit or authorized appeal
- Account information (email, name, the insurer your plan is with)
- Case metadata (timestamps, appeal status, outcome)
- Technical data needed to run the product (IP address for fraud prevention, coarse device info)
3. How we use it
Solely to (a) review your bills, (b) prepare and coordinate an authorized appeal, (c) keep you updated on the case, and (d) operate and secure the service. No ad networks, no behavioral tracking, no cross-site pixels.
4. Sub-processors
To run the product we rely on a small set of third-party providers, some of which may process your data on our behalf. We keep that surface area minimal and only pass along what a given step needs:
- Formspree — receives the email address and message you submit through our contact and signup forms; it does not receive a bill selected in the concierge interface
- Vercel — static hosting for this website
- Stripe — planned payment-method setup and payment processing for accepted cases, only after the agreement and payment workflow pass review. Stripe receives payment data directly plus opaque payment references; LifeDesk does not send bill details, medical codes, claim information, or patient identifiers in Stripe metadata or descriptions. This public concierge site does not currently expose payment setup or checkout.
- Telegram — a separate messaging assistant that currently uses DeepSeek for chat and Google Gemini via OpenRouter for image reading. It is not part of the real-patient-PHI critical path because LifeDesk does not have HIPAA business-associate agreements with those AI providers.
- Planned, not active: Render for the private API and Anthropic’s first-party Messages API for document extraction. No document is sent to either from this public concierge site. Live processing will remain off until the exact vendor workspaces are covered and enabled.
You can read more about how we handle data on our security page.
5. Data retention
The public website does not upload a bill at all. If secure intake is enabled and you engage LifeDesk to prepare or coordinate an appeal, we retain the documents and case records needed to do that work for up to 12 months after the case is resolved, then delete them. A covered Anthropic model can retain prompts and outputs for at least 30 days, subject to its published safety and legal exceptions and the controlling agreement. You can request deletion of records LifeDesk controls earlier at any time.
6. Your rights
You can request access, correction, export, or deletion of your data at any time by writing to hello@getlifedesk.com. We honor California, Virginia, Colorado, and EU privacy rights regardless of where you live.
7. Children
LifeDesk is not intended for children under 13. We do not knowingly collect data from them. Parents and legal guardians may manage cases for minors on their plan.
8. Changes
If we materially change this policy we will notify you by email at least 14 days before the change takes effect.