Legal

Privacy Policy.

Last updated July 28, 2026

1. Who we are and what this policy covers

BillFighter is a service operated by AAA Incubator, LLC ("BillFighter," "we," "us," or "our"). This Privacy Policy explains what personal information we collect when you use our websites and applications (the "Service"), how we use and share it, how long we keep it, and the choices and rights you have.

BillFighter helps you review medical and other bills, identify potential errors or overcharges, and generate dispute and related letters. Because the bills you upload can reveal health information, we treat that information as sensitive and describe our handling of it specifically below. BillFighter provides tools; it is not a law firm and does not provide legal advice.

The Service is intended for users in the United States. This policy is written for U.S. federal and state privacy law and is not directed to individuals in the European Economic Area, the United Kingdom, or other jurisdictions.

2. Quick summary

This summary is for convenience only; the full policy below controls.

  • We collect the information needed to run the Service: your account details, the bills you upload, addresses used to mail letters, and limited usage data.
  • Your bills can contain health information. We use it only to provide the Service. We do not sell it and never share it for advertising.
  • We use a small set of vetted service providers (listed below) to run the Service. They are contractually barred from using your data to train their models or for their own purposes, and from using it for advertising.
  • We do not use third-party advertising cookies or cross-site tracking pixels on our site.
  • You can access, correct, download, or delete your data, and you can delete your account at any time.

3. Information we collect

Information you provide

  • Account information: your name and email address when you create an account.
  • Mailing information: if you use our certified-mail or letter-fulfillment features, your mailing (return) address and the recipient's address, used to print and deliver letters.
  • Bills and documents you upload: the images or PDFs of bills you submit for analysis. These documents can contain personal identifiers (such as your name, address, and account or member numbers) and health-related information (such as provider names, dates of service, procedures, diagnoses or codes, and amounts).
  • Case details you enter: information you provide about your situation, including any account of contact you have had with a provider, insurer, or collection agency.
  • Payment information: if you purchase a paid plan, your payment is processed by our payment processor (Stripe). We receive confirmation of payment and limited billing details; we do not receive or store your full card number.

Information collected automatically

  • Usage and device data: basic information about how you use the Service, such as pages or screens viewed, actions taken, browser or device type, and similar log data.
  • Approximate location: we derive your country and region from your IP address in order to apply the correct state privacy requirements to your session. We store this as a region indicator, not as your IP address.
  • Cookies and similar technologies: see "Cookies, analytics, and session replay" below.

4. Sources of information

We collect information directly from you (for example, when you create an account, upload a bill, or enter an address); automatically from your use of the Service (for example, usage and device data); and from our service providers (for example, a payment confirmation from our payment processor).

5. How we use your information

  • Bill analysis: to extract text from your uploaded documents and identify potential billing errors, overcharges, and issues you may wish to dispute.
  • Letter generation: to draft dispute letters, debt-validation requests, appeals, and related correspondence using your case details.
  • Letter delivery: to print and mail letters, or email them for fulfillment, when you use those features.
  • Account and communications: to create and manage your account and to send transactional messages and service updates.
  • Product analytics and improvement: to understand how the Service is used and to improve it, using first-party analytics.
  • Security, fraud prevention, and rate-limiting: to protect the Service and our users from abuse.
  • Legal and compliance: to comply with law and enforce our terms.

6. Consumer health data

Because the bills you upload can reveal information about your health conditions or the health care you received, that information may qualify as "consumer health data" under the Washington My Health My Data Act and comparable laws in other states. We treat it as sensitive, and we apply the protections described in this section to that data.

What we collect. Health-related information contained in the bills and documents you choose to upload, and the case details you provide. This can include provider names, dates of service, the services or procedures billed, diagnostic or billing codes, amounts charged, and account, member, or record numbers that reflect health care you received or sought.

Why we collect it. Solely to provide the service you requested — to analyze your bill for errors and overcharges, generate dispute, debt-validation, and appeal letters, manage your case and its deadlines, and communicate with you about it. We do not use it for advertising, and we do not use it to build advertising profiles.

Where it comes from. Directly from you. We do not buy it, and we do not obtain it from data brokers.

Who we share it with. Only the service providers listed in "How we share information" below, each contractually restricted to using it solely to provide the Service and barred from using it to train AI models, for their own purposes, or for advertising. As an added safeguard, before your bill text is sent for AI analysis we apply automated redaction to remove direct identifiers where they appear in a recognizable form. This safeguard applies to the bill text at the analysis step and not to every part of the Service — "AI processing of your bills" below sets out exactly what is and is not redacted.

What we do not do. We do not sell your consumer health data. We do not share it for advertising or for any cross-context behavioral advertising. We would not sell it without your separate, valid written authorization, which the law requires and which we have never sought.

Your rights. You may confirm whether we collect, share, or sell your consumer health data and access that data; obtain a list of the third parties and affiliates with whom we have shared it; withdraw your consent to our collection and sharing of it; and have it deleted. On a valid deletion request, we will delete it from our records and notify the service providers that received it to delete it as well, within the timeframes the law requires — generally within 45 days, and up to 6 months for data held in archives or backups. We will not deny you the Service, charge you a different price, or provide a different level of quality because you exercised any of these rights. See "Your privacy rights and choices" below for how to make a request.

Washington residents: our separate Washington Consumer Health Data Privacy Policy describes these protections in the form that state's law requires.

7. AI processing of your bills

To analyze your bills and draft your letters, the text from your documents and the details you give us are processed by a third-party artificial-intelligence provider (Anthropic) and related infrastructure providers acting on our behalf. This text can include health-related information.

We reduce what we send where we can, but we do not send it anonymously, and what is protected depends on the step. We would rather tell you exactly where the line falls than leave you with an impression that is better than the truth.

  • Analyzing your bill. Before the text of your bill is sent for analysis, we apply automated redaction to remove direct identifiers — such as your name, mailing address, account number, and date of birth — where they appear in a recognizable form. This is a safeguard that reduces the identifying information we send. It is not de-identification: automated redaction can miss identifiers that appear in an unlabeled or unexpected form, and the health-related content of the bill is still processed in order to analyze it.
  • The details you type in your own words. Notes you write yourself — what your visit was for, the reason an insurer gave for a denial, or what a collector said to you — are sent as you wrote them and are not redacted. Redacting your own description of your situation would distort it and produce worse analysis.
  • Drafting your letter. A dispute letter has to identify you and the account in question to have any effect. When we draft one, we send your name, your mailing address, the account or reference number in dispute, and the provider's or collector's details. These are not redacted at this step.

The original text of your bill is kept in your own account on our systems, protected by per-user access controls; the redacted copy is what goes to the AI provider for analysis.

These providers process your data only as needed to deliver the Service, under commercial agreements that prohibit using your data to train their models or for their own purposes. They may retain limited data briefly for security and abuse-prevention in accordance with their own policies. We never send your data to any provider for advertising.

8. Cookies, analytics, and session replay

  • Essential cookies: we use cookies that are necessary for authentication, session state, and storing your region and your consent choices. These are always on.
  • First-party product analytics: we use one first-party analytics provider (PostHog) to understand how the app is used. We do not use third-party advertising cookies or cross-site advertising trackers on our site.
  • Session replay: we record app sessions to understand where users encounter difficulty. All on-screen text and all form inputs are masked in these recordings, so the content of your bill and your entries are not captured — only layout, clicks, scrolling, and navigation.
  • Your consent: for non-essential analytics we request your consent through an on-site control, opt-in where required (including for Washington users), and we honor the Global Privacy Control (GPC) browser signal as an opt-out.

9. Advertising and measurement

We do not engage in cross-context behavioral advertising, and we do not use third-party advertising pixels or cookies on our site. We never send your bill, your health details, your dispute activity, or your email address to any advertising platform.

To understand whether our advertising works, we send a limited signal to the advertising platform that referred you, indicating that a signup occurred and which campaign it came from. This signal is subject to your consent choices and to the Global Privacy Control, and it is not sent where you have opted out or where opt-in consent is required and has not been given. It does not include your name, email address, mailing address, IP address, bill contents, health information, or dispute activity.

10. How we share information: our service providers

We share your information only with service providers (subprocessors) that help us operate the Service, and only as needed for them to perform their function. They are contractually restricted from using your data for their own purposes, from using it to train AI models, and from using it for advertising.

  • Anthropic — AI analysis of bills and drafting of letters.
  • Amazon Web Services (AWS) — document text extraction (Textract) and temporary storage of uploaded documents (S3) during processing.
  • Supabase — account and case database and authentication, with per-user row-level security.
  • Lob — printing and certified-mail delivery of letters.
  • Resend — transactional and letter-fulfillment email.
  • Stripe — payment processing (we do not receive or store your full card number).
  • PostHog — first-party product analytics and masked session replay.
  • Upstash — rate-limiting and abuse-prevention infrastructure.

We do not share your consumer health data with our affiliates.

We may also disclose information when required by law, to enforce our terms, to protect the rights, safety, or property of BillFighter or others, or in connection with a merger, acquisition, or sale of assets (subject to this policy).

11. We do not sell your data

We do not sell or rent your personal information, and we do not share it for cross-context behavioral advertising. Your information is used to provide and improve the Service, not to build advertising profiles.

12. Data retention

  • Uploaded bill images and PDFs are deleted from our processing storage after text extraction is complete.
  • The extracted text and analysis results are kept as part of your case record for as long as your account is active, so you can return to your cases and letters.
  • When you delete your account, your associated data — including case records, letters, and analysis results — is permanently removed. We keep a minimal deletion record (such as the account email and the date) only as needed for fraud prevention, security, and legal compliance.
  • Residual copies in encrypted database backups are removed within 7 days, as the backup containing them rotates out of retention.

13. How we protect your information

We use administrative and technical safeguards designed to protect your information, including transmission over HTTPS/TLS, per-user row-level security in our database, access controls, and the data-minimization measures described above. No method of transmission or storage is completely secure, but we work to protect your information and to limit who can access it.

14. Your privacy rights and choices

Depending on where you live — including California and other states with comprehensive privacy laws — you may have the right to know what personal information we hold about you; to access or receive a copy of it; to correct it; to delete it; to obtain it in a portable form; to opt out of the sale or sharing of personal information and of targeted advertising; and to limit the use of sensitive personal information. You also have the right not to be treated differently for exercising these rights.

Because we do not sell your personal information, do not share it for cross-context behavioral advertising, and use sensitive information only to provide the Service, some of these rights may not apply to us in practice — but you may still exercise them.

How to exercise your rights

  • Delete your account yourself: sign in and go to Settings, then "Delete account," and confirm. Your account and associated data are permanently deleted.
  • In the mobile app: go to Settings and tap "Delete Account."
  • By email: contact hello@billfighter.com and tell us which right you wish to exercise. We will verify your request and respond within the time required by applicable law (generally 45 days, extendable where permitted). Where required, you may appeal a decision by replying to our response. If an appeal is denied and you are a Washington consumer, you may contact the Washington State Attorney General's Office.

15. Global Privacy Control and Do Not Track

We honor the Global Privacy Control (GPC) signal as a request to opt out of non-essential tracking. Because there is no common industry standard for older "Do Not Track" browser signals, we do not separately respond to them; our first-party, non-advertising analytics practices are described above.

16. Age requirement and children's privacy

You must be at least 18 years old to create an account or use the Service. The Service is intended for adults, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us personal information, contact us at hello@billfighter.com and we will delete it.

17. Data breach notification

If we experience a breach of security affecting your personal information or your health-related information, we will notify you and the appropriate authorities as required by applicable law, including the Federal Trade Commission's Health Breach Notification Rule and applicable state breach-notification laws.

18. International users

The Service is operated in the United States and intended for U.S. users. If you access it from outside the United States, you do so on your own initiative and are responsible for compliance with local law.

19. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the site, and we will update the "last updated" date.

20. How to contact us

If you have questions about this Privacy Policy or your data, or to submit a privacy request, contact us at hello@billfighter.com.

AAA Incubator, LLC 10676 Colonial Blvd, Ste 30 PMB 1019 Fort Myers, FL 33913 United States