Privacy Policy

Last Updated: September 2026

At Wikisurance, we build tools to empower patients. Because we handle highly sensitive medical and financial data, our privacy and security practices are designed to meet or exceed federal and industry standards. This Privacy Policy explains how we collect, use, protect, and disclose your information.

1. Information We Collect

We collect information you provide directly to us when you create an account, upload documents for review, or contact our support team.

  • Personal & Identity Data: Name, email address, phone number, and billing information.
  • Health & Claims Data: Medical records, insurance policy documents, Explanation of Benefits (EOBs), denial letters, and provider information that you upload to our platform.
  • Technical Data: IP addresses, browser types, and usage data collected automatically via cookies and similar tracking technologies.

2. Regulatory Compliance (HIPAA & FTC)

Depending on how you use our service, we may act as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) (e.g., if you are a healthcare provider using our tools). If you are a consumer using our platform directly, your data is protected by the FTC Health Breach Notification Rule and applicable state privacy laws.

Regardless of your status, we apply HIPAA-grade security protocols to all user data:

  • Encryption: All Protected Health Information (PHI) is encrypted in transit (TLS 1.3) and at rest (AES-256).
  • Access Controls: We employ strict role-based access controls and maintain immutable audit logs for all data access.

3. Artificial Intelligence & Data Usage

Wikisurance utilizes Artificial Intelligence (AI) and Machine Learning (ML) to analyze insurance policies and generate appeal drafts.

  • Your Identifiable Data: Your name, PHI, and specific medical history are never used to train public AI models or shared with third-party LLM providers without strict zero-retention agreements.
  • De-identified Data: We may aggregate and completely de-identify claims data (removing all PHI in accordance with the HIPAA Safe Harbor standard) to improve our internal algorithms and track national insurance denial trends.

4. Third-Party Sharing

We do not sell your personal or health data to third parties. Ever.

We may share data with trusted service providers (such as AWS for secure hosting or Stripe for payment processing) who are contractually bound to protect your data to the same standard we do. We may also disclose data if required by law or subpoena.

5. Your Privacy Rights

Depending on your jurisdiction (such as California under the CCPA/CPRA, or the EU under GDPR), you have the right to:

  • Request access to the personal data we hold about you.
  • Request deletion of your data (subject to legal retention requirements).
  • Opt-out of non-essential communications.

To exercise these rights, email us at support@indicwave.com. We process all deletion requests within 30 days.

6. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact our Data Protection Officer at support@indicwave.com or visit our Contact Page.