Privacy Policy
Last updated: March 27, 2026
1. Introduction
Lumio Ventures, LLC ("rekupr", "we", "our", or "us") operates the rekupr medical bill analysis service (the "Service"). This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
Effective date: March 27, 2026.
2. Information We Collect
We collect several categories of information depending on how you interact with the Service.
Documents You Upload
- Medical bills, statements, and invoices
- Explanation of Benefits (EOB) documents
- Insurance-related documents
The contents of these documents may include: patient names, provider and facility names, dates of service, medical procedure codes (CPT, HCPCS, ICD-10), diagnosis codes, financial amounts (billed, allowed, paid, patient responsibility), insurance member and group numbers, account numbers, and other health-related information.
Account Information (Registered Users)
- Email address
- Name
- Authentication method (magic link tokens or Google OAuth identifier)
Profile Information (Optional)
- Phone number
- Mailing address
- Date of birth
- Insurance member ID
All optional profile fields are encrypted at rest.
Anonymous Visitor Data
If you use rekupr without creating an account, we assign a unique visitor identifier to your browser session. We collect the following information, all of which is encrypted at rest:
- IP address and browser user agent
- Basic engagement data: pages visited, documents uploaded, and marketing attribution (UTM parameters, referrer URL)
Chat Conversations
If you use rekupr's AI assistant, your messages and the assistant's responses are stored and encrypted at rest.
Technical and Usage Data
- Device type, browser information, operating system
- Pages visited and features used
- General geographic location (country level)
Payment Information
Payments are processed by Stripe. We do not store your credit card number, expiration date, or CVC on our servers. We receive a transaction record from Stripe confirming payment.
3. How We Process Your Documents
When you upload a document, we use automated systems to analyze it:
- Your document is transmitted securely and stored with encryption
- We use optical character recognition (OCR) to extract text from your document
- Automated analysis, including AI, checks for potential billing issues
- If you upload both a bill and an EOB, we compare them for discrepancies
- Findings, potential savings estimates, and suggested actions are generated and stored encrypted in our database
Important: Your uploaded document content is transmitted to Google Cloud Platform for processing, including Google's Vertex AI and Gemini models for document analysis and data extraction. Google processes this data under our Business Associate Agreement and is prohibited from using it for any purpose other than providing these services.
4. Third-Party Processors
We use the following third-party services to operate rekupr:
| Provider | Purpose | Data Received |
|---|---|---|
| Google Cloud Platform | Document processing, analysis, and storage | Uploaded document content |
| Google (OAuth 2.0) | Social login ("Sign in with Google") | Email, name |
| Stripe | Payment processing | Payment card info, purchase records |
| Brevo (Sendinblue) | Transactional email | Email address, notification content |
| Google Analytics / Google Tag Manager | Product analytics (loaded only after cookie consent) | Pages visited, device info, behavioral analytics |
Google Cloud Platform services that process your document content are covered by a HIPAA Business Associate Agreement. Google OAuth is a separate service used only for social login and does not receive any document or health data.
5. How We Use Your Information
- Service delivery: Processing your documents, generating analysis results, and providing bill review insights
- Communications: Notifications about analysis results, account updates, and service announcements
- Product improvement: We use only aggregated, anonymized, and de-identified data that cannot identify individuals
- Legal compliance: Responding to lawful requests and enforcing our terms
We do NOT sell your individual data to third parties. We do NOT use your data for advertising or ad targeting. We do NOT share your document contents with other users.
6. Data Storage and Security
We implement multiple layers of security to protect your information:
- Application-level encryption: Over 50 database fields containing sensitive information (names, medical codes, diagnoses, financial identifiers, addresses, phone numbers, insurance IDs) are individually encrypted using AES-256-CBC
- File storage encryption: AES-256 server-side encryption on Google Cloud Storage
- Transport encryption: TLS 1.3 with HTTPS enforced on all connections
- Session encryption: Sessions are encrypted to prevent tampering
- Queue encryption: Background processing jobs use encrypted payloads
- Log protection: A PHI masking processor automatically redacts sensitive data from application logs
7. Data Retention
- Original uploaded files: Automatically deleted within 3 days of processing
- Analysis results: Retained for up to 7 years
- Audit logs: Retained for 6 years
- Account deletion: Personal information deleted within 30 days of your request, except where retention is legally required
- Anonymous visitor data: Automatically purged 90 days after the last interaction with the Service
Beta Program Data
All documents uploaded during the beta testing period, along with all associated extracted data, will be permanently deleted within 30 days of the beta program's conclusion. This includes line items, diagnosis codes, financial amounts, provider and patient information, detected billing issues, AI-generated summaries and letters, and chat conversations. The deletion is a full cascading purge; no derived or extracted data from your uploaded documents will be retained after this period.
We will notify all beta participants via email when the beta program concludes and the deletion window begins.
Exclusions: Anonymized or aggregated analytics data, audit logs (retained per our standard 6-year compliance retention policy), and your account record itself are not affected by beta data deletion. Your account will remain active unless you request its deletion separately.
8. Your Rights
You have the following rights regarding your personal information:
- Access: Download your data from Account Settings
- Correction: Update your profile information at any time
- Deletion: Permanently delete your account and all associated data from Account Settings
- Export: Request a portable copy of your data
- Opt out of marketing: One-click unsubscribe in any email, or manage preferences in Account Settings
To exercise any of these rights, visit your Account Settings or contact us at support@rekupr.co.
9. HIPAA and Health Data
rekupr is not a healthcare provider, health plan, or healthcare clearinghouse. We are not a HIPAA Covered Entity or Business Associate in the traditional sense.
You upload your own documents voluntarily. We do not receive health information from providers or insurers on your behalf (except through our optional payer connection feature, where you explicitly authorize the connection).
Despite not being a Covered Entity, we recognize that the documents you upload may contain Protected Health Information (PHI). We voluntarily apply HIPAA-grade safeguards, including:
- Encryption at rest for all health-related data fields
- A Business Associate Agreement with Google Cloud Platform
- PHI masking in application logs
- Access controls ensuring you can only view your own documents
- Comprehensive audit logging
- Automatic deletion of original uploaded files within 3 days
10. Children's Privacy
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at support@rekupr.co so we can promptly delete it.
11. Cookies and Tracking
We use the following categories of cookies and tracking technologies:
- Essential cookies (always active): Session cookies required for the Service to function, including maintaining your login state and preventing cross-site request forgery. These cannot be disabled.
- Analytics cookies (opt-in only): If you accept analytics cookies via our cookie consent banner, we load Google Analytics 4 (GA4) to understand how the Service is used. GA4 collects pages visited, device information, and general usage patterns. If you decline, GA4 is never loaded and no analytics data is collected.
We do not use advertising cookies or third-party tracking pixels. Analytics data collected through GA4 is not used for ad targeting.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with additional rights regarding your personal information.
Your Rights
As a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and sell (if applicable)
- Delete your personal information, subject to certain exceptions
- Correct inaccurate personal information we hold about you
- Opt out of the sale or sharing of your personal information
- Non-discrimination for exercising any of your CCPA rights
What We Do Not Do
- We do not sell your personal information to third parties
- We do not share your personal information for cross-context behavioral advertising
- We do not use sensitive personal information for purposes other than providing the Service
Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:
- Identifiers: name, email address, IP address, unique visitor ID
- Commercial information: purchase and transaction records
- Internet or electronic network activity: pages visited, device information, browser type
- Sensitive personal information: health-related data contained in documents you upload (medical codes, diagnosis codes, financial amounts, insurance identifiers). This information is collected only because you voluntarily provide it and is used solely to deliver the Service.
Exercising Your Rights
To exercise any of these rights, you may:
- Use the deletion and export features in your Account Settings
- Email us at support@rekupr.co with the subject line "CCPA Request"
We will verify your identity before processing your request and respond within 45 days as required by law. You may designate an authorized agent to make a request on your behalf.
13. Changes to This Policy and Contact
We may update this Privacy Policy from time to time. When we do, we will post the updated policy on this page and change the "Last updated" date at the top. For material changes, we will send an email notification to registered users.
If you have questions about this Privacy Policy, want to exercise your data rights, or have concerns about how your information is handled, please contact us:
Lumio Ventures, LLC
Email: support@rekupr.co