Your data deserves careful handling.
DenialDesk is built for sensitive RCM workflows. This policy explains what information we collect, why we collect it, and how we work to protect it.
Last updated: June 2026
Minimum necessary
We ask users to upload only the documents needed for denial review.
Packet generation only
Uploaded files are used to create the requested internal RCM packet and related case record.
User control
Users can contact us to ask privacy questions or request deletion where feasible.
We treat uploaded denial documents as sensitive business information.
DenialDesk is intended for medical billing and RCM teams. Uploaded files may contain protected health information, payer data, claim information, provider details, and other sensitive operational information.
1. Information we collect
We may collect the following information when you use DenialDesk:
- Name and email address submitted for verification and packet delivery.
- Uploaded EOBs, ERAs, denial letters, rejection documents, and optional supporting PDFs.
- Case metadata such as case ID, upload time, packet status, credit usage, and packet link.
- Basic website and technical information needed for security, troubleshooting, and service operation.
- Payment and checkout records from the hosted payment provider, when a plan is purchased.
2. How we use information
We use information to:
- Verify user email access.
- Generate the requested AI-assisted denial review packet.
- Email packet links and service notifications.
- Track free usage and paid packet credits.
- Improve reliability, debugging, support, and workflow quality.
- Protect against abuse, unauthorized use, spam, or security risks.
3. Uploaded documents
Uploaded documents are used to generate the requested DenialDesk packet. The workflow may extract text, analyze denial information, create a Google Docs-based internal working file, export or share a packet link, and record case details in a case tracker.
Users should not upload unrelated records or unnecessary PHI. If a document is not required for denial review, do not upload it.
4. AI processing
DenialDesk uses AI services to help extract denial details and generate internal review packets. AI output can be inaccurate or incomplete and must be reviewed by a qualified human before use.
We do not use DenialDesk to make final medical, legal, coding, compliance, payer-policy, or billing decisions automatically.
5. Sharing and third-party services
To operate DenialDesk, we may use trusted third-party tools for hosting, automation, file storage, AI processing, email delivery, analytics/debugging, and payments.
We do not sell user documents or uploaded claim information. We do not publish uploaded documents. Access is limited to what is needed to operate, support, secure, and improve the service.
6. Payment information
Payments are handled by a hosted checkout provider. DenialDesk does not ask users to type credit card details directly into our website pages.
We may receive payment confirmation, customer email, product purchased, and credit entitlement information so we can add packet credits to the user account.
7. Security measures
We use practical safeguards such as HTTPS, email verification, usage limits, access-controlled workflow tools, private working documents where appropriate, hosted checkout, and internal review practices.
No online system can be guaranteed 100% secure. If you believe information was submitted in error or may be at risk, contact us promptly.
8. Retention
We retain documents and case records for as long as needed to provide the service, support users, maintain audit records, improve reliability, and manage credits or disputes.
Users may request deletion of uploaded files or related case records. We will review such requests and delete data where feasible, subject to operational, legal, security, payment, or recordkeeping needs.
9. User choices
- You may choose not to upload a document.
- You may redact unnecessary information before upload, where appropriate.
- You may contact us to request deletion or correction of records.
- You may stop using the beta service at any time.
10. Children’s privacy
DenialDesk is intended for business and professional RCM use. It is not intended for children or personal consumer use by minors.
11. Changes to this policy
We may update this Privacy Policy as DenialDesk develops. The “Last updated” date will reflect the latest version. Continued use of DenialDesk after updates means the updated policy applies.
12. Contact us
For privacy questions, support, or data requests, contact:
Email: leadsyncintelligence@gmail.com
