Privacy methodology

Privacy-Protected Bill Comparisons

Private bill records and comparison observations are separate. Contribution is optional, versioned, and designed to exclude reusable personal and receipt identifiers.

Default

Private and contribution off

Identity

Scoped HMAC pseudonyms

Controls

Review · revoke · export · delete

Your private bill record

The account-scoped record can contain the original image, complete provider details, line items, and diagnostic patient or doctor details. Other users do not receive this private record as comparison evidence.

The limited comparison observation

When you explicitly consent, an eligible line can contribute only its canonical identity, normalised price and unit, broad location, provider ID where appropriate, observation date, consent version, quality flags, and a one-way scoped pseudonym. Supported diagnostics may also include allow-listed matching attributes such as sample type, body part, modality, and contrast use.

Fields excluded by design

The comparison projection excludes direct user IDs, reusable receipt IDs, raw item and store names, receipt images, contact and invoice fields, patient or doctor details, insurance details, and prescription details.

Controls remain with you

Review shows a redaction preview before you decide. Settings lets you choose a default, revoke prior contributions, download your data, and permanently delete your account. Pharmacy contribution remains disabled regardless of the toggle.

After deletion

Account deletion removes private account data and voids your active comparison observations. Non-identifying aggregate statistics that can no longer be linked back to an account may remain so historical cohort totals do not have to be reconstructed as personal records.