Your private bill record
The account-scoped record can contain the original image, complete provider details, line items, and diagnostic patient or doctor details. Other users do not receive this private record as comparison evidence.
Private bill records and comparison observations are separate. Contribution is optional, versioned, and designed to exclude reusable personal and receipt identifiers.
Default
Private and contribution off
Identity
Scoped HMAC pseudonyms
Controls
Review · revoke · export · delete
The account-scoped record can contain the original image, complete provider details, line items, and diagnostic patient or doctor details. Other users do not receive this private record as comparison evidence.
When you explicitly consent, an eligible line can contribute only its canonical identity, normalised price and unit, broad location, provider ID where appropriate, observation date, consent version, quality flags, and a one-way scoped pseudonym. Supported diagnostics may also include allow-listed matching attributes such as sample type, body part, modality, and contrast use.
The comparison projection excludes direct user IDs, reusable receipt IDs, raw item and store names, receipt images, contact and invoice fields, patient or doctor details, insurance details, and prescription details.
Review shows a redaction preview before you decide. Settings lets you choose a default, revoke prior contributions, download your data, and permanently delete your account. Pharmacy contribution remains disabled regardless of the toggle.
Account deletion removes private account data and voids your active comparison observations. Non-identifying aggregate statistics that can no longer be linked back to an account may remain so historical cohort totals do not have to be reconstructed as personal records.