Security & Privacy First

Privacy Policy

Last Updated: July 6, 2026

Key Highlights

Data is isolated per hospital/clinic using Supabase RLS.
Patient data processed via OCR is not stored in plain text long-term.
We never sell data or use patient logs to train public AI models.
All database contents are fully encrypted in transit and at rest.

1. Introduction

Welcome to ClaimPilot. We respect the privacy of our users and are committed to protecting the patient and hospital data processed through our platform. This Privacy Policy describes how we collect, use, and safeguard your information when you use our service to prepare HMO claim submissions and perform NHIA catalogue lookups.

2. Information We Collect

To provide our automated claim-preparation service, we collect and process the following categories of information:

  • Account Credentials: Usernames, business email addresses, and passwords when you register or sign in.
  • Hospital/Clinic Workspace Profile: Hospital name, NHIA provider number (HCP code), telephone number, physical address, and logo.
  • HMO Authorization & Claim Data: Patient names, insurance policy numbers, diagnosis codes, authorization text, upload logs, and itemized lists of NHIA codes, procedures, and drugs processed.
  • Billing Information: Payment reference tokens (via our secure payment processor, Paystack) for subscription management. We do not store credit card or bank details on our servers.

3. Data Isolation and Security

Healthcare data demands the highest security. We implement industry-leading technical measures:

  • Database Isolation: We use PostgreSQL Row-Level Security (RLS) policies on Supabase to ensure each hospital's claims, team memberships, and logs are completely isolated. No other subscriber can view or access your workspace.
  • Encryption: All data is encrypted in transit using secure HTTPS protocols and at rest.
  • OCR Processing: Any patient authorization text parsed from images or PDFs is analyzed temporarily to extract information. We do not retain uploaded authorization files for longer than required to complete the parsing.

4. How We Use and Share Information

We strictly limit our use of collected information:

  • We use your data exclusively to run the claim builder, validate claims, and export files.
  • We do not sell or share patient clinical data, names, or authorization logs with third-party advertising companies.
  • We do not use your private clinical data or claim histories to train public artificial intelligence models.
  • We share account information with service providers only as required to function (e.g., Supabase for database hosting, Netlify for application deployment, and Paystack for subscription invoicing).

5. Your Rights and Deletion

You have full control over your workspace:

  • You can invite or revoke access for team members within your workspace.
  • You can edit or delete draft and completed claims at any time.
  • If you wish to terminate your workspace and permanently delete all associated hospital profile information, please contact us.

6. Contact Information

If you have any questions or concerns regarding our privacy practices, please contact us via email or WhatsApp support: