Privacy

Privacy Policy

Last updated September 7, 2026

No accountServer drafts auto-delete in 7 days; downloads are yoursAutomated citation checks, not legal review

Overview

Parity is a self-help filing tool for Californians whose insurance has denied mental health care. This policy explains what information we collect when you use Parity, how we use it, and how we protect it. We aim to collect as little as possible, and to delete what we do collect as fast as the product allows.

The short version

Your answers stay in your browser until you generate a draft. Then whatever you typed — the clinical story, in your words — goes to our AI provider to write your letter. At that same request boundary, Parity encrypts the exact validated drafting payload in a separate recovery record; it and the resulting packet auto-delete from our live store within 7 days. Drafting never requires your name or member ID, and the finished letter uses labeled blanks ([MEMBER NAME], [MEMBER ID]) that you fill in at the end, on your own device — that filled-in step never touches our servers. Opening a free packet requires an email so we can send the private recovery link; it is stored with content-minimized case metadata, not inserted into the packet. The story boxes are free text and you're welcome to write freely — just know the plain truth about them: everything you type there is sent to our AI provider (Anthropic) to draft the letter, and the 7-day auto-delete is our servers' promise. Anthropic publishes its current retention details and exceptions for commercial API inputs and outputs in Anthropic's commercial data-retention policy. Names or IDs included in drafting text can reach Anthropic. Parity tries to replace detected identifiers with blanks, but detection can miss them, so leave them out and check your draft. Names and IDs are never needed — you fill those in at the end, on your own device. We never sell your data. The vendors and governing retention terms are detailed below.

What we collect

When you use the Path Finder and generate a draft, the following information is processed:

  • Your answers to the Path Finder's structured questions (such as insurer, treatment type, and denial reason). While you work, these live in your browser, on your device (localStorage and sessionStorage, so you can resume). When—and only when—you ask us to generate a draft, those answers are sent with the drafting request and Parity creates an encrypted IntakeRecoveryRecord containing that exact validated drafting payload. It contains no extra profile, account, member ID, generated letter, or filled-in letter details, and it expires no later than 7 days after that first request. Parity also keeps the drafted packet for up to 7 days (including your clinical summary and impact story, if provided), a thin generation support trace for 90 days (only which system path ran, never your prose, insurer, treatment, or denial category), and a content-minimized case record for 12 months when you open a packet or choose free case tracking. Your saved drafts (“My Drafts”) are different: that list lives only on your device and is never synced to our servers.
  • The exact-plan mailing-address check runs on your device, and the raw plan name, document or form code, administrator name, and group number you type for that check are not sent to Parity or Anthropic.
  • The free-text clinical summary and, if you add one, the personal impact story you optionally provide describing your case and how the denial has affected you. Both fields are treated identically: sent to the AI provider as you wrote them, and held in our letter draft store under the same 7-day auto-delete policy described below. We do not pre-redact identifying information from either field — we ask you not to include names, member IDs, or other directly identifying details, since the letter itself uses bracketed placeholders for those.
  • Standard server logs from our hosting provider (IP address, browser user agent, timestamps) when you visit the site.
  • Anonymous traffic analytics through Vercel Analytics on public informational pages. Analytics is disabled on case, clinician, letter, saved-draft, resume-link, and denial-document routes, and URLs containing case or access credentials are blocked from analytics.

We do not require an account. Opening a free packet requires an email address so Parity can immediately send the private packet-and-case recovery link; we attach that address to the content-minimized case when access is granted. This required recovery email does not enroll you in reminders or marketing. If you use "Email letter to me," we collect the email address you type into that form for that single send, and pass it to our transactional email provider (Resend) along with the letter body. If an AI draft fails, the failure screen separately lets you type an email and ask for a finish-later link. Parity never sends that link automatically and never asks for this address before a failed draft. The email contains the private link and retention instructions, not your answers or other clinical text; the recovery record keeps only a keyed digest of the address for unfamiliar-device confirmation.

If you submit the feedback form, the name and email are optional, while the feedback text is required. We send that submission through Resend to Parity's support inbox. It is then retained in that inbox until Parity deletes it. Do not put clinical details, member IDs, or other sensitive case information in the feedback form or an ordinary support email.

Information about minors. Parity is for adults — if you're filing for your child as their parent or legal guardian, the clinical details you type about them get the same treatment as everything else here: sent only to draft the documents, auto-deleted from our letter store within 7 days, and never used for anything else. We do not knowingly collect information directly from anyone under 18.

What we keep

Here's the honest version, feature by feature:

  • Your temporary drafting-answer recovery record. The instant Parity receives and validates your request for an AI draft—not while you are filling out the Path Finder—it encrypts the exact content-minimized drafting payload with an authenticated server-side key and stores the ciphertext in Upstash Redis. It has a hard 7-day lifetime measured from the first request; retries, resume visits, and email sends cannot extend it. A signed private token locates the record. The original browser gets a content-free trusted-device cookie; an unfamiliar device must confirm the email address that received the link before Parity returns the answers. Only after a draft fails, and only if you ask, Parity adds a keyed digest of that email and sends a content-free link through Resend. The same per-answer-set retry count follows the token across devices.
  • Your letter draft. When you generate a letter, we hold the drafted packet — including your clinical summary and impact story, if provided — server-side in Upstash Redis, keyed to a random preview ID, for up to 7 days. This is what powers thefree opening flow: you can close the tab, come back, and pick up where you left off. Your draft auto-deletes from our live application store automatically after 7 days — we treat this as a feature, not a compromise. Infrastructure snapshots and backups are controlled by the provider and age out on its separate backup schedule; they are not available through Parity.
  • Generation support trace. For 90 days after a document is generated, Parity keeps a separate thin support record containing only the generation time, document kind, governing track, plan-funding category, recommended filing, and generation or recovery mode. This lets us confirm which system path ran after the seven-day draft has expired. The record is addressed by a pseudonymous derivative of the preview ID rather than storing the raw ID, and it never contains the letter, user prose, clinical or impact-story signals, insurer, treatment, denial category, urgency, email, name, case ID, or packet-opening ID. Each record expires independently; later generations cannot extend it.
  • Notify-me list. If you give us your email on an off-ramp screen ("let me know when Parity covers my state" or similar), we store it in Redis with the state you indicated, the source screen, and a timestamp. We use it for one thing: emailing you when Parity expands to cover your situation. We keep it until that notice is sent or you ask us to remove it.
  • Law-update newsletter. This is a separate opt-in list from notify-me. We store the email address, signup source, and timestamp until you unsubscribe or ask us to remove it.
  • Saved letters. If you use "Save letter," it lives in your browser's localStorage on your device, capped at 10 most recent. We never see this copy — it's local to your device and clearing your browser data deletes it.
  • Rate-limiting. For abuse prevention we keep short-lived counters in Upstash Redis. The app converts your IP address into a pseudonymous one-way key before it reaches Redis; the counter expires automatically within its stated rate-limit window, usually an hour.
  • Tracked case pages. A packet gets a private recovery case automatically; a person using the free flow can choose "Track this case." In either path, we create a case record — insurer, treatment category, denial category, denial date, your stage checklist, and the required recovery email for a packet (or an optional email for a free case) — kept for 12 months after the last member-initiated access or saved update. Opening or updating the case renews that period. See "Case pages" below for the full detail.
  • Optional case check-ins. Attaching an email does not enroll you. If you separately check the optional check-in box, we stage a 30- and 60-day schedule so a daily dispatcher can find it. That schedule contains your email and private case link, expires within 90 days, and is deleted if you turn check-ins off or delete the case. Sending remains off until the launch flag is enabled.
  • Email suppression. If you unsubscribe, we keep the address and list category in a suppression record so automated email stays stopped. We keep that record until you ask us to remove it or subscribe again; removing it may allow the applicable automated email to resume.

Who processes what, in plain terms:

  • Anthropic (the company that makes Claude) sees the content needed for the AI action you request: routing answers and clinical story for drafting, statement text for optional polishing, denial-letter text for extraction, or case details for an escalation draft. Anthropic publishes its current handling and retention terms for commercial API inputs and outputs in its commercial data-retention policy.
  • Upstash (our Redis provider) holds encrypted temporary drafting-answer recovery records, letter drafts and entitlements, tracked cases, reminder schedules, clinician-link context, notify-me entries, suppression records, aggregate counters, and pseudonymous rate-limit counters — each with the retention behavior described in this policy or the feature itself.
  • Resend (our email provider) sees the recipient address, subject, message body, and any attachment when an email is sent. That includes a finish-later link you request after a failed draft, the required packet-and-case link, a letter you ask us to email, a requested case link, reminder/check-in content, newsletter or expansion notices, and feedback forwarded to Parity. The finish-later message contains no drafting answers or clinical text. Resend retains standard email data for 30 days on its standard service and describes a separate 30-day production-backup window; its terms and any account-specific agreement control.
  • Vercel, our hosting provider, serves every page and API request and keeps request/runtime logs according to the Parity account's plan. That means Vercel necessarily receives the URL you request, including a case, clinician, or drafting-resume token in a private link. Those sensitive routes are excluded from Web Analytics, but hosting is not the same thing as analytics. Parity's own application log statements do not print letter contents, clinical summaries, impact stories, email addresses, bearer tokens, record IDs, or packet-opening IDs.

AI processing

Parity uses AI to draft your documents, and we want you to know exactly what that means for your information.

  • What we use. Letter drafting, the optional impact-statement polish, and the paste-to-prefill extraction all use Claude, a commercial AI service made by Anthropic. This is Anthropic's business-grade API, not a consumer chatbot.
  • What gets sent. The information you type (your routing answers, clinical summary, and impact story) is sent to Anthropic's API for the sole purpose of drafting your documents. Nothing is sent for any other reason.
  • How Anthropic handles it. The drafting call is made under Anthropic's business-grade API agreement. Anthropic's current policy states that commercial API inputs and outputs are not used to train its models. Anthropic publishes its current retention details and exceptions in its commercial data-retention policy. For the controlling terms, see Anthropic's commercial terms — theirs govern, not ours.
  • Parity's retention. Parity does not keep your letter content or temporary drafting-answer recovery payload in its live application store beyond the separate 7-day windows described above. When either auto-deletes, it is gone from the live application store; infrastructure backups age out on the provider's separate schedule.

Parity runs automated checks against official citation sources before you see an AI-drafted letter. No-AI fill-ins are assembled only from the facts you provide and mark missing details as blanks. Neither path is legal review.

What we do not do

  • We do not sell your data to anyone.
  • We do not share your data with insurers, advertisers, or data brokers.
  • We do not use your clinical summary, impact story, or draft content for marketing.
  • We do not keep your letter draft or encrypted drafting-answer recovery record in the live application store past 7 days — each Redis record expires automatically, with provider backups aging out separately.
  • Details you type into the letter's fill-in-the-blanks editor (name, member ID, dates) and full-text edits stay in your browser. Filled and edited downloads are generated on your device; typing, blur, and restore-original do not send those edits to Parity. If you expressly use “Email to me,” the placeholder document you ask us to send goes to Resend under the email terms above. Editing removes Parity's citation-verification receipt from the changed text because your changes are not rechecked.

HIPAA, plainly

Parity is designed as a tool you choose and use for yourself, not as a service acting for your doctor or insurer. We therefore do not present Parity as a HIPAA-covered medical-record system. That does not make the information unimportant: clinical drafts are sensitive, so we minimize them, keep the Parity server copy for no more than 7 days, separate the longer-lived case record from the clinical narrative, and disclose each processor above. HIPAA obligations can depend on relationships and contracts, so this description is about Parity's current product role, not a promise that privacy law can never apply.

If you use a clinician link, Parity stores the request context described below, but the clinician's completed medical-necessity letter still travels directly between you and the clinician. The clinician page has no file-transfer or reply channel for sending that finished document to Parity.

Clinician links

Creating a clinician link requires a separate unchecked consent box that lists exactly what the clinician will see. Parity stores the treatment category, denial category, filing type, creation and expiration times, the consent version, and an optional patient first name only if you choose to add one. That context is stored in Upstash under a random link token and expires after 30 days. The private URL itself is the access key, so treat it like a password. The page does not contain your drafted appeal, clinical summary, member ID, or a way for the clinician to send a completed letter back to Parity. The creator receives a separate management secret and can revoke the link immediately from the same browser.

Opening, founder-help, and contact messages

The opening list and founder-help interest list are separate. The founder-help list stores the email address, form source, and submission time in Upstash Redis. Its per-email metadata expires after about 18 months; list membership is removed when you ask us to remove it. Use the removal button shown after joining or email privacy@parity.care from the address you want removed. Do not include health information when joining an interest list.

The Support contact form stores the email address, selected category, submission time, status, and the short message you enter. The message record expires after 90 days. It is visible only through an authenticated founder console. Because free text can be sensitive, the form asks you not to send health information, documents, member IDs, card details, or private links. You can instead email support@parity.care.

Case pages (included with a packet; optional in the free flow)

"Track this case" creates a private case page at a URL like parity.care/my-case/<token>. There is no account and no password — the long random token in the link is the key, plus one more check: opening your case on a device we haven't seen before asks you to confirm one detail from the case (the email you gave, or your denial-letter date) before anything renders. The link alone isn't enough on an unfamiliar device. Still treat the link like you would a password — don't post it or forward it to anyone you don't want near your case. We show this link on-screen the moment it is created (with a copy button) specifically so you never depend only on an email arriving. Opening a packet creates the case and Parity immediately sends the private link to the required recovery email.

A case record holds: insurer, treatment category, denial category, denial date, your stage checklist (letter sent, response due, IMR, etc.), your recorded outcome if any, and your required recovery email for a packet, or an email only if you chose to give one on a free case. It also records separate yes/no choices for optional case check-ins, anonymous aggregate outcome sharing, and testimonial contact. The email on a case is used for access/recovery, unfamiliar-device confirmation, and any email feature you separately request. It does not hold your drafted letter text or clinical summary — those stay in the separate 7-day letter store described above. Parity keeps this case record for 12 months after the last member-initiated access or saved update; opening or updating the case renews that period. You can delete the case at any time from that page; the next paragraph explains what is removed immediately and which limited records follow separate retention terms.

If you lose the private link, you can enter the email saved on the case and ask Parity to resend it. We keep a pseudonymous email-to-case index for this purpose: the storage key is created with a keyed digest rather than the address itself, contains only case identifiers, follows the case's rolling retention window, and is removed with the case. Parity always gives the browser the same response whether or not an active case uses the address. A link is sent only to the exact email already stored on a matching case, includes no case details, creates no entitlement, and still requires the ordinary unfamiliar-device check when opened. A new packet opening is paused unless required transactional delivery is available. Later recovery requests also require that transactional-email control and provider.

Delete this case on the case page removes your case record immediately from our live systems, including its deadline-reminder and outcome-check-in schedules — a real deletion, not a hidden flag. Any optional one-way aggregate outcome contribution is removed from its counter, and the link stops working the moment you delete the case. If the case used a multi-stage entitlement, we retain a minimal, content-free marker that the entitlement was consumed for up to 12 months. That marker contains no insurer, treatment, denial, date, email, checklist, outcome, or other case content; it exists only to prevent one entitlement from being reused for unrelated disputes and to support fraud prevention and refunds. Deleting a case does not reset that entitlement. Payment providers retain their own transaction records under their policies and legal obligations. Our infrastructure providers' backups age out on their own schedule, within their standard backup retention window, which is outside our direct control the way live deletion is.

Outcome check-ins and anonymous aggregates

If you separately opt in, we may check in at 30 and 60 days. The email contains one private case link; clicking it does not record an outcome. You can turn check-ins off without changing case access. You can record an outcome on the case page only after a matching case event, and you can keep that outcome private.

When you record an outcome, a separate unchecked box lets you include it in an anonymous aggregate. If you check it, the result increments a plain counter and Parity keeps only a one-way pseudonymous marker so retries do not double-count and you can later correct or withdraw the contribution. The counter and marker carry no email or case details. You can withdraw the aggregate contribution without deleting the private outcome or case, and case deletion withdraws it too. Aggregate sharing is separate from any testimonial permission. We use these counts only internally for now; we do not publish specific numbers or make claims about success rates from them.

Paste-to-prefill (Start With Your Letter)

If you paste the text of a denial letter on the "Start With Your Letter" page, the text is sent to our AI provider for one extraction call — insurer name, denial reason category, date, a short treatment description, and any deadline language — and the result is shown to you on a confirm screen. Parity does not write the document or extracted text to Redis, disk, or application logs; it exists in Parity's request memory only long enough to perform the extraction. The extracted text is an Anthropic API input, so Anthropic's commercial API retention described above still applies. The paste-only page is the only live path and does not accept files. A separate PDF route is kept dark by an environment switch, so PDF upload stays unavailable unless Parity has a current review of the processor's retention and training terms. If that route is enabled later, Parity will process a PDF's bytes to extract text; Anthropic will receive the extracted text, not the PDF file itself, and raw PDF text will not be returned to your browser.

Cookies and analytics

We use Vercel Analytics on public informational pages to understand how the site is performing. It is not loaded on case, clinician, letter, saved-draft, resume-link, or denial-document routes. A separate fail-closed filter also blocks events whenever the current or reported URL contains a case or access credential. We do not use third-party advertising cookies. Where access to the site is gated, we may set a single authentication cookie to remember that your browser is authorized; that cookie holds no personal information and expires after 30 days. If you track a case, we set a similar cookie remembering that this browser has confirmed access to that case; it holds no personal information and expires after 180 days. A drafting-answer recovery link uses a separate content-free trusted-device cookie that expires with the seven-day recovery copy.

Web Analytics and hosting logs are different. Vercel hosts the application and therefore receives every requested route and API call, including sensitive-route URLs. Parity suppresses Web Analytics on those routes and strips bearer and record identifiers from its own application log messages; Vercel's infrastructure-level request data follows the hosting account's retention and configuration.

We also collect a few points of generalized, anonymous usage statistics, like how many visitors reach the results step and which denial categories are most common, to understand what helps people most and to keep improving Parity. These are plain aggregate counters: never your name, never your story, no free text, no IP addresses, nothing that can be linked to you.

Your choices

Clearing your browser's site storage for parity.care wipes any saved letters in localStorage and any in-progress Path Finder answers in localStorage on your device. Your letter draft on our servers auto-deletes on its own within 7 days, whether or not you clear anything locally. If you requested a finish-later link after a failed draft, it can restore the exact encrypted drafting payload during the remainder of its original seven-day window; a new device must confirm the receiving email, and the visit does not extend retention or reset the retry count. If you opened a packet, the emailed private case link can recover that server packet during the remainder of its 7-day window after you verify the recovery email on the new device. After that window, only the content-minimized case metadata remains; local edits and downloads that were never saved elsewhere cannot be reconstructed. As described above, packet deletion is deletion from the live application store; provider backups age out separately.

Want it gone sooner? Email hello@parity.care with your preview ID (shown on your letter page) and we'll delete your live draft and matching support trace by hand, ahead of their automatic expiry.

Contact

Questions about privacy can go to hello@parity.care.