BillInsight
← Legal

Privacy Policy

⚠️ This document contains [To be confirmed by client] fields (e.g. governing state/court, arbitration clause) that must be finalized by legal before launch. Please confirm before going live.

Effective Date: 2026-06-30 · Version: 1.0.0 · App Name: BillInsight · Company: Jorion Inc. · Registered Address: 2004 Brockwell Ave, Monterey Park, CA, USA · Contact Email: privacy1@jovimastery.com · Privacy Contact: Privacy Officer

1. Overview

This Privacy Policy explains how Jorion Inc. and its affiliates (collectively, "we," "us," or "our") collect, use, disclose, store, retain, and otherwise process information in connection with your use of BillInsight. We take your privacy seriously and are committed to handling information in a manner that is lawful, fair, transparent, and limited to the purposes described in this Policy, subject to applicable law and platform requirements.

BillInsight is designed to help users review medical billing information, including CPT codes, related diagnosis and procedure codes, fee-range analysis, pattern-based matching observations, and report generation. We do not use your information for purposes unrelated to providing and improving these services unless we have a lawful basis to do so or you have expressly authorized it.

2. Scope and Definitions

For purposes of this Policy:

  • "Personal Information" means information that identifies, relates to, describes, or can reasonably be linked to you or your household.
  • "Sensitive Information" includes, where applicable, health-related information, medical billing records, insurance information, diagnosis codes, procedure codes, and similar data that may be considered sensitive under applicable law.
  • "Billing Data" means information you submit, upload, import, or authorize us to access in connection with medical billing review, reconciliation, or analysis.
  • "Service Data" means reports, flags, labels, scores, audit logs, and other outputs generated through your use of the App.
  • "Service Providers" means third parties that process information on our behalf to support hosting, authentication, analytics, messaging, customer support, security, or related functions.

This Policy applies to users located in the United States and to any use of the App within the United States. To the extent applicable law provides you with greater protection than this Policy, that law will control.

3. Information We Collect

3.1 Information You Provide

We may collect information that you submit directly to us, including:

  • Account details such as your name, email address, phone number, or other identifiers;
  • Medical bills, statements, EOBs, receipts, PDFs, images, scans, or other uploaded documents;
  • CPT codes, ICD-10 codes, HCPCS codes, billed amounts, dates of service, item descriptions, quantities, provider names, payer information, and related notes;
  • Comments, annotations, tags, feedback, or dispute-related notes that you add in the App;
  • Messages or attachments you send to customer support or review personnel.

3.2 Information Collected Automatically

When you use the App, we may automatically collect certain information, such as:

  • Device model, operating system version, app version, and language preferences;
  • IP address, access times, crash logs, diagnostic data, and performance metrics;
  • Login status, session duration, feature usage, and error events;
  • Basic technical information necessary for authentication, security, fraud prevention, and service integrity.

3.3 Information Received Through Authorized Integrations

If you choose to connect a third-party service or enable an import feature, we may receive information from that source based on your authorization. This may include files or records from cloud storage, document systems, or other services you elect to connect. We will process such information only to the extent needed to provide the features you requested.

4. How We Use Information

We use information for the following purposes:

  • To provide billing review, classification, comparison, explanation, and report-generation features;
  • To estimate fee ranges, relative distribution position, and statistical deviation for CPT codes;
  • To observe patterns between CPT codes and diagnosis codes, procedure codes, or other related codes;
  • To flag duplicate items, uncommon combinations, notable price deviations, or other entries that may warrant human review;
  • To maintain your report history, export history, and account settings;
  • To respond to support requests, technical inquiries, and rights requests;
  • To maintain security, prevent fraud and misuse, and detect unauthorized access or abnormal activity;
  • To improve product performance, model quality, usability, and reliability, subject to applicable law and any required consent.

5. Legal Basis and Consent

Where required by applicable law, we will process Personal Information only where we have a valid legal basis to do so, including:

  • Your consent;
  • Performance of a contract with you;
  • Compliance with a legal obligation;
  • Protection of our rights or the rights of others;
  • Other bases permitted by applicable law.

Where we process Sensitive Information, we generally apply heightened safeguards and, where required, obtain your explicit consent or separate authorization.

6. Disclosure of Information

We do not sell your Personal Information. Except as described below, we do not disclose your Billing Data or Sensitive Information to third parties:

  • At your direction: for example, when you export or share a report with a hospital, insurer, family member, attorney, consultant, or another recipient you designate;
  • Service Providers: to vendors that help us operate the App, subject to contractual confidentiality and security obligations;
  • Legal requirements: where disclosure is required or permitted by law, regulation, court order, subpoena, or other valid legal process;
  • Business transfers: in connection with a merger, acquisition, restructuring, financing, or sale of assets, provided that the recipient is bound by privacy and security obligations no less protective than those stated here.

Where we share information with third parties, we require them to use it only for the limited purposes for which it was disclosed and to protect it using appropriate safeguards.

7. Health-Related Information

The App may process information relating to medical billing, diagnoses, procedures, insurance claims, appointments, test items, and other health-related content. We generally treat such information as Sensitive Information and apply additional access controls, encryption, logging, and role-based restrictions as appropriate.

Where such information may be subject to special protections under applicable law, we will provide the notices, choices, access rights, deletion rights, or processing restrictions required by law.

7.1 HIPAA Notice

Unless we are acting in a capacity that makes HIPAA applicable to a particular data set, the App itself does not automatically mean that all data you submit is governed by HIPAA. In certain use cases, billing records or health-related information you upload may still be highly sensitive, and we will handle such information in accordance with this Policy and applicable law.

If we ever process HIPAA-regulated information in a specific business arrangement, we will do so under appropriate contractual and technical safeguards and only for authorized purposes.

8. California and Other State Privacy Rights

To the extent provided by applicable U.S. state law, you may have rights to:

  • Know what Personal Information we collect, use, disclose, or share;
  • Access your Personal Information;
  • Correct inaccurate information;
  • Delete certain Personal Information;
  • Limit certain uses of Sensitive Information;
  • Opt out of certain processing activities;
  • Be free from discriminatory treatment for exercising your privacy rights.

We will respond to verified requests in accordance with applicable law. We may decline a request, in whole or in part, where verification fails, where we must retain information for legal or security reasons, or where the request would adversely affect the rights of another person.

8.1 California Residents

If you are a California resident, you may have additional rights under the California Consumer Privacy Act, as amended, including the right to know, delete, correct, and limit the use of Sensitive Personal Information, and the right to opt out of the "sale" or "sharing" of Personal Information where applicable.

We do not sell Personal Information for monetary consideration. If we ever engage in practices that constitute "sharing" or "selling" under California law, we will provide the notices and mechanisms required by law. You may also use an authorized agent to submit a request, subject to verification requirements.

9. Data Retention

We retain information only for as long as reasonably necessary to fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, enforce agreements, maintain security, or otherwise protect our legitimate interests. When information is no longer required, we will delete it, anonymize it, or de-identify it in accordance with applicable law and our internal retention practices, unless retention is required by law.

10. Data Security

We implement reasonable administrative, technical, and organizational measures designed to protect your information, including:

  • Encryption in transit;
  • Encryption at rest or comparable safeguards;
  • Access controls and authentication;
  • Least-privilege permissions;
  • Logging and anomaly detection;
  • Periodic security review and remediation.

No system can be guaranteed to be completely secure. Accordingly, while we strive to protect your information, we cannot promise absolute security or that unauthorized access will never occur.

11. Children's Privacy

The App is not directed to children under 13, and we do not knowingly collect Personal Information from children under 13. If we learn that we have inadvertently collected such information, we will delete it as soon as reasonably practicable unless retention is required by law.

12. Third-Party Services

The App may contain links to, or integrate with, third-party services such as cloud storage, authentication providers, analytics tools, payment processors, or customer support systems. Those third parties are governed by their own privacy policies. We encourage you to review their privacy practices before using such services. We are not responsible for the privacy practices of third-party websites or services that we do not control.

13. Cross-Border Transfers

If your information is transferred to, stored in, or processed by service providers located outside the United States, we will take reasonable steps to ensure that such service providers are subject to appropriate confidentiality and data protection obligations. You understand that data protection laws may differ across jurisdictions, but we will endeavor to maintain protections consistent with this Policy.

14. Electronic Communications

You consent to receive service-related communications from us electronically, including notices, verification messages, account alerts, policy updates, billing-analysis notifications, and security-related messages. Where consent is required for particular communications, we will obtain it as required by law. You may be able to manage certain notification preferences in your account settings, though some essential security communications may not be disabled.

15. Automated Processing and Model Outputs

The App may use automated tools or models to identify, classify, score, or flag billing-related information. You understand that model outputs are provided for informational and assistance purposes only and are not intended to constitute final billing determinations, clinical advice, insurance coverage decisions, or legal conclusions. For matters that may affect your rights or obligations, you should review the underlying documents and seek human review where appropriate.

16. Legal Requests and Government Access

We may disclose information in response to a subpoena, court order, governmental request, or other legal process where required or permitted by law. Where lawful and appropriate, we will review the scope and validity of such requests and seek to disclose only the minimum information necessary. If permitted by law, we may notify you before disclosure, unless prohibited from doing so.

17. Policy Changes

We may update this Privacy Policy from time to time to reflect legal, operational, or technical changes. If we make material changes, we will provide notice through the App, by email, or by other reasonable means. The revised Policy will take effect on the date stated in the updated version, unless otherwise indicated.

18. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

  • Email: privacy1@jovimastery.com
  • Address: 2004 Brockwell Ave, Monterey Park, CA, USA
  • Privacy Contact: Privacy Officer