Privacy

Privacy Policy

Last updated September 23, 2026

No accountServer drafts auto-delete in 7 days; downloads are yoursAutomated citation checks, not legal review

Overview

Parity is a self-help document-preparation tool for mental-health insurance denials. Access to the beta may be gated by a shared site password. Private case links always have their own access checks. The current beta drafts in English.

The short version

Requesting a draft sends your drafting answers and story text to Parity and Anthropic. Names or IDs included in drafting text can reach Anthropic. Parity tries to replace detected identifiers with blanks, but detection can miss them, so leave them out and check your draft. Name and member-ID fill-ins are completed on your device. Parity keeps an encrypted recovery copy of the validated drafting request for up to 7 days from the first request, and a generated packet for up to 7 days from generation. A tracked case has a separate, rolling 12-month clock. Email, support records, backups, and processors have separate retention rules below. We never sell your data.

What we collect

  • Your structured Path Finder answers are saved in this browser so you can resume. Before you request a draft, drafting text is kept in browser session storage while you work. Limited category and usage counters can be sent while you use the site; they do not contain your story. A draft request sends the validated drafting answers and creates the encrypted recovery record described below.
  • The exact-plan mailing-address check runs on your device, and the raw plan name, document or form code, administrator name, and group number you type for that check are not sent to Parity or Anthropic.
  • Your optional clinical summary and personal impact story can contain sensitive information. We do not pre-redact those fields before sending the drafting request to Anthropic. Leave names, member IDs, and other identifying details out of those boxes. Optional polishing and denial-text extraction also send the text you submit to Anthropic.
  • Vercel receives web requests, including IP addresses, browser information, timestamps, and requested URLs. Hosting logs and Web Analytics have different rules, explained below.

We do not require an account. Opening a code-access packet requires an email address; after the access code is verified, Parity attaches it to the recovery case and attempts to email the private link. This required recovery email does not enroll you in reminders or marketing. Delivery can fail, so keep the private link shown on the access screen. If you use "Email letter to me," Resend receives the recipient address and the document you ask us to send, including any supplied PDF attachment.

If an AI draft fails, you can separately request a finish-later email. Parity does not send it automatically. It contains a private link and instructions, not your drafting answers. The recovery record keeps a keyed digest of the receiving email for confirmation on an unfamiliar device.

The feedback form accepts optional name and email fields and required feedback text. When delivery is available, that submission goes through Resend to hello@parity.care. Feedback and ordinary support emails can remain in the inbox until manually deleted; there is no automatic inbox deletion period. Do not include health details, member IDs, documents, or private case links in feedback or ordinary email.

Information about minors. Parity is intended for adults. A parent or legal guardian may provide information about a child when preparing a filing for them. That information follows the same processing and retention rules as other drafting information. The service is not intended to collect information directly from children.

What we keep

  • Temporary drafting-answer recovery. A validated draft request creates an encrypted IntakeRecoveryRecord in Upstash Redis. The encrypted payload contains the validated drafting answers, including any story text. It has a hard 7-day lifetime from the first request; retries, resume visits, and email sends cannot extend it. A private signed token locates it. The original browser receives a trusted-device cookie; an unfamiliar device must confirm the receiving email before the answers are returned. A retry counter follows that answer set across devices.
  • Letter drafts. We hold the generated packet and supporting drafting material, including story text, source facts, and review information, in Upstash Redis under a random preview ID for up to 7 days. This supports the preview-then-code flow. A new packet has its own seven-day window. Opening a case does not renew a packet. Download a copy you want to keep.
  • Generation support traces. Separate records keep the generation time, document kind, governing track, plan-funding category, recommended filing, and generation or recovery mode. Attempt records also keep progress, outcome, and a failure category. Each trace expires 90 days after its last write. Its key is a pseudonymous derivative of the preview or support reference. These records exclude document bodies, story text, email addresses, insurer, treatment, and denial category.
  • No payment in this mode. Parity collects no payment details and makes no Stripe payment request when you open a free packet. The Stripe payment integration remains in the product for paid offers.
  • Free-launch access code. A code is submitted with your preview ID and recovery email. We do not persist the raw code. The server registry holds an opaque code ID, purpose, and keyed digest. Claim records hold keyed code and preview/email bindings, a redemption time, and the reserved case binding for up to 397 days. These individual access codes are single-use. Each claim is bound to its packet and case. The case stores the code ID and purpose with its free-access permission under the rolling 12-month case clock. Case deletion removes the live claim binding and can leave a content-free consumed-claim marker for the remaining claim window. Removing an unused code stops its claim; it does not erase access already granted to a case.
  • Notify-me list. We store your email, source screen, signup time, and any state or country you selected so we can contact you about availability. New records expire within 365 days of signup or resubmission. List membership may expire earlier. Another person joining does not extend your record.
  • Law-update newsletter. This is a separate opt-in list. Email, source, and signup metadata expire within 365 days of signup or resubmission. List membership may expire earlier. Unsubscribing removes membership and creates the suppression record described below; remaining signup metadata follows its existing expiry.
  • Saved drafting answers. After you request a draft, this browser also saves up to six complete sets of drafting answers, including any story text, for a seven-day availability window. These local copies can survive closing the tab. Expired copies are removed when the app next checks them; a closed browser does not run timed deletion.
  • Saved letters. My Drafts keeps up to 30 entries in this browser, with a seven-day availability window for each version. It is not a synced account. Browser storage is cleaned when the application next checks it, or when you clear it; closed browsers do not run timed deletion. Files you download remain wherever you save them.
  • Rate limits. New abuse-prevention counters use keyed derivatives of IP addresses. Ordinary request limits are usually hourly; generation counters can remain for two days, and recovery retry counters can remain for the seven-day recovery window. Free generation has a per-connection allowance, a site-wide daily cap, and an operator pause control. These are availability controls, not a guarantee that every request will produce a draft.
  • Operational records. A preview-linked purchase-status marker lasts 30 days. We also save the first successful export-preparation time in your case under its case retention clock. These operational records are separate from our identifier-free aggregate counts.
  • Tracked cases. Case metadata and recovery email are kept for 12 months after the last member-initiated access or saved update. Opening or updating the case renews that period. The case can outlive every packet associated with it.
  • Optional case check-ins. Email alone does not enroll you. A separate opt-in stages 30- and 60-day check-ins with your email and private link. The schedule expires within 90 days of its last write and is removed when you turn check-ins off or successfully delete the case. Sending depends on the reminder-email setting.
  • Email suppression. An unsubscribe stores a keyed digest of the normalized email and its list category for up to 10 years from that request so reminders or newsletter mail can stay stopped. A later unsubscribe renews that period. Older suppression keys can still contain the raw email until they are migrated. Access and recovery emails, receipts, and a one-off letter email you request are separate and are not stopped by this opt-out. Joining a list again does not automatically clear suppression. Contact us if you want it reviewed.

Direct later-filing statements can be held in this browser session without a separate server packet copy. A later filing prepared through the packet drafting flow has the packet's separate seven-day server window.

Older records and backups. These automatic expiry rules apply to records written under the current rules. Older mailing-list entries, unsubscribe records, and retired generation or reminder lists may require manual cleanup. Deleting a live record does not delete existing backup or export files. Parity can make operator-held backups and mailing-list exports; those files do not inherit Redis expiry. The backup runbook calls for pruning backups after 90 days, but that is an operator procedure, not an automatic deletion guarantee. Provider backup and log windows depend on account settings; we cannot promise a single deletion date across those copies.

Who processes what:

  • Anthropic receives the inputs needed for the AI action you request and generates the output. See AI processing below.
  • Upstash holds the application records described here. The drafting-recovery payload is encrypted by Parity before storage; other records are not all encrypted by Parity at the application level. Opaque lookup indexes and aggregate counters can remain after the underlying content expires.
  • Resend receives recipients, subjects, message bodies, private links, and any attachments for emails the product sends. Its retention is separate from Parity's live-store expiry. See Resend's security and retention information; plan settings and account terms can change the window.
  • Vercel hosts pages and API requests, including sensitive URLs and private-link tokens. Application diagnostics include event types, timing, failure classes, and some email-delivery diagnostics such as the recipient domain. Hosting and runtime logs have their own retention settings. Web Analytics exclusions do not prevent hosting from receiving a request.
  • Support inbox and email infrastructure. Feedback forwarded to hello@parity.care also reaches the inbox provider, currently iCloud Mail. Domain authentication uses SPF, DKIM, and DMARC; these are delivery and anti-spoofing controls, not end-to-end encryption. DMARC reports can contain sending-server and authentication information. They do not give Parity a way to erase a delivered message from a recipient's mailbox.

AI processing

Parity uses Anthropic's commercial API for AI drafts, optional statement polishing, and denial-text extraction.

  • What gets sent. A drafting request can include routing answers, your clinical summary, and your impact story. Polishing sends the statement and relevant context. Extraction sends the denial text you submit. Later filings can use stored drafting material or details you provide again.
  • Anthropic's retention. Its published standard API policy says inputs and outputs are deleted within 30 days, with exceptions for different agreements or services, safety and usage-policy enforcement, and legal obligations. Flagged inputs and outputs may be retained for up to two years, with safety classifications retained longer. Parity does not promise zero retention at Anthropic. See Anthropic's commercial data-retention policy.
  • Model training. Anthropic says commercial inputs and outputs are not used for training by default; feedback or an explicit opt-in can change that. See its training policy and commercial terms.
  • Parity's retention. The packet and encrypted drafting-answer recovery record have separate seven-day windows in our live application store. Cases, diagnostics, emails, backups, and processor copies follow the separate rules above.

AI drafts pass automated release checks, including citation checks against official-source material. A document labelled as a no-AI fill-in uses software rules and marks missing details as blanks. Neither path is an attorney review.

What we do not do

  • We do not sell your data or share it with advertisers or data brokers.
  • Parity does not submit your filing to an insurer or regulator for you.
  • We do not use your clinical summary, impact story, or draft content for marketing.
  • Name and member-ID fill-ins and ordinary local full-text edits stay in your browser. Filled and edited downloads are generated on your device. Typing, blur, and restoring the original do not send those edits to Parity. If you request an email, the document submitted for that send goes through Parity to Resend. Check what you are sending; email copies follow different retention rules.
  • Edited text is not automatically citation-verified. A new drafting or review request can send the submitted text to Parity again.

HIPAA, plainly

Parity is designed as a tool you choose and use for yourself, not as a service acting for your doctor or insurer. We therefore do not present Parity as a HIPAA-covered medical-record system. That does not make the information unimportant: clinical drafts are sensitive, so we minimize them, apply a seven-day expiry to live packet records, separate the longer-lived case record from the clinical narrative, and disclose each processor above. HIPAA obligations can depend on relationships and contracts, so this description is about Parity's current product role, not a promise that privacy law can never apply.

If you use a clinician link, Parity stores the request context described below, but the clinician's completed medical-necessity letter still travels directly between you and the clinician. The clinician page has no file-transfer or reply channel for sending that finished document to Parity.

Clinician links

Creating a clinician link requires a separate unchecked consent box that lists exactly what the clinician will see. Parity stores the treatment category, denial category, filing type, creation and expiration times, the consent version, and an optional patient first name only if you choose to add one. That context is stored in Upstash under a random link token and expires after 30 days. The private URL itself is the access key, so treat it like a password. The page does not contain your drafted appeal, clinical summary, member ID, or a way for the clinician to send a completed letter back to Parity. The creator receives a separate management secret and can revoke the link immediately from the same browser.

Opening, founder-help, and contact messages

The opening and founder-help interest lists are separate. Founder-help records contain your email, source, and signup time. New records expire within 540 days (about 18 months) of signup or resubmission; list membership may expire earlier. Another signup does not prolong older membership. Use the removal button after joining or contact hello@parity.care from the address you want removed. Do not include health information.

The Support contact form stores your email, category, submission time, status, and message in Redis for 90 days. An authenticated founder console can read it. When email delivery is enabled, an operator alert sends a short reference, category, and timestamp through Resend to hello@parity.care; that alert excludes your address and message. Feedback forwarding is different: it sends the submitted feedback itself. Support is not a continuously monitored emergency service, and an alert does not guarantee a response time.

Case pages (included with a packet; optional in the free flow)

A case has a private link such as parity.care/my-case/<token>. There is no account password. An unfamiliar browser must also confirm the saved email or, for a case without an email, its denial date. Keep the link private. Opening a packet creates a recovery case and attempts delivery of the link to your recovery email; a failed email does not necessarily mean the case was not created.

The case stores insurer, treatment and denial categories, routing and filing role, event dates, stage checklist, outcome, optional authorization/reference number, packet identifiers, access grants, and email if provided or required for packet recovery. It also stores separate choices for check-ins, aggregate sharing, and testimonial contact. It does not store your letter body or clinical summary. Those belong to the separate seven-day drafting records. The case lasts 12 months after the last member-initiated access or saved update. Opening or updating the case renews that period.

Lost-link recovery uses a keyed email-to-case index. A recovery request gives the same browser response whether or not a match exists. Any link is sent to the stored case email and still requires the unfamiliar-device check. The index is refreshed with case access or updates and removed for that case on deletion. Access emails depend on the transactional-email setting and provider availability.

Delete this case removes the case and its reminder/check-in schedules from the live application store when deletion succeeds. The case link then stops working. The deletion path also removes the live recovery binding and withdraws an aggregate contribution if its contribution marker still exists. Content-free consumed-entitlement markers can remain for up to 12 months; code-claim markers have the separate window above. Deleting a case does not also delete its separately stored packet, a clinician link, an email, a download, a suppression record, or a backup. Those copies follow their own expiry or deletion paths.

Optional product feedback

After an export or on your private case page, we may ask whether Parity was useful, whether anything seemed wrong, whether you sent your filing, and what could be clearer. These questions are optional. Before you share answers, we explain that we add the selected choices to internal totals without keeping a response linked to your case. We keep these new totals in monthly groups that expire no later than 90 days after the start of that month. We cannot identify and remove an individual answer once it has been added. You can skip the questions or stop answering at any time. These totals are separate from your private case and its separately optional, withdrawable outcome contribution.

These short questions do not accept names, email addresses, health details, documents, or written comments. If you choose to email support@parity.care instead, your email reaches our support inbox and follows the email retention rules above. Please leave health details and private case links out of ordinary email. Requests to our website still pass through our hosting provider, as explained above.

Outcome check-ins and anonymous aggregates

If you separately opt in and sending is enabled, we may email two case check-ins at about 30 and 60 days after your case was created. These are optional check-ins, not deadline reminders. Opening a link does not record an answer. You can turn check-ins off on your case page or use the unsubscribe link without losing case access. The case page asks for the relevant event before an outcome can be recorded.

A separate unchecked choice lets you contribute an outcome to aggregate counters. A keyed, pseudonymous contribution marker records the outcome category for up to 365 days from its last write, allowing corrections or withdrawal while the marker exists. The aggregate counters contain no email or story and have no automatic expiry. After a marker expires, its old count cannot be tied back to your case for removal. The private outcome remains in the case under the case clock. Aggregate sharing and testimonial contact are separate choices; permission to contact you is not permission to publish a testimonial. These counters are currently used internally.

Paste-to-prefill (Start With Your Letter)

When the paste-to-prefill feature is available, the denial text you submit goes to Parity and Anthropic for extraction of proposed facts. You review those facts before using them. The extraction route does not write the source text to Redis or disk; processing happens in request memory. Facts you confirm can become browser answers and enter later drafting records. Anthropic's retention applies to the extraction request.

The paste page does not accept files. A separate PDF endpoint requires both its feature switch and a current processor-review setting. If enabled, Parity extracts text from PDF bytes and sends that text to Anthropic; it does not send the PDF itself or return the raw extracted PDF text to the browser.

Cookies and analytics

Vercel Analytics runs on allowed public pages. Case, clinician, letter, packet-opening, saved-draft, resume-link, and denial-document routes are excluded. A separate URL filter blocks known case and access credentials. Hosting still receives those requests and URLs. We do not use third-party advertising cookies.

Access to the beta may be gated by a shared site password and its access cookie. Private case links always have their own access checks. Private-case verification uses a signed cookie with a 180-day lifetime; drafting recovery uses a trusted-device cookie limited to the recovery window. These are access credentials even though they contain no story or email. Clearing local data does not revoke copies of a private link held elsewhere.

First-party usage statistics store category counts, including routing, outcomes where opted in, and generation progress or failure counts. Monthly product and generation counters have roughly two-year expiry windows; some lifetime totals and state-interest counts have no automatic expiry. These aggregate counters do not contain your story or email. Separate operational and access records can still be associated with a case or request, as described above.

To find problems and improve Parity, we keep daily aggregate counts of draft results by document type, filing route and regulator, requested urgency, software version, automated checks and repairs, rough letter length, number of requests, device category, drafting time, and export format. These content-free counts contain no letter text, names, contact details, IP addresses, or case identifiers, and expire within 90 days; our existing monthly totals follow the retention periods above.

Your choices

Separate identity fill-ins, local text edits and preferences may remain until you clear them. The clear-data button removes Parity local and session storage; it does not clear access cookies, revoke private links or delete downloaded files.

Use the button below or your browser's site-data controls to clear saved Parity data on this device. This does not delete server records, emails, downloads, or backups. My Drafts and local edits are not synced to an account.

A finish-later link requested after a failed draft can restore the encrypted drafting answers during the remaining original seven-day window. An unfamiliar device must confirm the receiving email. A packet's private case link can recover its server copy during that packet's seven-day window after case verification. You do not need to enter an individual access code again to recover a case that already has access. After packet expiry, the case metadata can remain; a new draft requires another drafting action and may need fresh answers.

To request deletion before automatic expiry, email hello@parity.care with the preview or support reference shown by the product. Do not send clinical text or a private access link. We may need to confirm which record is yours. Manual requests do not automatically erase delivered emails, downloads, or existing backups.

Contact

Questions about privacy can go to hello@parity.care.