Kestrel check
Effective August 5, 2026
The one thing that matters most: your billing file is read inside your own browser. Patient names, member IDs, and the file itself never reach Kestrel's servers. What we receive is a short list of billing codes and numbers, and we don't store even those — only counts.
This policy describes how the operator of Kestrel ("Kestrel", "we") handles information in Kestrel Check, the web tool at this site. The Kestrel iOS app is covered by its own policy.
When you drop a file:
| Information | Why | Kept |
|---|---|---|
| Email address | To sign you in and identify your account. Sign-in uses a one-time emailed code; we never handle a password. | Until you delete your account |
| Organization name, membership, role | So an owner can see their team's totals | Until deleted |
| Check records: time, number of lines, verdict and cause counts, payer ids, states, file type (CSV/Excel/837), whether column mapping came from memory or AI, count of auto-fixable findings, processing time | Your history, your organization's totals, our own service metrics | Currently retained; see §7 |
| Ask/chat questions (iOS app feature) | Answer quality and abuse prevention, with a filter that blocks messages containing patient details before they are processed or stored | See iOS policy |
| Technical logs: request paths, status codes, timing, and a hashed IP address | Security, rate limiting, debugging | Short-term |
We do not collect names, addresses, phone numbers, dates of birth, payment card details (Apple handles any subscription billing), precise location, or advertising identifiers. We do not use tracking cookies, advertising pixels, or third-party analytics. Your column mappings and preferences are stored in your own browser's local storage, not on our servers.
We process the limited information above to perform the service you request and for our legitimate interest in operating, securing, and improving it. Because Kestrel Check is designed not to receive protected health information, we do not act as a HIPAA business associate for this workflow and no business associate agreement is in place — see the compliance page.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We use a small number of service providers, each processing only what their function requires:
| Provider | Function | What it sees |
|---|---|---|
| Render | Application hosting | Requests to the service, hashed IPs |
| Supabase | Database and authentication | Email address, account records, check counts |
| Anthropic | AI for column mapping, pattern review, and rule extraction | Column header names, payer company names, and de-identified code lines with relative day numbers instead of dates; never names, keys, or files. Anthropic does not train on API data. |
| Apple | iOS subscriptions and Sign in with Apple | Handled by Apple; we never receive payment details |
We may also disclose information if legally required, to protect our rights or users' safety, or in connection with a merger or asset sale — in which case this policy continues to apply until superseded with notice.
Data is encrypted in transit. Database tables are restricted to the application's own credentials and are not reachable through any public data API. Administrative functions require an account explicitly authorized for them, and privileged actions are recorded with the actor's identity. We follow a least-data principle: the surest way to protect information is not to collect it, which is why the checking workflow is built to leave patient data on your device.
Files and claim lines are never retained, because they never arrive. Account records last until you ask us to delete them. Check records are aggregate counts and are currently retained to power your history and your organization's totals; we may adopt a fixed retention window and will describe it here if we do. Email kestrelaba@gmail.com to delete your account and associated records; we will act within 30 days.
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to opt out of sale or sharing (we do neither), and to be free from discrimination for exercising these rights. California residents have these rights under the CCPA as amended by the CPRA; residents of other states and countries may have comparable rights. Make a request at kestrelaba@gmail.com from your account email and we will verify and respond within the time the law allows.
Kestrel Check is a business tool for adults and is not directed to children. We do not knowingly collect information from anyone under 18, and the service is designed so that information about the children our users serve never reaches us at all.
The Service is operated in the United States and information is processed there. If you use it from another country, you understand that processing occurs in the United States under United States law.
We will update this policy as the service changes; the effective date above will change and material updates will be noted in the service. Continued use after an update means you accept it.
We measure how the website itself is used in two ways. First, our own servers record page views, sign-ins, and which features get exercised — with an ephemeral per-tab session id (no cookies), referrers reduced to their domain, and IP addresses only as keyed hashes. Second, we use Google Analytics for aggregate traffic measurement (visits, acquisition sources, device types), configured with advertising personalization disabled and with all URL query strings stripped before anything is sent.
What analytics never receives, from either rail: billing data, claim lines, patient information of any kind, organization names or invite codes, email addresses, or account identifiers. Your billing files are parsed on your device and are not part of any analytics stream. Usage data is never sold.