Data handling & security
This page summarizes how the ClaimSaver+ application handles information you provide. It is general information, not legal advice, and does not replace any contract or policy you agree to when using the service.
HIPAA scope — no certification claimed
Many users upload health- and accident-related documents. ClaimSaver+ is built as claim-preparation software for consumers. We do not operate as your health care provider or health plan under HIPAA, and we do not claim to be a HIPAA business associate for routine platform use. We do not display or rely on a third-party HIPAA “certification” badge. If you are a regulated entity that requires a Business Associate Agreement, contact us before using the platform for regulated workflows.
What we collect and store
We collect account information you provide, claim form fields you enter, calendar and expense entries you create, and files you upload. Uploads can include police or crash reports, medical records and bills, insurance cards or declarations pages, photos, and similar evidence. Operational logs may include IP address, device type, and timestamps for security and troubleshooting.
Encryption and storage
Traffic between your browser and our services uses TLS (HTTPS). The public website is hosted by Vercel. Uploaded files and application data are stored using our database and object storage providers (Supabase), which apply industry-standard encryption for data at rest. We do not describe this as “bank-level encryption.”
Payments (Stripe)
Card payments are processed by Stripe. We do not store full card numbers on ClaimSaver+ servers for hosted Checkout flows.
Accounts and authentication
Sign-in uses Supabase Auth. We recommend strong passwords and enabling MFA when available.
Email and domain mail policy
Platform support is support@claimsaverplus.com. Transactional account messages are sent from our claimsaverplus.com domain.
Retention and deletion
We keep account, worksheet, and uploaded files while your account is open. Signed-in customers can request deletion from the dashboard; we also accept email to support@claimsaverplus.com. After a verified deletion request or account closure (and any legal hold), we aim to delete or de-identify customer content within 30 days. Backups may persist on a longer rotation until they expire. We keep payment, tax, fraud, dispute, and legal-compliance records as required (typically up to seven years). Florida Statutes §501.171 may require notice of a personal-information breach. See the Privacy Policy for subprocessors, deletion requests, and breach-notice details.
Contact
Questions about this summary: support@claimsaverplus.com.

