Your data

Privacy Policy

Last updated June 21, 2026

The short version: Merits is built so a patient’s identity never reaches our servers. Here’s exactly how.

The design, in one line

The patient’s name, member ID, date of birth, and address are removed in your browser before any text is sent to us, and they’re filled back into the finished letter on your own device when you download it. The model that drafts the letter never sees who the patient is.

What you give us

To draft an appeal you provide the text of the denial you received (an EOB or remittance) plus answers to a few clinical questions. You also enter your own practice details for the letterhead, and your email so you can come back to your appeals.

How de-identification works

When you add a denial, your browser detects the direct patient identifiers — name, member ID, date of birth, address — and replaces them with placeholders before anything leaves your device. Only that de-identified text is sent for processing. At download, the placeholders are refilled with the real details locally.

No automated de-identification is perfect, which is why you also review every field and the full letter before it’s generated and before you download it. If you ever see a real detail that should have been masked, you can fix it on the spot.

What we store — and delete

We store the de-identified case data needed to produce and re-open your appeal, your generated letter, your email, and your practice/letterhead details. The original denial file you upload is deleted from storage after the letter is generated. We never store a patient’s identity, because it never reaches us.

What we never do

We don’t sell your data. We don’t put patient information into payment records or any third-party metadata. We don’t email the appeal letter — it stays on your device so the sensitive content isn’t sitting in an inbox.

Third parties we use

We rely on a small set of vetted providers to run the service: an AI infrastructure provider (drafts the letter from the de-identified text), a database provider, an email delivery provider (sign-in and account emails — no clinical content), a hosting provider, and Stripe (payment — no patient data is shared with it). Each operates under agreements that limit it to only what it needs, and none ever receives a patient’s identity.

Analytics and cookies

We use minimal product analytics to understand which pages are used and to catch errors. Automatic capture of page content and session replay are turned off, so we don’t record what you type. We use only the cookies needed to keep you signed in.

Your choices and contact

You can ask what we hold for your account, or ask us to delete it, at [email protected]. For how the service may and may not be used, see the Terms of Service.

Changes

If this policy changes, the “last updated” date above will change with it. Material changes will be reflected here before they take effect.