Privacy policy
Draft — not yet reviewed by counsel.

Privacy Policy

Last updated: 2026-09-01 (draft)

Searching without an account

You can search for facility prices, insurance plans, and coverage options without creating an account. Nothing about your search is required to identify you.

Accounts and sign-in

If you create an account, we authenticate you with a signed token (JWT) stored in an httpOnly cookie — a cookie your browser holds but that page scripts cannot read. The session stays valid for 7 days before you need to sign in again.

Pricing-estimate logging

We may keep a server-side log of pricing estimates for observability — to understand whether the estimates we're showing are accurate and useful. This logging is optional and controlled by a deployment setting (ENABLE_ESTIMATE_LOGGING); when it is on, we salt and hash any session identifier before it is stored, so the log entry cannot be reversed back to your session.

Consumer health records

If you use an account, you can choose to save estimates, procedure-price watches, insurance claim facts, denial notes, service dates, claim numbers, and HSA/FSA balances. These records can reveal health and financial activity even when they do not contain a diagnosis. Claim rows can be deleted individually. Whole-account deletion is not self-serve yet, and we have not ratified a universal retention or backup-deletion schedule; the Settings page states the available request channel honestly.

Bills and EOB documents

Rede does not currently accept, store, or send real bill or Explanation of Benefits document files to an AI processor. The bill checker receives only the line facts you type for that request; application code has no bill-document table or object store.

AI and external services

Text entered into AI chat, symptom guidance, or letter-polishing features is sent to OpenAI only in deployments configured for an executed health-data agreement and an approved API retention mode. Each input names the vendor before you submit. Letter flows remove the patient name and claim/account number first, but procedure, provider or insurer, date, and amount details may remain, so the call is not described as anonymous. Web-search text is sent to SerpAPI. Google Maps/Places receives location searches when Maps is enabled, but not the procedure, plan, or computed price held in Rede's search state. Optional distributed rate limiting sends only HMAC-pseudonymized limiter keys to Upstash, not raw account IDs or IP-address keys.

Coverage-options answers

The Coverage Options tool asks questions to help you find a coverage pathway, including about immigration status. Those answers are never sent to our servers — by design, the page makes no network requests, writes nothing to cookies or browser storage, and puts nothing in the URL. Your answers live only in your browser's memory for that page visit, and are gone the moment you close or navigate away from the tab.

Where our pricing data comes from

The prices and facility information we show are built from public CMS (Centers for Medicare & Medicaid Services) datasets and hospitals' own published machine-readable price files, which federal price-transparency rules require hospitals to make public.

We do not sell your data

We do not sell personal data to third parties.

Questions

This is a draft policy for a product still in development. If you have questions about how your information is handled, reach out through the provider portal contact channel.