Version 2026-08-25 · Effective 2026-08-25 · Last updated: August 18, 2026

Privacy Policy

nurevo LLC (“nurevo,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains what data we collect, why we collect it, where it is stored, which third-party services receive it, and the rights you have over your information.

1. Information We Collect

  • Account information: Name, email address, and authentication credentials when you register.
  • Health and billing data: Medical bills, insurance EOBs, provider names, service dates, charge amounts, insurance plan details, and documents you upload (PDFs, photos).
  • Family and pet profiles: Names, relationships, dates of birth, and insurance plan information you voluntarily add.
  • Usage data: Pages visited, features used, and interactions within the app for product improvement.
  • Device and technical data: IP address, browser type, and operating system collected automatically.

2. Why We Collect Your Data

  • To analyze and explain your medical bills and insurance coverage.
  • To identify potential billing errors, savings opportunities, and financial assistance programs.
  • To track deductibles, out-of-pocket maximums, and claims.
  • To send reminders about due dates, appeal deadlines, and appointments.
  • To provide, maintain, and improve the nurevo platform.
  • To comply with legal obligations and enforce our Terms of Service.

3. Where Your Data Is Stored

Your data is stored on secure cloud infrastructure provided by our hosting platform and its underlying cloud providers. Uploaded documents and files are stored in private storage accessible only through time-limited, authenticated signed URLs — they are not publicly accessible. All data is encrypted in transit (TLS/HTTPS) and at rest.

4. Third-Party Services

We use the following third-party services that may process your data:

  • Cloud hosting & database: Stores account data, health records, and uploaded files.
  • AI/LLM providers: Process bill text and documents to generate explanations, summaries, and savings insights. We share only the data necessary to perform the requested analysis.
  • Payment processor: Processes bill payments you initiate. Payment card details are collected directly by the processor on their secure checkout page — nurevo never sees or stores your card number.
  • Email delivery: Used to send account-related emails, notifications, and support responses to registered users.
  • OAuth providers (e.g., Google): Used for optional single sign-on and calendar/email integrations you explicitly authorize.

We do not sell your personal or health information to any third party.

Google Workspace Data (Limited Use)

When you explicitly connect Google services (Gmail or Google Calendar) to nurevo, we access your Google user data only after you grant OAuth permission, and only the data necessary to provide the feature you requested. nurevo requests the following Google API scopes:

  • Gmail (read access): https://www.googleapis.com/auth/gmail.readonly — used to identify and organize healthcare-related information such as medical bills, insurance claims, Explanation of Benefits (EOB) documents, pharmacy receipts, healthcare invoices, and related correspondence from your inbox.
  • Google Calendar (events): https://www.googleapis.com/auth/calendar.events — used to help you view, create, update, and manage healthcare-related appointments and reminders.

Gmail access is used to identify and organize healthcare-related information such as medical bills, insurance claims, Explanation of Benefits documents, pharmacy receipts, healthcare invoices, and related correspondence. We do not scan Gmail for advertising, unrelated analytics, or any purpose other than the medical billing features you requested.

Google Calendar access is used to help you view, create, update, and manage healthcare-related appointments and reminders you request.

You may disconnect Google services at any time from within nurevo (Profile → Security & Privacy) or by removing nurevo from your Google account permissions. Disconnecting stops all future Google API access, revokes your OAuth token, and deletes the Google-derived data we no longer need.

Retention & disconnect: When you disconnect Google, we stop all future Google API access, revoke your OAuth token, delete the Google-derived data we no longer need, and cancel any queued background processing of your Google data. An internal audit trail records when access was granted, disconnected, and when data was deleted. To fully revoke access, also remove nurevo from your Google account permissions at any time.

How Nurevo Uses Google User Data

“Google User Data” means any raw or derived data Nurevo receives from Google Workspace APIs (Gmail and Google Calendar) after you grant OAuth permission. Nurevo accesses Google User Data only to provide the specific feature you requested — for example, identifying a medical bill in Gmail and adding it to your bills, or syncing an appointment to your calendar.

  • Nurevo does not sell Google User Data.
  • Nurevo does not use Google User Data to build advertising profiles or serve ads.
  • Nurevo does not use Google User Data for unrelated analytics, profiling, or commercial datasets.
  • Nurevo does not use Google User Data to develop, train, fine-tune, evaluate, or improve generalized or foundational AI/ML models.
  • Google User Data is sent to a third-party AI provider only when (a) the provider has been explicitly approved in our internal registry, (b) the provider’s terms disable training on submitted data, and (c) the transfer is necessary for your requested feature. Every transfer (and every blocked attempt) is recorded in an internal audit log. See our Google Limited Use page for the full compliance statement and the list of approved AI providers.

The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Nurevo does not use Google user data to develop, train, or improve generalized or foundational artificial intelligence or machine learning models.

5. Data Retention

We retain your data for as long as your account is active or as needed to provide our services. You may request deletion of your account and associated data at any time. See our Data Deletion Request page.

6. Your Rights

  • Access & export: You can view and export your data from within the app (Profile → Security & Privacy → Data Export).
  • Correction: You can update your profile and bill information at any time.
  • Deletion: You can request permanent deletion of your account and data.
  • Consent withdrawal: You can manage and withdraw consent for AI assistance, notifications, and data processing in the Security & Privacy center.

7. Security

nurevo is built with privacy-first principles. We use encryption in transit and at rest, role-based access controls, and private file storage with signed, expiring URLs. However, no system can be guaranteed 100% secure. We do not claim HIPAA compliance unless and until a complete technical and vendor setup has been formally verified. We encourage you to review our Medical Disclaimer andAI Disclaimer.

8. Children’s Privacy

nurevo is not intended for use by children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal information, please contact us at support@nurevo.org.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make a material change to how Google user data is accessed, used, stored, or shared, we will: (1) update this Privacy Policy, (2) update the “Last updated” date above, (3) notify affected users inside the nurevo application with a brief explanation and a direct link to the updated policy, and (4) clearly explain what changed. Continued use of nurevo after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or your data, email us at support@nurevo.org.