Privacy Policy
This policy explains what Lazarus LLC d/b/a Offload (“Offload,” “we,” “us”) collects when you use our website and service, how we use and share it, how long we keep it, and the choices you have. The short version: we collect what we need to do the admin work you send us, we store your documents in private encrypted storage, we never use health information for marketing, and we never sell your personal information.
1. Who this covers
This policy applies to visitors of our website, customers with an Offload account, and the people customers add to their accounts (for example a parent). When a customer adds you to their account, the customer has told us they have authority to share your information with us for the requests they submit; if you believe that is not the case, contact us and we will stop work and remove your information.
2. What we collect
2.1 Information you give us
- Account information: your name, email address, phone number, time zone, and notification preferences.
- People you add: their name, relationship to you, date of birth, phone, email, mailing address, and any notes you write about them.
- Requests: what you ask us to do and the details you provide, such as the provider or company, account numbers, amounts, dates, and the outcome you want.
- Documents you upload: bills, itemized statements, explanations of benefits, denial letters, insurance cards, contracts, and similar files.
- Authorizations: the HIPAA authorizations and letters of authorization you e-sign, together with the signer's name, the time of signature, and the IP address and browser used to sign.
- Communications: messages you exchange with our agents in the app and emails you send us.
- Payment information: handled by Stripe, our payment processor. We receive and store the card brand and last four digits, the billing status of your subscription, and your purchase history. We do not receive or store full card numbers.
2.2 Information we create while working your requests
- Notes, call logs (who was called, when, the outcome, reference numbers, and a summary), documents we obtain from third parties on your behalf, and the savings entries we record.
- Recordings are not made of calls by default. Where a call is recorded because the law or the other party requires notice, we tell the other party, and the recording is kept with the request.
2.3 Information collected automatically
- Usage and device data: pages viewed, actions taken in the app, browser and device type, IP address, and approximate location derived from it, plus timestamps.
- Attribution: when you arrive from an ad or link, we store the campaign parameters in the URL (utm_source, utm_medium, utm_campaign, utm_content, utm_term, the message variant, and any ad click identifier), the page you landed on, and the referring site, in a first-party cookie for 30 days. If you create an account, we save these to your profile so we know which campaigns work.
- Cookies: a session cookie that keeps you signed in, the attribution cookie above, and, on marketing pages only, the Meta pixel cookies described in Section 6.
3. How we use it
- To do the work you ask for: contact third parties, negotiate, appeal, and cancel.
- To operate your account, bill you, and send you service messages about your requests.
- To record the savings we obtain for you, including for the annual guarantee described in the Terms of Service.
- To train and supervise our agents and improve our playbooks, using de-identified examples where possible.
- To secure the service, prevent fraud and abuse, and comply with law.
- To measure our advertising and, if you have opted in, to send you marketing email. You can opt out of marketing email at any time from settings or the link in the email; service messages about your requests continue.
4. Health information
Medical bills, explanations of benefits, claim records, and appeal files contain protected health information (“PHI”). We receive PHI in two ways: you upload it, or a provider or insurer releases it to us under the HIPAA authorization you or the patient signed. We use it only for the purpose stated in that authorization: to review, negotiate, dispute, and appeal bills and claims for the patient, and to communicate with providers, insurers, and billing offices for that purpose.
- Storage. Documents are stored in a private storage bucket, encrypted at rest and in transit, and served only through short-lived signed links to people who are authorized to see them. They are never placed on a public content network.
- Access. Only the agent assigned to your request and the operations staff who supervise them can open your documents. Agents cannot browse documents on requests they are not working.
- No marketing or advertising use. PHI is never used for marketing, included in analytics, or sent to any advertising platform. The events we send to Meta (Section 6) contain no request content, no document content, and no health information.
- Minimum necessary. We ask third parties only for the records needed to work the request, and we share with them only what is needed to identify the account and the issue.
- Your copy. You can download your signed authorization and the documents on any request from the app at any time.
Offload is not a health care provider or health plan. We handle your PHI as your authorized representative under the authorization you sign, and we hold ourselves to the safeguards above regardless of whether HIPAA applies to us directly in a given situation.
5. Who we share it with
5.1 Third parties, on your behalf
To do the work, we share information with the hospitals, physician groups, billing offices, insurers, pharmacies, utilities, banks, and companies involved in your requests, and we provide them copies of your authorizations when asked. We share what is needed to identify you or the person you added, the account, and the matter.
5.2 Service providers
We use the following companies to run the service. Each processes data only on our instructions and under a contract that limits its use.
| Provider | What it does | What it processes |
|---|---|---|
| Supabase | Database, authentication, and private file storage | Account data, requests, documents, authorizations |
| Vercel | Hosts the website and app | Web traffic, including IP address and usage logs |
| Stripe | Payments and subscriptions | Name, email, payment card, billing history |
| Resend | Sends our email | Email address, message content of service and marketing emails |
| Inngest | Runs background jobs such as reminders and digests | Account and request identifiers and the data needed for each job |
| Meta (Facebook) | Advertising measurement on marketing pages only | See Section 6. Never PHI or request content. |
5.3 Our staff and contractors
Our agents and operations staff, some of whom work for contracted service companies outside the United States, access your information to do the work. They are bound by written confidentiality obligations, trained on this policy, and can see only the requests assigned to them.
5.4 Legal and safety
We disclose information when required by law, subpoena, or court order; to enforce our Terms; or to protect the rights, property, or safety of our customers, our staff, or the public. Where permitted, we will tell you before responding to a legal request for your information.
5.5 Business transfers
If Offload is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you by email before your information becomes subject to a different privacy policy.
We do not sell personal information and we do not share it with third parties for their own marketing.
6. Advertising and analytics
On our public marketing pages (the home page, pricing, and legal pages) we use the Meta pixel and Meta's Conversions API to measure whether our ads work. These tools record that a browser viewed a page, viewed the pricing page, clicked a sign-up button, or started checkout, along with the Meta cookie identifiers, your IP address, and browser type. When you sign up, we may send Meta a hashed (SHA-256) version of your email address so the event can be matched to the ad you saw; Meta cannot read the email from the hash. We never send Meta anything about your requests, your documents, the people on your account, or your health.
The pixel is not loaded inside the signed-in app. You can limit Meta's use of this data through your Meta ad settings, and you can block the pixel with a browser content blocker without affecting the service.
7. How long we keep it
- Account information: for as long as your account exists, and for 24 months after you close it so we can answer questions about past requests and comply with our legal obligations.
- Request documents and PHI: 24 months after the request is closed, then deleted. You can ask us to delete a request's documents earlier once the request is closed, and we will, unless we are required to keep them.
- Authorizations: for the period stated on the document (24 months for HIPAA authorizations, 12 months for letters of authorization) plus 6 years, because third parties and regulators may ask us to prove we were authorized.
- Savings records: for as long as your account exists, because they support the annual guarantee.
- Billing records: 7 years, as required for tax and accounting.
- Attribution cookie: 30 days. Usage logs: 90 days.
8. Security
We use encryption in transit (TLS) and at rest, sign-in by one-time email link rather than passwords, role-based access with row-level security in our database, private storage with short-lived signed links. Agents work in a separate portal that shows only their assigned requests. No system is perfectly secure; if we learn of a breach affecting your information we will notify you and the relevant authorities as the law requires.
9. Your choices and rights
- Access and export. You can see your account information, people, requests, and documents in the app, and you can ask us for a copy of the information we hold about you in a portable format.
- Correction. You can edit your account and the people on it in the app, or ask us to correct anything else.
- Deletion. You can close your account from settings or by emailing us. We will delete your information on the schedule in Section 7, except what we must keep by law.
- Revoking authorizations. Email us at any time. See the authorization page for what revocation does.
- Marketing email. Opt out in settings or via the link in any marketing email.
- Cookies. Block or clear them in your browser. The sign-in cookie is required to use the app.
To exercise a right, email support@offload.help from the address on your account. We respond within 45 days. We will not treat you differently for exercising your rights.
10. Children
Offload accounts are for adults 18 and older, and we do not knowingly collect information from anyone under 18 as a customer. A customer may add their own minor child as a person on the account in order to handle that child's medical bills; in that case the parent or guardian provides the information and signs the authorization. If you believe a child has created an account, contact us and we will delete it.
11. California residents
If you live in California, the California Consumer Privacy Act (CCPA, as amended by the CPRA) gives you the rights described in Section 9, and the right to know the categories of personal information we collect, the sources, the purposes, and the categories of third parties we share it with, all of which are described above. In CCPA terms, in the last 12 months we have collected identifiers, customer records, commercial information, internet activity, geolocation derived from IP address, health information you or the patient authorized us to receive, and inferences limited to which of our modules you are likely to use.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising except to the extent that the Meta measurement described in Section 6 is considered “sharing” under California law. You may opt out of that by using a browser or extension that sends a Global Privacy Control signal, which we honor on our marketing pages, or by emailing us. We do not use or disclose sensitive personal information for purposes other than providing the service. You may designate an authorized agent to make a request on your behalf; we will ask the agent for proof of your permission. You have the right not to be discriminated against for exercising these rights.
12. Residents of other states
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with consumer privacy laws have similar rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising and the sale of personal information. Use the contact in Section 9. If we deny your request you may appeal by replying to our decision, and we will respond to the appeal within 45 days.
13. Changes to this policy
When we change this policy we update the date at the top. If a change materially reduces your rights or expands how we use your information, we will email the address on your account at least 30 days before it takes effect.
14. Contact
Lazarus LLC d/b/a Offload
Attn: Privacy
4413 Indigo Ln, Murrells Inlet, SC 29576
support@offload.help
Questions about this document: email support@offload.help or write to Lazarus LLC, Attn: Legal, 4413 Indigo Ln, Murrells Inlet, SC 29576.