Privacy Policy
Last updated September 2026
Paveo is a service, not software you log into. We read the denial, find the criterion it turned on, draft the appeal and — on live cases — file it as your delegate. That means we handle your records rather than watching your team handle them, so this page is about what we hold, why we hold it, how long it stays, and what we will never do with it.
1. Two phases, two different sets of rules
The free five-case audit runs on closed cases you have de-identified before sending. De-identified documents are not protected health information (PHI), so no Business Associate Agreement is required. That is deliberate: it is what lets you judge the work before either side signs anything.
Live case work is different. It involves identified patient records, which are PHI. We do not touch an identified record until the full agreement chain is signed — our AI provider to us, our host to us, and us to you — and until it is, nothing identified should be sent to us by any route.
2. Documents you send for the free audit
Before you pull a single case we send you the exact list of what to remove. It follows the HIPAA Safe Harbor method (45 CFR §164.514(b)) — the 18 categories of identifier, mapped to where they actually hide in a denial letter and a chart note.
Every page of every document is then screened by a person on our side before anything is processed. Not a spot check — the identifier is usually in a page-three footer or a fax banner.
If something identifying reaches us, we stop. We do not process the document, we do not silently redact it and carry on. We tell you, we delete it, we confirm the deletion in writing, and we ask for a clean copy. There is no such thing as mostly de-identified.
- What we ask you to strip: names, member ID, claim / authorization / reference numbers, MRN, date of birth, all date elements finer than the year, address and ZIP, phone, fax and email, the fax banner across the top of a page, and any barcode.
- What we ask you to keep: the payer, the drug and dose, the diagnosis, the denial reason and any criterion the payer quoted, labs, and prior therapies with how long each was tried. Over-redaction makes the audit worthless.
- What we record about the screen: the date, who screened it, our own opaque case reference and the verdict — never the patient's data, the document text, or a filename that carries a name.
3. Records we handle once a BAA is in place
On live cases we act as your business associate. We use and disclose PHI only to perform the work you have engaged us for, and only as HIPAA and the signed BAA permit.
In practice that means pulling the denial and the supporting clinical record, reading them against the payer's published policy, drafting the appeal, filing it once your named approver has signed off, and following it to a decision.
We do not sell your data. We do not use it for marketing. We do not use it to train models, and neither does our AI provider.
4. Delegated access to payer portals
Live filing runs on delegated access to the portals your team already uses. That access is held by named Paveo operators, used only for your cases, and never shared outside the people working them.
You can revoke it at any time, and revocation takes effect immediately — there is no notice period and nothing to uninstall. We record what we filed and when, so there is a trail on your side as well as ours.
5. What we store, and what we don't
Documents you send us are stored. A service that loses your denial letter is not a service — the operator working your appeal next week needs the file that arrived this week.
They are held in a private store with no public link, under a key scoped to your organization and the specific case, built from a random identifier rather than the filename. Two independent rules enforce that scope: a constraint in the database refuses to record a file at another organization's path, and a policy on the store itself refuses to reveal one. Filenames and file contents are never written to our logs or error reports.
We keep documents for 12 months after a case closes, or delete them sooner whenever you ask. When we stop working together we return or destroy everything.
The completed analysis is saved against the case so your work can be reopened, reviewed and audited. It is isolated to your organization by row-level security in the database — enforced by the database itself, not by a screen that hides a button.
Case actions — creation, status changes, assignment and the sign-off that authorises filing — are written to an append-only audit log: who did what, and when. It records the action, never the document's content, and the application has no permission to edit or delete an entry once written.
An identical repeat request may be answered from an in-process cache for up to 24 hours. It holds finished results only, never the source files, it is never written to disk, and it is emptied whenever the service restarts.
PHI never goes into application logs, error reports or metrics. That is a design rule the code is written to, not a setting someone could switch off in a hurry.
6. Information from the website
If you contact us, we collect what you type: your name, work email, organization, role and your message. We use it to reply, and to talk to you about Paveo. We do not sell it and we do not pass it to advertisers.
Our hosting providers record the ordinary technical information needed to serve and secure a website.
7. Who else processes your information
We use third-party AI infrastructure to read documents and draft output, cloud hosting for the website and the API, and a managed Postgres database for case records.
Until each of those providers is covered by a BAA, only synthetic or de-identified content ever reaches them. That is the same rule as everywhere else on this page, applied to our suppliers.
8. Retention and deletion
For the free audit: tell us and we delete the documents and the analysis. We keep the record that a screen happened — date, screener, our case reference, verdict — because that record is how we can show the procedure was followed, and it contains no patient information.
For live case work: retention periods are set out in the BAA and services agreement, and at the end of the engagement we return or destroy PHI as that agreement requires.
To ask what we hold or to request deletion, email faiz@paveohealth.com.
9. Security, and what arrives before live cases
In place today: encryption in transit over HTTPS, access limited to named operators, per-organization isolation enforced in the database, an append-only audit log, and logging built to be PHI-free by construction.
Landing before the first identified record reaches us: HIPAA-eligible hosting, encryption-at-rest guarantees we can put our name to, and the retention periods set out in the BAA. That sequence is the reason the free audit runs on de-identified documents — there is no protected health information in the system until those are done.
10. If you are a patient
We do not have a relationship with patients directly. Your pharmacy or clinic is the covered entity that holds your record; requests about access, correction or deletion go to them, and we support them in answering.
11. Changes, and how to reach us
We will update this page as the service changes, and the date at the top will say when. Questions, or anything that looks wrong: faiz@paveohealth.com.
This page describes how an early-stage service actually operates; it is not legal advice. Have qualified counsel review it, and the BAA, before any identified patient record changes hands.