Privacy
Arvo reads a photo of an insurance denial letter and drafts an appeal for you to review and sign. A denial letter is health information, so this page says exactly what Arvo collects, who sees it, how long it is kept, and how to delete it. Last updated 2026-09-30.
What Arvo collects
Only what you send it and what it makes from that:
- The photo or PDF of the letter you send.
- What it reads from the letter: the insurer, plan type, patient name, member ID, claim number, service, denial reason and codes, amount, dates, deadline, and where appeals go. You see and can correct every one of these before anything is drafted.
- Your answers to its questions. They shape the letter and are never stored on their own.
- The appeal letter, the physician letter draft, and, if you sign, the signed packet and the record of that signature.
- If you sign in: your email address, used for sign-in links and appeal reminders.
- If you use the Telegram bot: the chat's numeric ID, so replies and reminders reach you.
- If you tap “Fax it now”: the number the fax goes to (encrypted), the fax's status and receipt, and a transmission record: when it went, a keyed fingerprint of the number, the page count, and the wording you agreed to. The record never holds your name or the letter.
- With each consent you give: the version of the text you saw, the time, and a one-way hash of your IP address.
- Anonymous outcome statistics: plan type, denial codes, and whether an appeal was overturned. Nothing that identifies you.
Who sees it
Arvo does not sell your information, does not use it for advertising, and does not use it to train models. The organisations that handle it, by role:
- The AI model provider (Anthropic) receives the letter image and the details read from it, to read the letter and draft the appeal.
- The fax provider (Sinch) receives the signed packet only when the member taps “Fax it now” where faxing is on, and keeps no pages once the fax is done; it keeps the fax's own record (time, numbers, pages, status) for 13 months. Nothing is sent to an insurer otherwise.
- The messaging provider (Telegram, if you use the bot) carries the chat. Telegram bot chats are not encrypted end to end; Telegram can read what you send, and the bot asks you to acknowledge that before it reads a letter.
- The email provider [Miras: Resend or Postmark, whichever is configured] sends sign-in links and reminders. Those emails name no claim, no insurer, and no diagnosis.
- The hosting provider (Render) runs the server and holds the encrypted database.
No one else. Arvo reaches your insurer only through a fax you tap “Fax it now” for, and never contacts your doctor or anyone else. The cover sheet asks the plan to reply to you, and Arvo's fax number does not accept faxes.
How long it is kept
- Without an account or tracking: your letter, the details read from it, your answers, and the PDF live in memory only, for 30 minutes or until the PDF is delivered, and are then gone. Nothing is written to disk.
- With an account, or tracking on in the bot: the details read from the letter, the letter photo, and the packets are stored encrypted (AES-256-GCM) until 60 days after your appeal deadline. An unsigned draft is deleted after 30 days.
- Backups: encrypted copies of the database made for safety expire within 30 days.
- Transmission records are kept for six years, even after you delete your account, as proof a fax was sent at your direction. They hold no name and no letter.
- Anonymous statistics are kept after everything else is deleted.
Deleting it
From your account page, Export my data gives you everything stored under your account as one file, and Delete my account removes it. In the Telegram bot, /forget does the same for that chat, and Stop tracking removes one appeal. Deletion is immediate from live systems; encrypted backups expire within 30 days. Transmission records stay for their six years; download a fax receipt before deleting the appeal if you want your own copy.
Security
Connections use TLS. Stored letters and details are encrypted at rest under a key held separately from the database. Sign-in is by single-use email link, and faxing needs a sign-in link opened in the last ten minutes. The FTC Health Breach Notification Rule applies to Arvo, and if your information were ever disclosed without authorisation you would be told within 60 days.
Your rights
You can see everything Arvo holds about you, take it with you, correct it, or delete it, at any time and without giving a reason. You can withdraw consent to tracking by stopping it. Some states (Washington, Nevada, Connecticut, and California among them) give these rights by law for consumer health data; Arvo gives them to everyone.
Changes
Every text you agree to is versioned and its exact wording is recorded with your consent, so what you saw can always be reproduced. Changes to this page carry a new date at the top.
Contact
Questions or requests: maratuly.miras.zharas@gmail.com.