Privacy Policy
InstantVerify AI (“InstantVerify,” “we,” “us”) provides software that automates dental insurance eligibility verification for dental practices. This policy explains what information our software handles, where that information lives, and the choices you have. It applies to the InstantVerify AI desktop application and to instantverifyai.com.
The short version
InstantVerify AI is built local-first. Our software runs on your practice’s own computers. Patient information, insurance portal credentials, and email data are processed on your machines and are not transmitted to or stored on servers operated by InstantVerify AI.
Information the software processes on your computers
Appointment and patient information. The software reads your practice management system’s appointment schedule (patient names, dates of birth, appointment details, insurance carrier information) in order to perform eligibility verification. This information is processed entirely on your practice’s computers and is never sent to InstantVerify AI.
Insurance portal credentials. Login credentials for insurance carrier portals are stored on your practice’s computer, encrypted using Windows’ built-in data protection (DPAPI). They are used solely to log in to carrier portals on your behalf and are never transmitted to InstantVerify AI.
Verification results. Eligibility and benefits information retrieved from carrier portals is delivered to your practice and remains on your systems.
How we use Google user data (Gmail access)
Some insurance carrier portals require a one-time verification code sent by email at login. If your practice connects a Google account, the InstantVerify AI application uses Google’s Gmail API with read-only access (the gmail.readonly scope) for one purpose: to locate messages sent by your insurance carriers and extract the one-time verification code so the software can complete the portal login.
Specifically:
- What we access: email messages matching your insurance carriers’ sender addresses, retrieved on your practice’s computer at the moment a login code is needed.
- What we do with it: extract the one-time code and use it to complete the carrier portal login. Nothing else.
- Where processing happens: entirely on your practice’s computer. Gmail data is not transmitted to, stored on, or accessible from any server operated by InstantVerify AI.
- What we store: the application does not retain email content. Google sign-in tokens are stored only on your practice’s computer, encrypted with Windows DPAPI.
- What we never do with Gmail data: we do not sell it, use it for advertising, use it to train machine-learning or AI models, or allow humans to read it (except with your explicit permission for support, where required for security purposes, or to comply with applicable law).
You can revoke InstantVerify AI’s access to your Google account at any time at https://myaccount.google.com/permissions. Revoking access stops the software’s automated code retrieval immediately; no other action is required.
Limited Use disclosure: InstantVerify AI’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Information we collect on our own systems
We keep customer account and business records: your practice’s name, contact information, subscription and billing status, license identifiers, and support correspondence. We use this information to provide and bill for the service, to notify you about your subscription, and to provide support. We do not sell personal information.
Our website may use standard analytics to understand site traffic.
Protected health information
InstantVerify AI’s software is designed so that protected health information (PHI) processed during verification remains on your practice’s systems. Where required, InstantVerify AI will enter into a Business Associate Agreement (BAA) with covered entities. Contact us to request one.
No generative AI processing of patient data
InstantVerify AI does not use generative artificial intelligence, large language models, or AI chatbot services (such as ChatGPT) in the operation of its software. Patient information is never transmitted to any third-party AI service and is never used to train, tune, or evaluate any machine-learning model. No machine-learning model or AI reads, interprets, or makes decisions about patient information; that work is done with fixed, deterministic rules on the practice’s own computer. The software does include a self-contained learning component that adapts to changes in carrier portal structure — it processes portal layouts, never patient data, and is not a third-party AI service. For a plain-language explanation, see How We Handle Patient Data.
Data sharing
We do not sell your information. We do not share Gmail data, patient information, or portal credentials with third parties — by design, that information never reaches us. Business records described above may be shared with service providers who support our operations (for example, payment processing), under confidentiality obligations, or where required by law.
Data retention and deletion
Information processed by the desktop application lives on your systems and under your control; uninstalling the application removes its stored tokens and credentials from your computer. Business records on our side are retained while your account is active and as required for legal and accounting purposes. To request deletion of your business records, contact us at the address below.
Security
The application encrypts stored credentials and tokens using Windows data protection, requests only read-only email access, and communicates with insurance portals and Google over encrypted (HTTPS/TLS) connections.
Changes to this policy
If we make material changes, we will update this page and revise the effective date above.
Contact
InstantVerify AI
Email: support@instantverifyai.com
Web: https://instantverifyai.com