Last updated August 27, 2026.
From you, the provider: email address, practice name, provider name, NPI, and TIN.
From each estimate you create: client name, date of birth, and, if you provide it, email address and a diagnosis note. We don’t ask for anything beyond what a Good Faith Estimate requires — no clinical notes, treatment history, or insurance information.
Client name, date of birth, client email, and your practice TIN are encrypted at rest with AES-256-GCM before they touch the database. Everything is stored in a Postgres database hosted by Neon, in the United States. We don’t sell client or provider data, and we don’t use it for advertising.
Three processors touch estimate data in the course of running the service: Neon (database hosting), Resend (delivering the client email), and Stripe (billing — Stripe never sees client-level data, only your account’s billing information). Clerk handles authentication and sees your email address only. None of these processors are permitted to use the data for their own purposes.
Each estimate gets a unique, unguessable link so a client can view it without creating an account. Anyone with that link can view the estimate — treat it like you would any document containing a client’s name and date of birth.
Email support@estimateharbor.com to delete your account or a specific client’s estimate. We’ll remove the underlying record; note that email delivery logs at Resend follow their own retention schedule, which we don’t control.
See the data & PHI notice for how this policy interacts with HIPAA.