Privacy Policy
Last updated: April 23, 2026
We never share your data without your explicit consent. Here's exactly what we collect and why.
Our promise in one paragraph
Nkasi collects only what you give us. We use it to estimate costs, match you with programs, and let you track applications. We do not share your data with advertisers or use it to train AI models. Health-related context is treated with HIPAA-aware care, even though Nkasi itself is not a covered entity under HIPAA.
1. Who we are
This Privacy Policy explains how Nkasi ("Nkasi," "we," "us") handles your information. Nkasi is operated by Tochukwu Godswill Oyi. Contact: contact@getnkasi.com.
2. Information we collect
Information you provide
- Account info: name, email, password (hashed), preferred language, ZIP, state.
- Assessment answers: household size, annual income, insurance status, residency status, ZIP, hospital name, care type, condition tags/text, bill stage.
- Bill uploads: medical bill or EOB documents you upload to the AI Bill Decoder, plus the AI-generated summary and flags.
- Application tracking: programs you save, status updates, notes, reminder dates.
- Communications: emails you send us.
Information collected automatically
- Basic technical logs (IP, browser, timestamps) for security and debugging — retained briefly.
- No advertising or marketing tracking pixels. No cross-site tracking.
3. How we use your information
- Estimate your out-of-pocket cost and match you with assistance programs.
- Generate plain-language summaries of bills you upload.
- Save your applications and surface reminders.
- Authenticate you and keep your account secure.
- Improve the service (in aggregate, de-identified form only).
- Comply with legal obligations.
We do NOT use your data to train AI models, share it with advertisers, or share it with hospitals/programs without your explicit action (e.g., you clicking "Apply").
4. Health information & HIPAA
Nkasi is a consumer tool, not a healthcare provider, health plan, or business associate, so HIPAA does not directly apply. However, because the information you share is health-adjacent, we treat it with HIPAA-aware care: encryption in transit and at rest, strict access controls, and minimum-necessary handling.
5. Sharing & disclosure
We share your information only in these limited cases:
- Service providers who help us operate Nkasi (cloud hosting, database, AI inference). These providers are bound by contract to use your data only to provide services to us.
- With your explicit consent — for example, when you choose to apply to a third-party program through a link.
- Legal requirements — to comply with valid legal process, protect rights and safety, or respond to lawful requests by public authorities.
- Business transfer — if Nkasi is acquired or merged, your data may transfer; we will notify you and give you the option to delete your account.
6. AI processing
Bill Decoder and Nkasi use third-party large-language model providers. When you upload a bill or ask Nkasi a question, the relevant content is sent to the model provider for processing. We use providers that contractually agree not to retain or use your inputs to train their models. AI output may be inaccurate — verify important details with your hospital, insurer, or a qualified professional.
7. Data retention
We retain your account and assessment data for as long as your account is active, plus a short period afterward for backups and legal compliance. You can delete your account at any time by emailing us; we will delete your personal data within 30 days, except where retention is required by law.
8. Your rights
Depending on where you live (e.g., California, Colorado, Virginia, EU/UK), you may have rights to:
- Access, correct, or delete your personal information.
- Request a copy of your data.
- Opt out of certain processing.
- Withdraw consent at any time.
To exercise any right, email contact@getnkasi.com.
9. Cookies & similar tech
We use only essential cookies needed to keep you signed in and to remember your language preference. We do not use advertising cookies, marketing pixels, or third-party analytics that profile you across sites.
10. Security
We use industry-standard safeguards: TLS encryption in transit, encryption at rest for stored data, hashed passwords, role-based access controls, and Row-Level Security on our database so your records are isolated to your account. No system is 100% secure — please use a strong, unique password.
11. Children
Nkasi is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, email us and we will delete it.
12. International users
Nkasi is intended for users in the United States. If you access it from outside the U.S., your information will be processed in the U.S., where data-protection laws may differ from your country.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by an in-app notice.
14. Contact
Questions, requests, or concerns about your privacy? Email contact@getnkasi.com. See also our Terms of Service.