BillOkay
How It WorksRead Your BillCGHS RatesDispute a BillAbout
Audit on WhatsApp

Privacy Policy

Your bill. Your data. Your call.

You are trusting us with a hospital bill during what is probably a stressful time. We take that seriously. This page explains, in plain language, what data we hold, why we hold it, how long we keep it, and how you can ask us to delete it.

Last updated: 30 July 2026

The short version

  • We only look at your bill to audit it — nothing else.
  • We never sell your data. We never share it with your hospital or insurer without your say-so.
  • Your bill photos are deleted after we have finished the audit and sent your letter (hard cap: 90 days).
  • Everything sits on Indian servers, encrypted.
  • Ask us to delete anything, anytime, and we will — within a few days.

1. Who we are

BillOkay is an AI-assisted hospital bill audit service for patients in India. Send us a photo of your hospital bill on WhatsApp (+91 99716 01653) and we compare every line against government benchmark rates — CGHS, NPPA, PMJAY, IRDAI — then send you back a plain-language audit and a dispute letter you can hand to the hospital.

For the purposes of India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"), BillOkay is aData Fiduciary. You are the Data Principal. Because hospital bills reveal your health, we treat everything you send us as sensitive personal data.

2. What we collect

We collect only what the audit needs. Nothing more.

When you use the WhatsApp service

  • Your hospital bill — photos, PDFs, or screenshots you send us.
  • Your WhatsApp phone number — how we message you back.
  • Your name and city, if you choose to share them.
  • What you tell us about the bill — the hospital, the treatment, insurance details, the problem you want us to look into.
  • Consent record — a timestamped log of when you agreed to us auditing your bill, and what version of this notice was in force at the time.

When you visit billokay.com

  • Waitlist form (optional) — the phone number and any other details you enter.
  • Basic server logs — IP address, browser, time of request. Used to keep the site running securely, not to profile you.

We do not ask for Aadhaar, PAN, insurance policy documents, or ID proof. If you send them anyway, we redact the identifiers before processing and delete the originals.

3. Why we collect it (and what we do with it)

We use your data for one purpose: to audit the bill you sent us and get you an answer. That means:

  1. Reading the bill — we run the photo through OCR (optical character recognition) to pull out line items, quantities, and prices.
  2. Comparing against government rates — CGHS 2025, NPPA drug ceilings, PMJAY package rates, AIIMS reference rates, IRDAI non-payables lists.
  3. Flagging overcharges — line by line, with the rule or rate we relied on.
  4. Drafting your dispute letter — a ready-to-send letter you can give the hospital billing department.
  5. Messaging you back on WhatsApp with the report and letter.

That is it. We do not use your bill to train AI models, market to you, or build a profile of your health. If we ever want to use your data for anything beyond auditing your bill, we will ask you separately, in clear language, and you can say no without losing access to the audit.

4. The legal basis: your consent

Under the DPDP Act, we process your data because you have given us specific consent to audit your bill. That consent is:

  • Free — you can walk away at any point.
  • Specific — one purpose only: auditing the bill you sent.
  • Informed — this page tells you what we do; the WhatsApp flow confirms it.
  • Unambiguous — you actively opt in by sending us the bill and confirming.
  • Revocable — you can withdraw consent any time by messaging "DELETE" on WhatsApp or emailing us (see Section 11). Withdrawing consent is as easy as giving it, and it triggers deletion of everything we hold about you.

Simply having our WhatsApp number in your contacts, or messaging us to ask a question, does not count as consent to process a bill. We ask you to confirm before we start.

5. Who else touches your data

To run the service, a small number of vetted providers process your data on our behalf. Each of them is aData Processor under the DPDP Act, bound by a written Data Processing Agreement that restricts them to instructions from BillOkay only.

ProviderWhat they doWhere
Meta (WhatsApp Business)Delivers messages between you and us.WhatsApp infrastructure. We pull your bill into Indian infra as soon as it arrives.
Sarvam AIOCR and language processing to read the bill.India. Contractually barred from training on BillOkay data. Deletes within 24 hours.
Cloud hostingStorage, compute, backups.India (mumbai/hyderabad regions).

We do not share your bill with your hospital, your insurer, TPAs, lawyers, or anyone else — unless you tell us to (for example, you ask us to email the dispute letter to the hospital on your behalf).

We may disclose data if a court, regulator, or law-enforcement authority formally compels us. If that happens, we will tell you unless the order forbids it.

6. How long we keep your data

  • Bill images and identifiable content: deleted after we have delivered your audit and dispute letter, and in any case no later than 90 days from the day you sent them.
  • Advance notice of deletion: at least 48 hours before we erase your data, we will send you a WhatsApp message so you can save anything you want to keep.
  • De-identified findings (aggregate stats — "typical overcharge on a stent in Mumbai" — with your name, hospital, and identifiers stripped out): kept for up to one year so we can meet DPDP record-keeping obligations and improve the audit engine.
  • Consent and processing logs: kept for the statutory audit window (currently one year), then deleted.

7. Your rights

As a Data Principal under the DPDP Act, you have the following rights. All of them are free.

  • Right to know — ask us what data we hold about you and what we have done with it.
  • Right to correct — ask us to fix anything inaccurate or out of date.
  • Right to erase — ask us to delete everything. We will confirm within a few days, and complete deletion within 30 days at the outside.
  • Right to withdraw consent — turn off future processing whenever you want.
  • Right to nominate — name someone to exercise these rights on your behalf if you can't.
  • Right to grievance redressal — complain to us. We will respond within90 days (usually much sooner). If you are still unhappy, you can escalate to the Data Protection Board of India.

To exercise any right, message us on WhatsApp (+91 99716 01653) or email[email protected]. To help us find your data, please write from the phone number you originally used, or include it in your message.

8. How we keep your data safe

  • Encryption in transit — TLS 1.2 or higher for every network hop.
  • Encryption at rest — AES-256 on stored bills, databases, and backups.
  • Role-based access — only a small number of BillOkay team members can access identifiable data, and only when they need to.
  • Tamper-evident logs — every access and processing action is logged.
  • Data residency — bills, databases, and backups live on Indian-region infrastructure. We do not export health data outside India.
  • No client-side storage — we do not stash bills in browser storage, URLs, or analytics events.

If we ever suffer a personal-data breach, we will notify the Data Protection Board of India and every affected person within 72 hours, in plain language, explaining what happened, what data was involved, what we are doing about it, and what you can do to protect yourself.

9. Cookies and tracking

billokay.com uses no advertising cookies, no analytics cookies, and no third-party trackers. If you fill in the waitlist form, we store your entry in our own India-hosted database — nothing goes to Google, Meta, or ad networks.

The only cookies you may see are strictly necessary ones (for example, a session cookie if we add a login in future). If we add analytics later, we will update this page and tell you first.

10. Children's data

BillOkay is designed for adults handling hospital bills — often for their family members, including children.

  • Where the patient is under 18, the parent or legal guardian is the Data Principal. They give consent, and they exercise all the rights above.
  • We do not profile children, do not target advertising at children, and do not track their behaviour.
  • Where a bill relates to a minor, we minimise and redact the child's identifiers as soon as the audit is complete, and apply the shortest reasonable retention window.

11. Contact and grievance officer

For anything to do with your data — questions, requests, corrections, complaints — please reach us:

Grievance Officer, BillOkay

Email: [email protected]

WhatsApp: +91 99716 01653

Response time: within 90 days (in practice, within a few working days)

If we can't resolve your concern, you can complain to the Data Protection Board of India once it is operational.

12. Changes to this policy

We will update this page if the service changes, the law changes, or we start doing something new with data. When we make a material change, we will:

  • Update the "Last updated" date at the top of this page.
  • Post a summary of what changed.
  • For anything that affects an existing user, message you on WhatsApp before the change takes effect, and — where the change materially expands how we use data — ask for fresh consent.
BillOkay

Making hospital bills fair for every Indian family.

Guides

How to Read Your Hospital BillCGHS Rate List 2025How to Dispute a Hospital Bill

Company

AboutHow It Works[email protected]

Legal

Privacy PolicyTerms of ServiceAI Instructions

© 2025 BillOkay · WhatsApp +91 99716 01653

BillOkay provides bill auditing and advisory services. We are not a legal firm or an insurance provider.

भाषा चुनें · Choose your language

We'll remember your choice for next time.

We've saved your preference — that language is on its way. The site is in English for now.