Last updated: July 23, 2026. Plain-language draft. The short version is genuinely short: by default, we don't have your data.
SuperQuick Bill is browser-only by default — and in v1, that is the only architecture: nothing you enter is ever sent to our servers. Everything you type into the generator — your practice details, your clients' names and dates of birth, session dates, codes, and fees — is stored in your web browser's local storage (localStorage) on your own device. None of it is transmitted to, processed by, or stored on our servers. There is no account database of client information because the architecture doesn't send us any.
Practical consequences of this design:
Superbill PDFs are generated on your device using your browser's own print-to-PDF function. The document is created locally and saved wherever you choose. We never receive a copy.
This site uses Cloudflare Web Analytics on its pages — a privacy-respecting, cookieless analytics tool. It measures only aggregate page activity (which pages are viewed, approximate region, browser type). It sets no cookies, does not fingerprint you or track you across other websites, and collects no personal information. We do not run advertising trackers. Critically, the generator's form fields are never analytics-instrumented: what you type — your practice details and your clients' names, dates of birth, and codes — is not observed, measured, or sent anywhere. Analytics can see that a page was opened, never anything you enter on it.
There are no paid plans during early access, so no payment information is collected at all. If a paid tier launches in the future, payments would be handled by a third-party payment processor under its own privacy policy — we would never see or store full card numbers, and your clients' information would play no part in checkout. This policy will be updated before any paid plan exists.
If you email us for support, we'll have your email address and whatever you include in the message. Please don't include client health information in support emails — we don't need it to help you, and by design we'd rather never hold it.
We do not claim HIPAA compliance, and we're deliberate about that. Three plain statements:
The service is for use by professional providers and is not directed at children. Providers (such as SLPs and IBCLCs) may enter information about minor clients; that information stays in the provider's browser as described above and never reaches us.
If we change how the product handles data — for example, if a future opt-in account or sync feature ever stores anything server-side — we will update this policy first and say so clearly in the product. The browser-only default described here will not change silently.
A contact email for privacy questions will be listed here before launch.