Privacy Policy
Effective August 29, 2026
RemitRobin, a product of Small Dev Shop Inc. ("we," "us"), helps physical therapy clinics read explanation-of-benefits (EOB) documents from payer portals and post payments into their billing software. This policy explains what information we collect, how we use it, and the choices you have. Questions are always welcome at hello@remitrobin.com.
Information we collect
Early-access list. If you join our sign-up list, we collect your email address so we can send you the updates we promised. You can unsubscribe at any time by replying to any email or writing to us.
Account information. When a clinic creates an account, we collect the account holder's email address and authentication details (including multi-factor authentication enrollment), managed through our authentication provider.
Clinic documents. The service exists to process EOB documents your clinic fetches or uploads. These documents contain protected health information (PHI) about your clinic's patients — names, dates of service, claim lines, and payment amounts. We handle this data only to provide the service, as described below.
Operational data. Like most web services, our servers keep standard technical logs (such as IP addresses and request timestamps) for security and troubleshooting.
Protected health information and HIPAA
When RemitRobin processes PHI on behalf of a clinic, we act as a business associate under HIPAA. We sign a Business Associate Agreement (BAA) with every customer clinic, and every subcontractor that touches PHI — including our cloud hosting, storage, and AI processing infrastructure — operates under a signed BAA with us. We use PHI only to provide the service to your clinic, never for marketing, and we never sell it.
Emails we send never contain PHI. Patient data stays inside the application; email only ever carries account and billing information.
AI processing
RemitRobin uses AI models to read documents and extract claim lines, running on cloud infrastructure covered by our BAAs. Your documents and data are not used to train AI models, and are not retained by the model provider after processing. Every extraction is checked against the payer's own printed totals, and a member of your clinic's staff reviews every entry before it is saved.
How we use information
- To provide, maintain, and improve the service
- To authenticate accounts and keep them secure
- To communicate with you about your account and, for the early-access list, the updates you signed up for
- To comply with legal obligations
What we share
We do not sell personal information, and we do not share it for advertising. We share information only with the service providers that run RemitRobin — cloud hosting, document storage, database, authentication, AI processing, and email delivery — each bound by contract (and, where PHI is involved, by a BAA) to use it only on our behalf. We may also disclose information if the law requires it.
Cookies
We use only the cookies needed to keep you signed in. There are no advertising cookies and no third-party analytics trackers on our site.
Retention and deletion
We keep account data for as long as the account is active. Clinic documents and PHI are retained and returned or destroyed as the BAA with your clinic provides. If you are on the early-access list, we keep your email address until you unsubscribe. To request deletion, write to hello@remitrobin.com.
Security
Data is encrypted in transit and at rest. Application access requires authentication with multi-factor authentication, and database connections are TLS-verified. No system is perfectly secure, but security decisions here are made HIPAA-first.
Your choices
You can unsubscribe from our emails at any time, and you can ask us to access, correct, or delete the personal information we hold about you. If you are a patient of a clinic that uses RemitRobin, your health information is controlled by your clinic — please direct requests to them, and we will support the clinic in honoring them as the BAA requires.
Children
RemitRobin is a business tool for clinics and is not directed to children. We do not knowingly collect personal information directly from anyone under 13.
Changes to this policy
If we make material changes, we will update the date above and, for significant changes affecting account holders, notify you by email.
Contact
See also our Terms of Service.