Skip to main content
VeriPlan

Privacy Policy

Operated by Mixma AI · Last updated: 20 July 2026

This policy explains what VeriPlan collects, processes, and stores when you check an NDIS invoice, manage your account, or subscribe to a paid plan.

1. Overview

VeriPlan is operated by Mixma AI. We designed the service with privacy-first defaults: invoice PDFs are processed temporarily, participant identifiers are never stored, and check history retains only the minimum metadata needed for duplicate context and your records.

2. Invoice processing

When you upload an invoice PDF, it is processed temporarily to extract fields — provider name, ABN, invoice number, date, and line items — for your review. The file itself is not stored by default and is discarded once processing completes.

Extraction may use Cloudflare Workers AI and, when enabled, OpenAI document recognition. Invoice bytes are sent to these services in memory for processing only and are not retained by VeriPlan after the request completes.

3. AI-assisted processing and human review

VeriPlan uses AI-assisted processing to help extract invoice fields and surface review questions. Depending on configuration, this may include Cloudflare Workers AI and OpenAI for document recognition and structured extraction. Extracted fields are then checked against VeriPlan's pricing references and privacy-safe invoice context held for your organisation (for example hashed invoice identifiers used only for possible duplicate context).

AI-assisted outputs may surface questions such as:

  • Missing information needed for a reliable review
  • Pricing questions relative to published NDIS price-guide references
  • Uncertain extraction that needs human correction
  • Claim-age prompts where timing may warrant a second look
  • Possible duplicate context based on privacy-safe identifiers

These outputs are review prompts only. They may be incomplete or inaccurate. You can inspect and correct extracted information before relying on any flag. VeriPlan does not approve or reject invoices, determine fraud, decide payment eligibility, or replace human judgement. A responsible person in your organisation remains accountable for follow-up and any payment decision.

4. Participant information

Any NDIS participant identifier found on an invoice is shown during the review step for your own context only. It is never sent to our database and is not retained after your session ends.

5. What we store

After you run checks on an invoice, we retain only:

  • Provider name and ABN (as extracted or corrected by you)
  • A salted, one-way hash of the invoice number (not the invoice number itself)
  • Support item codes referenced on the invoice
  • The check result and flags raised
  • The date and time of the check
  • Which team member ran the check (organisation accounts)

6. What we do not store

We never store raw invoice PDFs or participant identifiers as part of your check history. Invoice numbers are hashed before storage so we can surface possible duplicate context without keeping the original value.

7. Account, billing, and processors

We use third-party processors to run the service. Each handles data under its own privacy and security practices:

  • Supabase — authentication and PostgreSQL hosting
  • Cloudflare — application delivery, Workers runtime, and Workers AI
  • OpenAI — document recognition and structured extraction when that path is enabled (invoice bytes processed in memory for the request only)
  • Stripe — subscription billing and payment details

Your email address, authentication credentials, and billing details are managed by these providers according to their respective policies.

8. Data deletion

Deleting your account removes your profile and check history. Because raw invoices and participant identifiers are never stored, there is nothing further to delete on that front.

If you need a record removed sooner, contact us at hello@mixma.ai and we will process the request manually.

9. What VeriPlan is not

VeriPlan is a checking assistant. It does not make payment decisions, provide legal advice, determine fraud, decide payment eligibility, or guarantee compliance. It does not build profiles of providers, and it does not contact NDIS participants on your behalf.

10. Contact

Questions about this policy can be sent to hello@mixma.ai.