InsureClarity LLC ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered insurance education and document analysis platform (the "Service"). This policy applies to all users of insureclarity.ai and associated applications.
We do not store your credit card information. All payments are processed securely through Stripe, a PCI DSS Level 1 certified payment processor. Each year, you authorize your payment directly through Stripe's secure checkout, giving you complete control over your payment information. We retain only your Stripe customer ID for account management purposes.
We collect information that you provide directly to us, including:
We automatically collect certain information when you use our platform:
To protect your account, we collect and process:
We use the information we collect to:
We use artificial intelligence to read and analyze your insurance documents, translate policy language into plain language, identify potential coverage review areas, and generate personalized portfolio reports. Your data is processed securely and is never used to train AI models that would be accessible to other users or third parties.
Before any document content or portfolio data is sent to our AI provider (Google Cloud Vertex AI), a three-layer masking pipeline finds and removes your personally identifiable information:
After masking, quasi-identifiers are also generalized to reduce re-identification risk: 5-digit ZIP codes become 3-digit prefixes, and exact birth dates in document text are converted to birth year only. The AI processes only masked data and returns analysis using those same placeholders. Your real details are restored only within InsureClarity before display to you.
What IS sent to the AI (because it's needed for accurate insurance analysis): coverage amounts, deductible structures, plan language, age ranges, birth years, state of residence, 3-digit ZIP prefix, and carrier names. For the complete, precise list, see our AI Transparency page.
Google Cloud Vertex AI is our sole AI provider — we do not use OpenAI, Anthropic, consumer-grade Gemini, or any other AI service. We access Vertex AI directly through Google Cloud's enterprise platform (no intermediary services or sub-licensed AI). Vertex AI operates under the Google Cloud Data Processing Addendum (CDPA), a legally binding contract that prohibits Google from using customer data for AI training — you can read this commitment yourself. We do not use AI to make automated decisions that produce legal or similarly significant effects on you — all AI output is informational and educational.
Before any document text is sent to the AI, an automated content classifier scans the text to detect health insurance content. If health content is detected and you have not granted health data consent, the document is blocked immediately — the AI never receives it. This gate runs before any external API call. A secondary check provides defense-in-depth. For health documents, the identity masking pipeline operates in fail-closed mode: if any verification layer is temporarily unavailable, the health document is blocked rather than proceeding with incomplete masking.
Important: Our AI analysis describes what your policy documents contain. It does not constitute a coverage determination, guarantee of benefits, or replacement for your carrier's claims process. Only your insurance company can make final coverage decisions.
We do not sell, trade, or rent your personal information. We do not share your personal information for cross-context behavioral advertising. We may share your information only in the following limited circumstances:
A complete list of our current sub-processors is available upon request by contacting admin@insureclarity.ai.
Important: We never share your insurance information with insurance companies, brokers, or agents without your explicit permission. We never sell your data to data brokers, advertisers, or any third party.
InsureClarity is hosted on the Base44 Enterprise platform (SOC 2 Type II, ISO 27001, GDPR compliant) with additional enterprise controls including SSO enforcement, IP allowlisting, training data opt-out, data residency controls, and a 99.9% uptime SLA. We implement rigorous security measures to protect your information, including:
Our hosting provider's SOC 2 Type II audit report is available under NDA via the Base44 Security Trust Center. While we implement enterprise-grade protections, no method of transmission over the internet is 100% secure.
In the event of a data breach that affects your personal information, we will notify you via email within 72 hours of becoming aware of the breach, or as otherwise required by applicable state law (which may require faster notification in certain jurisdictions). The notification will include the nature of the breach, the types of data affected, and the steps we are taking to address it.
Regardless of your state of residence, you have the right to:
To exercise any of these rights, use the self-service tools in your account Settings, or contact us at admin@insureclarity.ai. We will respond within 45 days (or sooner if required by your state's law).
You may delete your account at any time through the self-service deletion feature in Settings. When you delete your account, we permanently remove:
Any active Stripe payment authorization is automatically cancelled. A deletion confirmation email is sent to your email address. Deletion is processed immediately and cannot be undone.
Retention exception: Standard operational security audit logs are retained for up to 3 years post-deletion for incident investigation purposes (per MHMD Act RCW 19.373 statute of limitations and CCPA/CPRA Cal. Civ. Code §1798.130(a)(2) 24-month lookback requirement), and affirmative consent compliance records are retained for 3 years post-deletion to satisfy regulatory record-keeping requirements under the MHMD Act and CCPA, as detailed in the Data Retention table above. These retained records contain only timestamped event metadata — not your documents, policies, or personal content.
We retain your information for as long as your account is active or as needed to provide you services. If you delete your account, all personal data is purged immediately as described above.
| Data Type | Retention Period |
|---|---|
| Account data (profile, preferences) | Until account deletion |
| Uploaded documents (policies) | Until account deletion |
| AI analysis results & conversation history | Until account deletion |
| Security & audit logs | 3 years (auto-purged; MHMD/CCPA statute of limitations) |
| MFA codes & trust tokens | 7 days (codes: 10 minutes) |
| Inactive accounts (expired access period, no login for 12+ months) | Automated deletion notice sent; data purged 30 days after notice if no response |
| Anonymized / aggregated analytics | Indefinite (cannot identify you) |
Inactive Account Policy: If your annual access period ends and you do not log in for 12 consecutive months, we will send a notification to your registered email address. If you do not respond or reactivate within 30 days, your account and all associated data will be permanently deleted. This ensures we do not retain personal data longer than reasonably necessary, consistent with data minimization principles.
Anonymized and Aggregated Data: We may retain and use anonymized, de-identified, or aggregated data that does not identify you personally for analytical purposes, service improvement, and industry benchmarking. This data cannot be used to re-identify you.
If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:
Categories of Personal Information Collected: Identifiers (name, email), financial information, insurance policy details, health-related information, internet activity information, device identifiers, and inferences drawn from the above. We do not sell any of these categories.
Residents of states with comprehensive data privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Iowa, Tennessee, Indiana, Kentucky, Rhode Island, Delaware, Nebraska, New Hampshire, New Jersey, Maryland, and Minnesota) may have rights including:
We honor these rights for all users regardless of state. Contact admin@insureclarity.ai or use the self-service tools in Settings. We will respond within the timeframe required by your state's law (typically 45 days, with extensions available where permitted).
HIPAA Notice
InsureClarity is NOT a "covered entity" or "business associate" under the Health Insurance Portability and Accountability Act (HIPAA). When you voluntarily upload health-related insurance documents, you do so at your own discretion. You are solely responsible for determining whether it is appropriate to share such information with our Service.
InsureClarity maintains a separate, standalone Consumer Health Data Privacy Policy as required by the Washington My Health My Data Act (RCW 19.373). This policy details the categories of consumer health data we collect, how we use it, who we share it with (including specific affiliate names), and your rights regarding your health data — including the right to access, delete, and withdraw consent at any time. Before uploading health insurance documents, users are required to provide separate, affirmative opt-in consent for both (1) collection and (2) sharing of consumer health data.
Under various state privacy laws, health-related information and financial data are classified as "sensitive personal data." We process this data only with your explicit, affirmative consent (obtained separately before health document uploads) and solely for the purpose of delivering the Service. We recommend removing or redacting any information that is not necessary for the analysis you are seeking.
If we deny any privacy request, you may appeal by emailing admin@insureclarity.ai with "Privacy Appeal" in the subject line. We will respond to all appeals within 45 days with a written explanation of our decision. If you are unsatisfied with the outcome, you may file a complaint with your state's Attorney General office.
If you believe an AI-generated analysis contains a technical error (e.g., incorrectly extracted data, a mathematical discrepancy, or a misread policy term), you may request a technical accuracy review. To protect your privacy and maintain the integrity of our identity masking pipeline:
Upon receiving a flagged review request, InsureClarity will check the software's processing logs, masking output, and extraction results using only the anonymized session data — without viewing or requesting your original unmasked documents. We will respond within 45 days with a technical finding.
Our AI does not make automated decisions that produce legal or similarly significant effects — all output is educational and informational. A technical accuracy review verifies that the software processed your document correctly; it does not constitute a coverage determination, professional insurance opinion, or legal analysis. For full details about our AI systems, see our AI Transparency page.
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will promptly delete it. If you believe a child has provided us with personal information, please contact us at admin@insureclarity.ai.
The Service is operated from and designed for users in the United States. If you are accessing our services from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to the transfer of your information to the United States, which may have different data protection laws than your country of residence.
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting the updated policy on this page with a new "Last updated" date. Your continued use of our services after notification constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
This Privacy Policy is governed by the laws of the State of Delaware, without regard to its conflict of law provisions, consistent with our Terms of Service.
If you have questions or concerns about this Privacy Policy, our privacy practices, or wish to exercise your data rights, please contact us at:
Email: admin@insureclarity.ai
Privacy inquiries: admin@insureclarity.ai
Your Privacy Matters: At InsureClarity, we're committed to transparency and protecting your sensitive insurance information. We will never sell your data or share it with insurance companies. You always have full control over your data, including the right to export or permanently delete it at any time. For details on how our AI works and what it sees, read our AI Transparency page. For health-specific data protections, read our Consumer Health Data Privacy Policy.
InsureClarity LLC · Privacy Policy · Last updated September 1, 2026