Privacy Policy

Last updated: September 1, 2026

Introduction

InsureClarity LLC ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered insurance education and document analysis platform (the "Service"). This policy applies to all users of insureclarity.ai and associated applications.

Payment Information

We do not store your credit card information. All payments are processed securely through Stripe, a PCI DSS Level 1 certified payment processor. Each year, you authorize your payment directly through Stripe's secure checkout, giving you complete control over your payment information. We retain only your Stripe customer ID for account management purposes.

Information We Collect

Personal Information You Provide

We collect information that you provide directly to us, including:

  • Name and email address (account registration)
  • Demographic information (age, marital status, state of residence, dependents)
  • Financial information (income ranges for insurance adequacy analysis)
  • Insurance policy documents and details you upload
  • Conversations with our AI Navigator
  • Support tickets and feedback you submit

Automatically Collected Information

We automatically collect certain information when you use our platform:

  • Usage data and analytics (pages visited, features used)
  • Device information and IP address
  • Browser type and operating system
  • Essential session cookies required to keep you logged in — we do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies

Security and Authentication Data

To protect your account, we collect and process:

  • Multi-factor authentication (MFA) verification records, including hashed one-time codes and timestamps
  • Device trust tokens — cryptographic identifiers stored on your device to recognize trusted browsers for up to 7 days, reducing repeated MFA prompts
  • Browser fingerprint identifiers used solely for MFA device recognition (not for tracking or advertising)
  • Security audit logs recording authentication events (login, MFA verification, trust grants) for fraud detection and account protection

How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process your transactions and manage your annual access
  • Analyze your insurance documents and provide educational insights
  • Generate your personalized Insurance Story educational summary
  • Send you alerts about policy renewals, premium due dates, and coverage concerns
  • Authenticate your identity and protect your account via multi-factor authentication
  • Maintain security audit trails to detect and prevent unauthorized access
  • Communicate with you about the Service, including support responses
  • Detect, prevent, and address technical issues, fraud, and abuse
  • Comply with legal obligations

AI Processing

We use artificial intelligence to read and analyze your insurance documents, translate policy language into plain language, identify potential coverage review areas, and generate personalized portfolio reports. Your data is processed securely and is never used to train AI models that would be accessible to other users or third parties.

How We Protect Your Identity from AI

Before any document content or portfolio data is sent to our AI provider (Google Cloud Vertex AI), a three-layer masking pipeline finds and removes your personally identifiable information:

  • Layer 1 — Dictionary matching: A personalized dictionary catches known names (including variants like initials, reversed order, and titles), dates of birth, addresses, and account numbers. Policy numbers are intentionally passed through unmasked to improve extraction accuracy.
  • Layer 2 — Pattern detection: Rules-based scanning catches SSNs, Medicare Beneficiary Identifiers, driver's license numbers, phone numbers, street addresses, and more.
  • Layer 3 — AI-powered verification: A secondary scan reviews the already-masked text for any remaining personal identifiers missed by the first two layers.

After masking, quasi-identifiers are also generalized to reduce re-identification risk: 5-digit ZIP codes become 3-digit prefixes, and exact birth dates in document text are converted to birth year only. The AI processes only masked data and returns analysis using those same placeholders. Your real details are restored only within InsureClarity before display to you.

What IS sent to the AI (because it's needed for accurate insurance analysis): coverage amounts, deductible structures, plan language, age ranges, birth years, state of residence, 3-digit ZIP prefix, and carrier names. For the complete, precise list, see our AI Transparency page.

AI Provider and No-Training Guarantee

Google Cloud Vertex AI is our sole AI provider — we do not use OpenAI, Anthropic, consumer-grade Gemini, or any other AI service. We access Vertex AI directly through Google Cloud's enterprise platform (no intermediary services or sub-licensed AI). Vertex AI operates under the Google Cloud Data Processing Addendum (CDPA), a legally binding contract that prohibits Google from using customer data for AI training — you can read this commitment yourself. We do not use AI to make automated decisions that produce legal or similarly significant effects on you — all AI output is informational and educational.

Pre-AI Health Content Gate

Before any document text is sent to the AI, an automated content classifier scans the text to detect health insurance content. If health content is detected and you have not granted health data consent, the document is blocked immediately — the AI never receives it. This gate runs before any external API call. A secondary check provides defense-in-depth. For health documents, the identity masking pipeline operates in fail-closed mode: if any verification layer is temporarily unavailable, the health document is blocked rather than proceeding with incomplete masking.

Important: Our AI analysis describes what your policy documents contain. It does not constitute a coverage determination, guarantee of benefits, or replacement for your carrier's claims process. Only your insurance company can make final coverage decisions.

Information Sharing and Disclosure

We do not sell, trade, or rent your personal information. We do not share your personal information for cross-context behavioral advertising. We may share your information only in the following limited circumstances:

  • Service Providers: With trusted third-party service providers who assist in operating our platform, including:
    • Application hosting platform (Base44 Enterprise E1, SOC 2 Type II, ISO 27001, GDPR) — stores your structured data (policy metadata, analysis results, account information)
    • Document storage (Google Cloud Storage) — stores your uploaded PDF files in our own private bucket
    • Payment processor (Stripe) — processes annual access fee payments only; does not receive insurance or health data
    • AI document analysis (Google Cloud Vertex AI) — receives only identity-masked text for analysis; operates under Google Cloud Data Processing Addendum (CDPA) which prohibits training on customer data
    • Encryption key management (Google Cloud KMS) — protects the per-user encryption keys used for your sensitive fields
  • Legal Requirements: When required by law, court order, subpoena, or government request
  • Business Transfers: In connection with a merger, acquisition, or sale of assets — you will be notified via email and/or a prominent notice on the Service before your information is transferred
  • Safety & Rights Protection: When necessary to protect the rights, property, or safety of InsureClarity, our users, or the public
  • Your Consent: With your explicit consent for any other purpose

A complete list of our current sub-processors is available upon request by contacting admin@insureclarity.ai.

Important: We never share your insurance information with insurance companies, brokers, or agents without your explicit permission. We never sell your data to data brokers, advertisers, or any third party.

Data Security

InsureClarity is hosted on the Base44 Enterprise platform (SOC 2 Type II, ISO 27001, GDPR compliant) with additional enterprise controls including SSO enforcement, IP allowlisting, training data opt-out, data residency controls, and a 99.9% uptime SLA. We implement rigorous security measures to protect your information, including:

  • AES-256 encryption at rest for all stored data, plus TLS 1.2+ / HTTPS encryption in transit
  • Data redundancy and backups managed by our hosting provider's infrastructure
  • Multi-factor authentication (MFA) enforced for all user accounts with email-based verification codes, device trust management, and brute-force lockout protections
  • MFA-enforced administrative access with credential separation
  • Security audit logging — all sensitive data access, authentication events, and administrative actions are logged and monitored
  • Hashed credential storage — MFA codes and device trust tokens are cryptographically hashed, never stored in plaintext
  • Secure authentication mechanisms with rate limiting and anti-brute-force protections
  • Access controls limiting employee access to user data (administrators view only masked/anonymized data during routine operations; raw user data access requires documented justification)
  • Multi-layer identity masking before AI processing — all personally identifiable information (names and name variants, emails, SSNs, Medicare Beneficiary Identifiers, driver's license numbers, phone numbers, member IDs, street addresses, and more) is automatically found and replaced with anonymous placeholders through multiple layers of detection before any data is sent to our AI provider, and restored only within InsureClarity before display to you. Policy numbers are passed through unmasked because they improve document extraction accuracy and cannot identify a person without other linked personal information. Quasi-identifiers (ZIP codes, exact birth dates) are generalized to reduce re-identification risk.
  • Private document storage — your uploaded PDF files are stored in our own private Google Cloud Storage bucket, separate from the application platform, with direct browser-to-storage uploads and time-limited access links
  • Per-user field encryption — your sensitive fields (names, addresses, financial data, dates of birth, policy numbers) are individually encrypted with a unique key per user, protected by Google Cloud's hardware security module

Our hosting provider's SOC 2 Type II audit report is available under NDA via the Base44 Security Trust Center. While we implement enterprise-grade protections, no method of transmission over the internet is 100% secure.

Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you via email within 72 hours of becoming aware of the breach, or as otherwise required by applicable state law (which may require faster notification in certain jurisdictions). The notification will include the nature of the breach, the types of data affected, and the steps we are taking to address it.

Your Rights and Choices

Regardless of your state of residence, you have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your account and all personal information via self-service account deletion in Settings, or by contacting us
  • Export your data in a portable format via our built-in data export feature
  • Opt-out of marketing communications
  • Revoke MFA device trust at any time by logging out (which clears all trust tokens) or via account settings
  • Disable cookies through your browser settings

To exercise any of these rights, use the self-service tools in your account Settings, or contact us at admin@insureclarity.ai. We will respond within 45 days (or sooner if required by your state's law).

Account Deletion

You may delete your account at any time through the self-service deletion feature in Settings. When you delete your account, we permanently remove:

  • All uploaded insurance policies and documents
  • Your profile and demographic information
  • All AI conversation history
  • All active security records (MFA codes, trust tokens)
  • All alerts, referrals, support tickets, and onboarding data

Any active Stripe payment authorization is automatically cancelled. A deletion confirmation email is sent to your email address. Deletion is processed immediately and cannot be undone.

Retention exception: Standard operational security audit logs are retained for up to 3 years post-deletion for incident investigation purposes (per MHMD Act RCW 19.373 statute of limitations and CCPA/CPRA Cal. Civ. Code §1798.130(a)(2) 24-month lookback requirement), and affirmative consent compliance records are retained for 3 years post-deletion to satisfy regulatory record-keeping requirements under the MHMD Act and CCPA, as detailed in the Data Retention table above. These retained records contain only timestamped event metadata — not your documents, policies, or personal content.

Data Retention

We retain your information for as long as your account is active or as needed to provide you services. If you delete your account, all personal data is purged immediately as described above.

Data TypeRetention Period
Account data (profile, preferences)Until account deletion
Uploaded documents (policies)Until account deletion
AI analysis results & conversation historyUntil account deletion
Security & audit logs3 years (auto-purged; MHMD/CCPA statute of limitations)
MFA codes & trust tokens7 days (codes: 10 minutes)
Inactive accounts (expired access period, no login for 12+ months)Automated deletion notice sent; data purged 30 days after notice if no response
Anonymized / aggregated analyticsIndefinite (cannot identify you)

Specific Retention Rules

  • Uploaded PDF files: Stored in our private Google Cloud Storage bucket for as long as your account is active. Deleted immediately and irreversibly when you delete the record or your account.
  • AI analysis results: Stored as structured data in our database. Deleted when the parent policy record is deleted, or when your account is deleted.
  • Navigator conversations: Retained for 90 days of inactivity, then automatically purged by our cleanup automation. Active conversations persist for the life of your account.
  • Security & audit logs: Retained for up to 3 years (per MHMD Act and CCPA statute of limitations requirements), then permanently deleted. Logs under active litigation hold are exempt from automated cleanup and may be retained longer as required by law.
  • Consent records: Retained for the life of your account plus 3 years post-deletion for regulatory compliance (MHMD Act, CCPA record-keeping requirements).
  • Stripe payment records: Managed by Stripe per their retention policy. InsureClarity never stores credit card numbers. Our internal access status records are deleted with your account.
  • MFA codes: Expire and are deleted after 10 minutes. Device trust tokens expire after 7 days.

Inactive Account Policy: If your annual access period ends and you do not log in for 12 consecutive months, we will send a notification to your registered email address. If you do not respond or reactivate within 30 days, your account and all associated data will be permanently deleted. This ensures we do not retain personal data longer than reasonably necessary, consistent with data minimization principles.

Anonymized and Aggregated Data: We may retain and use anonymized, de-identified, or aggregated data that does not identify you personally for analytical purposes, service improvement, and industry benchmarking. This data cannot be used to re-identify you.

State-Specific Privacy Rights

California (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:

  • Right to Know: You may request information about the categories and specific pieces of personal information we have collected, the sources, our business purposes, and the third parties with whom we share it.
  • Right to Delete: You may request deletion of your personal information, subject to certain legal exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We recognize and honor the Global Privacy Control (GPC) browser signal as a valid opt-out of sale/sharing request under the CCPA/CPRA.
  • Right to Limit Use of Sensitive Personal Information: You may request we limit use of sensitive personal information to what is necessary to provide the Service.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

Categories of Personal Information Collected: Identifiers (name, email), financial information, insurance policy details, health-related information, internet activity information, device identifiers, and inferences drawn from the above. We do not sell any of these categories.

Virginia, Colorado, Connecticut, and Other States with Comprehensive Privacy Laws

Residents of states with comprehensive data privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Iowa, Tennessee, Indiana, Kentucky, Rhode Island, Delaware, Nebraska, New Hampshire, New Jersey, Maryland, and Minnesota) may have rights including:

  • Right to access, correct, and delete personal data
  • Right to data portability
  • Right to opt out of targeted advertising, sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects
  • Right to opt in before processing of sensitive data (where required by your state's law)
  • Right to appeal a denial of a privacy request

We honor these rights for all users regardless of state. Contact admin@insureclarity.ai or use the self-service tools in Settings. We will respond within the timeframe required by your state's law (typically 45 days, with extensions available where permitted).

Health Information & Sensitive Data

HIPAA Notice

InsureClarity is NOT a "covered entity" or "business associate" under the Health Insurance Portability and Accountability Act (HIPAA). When you voluntarily upload health-related insurance documents, you do so at your own discretion. You are solely responsible for determining whether it is appropriate to share such information with our Service.

Washington My Health My Data Act (MHMD Act)

InsureClarity maintains a separate, standalone Consumer Health Data Privacy Policy as required by the Washington My Health My Data Act (RCW 19.373). This policy details the categories of consumer health data we collect, how we use it, who we share it with (including specific affiliate names), and your rights regarding your health data — including the right to access, delete, and withdraw consent at any time. Before uploading health insurance documents, users are required to provide separate, affirmative opt-in consent for both (1) collection and (2) sharing of consumer health data.

Under various state privacy laws, health-related information and financial data are classified as "sensitive personal data." We process this data only with your explicit, affirmative consent (obtained separately before health document uploads) and solely for the purpose of delivering the Service. We recommend removing or redacting any information that is not necessary for the analysis you are seeking.

Right to Appeal

If we deny any privacy request, you may appeal by emailing admin@insureclarity.ai with "Privacy Appeal" in the subject line. We will respond to all appeals within 45 days with a written explanation of our decision. If you are unsatisfied with the outcome, you may file a complaint with your state's Attorney General office.

Right to Technical Accuracy Review of AI Analysis

If you believe an AI-generated analysis contains a technical error (e.g., incorrectly extracted data, a mathematical discrepancy, or a misread policy term), you may request a technical accuracy review. To protect your privacy and maintain the integrity of our identity masking pipeline:

  • Use the in-app "Flag for Review" feature on any policy detail or Navigator response. This submits a masked, anonymized technical support ticket referencing only your session log ID — your raw documents are never transmitted outside the platform's masking pipeline.
  • Do NOT email raw insurance documents or other unmasked personal files to admin@insureclarity.ai. Doing so would bypass the platform's 3-layer identity masking pipeline and expose your personal information in an unencrypted email channel.

Upon receiving a flagged review request, InsureClarity will check the software's processing logs, masking output, and extraction results using only the anonymized session data — without viewing or requesting your original unmasked documents. We will respond within 45 days with a technical finding.

Our AI does not make automated decisions that produce legal or similarly significant effects — all output is educational and informational. A technical accuracy review verifies that the software processed your document correctly; it does not constitute a coverage determination, professional insurance opinion, or legal analysis. For full details about our AI systems, see our AI Transparency page.

Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will promptly delete it. If you believe a child has provided us with personal information, please contact us at admin@insureclarity.ai.

International Users

The Service is operated from and designed for users in the United States. If you are accessing our services from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to the transfer of your information to the United States, which may have different data protection laws than your country of residence.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting the updated policy on this page with a new "Last updated" date. Your continued use of our services after notification constitutes acceptance of the updated policy. We encourage you to review this policy periodically.

Governing Law

This Privacy Policy is governed by the laws of the State of Delaware, without regard to its conflict of law provisions, consistent with our Terms of Service.

Contact Us

If you have questions or concerns about this Privacy Policy, our privacy practices, or wish to exercise your data rights, please contact us at:

Email: admin@insureclarity.ai

Privacy inquiries: admin@insureclarity.ai

Your Privacy Matters: At InsureClarity, we're committed to transparency and protecting your sensitive insurance information. We will never sell your data or share it with insurance companies. You always have full control over your data, including the right to export or permanently delete it at any time. For details on how our AI works and what it sees, read our AI Transparency page. For health-specific data protections, read our Consumer Health Data Privacy Policy.

InsureClarity LLC · Privacy Policy · Last updated September 1, 2026