Table of Contents
Contact Information
Information We Collect
Category | Examples | Source |
---|---|---|
Account Info | Name, username, email, password hash, Google OAuth ID | You |
Profile Details | Age, sex, location | You |
Insurance Docs | Uploaded EOBs, policies, claims | You |
Payment Info | Handled by Stripe | You / Stripe |
Analytics | IP address, location, session data | Google Analytics |
Device Data | Browser, OS, screen resolution, errors | Automatic |
AI Interactions | Inputs and feedback provided to AI | You / AI Providers |
How We Use Your Information
We use your data to:
- Provide and maintain the Service
- Analyze insurance documents with AI
- Authenticate users (email or Google)
- Process payments via Stripe
- Communicate with you
- Meet legal and regulatory obligations (HIPAA, GDPR, CCPA, etc.)
We do not sell your data.
Sensitive Information & HIPAA
If you upload Explanation of Benefits (EOBs), claims, or other medical data, we may process Protected Health Information (PHI). We comply with HIPAA and implement safeguards including:
- Role-based access
- AES-256 encryption
- Limited PHI access
- Business Associate Agreements (BAAs) with vendors when needed
AI Use Disclosure
Insurly offers AI-powered tools, including:
- Claim estimators
- Appeal generators
- Policy analyzers
These are powered by trusted AI providers (e.g., OpenAI) under data protection agreements. By using these features, you consent to your inputs being processed accordingly.
Note: AI outputs are informational only and do not constitute legal, medical, or financial advice.
User Rights (GDPR, CCPA, etc.)
Depending on your location, you may have the right to:
To exercise your rights, visit https://www.insurly.io/data-request or email us.
Data Retention & Deletion
- Your data is retained only while your account is active
- We delete all personal data 90 days after account deactivation
- Encrypted backups are purged within an additional 30 days
- You may request earlier deletion at any time
Do Not Track & GPC
We do not currently respond to "Do Not Track" (DNT) browser signals.
We do honor Global Privacy Control (GPC) signals where required by law.
Security
We protect your data with:
- TLS 1.2+ encryption in transit
- AES-256 encryption at rest
- Role-based access controls
- Regular security reviews and threat modeling
- Mandatory 2FA for staff access
Still, no method is 100% secure. Use the Service at your own risk.
International Transfers
If you use the Service outside the U.S., your data may be transferred to our U.S. servers. We use safeguards such as Standard Contractual Clauses (SCCs) to protect international data flows.
Children's Privacy
We do not knowingly collect personal information from anyone under 18 years old. If you believe we've done so, contact us and we will delete the data.
Third-Party Services
We rely on:
- Stripe for payment (Stripe Privacy)
- Supabase for user database (Supabase Privacy)
- Google Analytics for site analytics
- OpenAI and others for AI services
We do not sell or share your data with advertisers.
Changes to This Policy
We may update this Privacy Policy from time to time. We'll notify users of significant changes via email or an in-app alert.
Contact Us
Insurly, LLC
Need help with your data? Visit https://www.insurly.io/data-request
Social Logins
You may sign in using Google OAuth. If you do, we receive:
We only use this data for authentication and user management.