Privacy Policy

Last updated: September 5, 2026

ClaimOps is a product of Canaan Digital LLC. This Privacy Policy explains what information ClaimOps collects, how we use it, and the choices you have. By using the Service, you agree to the practices described below.

1. Information We Collect

2. How We Use Your Information

We use the information we collect to:

3. Data Sharing

We share data with the following categories of vendors strictly to operate the Service:

We do not sell your data. We do not share data with advertisers. We do not allow vendors to use your data for purposes other than operating the Service on our behalf.

ClaimOps personnel may access your account data when needed to provide support or review services. That includes the founder review, which runs automatically on a first supplement package before you send it to a carrier and does not have to be requested, and any other review services you request. Such access is on a least-privilege basis, is revocable by you at any time, and your data (including your clients' information) is treated as confidential.

4. Data Retention

Account and claim data is retained while your account is active. When you delete your account, your data is scheduled for deletion and permanently purged within 30 days, except where we are legally required to retain certain records (for example, tax invoices). During this 30-day window your account is immediately deactivated and inaccessible; the window exists to allow recovery from accidental or unauthorized deletions. Anonymized benchmark snapshots that contain no organization identifiers are retained indefinitely for product analytics.

5. Multi-Tenant Isolation

ClaimOps is built with strict multi-tenant isolation. Each organization's data is completely isolated from every other organization's data — no cross-tenant data access is possible. This isolation is enforced at the database query layer, not at the application layer alone, so a bug in our application logic cannot expose another tenant's data. Every query that touches organization-owned data is filtered by organization ID by default.

6. Security

We use industry-standard practices to protect your data:

7. Your Rights

You have the right to access, correct, export, and delete your data. To exercise any of these rights, contact us at contact@claimops.io. We will respond within 30 days. Depending on where you live, you may also have additional rights under applicable law (such as GDPR or the CCPA).

8. AI & Third-Party Processing

Claim data you upload (estimates, line items, document text, and photo metadata) is sent to the Anthropic Claude API for AI-assisted analysis — including estimate parsing, narrative generation, evidence matching, and quality review of generated packages. Anthropic's data handling and retention are governed by their own published policy: Anthropic Privacy Policy. If your organization needs AI features disabled (for example, due to internal policy or a client confidentiality requirement), contact contact@claimops.io and we will scope access for your organization. AI outputs are AI-assisted drafts; you are responsible for reviewing them before sending anything to a carrier.

Separately from AI processing, ClaimOps looks up public property records for the property on a claim, to fill in details such as year built, square footage, and permit history. The property address is sent to a third-party public-records provider for that lookup. This happens automatically when a claim is opened or its estimates are parsed. No estimate figures, documents, or photos are included in that request. If your organization needs this lookup disabled, contact contact@claimops.io.

9. Cookies & Analytics

We use a small number of first-party cookies. The session cookie that keeps you signed in is strictly necessary, HttpOnly, and Secure in production. We do not use third-party advertising or cross-site tracking cookies.

If you arrive from a link we sent you, claimops.io stores one more first-party cookie, named "co_ref", for 30 days. It holds only the short code from that link and any campaign tags the link carried, so that if you go on to create an account we can tell which message brought you. That code is then stored with your organization record. It is not strictly necessary, and it is not HttpOnly, because the signup form reads it in your browser. It contains no name, email address, or company name, it is readable only by our own site, and it is never sold or shared with anyone. Clearing your cookies removes it, and blocking it changes nothing about how the site works for you.

The marketing site (claimops.io) uses Vercel Analytics to measure aggregate traffic (pages visited, referrer, browser type). Vercel Analytics is cookieless and does not set any tracking cookies or build individual visitor profiles — it uses anonymized, aggregated measurements only. No data is sold or shared with advertisers.

10. Children's Privacy

The Service is intended for business users and is not directed at children under 13. We do not knowingly collect personal information from children. If we learn that we have, we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.

12. Contact

Privacy questions? Reach us at contact@claimops.io. For our legal terms, see our Terms of Service.