This Privacy Policy explains what information ClaimOps collects, how we use it, and the choices you have. By using the Service, you agree to the practices described below.
1. Information We Collect
- Account information (name, email, organization name)
- Claim data you upload (insured information, property address, contractor and carrier estimates, photos, supporting documents)
- Usage data (feature usage, pages visited, anonymized analytics) collected via Vercel Analytics
- AI processing data (prompts and inputs sent to the Anthropic Claude API to generate comparisons, narratives, and matched evidence)
- Operational logs (request IDs, error metadata, performance metrics)
2. How We Use Your Information
We use the information we collect to:
- Provide and operate the Service (estimate comparison, supplement generation, etc.)
- Send essential transactional email (password reset, billing receipts, security alerts)
- Generate anonymized benchmark snapshots that contain no organization identifiers
- Improve product reliability and detect abuse
3. Data Sharing
We share data with the following categories of vendors strictly to operate the Service:
- Anthropic — for AI processing of estimate parsing, narrative generation, evidence matching, and quality review of generated packages (see §8 below)
- Email delivery providers — to send transactional email
- Hosting and infrastructure providers — for application hosting and storage
We do not sell your data. We do not share data with advertisers. We do not allow vendors to use your data for purposes other than operating the Service on our behalf.
ClaimOps personnel may access your account data when needed to provide support or review services you request — for example, founder review of a supplement package before you send it to a carrier. Such access is on a least-privilege basis, is revocable by you at any time, and your data (including your clients' information) is treated as confidential.
4. Data Retention
Account and claim data is retained while your account is active. When you delete your account, we purge your data within 30 days, except where we are legally required to retain certain records (for example, tax invoices). Anonymized benchmark snapshots that contain no organization identifiers are retained indefinitely for product analytics.
5. Multi-Tenant Isolation
ClaimOps is built with strict multi-tenant isolation. Each organization's data is completely isolated from every other organization's data — no cross-tenant data access is possible. This isolation is enforced at the database query layer, not at the application layer alone, so a bug in our application logic cannot expose another tenant's data. Every query that touches organization-owned data is filtered by organization ID by default.
6. Security
We use industry-standard practices to protect your data:
- Encryption in transit (HTTPS/TLS) and at rest
- HttpOnly authentication cookies with strict same-site policy
- CSRF protection on state-changing requests
- Per-IP rate limiting and request logging
- Audit logs for sensitive actions
- Limited internal access on a least-privilege basis
7. Your Rights
You have the right to access, correct, export, and delete your data. To exercise any of these rights, contact us at contact@claimops.io. We will respond within 30 days. Depending on where you live, you may also have additional rights under applicable law (such as GDPR or the CCPA).
8. AI & Third-Party Processing
Claim data you upload (estimates, line items, document text, and photo metadata) is sent to the Anthropic Claude API for AI-assisted analysis — including estimate parsing, narrative generation, evidence matching, and quality review of generated packages. Anthropic's data handling and retention are governed by their own published policy: Anthropic Privacy Policy. If your organization needs AI features disabled (for example, due to internal policy or a client confidentiality requirement), contact contact@claimops.io and we will scope access for your organization. AI outputs are AI-assisted drafts; you are responsible for reviewing them before sending anything to a carrier.
9. Cookies
We use a small number of strictly necessary cookies, including a session cookie that keeps you signed in. These cookies are HttpOnly and Secure in production. We do not use third-party advertising or tracking cookies.
10. Children's Privacy
The Service is intended for business users and is not directed at children under 13. We do not knowingly collect personal information from children. If we learn that we have, we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact
Privacy questions? Reach us at contact@claimops.io. For our legal terms, see our Terms of Service.