Skip to content

Trust

What happens to your policy after you upload it

No generalities. Every sentence here describes something the code does today.

Where your data does not go

We do not sell, share, or transfer policyholder or portfolio data to insurers, banks, or third-party agencies.

That is not a marketing promise: it is a clause in our contract with you (Terms of Service, §3), so it binds us legally.

The only exception is the one you create. If you connect your own advisor, they see exactly what you granted them — and you can take it back whenever you want.

We take no commission from insurance companies. We are paid only by subscription, so we gain nothing from what your analysis says.

Your documents

Your files are encrypted in transit (TLS) and at rest, and stored on infrastructure inside the European Union — specifically the eu-west-3 region (Paris).

There is no public link to a policy document. Every time one is opened, permission is checked again and a link is created that expires within minutes.

What the AI does — and what it does not decide

Analysis starts only after you give explicit consent. Without it, the document never leaves for a model provider.

The AI providers' data-processing terms do not permit your data to be used to train their models.

The AI reads your document and explains it. It does not decide which coverage gaps you have: rules do that, checking the data extracted from your policy, and every finding records which rule found it and what that rule read.

Who can see what

Every read of a policy goes through one checkpoint in the application, which asks the same question every time: do you own it, or has someone explicitly shared it with you? A CI test checks every route and action that can name a policy, and fails if a new one does not go through it.

An advisor's access ends with your relationship. If you end it, they stop seeing even the policies they uploaded for you themselves.

When one of our administrators opens your account, we record who opened it, whose account it was, and which category of information they saw. Administrator records are kept for five years; ordinary usage logs are deleted after twelve months.

Taking your data with you

You can download a copy of your data whenever you want, yourself, without asking anyone. It is a structured file, not screenshots.

A few things are not in that copy and are provided on request: payment-method details, session and security records, the history of who viewed your data, usage metering, and the free-text notes your advisor wrote about you. Their structured assessment of you is included.

Deletion you ask for with one click; a person carries it out and it completes within one month at the latest. Anything the law requires us to keep — invoices for five years, for example — remains in anonymized form.

Who is accountable

The controller of your data is Insurance Martech IKE, GEMI 188863359000, Tax ID (ΑΦΜ) 302659440, Chios Tax Office, registered seat Kalamoti, 82102, Chios, Greece.

For any question about your data: dpo@policywallet.gr