Skip to content

Privacy and data rights

Privacy Policy

This policy explains how ClaimParrot collects, uses, shares, protects, exports, and deletes personal data, including insurance policy files, claim documents, and AI audit records.

Last updated July 21, 2026

Information we collect

Account data: name, email address, avatar, authentication identifiers, subscription tier, billing status, and support communications.

Claim data: policy documents, denial letters, EOBs, receipts, photos, contractor quotes, incident descriptions, claim values, deadlines, generated letters, chat messages, and delivery records.

Usage and device data: product events, feature-flag exposure, performance telemetry, error reports, IP-derived approximate location, browser type, and session diagnostics used to keep the service secure and reliable.

Pilot inquiry data: business contact name, work email, organization, website, role, team size, denial-volume range, workflow bottleneck, plan interest, and referral source. The pilot form is not designed to receive patient, member, diagnosis, claim, or other protected health information.

Sensitive insurance and health information

ClaimParrot may process sensitive personal information when users upload health, disability, dental, property, or accident records. We use this information only to provide claim analysis, letter generation, reminders, delivery, compliance logging, security, and support.

Do not upload another person's medical, financial, or insurance information unless you have authority to do so.

How we use AI

Uploaded documents and claim details may be sent to contracted AI providers to extract text, summarize policy terms, estimate damage, draft letters, and power contextual chat.

AI prompts and responses are logged in an audit table for product safety, regulatory traceability, dispute investigation, abuse prevention, and quality review. We do not use AI output to guarantee a claim outcome.

Legal bases for GDPR

For users in the European Economic Area, United Kingdom, or Switzerland, we process personal data based on contract performance, consent, legitimate interests, legal obligations, and, where applicable, explicit consent for sensitive data.

Users may withdraw consent where processing is based on consent, but withdrawal may limit features that require document analysis, communications, or reminder delivery.

CCPA and CPRA rights

California residents may request access to categories and specific pieces of personal information, correction, deletion, portability, restriction of sensitive personal information use, and information about sharing.

ClaimParrot does not sell personal information. If future analytics or advertising activity is treated as sharing under California law, we will honor opt-out preference signals where required.

GDPR rights

Eligible users may request access, rectification, erasure, restriction, portability, objection to certain processing, and review of decisions based solely on automated processing where applicable.

Users may also lodge a complaint with their local supervisory authority. We ask that you contact us first so we can try to resolve the concern quickly.

Sharing and subprocessors

We share data with service providers needed to operate ClaimParrot, including hosting, database, storage, authentication, payments, email, SMS, fax, physical mail, analytics, error monitoring, logging, and AI providers.

We may disclose information if required by law, to protect users or the service, to investigate abuse, or as part of a merger, financing, acquisition, or similar corporate transaction with appropriate safeguards.

Retention, export, and deletion

Users can request a data export from the product. Claim files are retained while the account is active and for a reasonable period afterward unless deletion is requested or a longer retention period is legally required.

Deletion requests anonymize personal identifiers where possible. AI audit logs, payment records, fraud-prevention records, and legal compliance logs may be retained when required for security, financial, or regulatory reasons.

Unconverted pilot inquiries are assigned an 18-month retention date and are automatically deleted after that date so ClaimParrot can follow up on the requested business conversation without retaining prospect data indefinitely.

Security

We use authentication controls, role-based access, Supabase row-level security, scoped storage paths, encrypted transport, audit logging, rate limits, and production monitoring.

No system is perfectly secure. Users should keep account credentials private and contact security@claimparrot.com if they suspect unauthorized access.

Contact

Privacy requests can be sent to privacy@claimparrot.com. We may need to verify your identity before exporting, correcting, or deleting account data.

Questions or requests?

Email privacy@claimparrot.com for privacy requests or legal@claimparrot.com for terms and disclaimer questions.