Privacy
Privacy Policy
Last updated August 16, 2026 · Consumer Clarity LLC, Prescott, Arizona
POLICYsplain reads an insurance policy you upload and explains what it actually covers. This page describes what we collect, why, and what happens to it — in particular the difference between your uploaded policy document, which is temporary, and the records about your progress and your order, which are not.
The short version. Your uploaded policy PDF is stored privately and deleted once your report is delivered — or within about 72 hours if you never finish. Your email address, the milestones of your progress, your order record and any support message you send are kept so the service can work and so we can stand behind what we sold you.
Your email address
You start by entering an email address. We trim spaces and lowercase it, and we store a keyed one-way representation of it so we can recognise the same address again without keeping a searchable list of plain addresses in that lookup column. The address itself is stored on your record so we can send your report.
We use it for three things: to recognise you when you come back and resume the right step, to deliver your report, and — if you buy one — to attach your order. We do not use it to build an advertising profile.
Recognising you is not verifying you
When you enter your address we create or find an internal record so we can remember where you were. That is continuity: it lets you close the tab, come back on another device, and carry on. It is not proof that you control the mailbox, and we do not treat it as proof.
We can separately verify a mailbox by emailing a six-digit code, and we use that where an action needs it. Ordinary browsing, uploading and checking out do not require it. We do not verify legal identity, and we do not ask for a password or an account.
Your uploaded policy document
When you upload a policy PDF it is checked, then stored in private storage under an address that is not guessable and not published. It is used to detect your policy type, extract the details you review, and produce your report.
- If your report is delivered, the source PDF is deleted at delivery, and your report records whether that deletion was confirmed.
- If you upload and never finish, an automated sweep removes abandoned uploads after about 72 hours.
- If a file fails our checks, it is not stored at all.
Deletion is requested and confirmed programmatically. Like any operation it can fail; when it does, the failure is recorded rather than hidden, and the file remains subject to the automated sweep. We describe this as scheduled and confirmed deletion rather than promising an exact moment.
What remains after the PDF is gone
Deleting the document does not delete everything, and we would rather say so plainly. We keep:
- Progress milestones — a short list of steps you reached, such as answering the policy-question, entering Find My Policy, completing an upload, or confirming a policy type. These let you resume the right step. They are milestones only: we do not record your clicks, scrolling, mouse movement or keystrokes in them.
- A record that an upload existed — an internal reference, its status and timestamps. When the document is deleted, that record is marked deleted and its pointer to the file is cleared.
- Your report and order records — including the findings we produced, the amount paid and the name shown on the policy. We keep these to support the purchase, to honour a returning-customer price, and because they are business records.
- Support messages you choose to send us, and our handling of them.
Payment
Payments are processed by Stripe. Card details are entered on Stripe’s systems and we do not receive or store full card numbers. We do receive and keep the information needed to know that an order was paid — a Stripe session reference, payment status, the amount, and the email address on the order.
Service providers
We use a small number of providers to run the service. Your uploaded policy, or text extracted from it, may be processed by:
- Anthropic — reads the policy to detect its type and extract the details you review and correct.
- LlamaIndex (LlamaParse) — used only as a fallback when a PDF cannot be read directly, for example a scanned document.
- Vercel — hosting, and the private storage that holds your PDF until it is deleted.
- Airtable — stores your record, progress milestones, orders and support cases.
- Postmark — sends your report, verification codes when used, and support notifications.
- Stripe — payment processing.
Each handles data under its own terms. We do not sell your personal information, and we do not share your policy contents or findings with advertisers.
Cookies and analytics
We set two cookies of our own. Both are HttpOnly, restricted to this site, secured in production, and last up to 30 days. One remembers which record is yours so you can resume; the other records that a mailbox has been verified, when that has happened. Neither is an advertising cookie.
We also use Google Analytics and Microsoft Clarity to understand how the site is used. Clarity records interaction and session-replay data for pages you visit. These are ordinary web analytics, and we would rather name them than claim we do not measure anything. They are not given your uploaded document or your findings.
Support messages
If you tell us something went wrong, we keep what you selected, what you typed, and our handling of it, so a person can review it. Please do not include passwords, Social Security numbers, card numbers, or other sensitive details — they are not needed to help you, and the form says so.
Security
Uploaded documents are held in private storage at unguessable addresses; internal storage references are not returned to your browser. Our cookies are signed and HttpOnly. Access to stored records is limited to the people operating the service. No system can be guaranteed completely secure, and we do not claim otherwise.
Children
POLICYsplain is intended for adults reviewing their own insurance and is not directed to children.
Your choices and contacting us
You can use POLICYsplain without creating an account or a password. If you would like to ask what we hold about you, request a correction, or ask us to delete your records, email support@policysplain.com from the address you used and we will respond. Some records — for example a completed order — may be retained where we need them for business or legal reasons.
Changes
If this policy changes we will update the date at the top of this page. This page describes how POLICYsplain works today; it is not legal advice.
← Back to home