Privacy Policy
Nexture AI LLC
Effective Date: October 8, 2026
This document was last reviewed and updated on the effective date above.
Brand notice. This service is offered publicly under the name MiaSure. "MiaSure" is a trade name of Nexture AI LLC, the Wyoming limited liability company that operates the Service and is your contracting party under this document. Any reference herein to "Nexture AI," "Nexture AI LLC," "the Company," "we," "us," or "our" means Nexture AI LLC operating as MiaSure.
This Privacy Policy describes how Nexture AI LLC ("Nexture AI," "we," "us," or "our") collects, uses, processes, stores, and discloses your personal information when you use the MiaSure platform and related services (the "Service"). The Service is offered only to people and businesses located in the United States and its territories. Your privacy is important to us, and we are committed to protecting your personal information.
By accessing or using the Service, you agree to the collection, use, and disclosure of your information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
1. Introduction & Your Commitment to Privacy
Nexture AI is dedicated to providing an innovative platform for insurance brokers and buyers while maintaining high standards for privacy and data security. This Privacy Policy explains our practices concerning the information we collect and process, particularly Nonpublic Personal Information (NPI) as defined by the Gramm-Leach-Bliley Act (GLBA) and personal information under various U.S. state privacy laws.
Important Note — Health and Other Sensitive Information in Documents
The Service is designed for Property & Casualty (P&C) and related commercial insurance documents. Some documents that users upload — for example, workers' compensation loss runs, accident & health or employee-benefits documents, and driver or vehicle schedules — may incidentally contain health information, driver's license numbers, or dates of birth. When they do, we process that information only to provide the Service to the user who uploaded it, and we store it encrypted at rest as described in Section 9. Nexture AI is not a covered entity under the Health Insurance Portability and Accountability Act (HIPAA), and we do not act as a business associate of any covered entity unless we have signed a business associate agreement with it. Unless such an agreement is in place, you must not use the Service to store or process Protected Health Information (PHI) on behalf of a HIPAA covered entity.
GLBA Compliance: As a service provider to financial institutions (insurance brokers), Nexture AI maintains an information security program and privacy practices consistent with GLBA requirements, including:
- Limiting the collection and use of NPI to what is necessary to provide and improve the Service.
- Not disclosing NPI to nonaffiliated third parties except as permitted under GLBA (e.g., to service providers under contract, as required by law, or with your consent).
- Maintaining administrative, technical, and physical safeguards to protect NPI as described in our Security Statement.
- Providing this privacy notice at account opening and annually thereafter for the duration of the customer relationship, as required by Regulation P.
2. Your Role as Data Controller/Processor
2.1. For Insureds: When you, as an individual insured, upload your own documents and use the Service for your personal insurance management, Nexture AI acts as the "Controller" of your personal information, determining the purposes and means of processing your data.
2.2. For Brokers: When you, as an insurance broker or firm ("Broker User"), upload documents containing your clients' information, Nexture AI acts as a "Service Provider" or "Processor" for your clients' Nonpublic Personal Information (NPI). In this context, the Broker User is the "Financial Institution" or "Controller," and you retain primary responsibility for your clients' NPI. Our processing of such NPI is governed by our Terms of Service and, where one has been executed between you and Nexture AI, a Data Processing Addendum or GLBA Addendum.
2.3. For Clients Using a Broker's Portal: An insurance broker may make the Service available to its own clients through a client portal presented under the broker's name or brand, which may be embedded in the broker's own website. If you use such a portal, the broker is responsible for your personal information, and Nexture AI (operating as MiaSure) processes it as the broker's service provider, on the broker's instructions and to provide the portal to you. The broker's own privacy notice governs how the broker uses your information; questions about it, and requests to access or delete it, should go to the broker, and we will assist the broker in responding. This Privacy Policy describes how we handle the information while we process it for the broker, including the account we create for you so that you can sign in.
2.4. For Recipients of Shared Documents: When a user shares a document with you through the Service, we process your name, email address, and the record of what was sent to you and opened (Section 3.3a) on behalf of that user. If you create an account to accept the document, the accepted copy is held in your own account and this Privacy Policy applies to it as it does to any other account.
3. Information We Collect
We collect various types of information, including personal information, to provide and improve our Service.
3.1. Information You Provide Directly:
- User Profile Data: When you register for an account, we collect your name, email address, physical address, phone number, company name (for Broker Users), job title (for Broker Users), and login credentials.
- Communications: Records of your correspondence with us, such as customer support inquiries or feedback.
3.2. Information from User-Uploaded Documents: When you upload insurance documents (e.g., policies, binders, endorsements, quotes) to the Platform, our Service processes the content of these documents. This includes, but is not limited to, extracting and storing:
- Insurance Policy Data: Named insureds, carriers, policy numbers, coverage limits, deductibles, premiums, effective dates, types of coverage, insured property addresses, vehicle identification numbers (VINs), driver information (including names, dates of birth, driver's license numbers), loss history, and other details contained within the insurance documents you upload. Where a document incidentally contains health information (for example, injury descriptions in a workers' compensation loss run), that information is processed as part of the document; see the Important Note in Section 1.
- No SSNs: As stated in our Terms of Service, we expressly prohibit the upload of Social Security Numbers (SSNs) and do not intentionally collect or store them. Nexture AI disclaims all liability for SSNs uploaded in violation of our Terms.
Prohibited Data: Users must not upload documents containing Social Security Numbers. See our Terms of Service for full details on prohibited content.
3.3. Information Collected Automatically: When you access or use the Service, we may automatically collect certain information about your device, browsing actions, and patterns, including:
- Usage Data: Details of your access to and use of the Service, including traffic data, location data, logs, and other communication data and the resources that you access and use on the Service. This includes interactions with AI tools (e.g., chatbot queries, summaries generated).
- First-Party Usage Analytics: We operate a first-party analytics tracker that records how you use the Service — the pages you view, the features you use, the search query terms you enter within the platform, and the exports you generate — together with device and browser characteristics (a "fingerprint" consisting of your user-agent string, browser language, screen and viewport dimensions, and timezone) and a per-session identifier stored in your browser's session storage. This information is tied to your account and stored in our own systems. We use it solely on a first-party basis to understand product usage, diagnose issues, and improve the Service. It is not sold and is not used for cross-site or cross-context behavioral tracking or advertising.
- Device Information: Information about your computer and internet connection, including your IP address, operating system, browser type, and unique device identifiers.
3.3a. Document Access Records: When a policy, a deliverable, or a document we produced is opened, we record that it was opened: which document, which screen, which page, the time, and who opened it. For someone signed in to an account we record their account identifier and not their network address. For a recipient opening a link or a client portal, where there is no account, we record the network their request came from (for example 203.0.113.0/24) rather than their individual address, and we do not record a more precise location. Where a file is delivered we also record a cryptographic fingerprint of the exact bytes sent, so it can later be shown which version was received. This record exists because it is the broker’s professional-liability evidence of who was shown what, and it is kept on the schedule in Section 9.
3.3b. Voice Conversations, Meetings, Recording, and Transcription:
- Talk to Mia (voice). Mia is an AI assistant, not a person. When you choose to talk to Mia by voice, your voice is streamed in real time to the third-party AI voice and speech providers listed on our Sub-processors page so that Mia can understand and answer you. The transcript of the conversation is saved to your account as part of your Mia chat history. We do not store the audio recording of the conversation. The voice service provider that runs the session keeps its own copy of the transcript. When you close your account we delete the transcripts we hold and we ask the voice service provider to delete your meeting and interview records, but we cannot confirm what its deletion removes, and it may retain a copy. If you want to ask about that copy, contact us at [email protected].
- Meeting assistant and AI voice interviews (coming soon). Features in which Mia joins a third-party meeting (for example, a Microsoft Teams meeting) as an AI notetaker, or conducts an AI voice interview with a person you invite, are not yet available in the production Service. When they become available, the following will apply, and we will update this Policy before launch if anything differs: where a user connects a calendar account and enables the meeting assistant for a meeting, the assistant joins that meeting and a transcript is produced from the audio by a third-party speech-to-text provider. We store the transcript, a summary, and the identities of the people in the meeting (names and email addresses from the calendar invitation) so the meeting can be linked to the correct account and the right people can see it. We do not store the meeting audio or video. The assistant is not enabled unless the user turns it on for that meeting.
- Notice and consent are the responsibility of the account holder who enables recording or transcription: several U.S. states require the consent of every participant before a conversation is recorded or transcribed, and the account holder must give notice and obtain it, as our Terms of Service require. We provide the tools; we do not obtain consent on anyone’s behalf.
- Retention. Meeting transcripts and summaries, and transcripts of voice conversations with Mia, are kept for the period stated in Section 7 and are deleted sooner when the associated policy or account is deleted. This applies to the copies we hold; when you close your account we ask the voice service provider to delete its own copy of a Talk to Mia transcript, but we cannot confirm what its deletion removes and it may retain a copy (see the Talk to Mia paragraph above).
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential / Session | Authentication, security, and core platform functionality | Session (cleared on browser close) or up to 24 hours |
Essential authentication and session cookies are the only cookies the Service sets, and they are strictly necessary for the platform to function. We do not set analytics or advertising cookies, and we do not allow third parties to set them. Our usage analytics are gathered through a first-party tracker (described in Section 3.3) and through Plausible, a cookieless, aggregate page-analytics service that runs across the site except on a short list of excluded areas (for example shared-document pages, password-reset and set-password pages, the client-portal embed, and administrative and developer pages), where it does not load or report. On the pages where it runs, the query string is removed from every address it records and identifier-like path segments are replaced with a placeholder. Your interface preferences (e.g., layout and theme) are saved in your browser's local storage on your own device — not in cookies. You can control or clear browser storage at the individual browser level. Disabling essential cookies may prevent you from using the Service.
No Sale, No Sharing for Advertising, No Tracking Technologies: We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined in the California Consumer Privacy Act. The Service contains no advertising pixels or tags, no third-party analytics or advertising cookies, no session-replay or screen-recording tools, and no third-party chat widgets. We have not sold or shared personal information in the preceding 12 months, and we do not knowingly sell or share the personal information of consumers under 16.
Global Privacy Control (GPC): We honor the Global Privacy Control signal as a valid request to opt out of the sale and sharing of personal information for the browser or device that sends it (and, where you are signed in, for your account). Because we do not sell or share personal information, honoring the signal does not change how the Service works for you.
Do Not Track (DNT) Signals: Some browsers transmit "Do Not Track" signals to websites. Because there is no common industry standard for interpreting DNT signals, we do not currently alter our data collection and use practices based on DNT signals. We will update this policy if a uniform standard is established.
4. How We Use Your Information
We use the information we collect for various purposes, primarily to provide, maintain, and improve our Service, and for legitimate business operations.
4.1. To Provide the Service:
- To operate and maintain the Platform, including storing your documents and account information.
- To enable AI functionality such as smart sorting, document summarization, policy comparison, and chatbot responses.
- Mia’s memory: Mia, our AI assistant, keeps a lasting record of what it learns from your activity on the Service — including your conversations with it, your preferences, your role and focus areas, and the documents and actions you take — and uses that record to personalize its answers in later conversations. Mia learns these items automatically as you use the Service; it does not ask each time. You can see and delete remembered items at any time under Settings › Mia, in Memory.
- To process payments you make for the Service (via our third-party payment processor).
- To communicate with you about your account and provide customer support.
- Support access (off by default, with your consent): Only where you have explicitly enabled it in your account settings, authorized Nexture personnel may access your account — including by securely accessing the Service as your account in a read-only support session — solely to operate, troubleshoot, and support the Service. This access is disabled by default, restricted to authorized personnel, time-limited, and recorded in an audit log, and you can enable or disable it at any time in your account settings.
4.2. To Measure and Improve the Accuracy of the Service: We use information in the following specific ways to measure and improve how accurately the Service reads insurance documents. You can opt out of the uses marked "(opt-out available)" as described in Section 6.
- Your corrections as evaluation records (opt-out available): When you or your team correct a value the Service extracted from a policy, we keep the corrected value, together with the policy it belongs to, as an evaluation record (sometimes called "ground truth"). These records are not anonymized: they are stored linked to the policy and your account, encrypted at rest under your account's keys, and used by our staff and systems to measure the Service's accuracy and to test changes to it before release. They are deleted when the policy is permanently deleted or your account is closed.
- Internal quality review: A small number of documents may be reviewed by authorized Nexture AI personnel, or processed by our evaluation systems, to investigate errors and check the quality of results. This review is limited to personnel who need it, is subject to access controls, and is carried out only for quality and evaluation purposes.
- Aggregated, de-identified benchmarks (opt-out available): We compute statistics across many customers' policies — for example, typical limits or premium ranges for a line of coverage within an industry group and period. These statistics contain no names, policy numbers, or account identifiers, and a statistic is not produced for any group of fewer than five policies. We maintain and use such information only in de-identified form, we will not attempt to re-identify it, and we require anyone we share it with to make the same commitment, as provided in California Civil Code § 1798.140(m).
- Shared forms library and platform defect descriptions (opt-out available): the generic, account-free contributions described in Section 6.
- No fine-tuning of third-party models: We do not use your documents or data to train or fine-tune any third-party AI model, and we do not authorize our AI providers to use it to train their own models (see Section 5.1).
- Analytics: To analyze usage patterns and improve the user experience, functionality, and performance of the Service. This is done on a first-party basis using our own usage-analytics tracker (described in Section 3.3), the cookieless, aggregate Plausible service, and Sentry for error and performance diagnostics (with personal information scrubbed before transmission and no session recording or replay). We use this information only to operate and improve the Service — never to sell your data or to track you across other sites.
4.3. For Security & Compliance:
- To monitor, detect, and prevent security incidents, fraud, and other malicious or illegal activities.
- To comply with our legal obligations, including under the Gramm-Leach-Bliley Act (GLBA) and various U.S. state data privacy and breach notification laws.
- To enforce our Terms of Service.
5. How We Share Your Information
Nexture AI does not sell your personal information or share it with third parties for their independent marketing or cross-context behavioral advertising purposes. We only share your information in the following limited circumstances:
5.1. With Service Providers (Our Sub-processors): We engage third-party service providers to perform functions on our behalf and help us operate the Service. We disclose personal information to them only for those business purposes, under terms that require them to protect it. The categories are: infrastructure and hosting; database, storage, and email delivery; authentication; AI language-model providers; AI voice and speech-to-text providers; document text-recognition (OCR) providers; data-enrichment and web-research providers; cloud-storage and email connectors you choose to connect; billing; error monitoring; web-font delivery (when a page loads typefaces from Google's font servers, your browser sends your IP address and standard request headers to Google); and security and abuse prevention.
The list of our sub-processors is maintained in one place: miasure.com/legal/sub-processors. For each provider it states the provider's role, the data it receives, where it processes that data, the terms we use it under, and what those terms say about training on and retaining the data. AI providers process the text of your documents and your questions to Mia in order to return a result; some of them may retain inputs and outputs for a limited period for abuse monitoring under their terms, as stated for each provider on that page. We give at least 30 days' advance notice, by email and in the Service, before adding a sub-processor that will receive customer data, as described on that page.
5.2. As Required by Law: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order, subpoena, or government agency request).
5.3. To Protect Our Rights: We may disclose your information when we believe it is necessary to protect the rights, property, or safety of Nexture AI, our users, or others.
5.4. Business Transfers: In the event of a merger, acquisition, sale of assets, or other corporate change, your personal information may be transferred to the acquiring entity, subject to their commitment to similar privacy protections. We will notify you via email and/or a prominent notice on the Service of any such change in ownership or control of your personal information.
5.5. At Your Direction: We disclose information to the people you choose to share it with — for example, when you share a document or deliverable, send a message through the Service, or give colleagues in your firm access to your work — and, where you use a broker's client portal (Section 2.3), to that broker.
5.6. Third-Party AI Assistants You Connect: You can connect your account to a third-party AI assistant or application (for example, Claude or ChatGPT). When you do, that assistant can request information from your account, and we return the information it asks for, at your direction. Information delivered to that assistant is received by its provider, and its use, retention, and disclosure are governed by that provider's terms and privacy policy, not by this Policy. You can revoke a connection at any time from your account.
6. AI & Your Data (Transparency & Your Control)
AI-Generated Outputs: The Service uses artificial intelligence to generate document summaries, policy comparisons, data extractions, and chatbot responses. All AI-generated outputs are presented as aids and should be reviewed by qualified professionals before reliance. Mia is identified in the Service as an AI assistant. Documents the Service prepares from its AI reading of your policies, such as a Summary of Insurance, a comparison or a report, show a visible statement that they were prepared with AI assistance, on the page and in their PDF, Word and Excel files. Letters and emails that go out over a person's signature, such as a Broker of Record letter, do not show that statement. All of these files carry machine-readable information identifying them as AI-assisted (for example, in the metadata of exported PDF, Word, and Excel files), and images the Service generates are labeled as AI-generated.
No Automated Decision-Making: Nexture AI does not use automated decision-making or profiling that produces legal or similarly significant effects on you. All AI outputs are informational tools intended to assist human decision-making, not replace it.
Platform Improvement: Section 4.2 describes exactly how we use information to measure and improve the Service. We do not fine-tune or train any third-party AI model on your data.
Your Right to Opt Out of Platform Improvement: You can opt out of the uses marked "(opt-out available)" in Section 4.2.
- How to Opt-Out: To exercise this right, please contact us at [email protected], or use the in-product controls below.
- Platform-improvement setting: The Help improve MiaSure setting, under Settings → Mia, lets you opt out of platform improvement. When it is turned off, your corrections are no longer kept as evaluation records and your data is excluded from the cross-customer benchmarks described in Section 4.2. It does not affect the checks we run on your own results for your benefit, which are part of providing the Service to you.
- In-Product Controls: In addition, two switches in your account under Settings → Mia — each on by default — control two specific, generic contributions your account makes to platform improvement:
- "Contribute to the shared forms library" — We build generic knowledge about standard insurance forms (what a form does and what it changes) and share it across accounts so that every policy is read more accurately. Nothing about your policies enters that library: no named insured, no policy number, no premium, no policy period, and no location. Every entry must pass a genericity check enforced in our code before it is written, and an entry we cannot describe generically is refused rather than shared. Turning this off keeps your documents out of it entirely; you continue to benefit from what other customers have contributed.
- "Help us fix the platform's own mistakes" — When we check a finished summary or comparison and find a flaw in how we produced it, we keep a description of the flaw itself — which rule broke, and where in our software — so that we can correct it for every customer. Only that generic, account-free description of the defect ever leaves your account, and it must pass the same kind of fail-closed check described above before it does: a description we cannot generalize is discarded, not shared. Checking your own deliverables for your own benefit is part of delivering the Service to you and is not affected by this switch.
- Effect of Opt-Out: An opt-out applies from the time you make it. Evaluation records already made from your corrections remain linked to your policies and are deleted when those policies are permanently deleted or your account is closed, or earlier on request to [email protected]. Aggregated statistics already computed before your opt-out cannot be separated back into their inputs, but they contain no information that identifies you, your firm, or your clients.
7. Data Retention & Deletion
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, to provide the Service, to comply with our legal obligations (including GLBA and state record-keeping requirements), resolve disputes, and enforce our agreements. Specific retention periods are as follows:
| Data Category | Retention Period |
|---|---|
| Account profile data | Duration of account. After the account is closed, only the limited closure record described below (your email address and when the account was opened and closed) is kept, for up to 3 years |
| Uploaded documents & extracted policy data — Trash | Held indefinitely until you choose to permanently delete or restore |
| Uploaded documents & extracted policy data — Permanently deleted | Purged from active systems within minutes; aged out of backups on the next rotation cycle (within 90 days). Published or sent deliverables made from the document are kept as business records (see below) |
| Published or sent deliverables (for example, a Summary of Insurance shared with a client) | Kept as business records until you permanently delete them individually or close your account, including after the document they were made from is permanently deleted |
| Mia chat history (your written conversations with Mia) | Retained for the life of your account unless you delete a conversation; deleted when you close your account. There is no automatic deletion after a fixed period. |
| Transcripts of voice conversations with Mia (Talk to Mia) | Part of your Mia chat history: retained for the life of your account so Mia can refer back to them, unless you delete the conversation; the copy we hold is deleted when you close your account. The voice service provider keeps its own copy; on account closure we ask it to delete that copy but cannot confirm what its deletion removes (Section 3.3b). There is no automatic deletion after a fixed period. |
| Meeting transcripts and summaries (when the meeting assistant is available) | 12 months from the meeting, or sooner if you delete them or the associated policy, or close your account |
| Mia’s memory (items Mia has learned about you) | Kept until you delete them under Settings › Mia, in Memory, or close your account |
| Evaluation records made from your corrections (Section 4.2) | Kept while the policy they relate to is in your account; deleted when that policy is permanently deleted or your account is closed |
| Usage and analytics data (first-party usage events and activity logs) | Up to 90 days, then automatically deleted |
| In-app notifications | Up to 90 days, then automatically deleted (sooner once dismissed) |
| Payment and billing records | Kept for as long as required for tax, accounting, and regulatory purposes (generally at least 7 years). When you close your account they are kept, but their link to your policies is removed. |
| Operational and error logs | Most are deleted automatically after between 7 and 90 days. Records of processing jobs and AI usage (which hold identifiers, timings, and costs, not document content) and a log of security-relevant account events are kept for operational, billing, security, and fraud-prevention purposes and are not automatically deleted. |
| Document access records (who opened a policy or a deliverable, and when) | 7 years from the access. Suspended while a legal or litigation hold is in place. This is a professional-liability record: the record of who was shown what is the broker’s evidence. |
| Backup copies | Within 90 days of deletion from active systems (on the next backup rotation cycle) |
- Trash (soft delete): Moving a document to Trash hides it from your active library and from every list, search, deliverable, calendar event, and notification that references it. Trashed items do not auto-expire — they remain available for restore until you choose to permanently delete them.
- Permanent Deletion (Delete Forever): When you choose Delete Forever, our cascade-deletion routine removes the Document and the records made from it from our active systems within minutes. This covers the Document record, its draft deliverables, all extraction tables, the canonical policy snapshot, the encrypted PDF and OCR transcript in S3, page-image artifacts, indexed vector-store chunks, shares + share-conversation history, review-session snapshots, workspace and view memberships, calendar events, notifications, and deliverable edit-request audit trails. Published or sent documents are kept as business records. A deliverable you published or sent (for example, a Summary of Insurance shared with a client) is not removed when the document it was made from is permanently deleted; it stays in your Deliverables, marked as made from a deleted document, and is removed when you permanently delete it individually or close your account. See our Security Statement § 4.5 for the full cascade detail.
- Backups: MongoDB Atlas point-in-time backups are governed by their retention policy (maximum 90 days), and permanently-deleted data ages out of them on the next rotation cycle. Our S3 storage has versioning enabled: when a stored file is deleted, the deleted object becomes a noncurrent version that a bucket lifecycle rule removes within 90 days. The customer-controlled key revocation feature described in Security Statement § 3.1.1 will, once shipped, enable cryptographic destruction of data including backups.
- Deleting Your Account Yourself: You can close your account from inside the Service, under Settings › Security › Your data › Delete my account (on an insured account, also on the Your data page). Before anything is deleted, we first check that your account can be closed this way, then ask you to confirm it is you by entering your current password — and, if you use an authenticator app, its current code — and to type “delete my account”. An account cannot be closed from a support session. When you confirm, our account-erasure routine deletes your account profile, the documents in your account and the policy data extracted from them, your deliverables (published or sent ones included), your Mia chat history and Mia’s memory, and the other records tied to your account, and removes the stored files from our active systems. Copies you shared that a recipient has already accepted are in the recipient’s own account and are not deleted. Payment and billing records are kept for the period stated in the table above. Closing your account cannot be undone, so you may wish to download a copy of your data first (see Section 8). If the deletion cannot be completed, the Service tells you so rather than reporting success; you can then contact us at [email protected].
- Accounts That Must Be Closed by Email: Some accounts cannot be closed from inside the Service, because closing them would remove records that other people rely on or would leave a charge unsettled: accounts that belong to a firm or an organization on the Service (including a firm’s owner and administrators), MiaSure administrator accounts, and accounts with a recurring billing plan or a paid balance. An account also cannot be closed while a copy of its data is still being prepared. In each case the Service tells you why. To close such an account — or if you prefer not to use the in-app option — email [email protected] from the address you sign in with, and we will verify your identity before acting on the request.
- Account Deletion: If you close your account entirely, we will retain limited account metadata (email, account creation/closure timestamps) for up to three (3) years to comply with legal obligations, prevent fraud, and resolve disputes, after which it will be securely deleted or anonymized. When you close your account yourself, the email address in this record is stored encrypted.
- Legal Compliance: We may retain specific records for longer periods if required by law (e.g., GLBA, state insurance regulations) or for legitimate business interests such as auditing or maintaining business records (e.g., payment records held for 7 years).
- Platform-Improvement Data: Evaluation records made from your corrections are deleted with the policy or account they relate to. Aggregated, de-identified statistics (Section 4.2) are not deleted, because they contain no information that identifies you.
8. Your Privacy Rights (U.S. State-Specific)
Depending on your state of residency, you may have specific rights regarding your personal information under laws such as the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Utah Consumer Privacy Act (UCPA), Connecticut Data Privacy Act (CTDPA), and other applicable state laws.
8.1. Notice at Collection (California). The table below describes, for the preceding 12 months and going forward, the categories of personal information we collect, where it comes from, why we collect it, the categories of recipients to whom we disclose it for a business purpose, and how long we keep it. Where the Service is provided to you by a broker (Section 2.2 and 2.3), we collect and use this information on the broker's behalf. We do not sell or share personal information (Section 3.4).
| Category of personal information | Sources | Business purposes | Categories of recipients | Retention |
|---|---|---|---|---|
| Identifiers — name, email address, postal address, phone number, account identifier, IP address | You; your firm or broker; people who share documents with you; your device | Providing and securing the Service; account administration; support; communications; restricting access to the United States | Service providers (hosting, database, authentication, email delivery, security); people you choose to share with; your firm's administrators | Life of the account; a closure record for up to 3 years after closure (Section 7) |
| Customer records and insurance information — named insureds, policy numbers, coverage, premiums, addresses, loss history, and other content of uploaded documents | You; your firm or broker; cloud-storage or email accounts you connect | Providing the Service (extraction, deliverables, Mia's answers); measuring and improving accuracy (Section 4.2) | Service providers (hosting, storage, AI language-model and OCR providers, data-enrichment providers); people you choose to share with | Until you permanently delete it or close your account (Section 7) |
| Commercial information — Credit purchases and usage of paid features | You; our payment processor | Billing; accounting; fraud prevention | Payment processor; professional advisers | As required for tax and accounting (generally at least 7 years) |
| Internet or other electronic network activity — usage events, device and browser information, document access records | Your device; your use of the Service | Operating, securing, and improving the Service; the document access record kept as the broker's evidence (Section 3.3a) | Service providers (hosting, error monitoring) | Usage events up to 90 days; document access records 7 years (Section 7) |
| Approximate location — country derived from IP address; for link recipients, the network a request came from | Your device | Restricting access to the United States; security; the document access record | Service providers (hosting, security) | Country is used at the time of the request; network as part of the document access record (7 years) |
| Audio and electronic information — your voice while you talk to Mia (streamed, not stored); transcripts of voice conversations and, when available, meetings | You; meeting participants | Providing voice and meeting features | AI voice and speech-to-text providers; hosting providers | Voice conversation transcripts: life of the account unless you delete them (our copy; we ask the voice service provider to delete its own copy on account closure but cannot confirm it does, Section 3.3b); meeting transcripts: 12 months (Section 7); audio is not stored by us |
| Professional information — company, job title, firm membership | You; your firm | Providing the Service; account administration | Service providers (hosting, database) | Life of the account |
| Inferences — Mia's memory of your preferences, role, and focus areas | Your use of the Service | Personalizing Mia's answers (Section 4.1) | AI language-model providers, when Mia uses them to answer you | Until you delete it or close your account |
| Sensitive personal information — account log-in credentials; driver's license numbers and any health information contained in uploaded documents | You; your firm or broker | Authenticating you; providing the Service | Authentication provider (credentials); the service providers listed for customer records (document content) | As for the account, or for the document that contains it |
8.2. Sensitive Personal Information. Uploaded documents may contain driver's license numbers, dates of birth, or incidental health information, and we collect your account log-in credentials. We use and disclose sensitive personal information only to provide the Service you requested, to secure the Service and your account, and for the other purposes permitted by California Code of Regulations, title 11, § 7027(m). We do not use sensitive personal information to infer characteristics about you. Because we use it only for those permitted purposes, we do not offer a separate right to limit its use, as the California Consumer Privacy Act does not require one in that case. We do not intentionally collect Social Security Numbers, and our Terms of Service prohibit uploading them.
Sensitive identifiers and our AI model providers. Insurance documents can contain Social Security numbers, driver's license numbers and dates of birth, for example in a driver schedule. If a document you upload contains any of them, the text of that document, including those identifiers, can be sent to the AI model providers listed on our Sub-processors page while we extract its contents. We send the text as it is printed because the extraction has to read it for the Summary of Insurance to show schedules such as driver schedules. Before a document's text is indexed for search, we redact Social Security numbers and labeled driver's license numbers from the indexed text; dates of birth are kept in the index because a date of birth can be a coverage fact. The commercial terms under which we use each AI provider exclude the data we send from the provider's model training, and we do not authorize any provider to train on it (Section 5.1). Those providers may keep inputs and outputs for a limited period for abuse monitoring under their own terms, as the Sub-processors page states for each one. This does not change the prohibition on uploading Social Security numbers in our Terms of Service.
8.3. Your Rights. These rights may include:
- The Right to Know: To request information about the categories and specific pieces of personal information we have collected about you, the sources from which it is collected, the purposes for collecting/selling/sharing it, and the categories of third parties to whom we disclose it.
- The Right to Delete: To request the deletion of your personal information, subject to certain exceptions (e.g., to complete transactions, for security purposes, to comply with legal obligations).
- The Right to Correct/Rectify: To request the correction of inaccurate personal information.
- The Right to Data Portability: To receive a copy of your personal information in a structured, commonly used, machine-readable format.
- The Right to Opt-Out of Sale/Sharing: Nexture AI does not sell your personal information or share it for cross-context behavioral advertising (Section 3.4). We honor Global Privacy Control signals as opt-out requests.
- The Right to Limit Use and Disclosure of Sensitive Personal Information: We use sensitive personal information only for the purposes described in Section 8.2, for which this right does not apply.
- The Right to Opt Out of Platform Improvement: You can opt out of the platform-improvement uses described in Sections 4.2 and 6.
- The Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
How to Exercise Your Rights: To exercise any of these rights, please contact us at [email protected]. We may need to verify your identity before processing your request.
In-App Self-Service: You can also exercise two of these rights yourself, from inside the Service, under Settings › Security › Your data (on an insured account, also on the Your data page). Neither option can be used from a read-only support session.
- Download a copy of your data (Right to Know and Right to Data Portability): We prepare one .zip file containing your account details, every document in your account in the form it was uploaded, the deliverables you saved (as they were saved), and the policy data we extracted from each document in a structured, machine-readable format (JSON), together with a manifest listing everything in the file. If an item does not fit within the file’s size or time limit, or cannot be read, the manifest names it and says why. The file is stored encrypted and can be downloaded for 24 hours, only while you are signed in to your account, through a short-lived download link. After 24 hours it can no longer be downloaded, and the stored file is deleted the next time you return to that page or request a new copy, and in any case when you close your account. We never email the file or a link to it. When a copy is requested, we email a notice to the address you sign in with, so that you would know if someone else requested it; the notice contains none of your data. You can request up to three copies a day. The file does not include Mia chat history, account activity logs, or billing records; for a copy of those, email [email protected] from the address you sign in with.
- Delete my account (Right to Delete): You can close your account after confirming it is you with your current password and, if you use one, your authenticator code. What is deleted, what is kept, and which accounts must be closed by email instead are described in Section 7.
The Response Timeframe below applies to requests made by email. The in-app options act without waiting for us: a copy of your data is usually ready within minutes, and an account is closed when you confirm.
Response Timeframe: We will acknowledge receipt of your request within 10 business days. We will respond to verified requests within 45 calendar days from receipt. If we require additional time (up to an additional 45 days), we will inform you of the reason and extension in writing.
Authorized Agents: You may designate an authorized agent to submit a privacy rights request on your behalf. To do so, you must provide the authorized agent with written permission and we may require you to verify your identity directly with us. An authorized agent may also submit a request with a valid power of attorney.
Appeal Process: If we deny your privacy rights request in whole or in part, you have the right to appeal our decision. To appeal, please contact us at [email protected] with the subject line "Privacy Rights Appeal" within 60 days of receiving our decision. We will respond to your appeal within 60 days. If the appeal is denied, we will provide you with instructions on how to contact your state's Attorney General to submit a complaint.
California "Shine the Light" (Civil Code § 1798.83): California residents may request information about whether we have disclosed personal information to third parties for their direct marketing purposes. As stated above, Nexture AI does not share personal information with third parties for their direct marketing purposes.
9. Data Security
We implement robust technical and organizational measures to protect your personal information from unauthorized access, use, alteration, or disclosure. For a detailed description of our security practices, please refer to our Security Statement.
What is encrypted at rest: Your uploaded documents and the structured policy data we extract from them are encrypted at rest by our application using AES-256-GCM, under per-account keys that are themselves protected by a key held in AWS Key Management Service (KMS). This includes the named insured, carrier name, policy number, and document filename on each policy, your clients' names, coverage details, limits, premiums, agent reasoning, audit history, deliverable content, communications bodies, meeting and voice transcripts, and client contact details. Your account email address, name, and company are encrypted under a separate server-held key, with a keyed one-way index so that you can still sign in by email.
What is not encrypted by our application: A limited set of information is stored without application-level encryption, protected instead by our database provider's storage encryption, per-account access scoping, multi-factor employee authentication, audit logging, and TLS encryption in transit. It consists of: your firm's business name; internal identifiers, timestamps, status values, and categories used to route and scope records; numerical search representations (embeddings) derived from document text; and the platform-wide reference library of standard insurance forms, which contains no customer identifiers. Customer-controlled key revocation remains on our roadmap (Security Statement § 3.1.1).
What we can see while you are an active customer: Our extraction pipeline and AI agents must process your documents in plaintext to do their work (OCR, language-model extraction, SOIFA responses, deliverable generation). Employees with production code-deploy access therefore have the technical capability to access in-flight data while your account is active; that access is constrained by access controls, audit logging, and the contractual obligations described in our Security Statement. We do not claim that our employees cannot read your data while you use the Service; we claim they are constrained from doing so without authorization.
10. Data Breach Notification
In the event of a security breach that results in the unauthorized access, acquisition, or disclosure of your personal information, Nexture AI will:
- Investigate promptly: We will immediately investigate the scope and nature of the breach and take steps to contain and remediate it.
- Notify affected individuals: We will notify affected users without unreasonable delay, and no later than 60 days after discovery of the breach (or sooner where required by applicable state law). Notification will be provided via email to the address associated with your account.
- Notify regulators: We will notify applicable state attorneys general and regulatory authorities as required by law.
- Notification content: Breach notifications will include a description of the incident, the types of information involved, the steps we are taking in response, and steps you can take to protect yourself.
- Broker notification: For Broker Users, we will also notify you of any breach affecting your clients' NPI so that you can fulfill your own notification obligations as the data controller.
11. International Data Transfers
Nexture AI is based in the United States and primarily stores and processes data within the United States (AWS us-east-1, N. Virginia). The Service is offered only to users located in the United States and its territories. However, some of our sub-processors may process data in other regions as part of their service delivery; the Sub-processors page states the processing region for each. In all cases:
- We ensure that sub-processors are bound by contractual obligations to protect your data consistent with this Privacy Policy.
- Data transfers are limited to what is necessary for the specific processing purpose.
- If you are located outside the United States and choose to use our Service, you understand and consent to your data being transferred to, stored, and processed in the United States, which may have different data protection standards than your jurisdiction.
The Service is not offered in the European Economic Area, the United Kingdom, or any other jurisdiction outside the United States and its territories, and we restrict access from outside them at the network edge of our production service (through Cloudflare) and, when an account is created, in our application. These location controls rely on location signals, are not perfect, and do not replace your own obligation to use the Service only from the United States or its territories. If you have questions about international data use, please contact us at [email protected].
12. Children's Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will take steps to delete that information as quickly as possible.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top. For material changes, we will also provide notice via email or a prominent in-app notification before the changes take effect, and where the change is to how we use personal information already collected, we will ask for your consent where the law requires it. We encourage you to review this Privacy Policy periodically.
14. Contact Information
If you have any questions or concerns about this Privacy Policy or our privacy practices, please contact us at:
Nexture AI LLC
Attn: Privacy Officer
1521 Alton Rd. PMB 106, Miami Beach, FL 33139, United States
Privacy inquiries [email protected]
General inquiries [email protected]