Published data unavailable. RateFileAI could not verify current source and as-of metadata. No unverified factual claim is being shown.

Legal

Privacy Policy

Plain English. We collect the minimum we need to operate the service. We don't sell your data. We don't track you across the web.

Effective: 2026-05-18 · Last updated: 2026-06-29

1. Who we are

RateFileAI is operated by RateFileAI, LLC, a Florida limited liability company, as an independent research and intelligence platform for U.S. property & casualty insurance professionals. This policy explains what personal information we collect about you when you visit ratefileai.com or use the service, why we collect it, and your rights.

2. What we collect

CategoryExamplesPurpose
Account infoName, email address, company, ZIP code, phone number (company, ZIP and phone are optional profile fields collected at onboarding)Authenticate you; deliver alerts and digests; reach you about account or service changes
Billing infoPayment method (handled by Stripe — we do not see your card number), billing address as provided to Stripe, subscription tier and statusProcess subscription payments and confirm your tier
Usage analyticsPages visited, time on page, anonymized IP address, browser/OS familyUnderstand which features get used; debug issues; improve product
Saved preferencesSaved alert scope (carriers/states/LOBs), alert rules you create, email delivery togglesDeliver the alerts and digests you've configured
Saved renewal book (Renewal Defender)Only if you save a renewal book to your account in the app: the policy rows you upload — which may include a customer name, ZIP, and policy number — plus the renewal-risk scores and talking points we generate from themDeliver and persist your renewal-defense analysis across sessions, so your filing intelligence and talking points are there when you sign back in. Stored only for your agency; not sold; not used for any other customer; deletable at any time (see §3 and §7)
Search historyFiling searches and queries you runMake the platform faster for you (caching); aggregate, anonymous trend analysis

The personal information described above covers what we collect about you as a subscriber. The platform separately aggregates and displays publicly available regulatory filing data — including rate filing records, carrier-state-line-of-business data, and state regulatory filing reference identifiers sourced from state insurance departments' public filing systems. That public regulatory data is not personal information of any subscriber and is not covered by this Privacy Policy.

3. What we don't collect

4. How we use your information

We do not sell your personal information. We do not share your personal information with advertisers. We do not let third parties use our system to track you across other sites.

5. Sub-processors

We use the following third-party services to operate the platform. Each receives only the data necessary to perform its function:

ProviderPurposeData shared
ClerkAuthentication, session management, user identityEmail, name, hashed password (if used), OAuth tokens (if you sign in with Google)
StripePayment processing, subscription managementEmail, billing address (collected by Stripe), payment method (handled by Stripe)
PlausiblePrivacy-friendly product analyticsAnonymized IP, page path, referrer, browser/OS family — no cookies, no cross-site tracking
Anthropic (Claude)Generating genuine AI summaries for some public filing PDFs (server-side, not user-driven)Excerpts of public filing PDFs only; no user-identifiable content is sent. Anthropic does not use API inputs or outputs to train its models (confirmed by Anthropic's API usage policy and our account-level zero-retention configuration). Your renewal book data is not sent to Anthropic and is not used to train any model.
Google Workspace (Gmail)Internal and transactional email (CEO mailbox, account communications)Recipient email, message body
ResendTransactional email delivery (account alerts, weekly digest, billing notifications, account lifecycle email)Recipient email address and message content delivered on our behalf; no persistent storage of content by Resend beyond transient delivery
HetznerServer hosting (Germany / Finland)Application data at rest and in transit
2CaptchaAutomated processing of publicly available challenge-response prompts encountered when accessing public regulatory portals (does not touch user data)Public challenge-response data from regulatory portals — no user data

6. Cookies

We use cookies only for:

We do not use advertising cookies, social-media tracking pixels, or third-party analytics cookies. Our analytics (Plausible) is cookieless — it sets no cookies and stores no identifier on your device. Your browser's local storage is used only for functional preferences you set yourself (such as saved favorites) and is not shared with third parties.

Because the only cookies we set are strictly necessary for the service to function, and our analytics operates without cookies or persistent identifiers, no cookie-consent banner is required — strictly necessary cookies are exempt from consent requirements under applicable privacy law (including the EU ePrivacy Directive). If we ever introduce non-essential cookies, a consent mechanism will be added before non-essential cookies are set.

7. Data retention

You can request deletion of your account and personal data at any time by emailing us at the address below; requests are processed within 30 days unless we are required to retain data for legal compliance.

These retention periods follow a documented data-retention schedule, and deletion requests are fulfilled under a documented deletion procedure (aligned to CCPA/CPRA and GDPR Article 17) within the timeline above. Enterprise customers can review the per-category processing and retention summary in our Data Processing Addendum (Schedule A).

8. Your rights

Subject to applicable law, you have the right to:

8a. Your U.S. state privacy rights

Depending on your state of residence, you may have additional rights under your state’s consumer-privacy law — including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. Subject to your state’s law, these may include the right to confirm whether we process your personal data and to access it; to correct inaccuracies; to delete it; to obtain a portable copy; and to opt out of the “sale” of personal data, “targeted advertising,” or certain “profiling.” We do not sell your personal data, we do not share it for cross-context behavioral or targeted advertising, and we do not use it for profiling that produces legal or similarly significant effects — so for most residents these opt-out rights have no applicable processing to suppress.

Opt-out preference controls. Because we do not sell or share personal data or process it for targeted advertising, browser opt-out preference controls such as Global Privacy Control (GPC) have no applicable processing for us to suppress; we honor the no-sale / no-targeted-advertising posture above for all visitors regardless of signal.

How to exercise / verification. Email info@ratefileai.com. We verify requests against account information on file and respond within the timeframe your state’s law requires (generally 45 days, extendable once where permitted). You may use an authorized agent where your state’s law allows.

Right to appeal. If we decline your request, you may appeal by replying to our decision email; we respond within the period your state’s law requires (typically 45–60 days). If your appeal is denied, you may contact your state Attorney General.

Non-discrimination. We do not discriminate against you for exercising any of these rights.

9. Security

We use industry-standard security measures: TLS everywhere, encrypted-at-rest databases, hashed-not-stored credentials (via Clerk), short-lived authentication tokens, principle-of-least-privilege access controls internally. No system is 100% secure; affected users are notified without undue delay if a breach involving personal information occurs.

10. International transfers

Our servers are located in the European Union (Hetzner — Germany / Finland). If you access the service from outside the EU, your personal information will be transferred to and stored in the EU. We rely on standard contractual clauses and equivalent legal mechanisms where required.

11. Children

RateFileAI is a B2B service intended for licensed insurance professionals. It is not directed at children under 16, and we do not knowingly collect personal information from children.

12. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or by prominent notice in the product. The "Last updated" date at the top of this page reflects the current version.

13. Contact

For privacy questions, deletion requests, or any data-rights exercise:

info@ratefileai.com