Privacy Policy
Plain English. We collect the minimum we need to operate the service. We don't sell your data. We don't track you across the web.
Effective: 2026-05-18 · Last updated: 2026-06-29
1. Who we are
RateFileAI is operated by RateFileAI, LLC, a Florida limited liability company, as an independent research and intelligence platform for U.S. property & casualty insurance professionals. This policy explains what personal information we collect about you when you visit ratefileai.com or use the service, why we collect it, and your rights.
2. What we collect
| Category | Examples | Purpose |
|---|---|---|
| Account info | Name, email address, company, ZIP code, phone number (company, ZIP and phone are optional profile fields collected at onboarding) | Authenticate you; deliver alerts and digests; reach you about account or service changes |
| Billing info | Payment method (handled by Stripe — we do not see your card number), billing address as provided to Stripe, subscription tier and status | Process subscription payments and confirm your tier |
| Usage analytics | Pages visited, time on page, anonymized IP address, browser/OS family | Understand which features get used; debug issues; improve product |
| Saved preferences | Saved alert scope (carriers/states/LOBs), alert rules you create, email delivery toggles | Deliver the alerts and digests you've configured |
| Saved renewal book (Renewal Defender) | Only if you save a renewal book to your account in the app: the policy rows you upload — which may include a customer name, ZIP, and policy number — plus the renewal-risk scores and talking points we generate from them | Deliver and persist your renewal-defense analysis across sessions, so your filing intelligence and talking points are there when you sign back in. Stored only for your agency; not sold; not used for any other customer; deletable at any time (see §3 and §7) |
| Search history | Filing searches and queries you run | Make the platform faster for you (caching); aggregate, anonymous trend analysis |
The personal information described above covers what we collect about you as a subscriber. The platform separately aggregates and displays publicly available regulatory filing data — including rate filing records, carrier-state-line-of-business data, and state regulatory filing reference identifiers sourced from state insurance departments' public filing systems. That public regulatory data is not personal information of any subscriber and is not covered by this Privacy Policy.
3. What we don't collect
- Insureds' PII we don't need. Our research platform runs on public regulatory filings; using it does not require your customers' personal information. The only personal information about your customers that we process is the portfolio data you choose to upload. It is used solely to power your portfolio-analysis tools — Renewal Defender and the related renewal, retention, leakage, and prospecting views it feeds — and is not shared with or sold to third parties, or combined across customers. The rest of the platform runs on public regulatory filings and requires no customer personal information.
- Saved renewal books (in a paid account) are stored — and you control them. This is the one case where customer data is stored on our servers, and only because you chose to save it. When you save a renewal book to your account, the policy rows, scores, and talking points are stored (encrypted at rest, in the EU) so your filing intelligence is there next time you sign in. This data is used only to deliver your own analysis, is not sold, not shared with other customers, and not used to train our AI models or any third-party model. You can delete any saved book — or your whole account — at any time (see Data retention and Your rights).
- Holding rule for uploads. If a RateFileAI surface does not explicitly say it is the public in-browser demo, treat uploaded or saved Renewal Defender books as account data processed server-side for your workspace and retained until you delete the book or account. The original file you uploaded is deleted 90 days after upload; the book itself — the rows, scores and filed-rate context — stays until you delete it.. Demo-only browser parsing does not apply to signed-in upload, save, Team Scorecard, or Revenue-Leakage workflows.
- Credit card numbers, CVV, or full payment data. All payment data is collected and stored by Stripe under their PCI-compliant systems; we receive only a token and subscription status from Stripe.
- Cross-site tracking or third-party advertising cookies. We don't run ads on the platform.
4. How we use your information
- To provide, maintain, and improve the service
- To authenticate you and prevent account fraud
- To send transactional emails (account verification, alerts you've enabled, weekly digest, billing receipts, service announcements)
- To detect abuse (rate-limit anomalies, scraping, credential stuffing)
- To aggregate anonymized product analytics for product decisions
We do not sell your personal information. We do not share your personal information with advertisers. We do not let third parties use our system to track you across other sites.
5. Sub-processors
We use the following third-party services to operate the platform. Each receives only the data necessary to perform its function:
| Provider | Purpose | Data shared |
|---|---|---|
| Clerk | Authentication, session management, user identity | Email, name, hashed password (if used), OAuth tokens (if you sign in with Google) |
| Stripe | Payment processing, subscription management | Email, billing address (collected by Stripe), payment method (handled by Stripe) |
| Plausible | Privacy-friendly product analytics | Anonymized IP, page path, referrer, browser/OS family — no cookies, no cross-site tracking |
| Anthropic (Claude) | Generating genuine AI summaries for some public filing PDFs (server-side, not user-driven) | Excerpts of public filing PDFs only; no user-identifiable content is sent. Anthropic does not use API inputs or outputs to train its models (confirmed by Anthropic's API usage policy and our account-level zero-retention configuration). Your renewal book data is not sent to Anthropic and is not used to train any model. |
| Google Workspace (Gmail) | Internal and transactional email (CEO mailbox, account communications) | Recipient email, message body |
| Resend | Transactional email delivery (account alerts, weekly digest, billing notifications, account lifecycle email) | Recipient email address and message content delivered on our behalf; no persistent storage of content by Resend beyond transient delivery |
| Hetzner | Server hosting (Germany / Finland) | Application data at rest and in transit |
| 2Captcha | Automated processing of publicly available challenge-response prompts encountered when accessing public regulatory portals (does not touch user data) | Public challenge-response data from regulatory portals — no user data |
6. Cookies
We use cookies only for:
- Authentication (Clerk session cookies) — strictly necessary; the service can't function without these
- CSRF protection — strictly necessary
We do not use advertising cookies, social-media tracking pixels, or third-party analytics cookies. Our analytics (Plausible) is cookieless — it sets no cookies and stores no identifier on your device. Your browser's local storage is used only for functional preferences you set yourself (such as saved favorites) and is not shared with third parties.
Because the only cookies we set are strictly necessary for the service to function, and our analytics operates without cookies or persistent identifiers, no cookie-consent banner is required — strictly necessary cookies are exempt from consent requirements under applicable privacy law (including the EU ePrivacy Directive). If we ever introduce non-essential cookies, a consent mechanism will be added before non-essential cookies are set.
7. Data retention
- Account data: kept while your account is active. On deletion, your account record, uploaded books, policies, scores and alerts are deleted. Billing records are retained separately as described below
- Billing records: retained per applicable U.S. tax law (typically 7 years)
- Saved renewal books (Renewal Defender): kept until you delete the book or your account; there is no fixed time limit while a book is saved, and deletion (per-book or whole-account) takes effect on request
- Original uploaded files (Renewal Defender source CSVs): deleted 90 days after upload. This is the raw file you uploaded, not your book — the rows, scores and filed-rate context derived from it are kept under the line above until you delete the book or your account.
- Backups: encrypted backups are retained offsite for 30 days, and four weekly full database base backups are kept for disaster recovery. Data you delete may therefore persist inside a backup for up to 30 days after deletion, after which the backup containing it is pruned automatically. Backups exist to restore the service after a failure, not to look up individual records.
- Operational data (including email delivery logs and product analytics): retained for the period necessary to fulfil the purpose for which the data was collected, consistent with our documented data-retention schedule.
- Server access logs (Caddy web server): our web server records structured access logs that include your IP address, the URL path requested, HTTP status code, timestamp, and browser/client information for each request to ratefileai.com and api.ratefileai.com. These logs are retained for 90 days on a rolling basis (older entries are automatically overwritten). Purpose: security monitoring, abuse detection, and forensic investigation of unauthorized access or service incidents. The logs are stored on our Hetzner servers in the EU, are not shared with third parties except as required by applicable law, and are not used for marketing or analytics profiling. IP address constitutes personal data under GDPR; if you wish to exercise a right of access, erasure, or restriction with respect to these logs, contact us at the address below (note that erasure of specific IP records from rolling logs may not be technically feasible, in which case processing will be restricted).
You can request deletion of your account and personal data at any time by emailing us at the address below; requests are processed within 30 days unless we are required to retain data for legal compliance.
These retention periods follow a documented data-retention schedule, and deletion requests are fulfilled under a documented deletion procedure (aligned to CCPA/CPRA and GDPR Article 17) within the timeline above. Enterprise customers can review the per-category processing and retention summary in our Data Processing Addendum (Schedule A).
8. Your rights
Subject to applicable law, you have the right to:
- Access — request a copy of the personal information we hold about you
- Correct — fix inaccurate personal data; you can update most of this directly from your account page
- Delete — request deletion of your account and associated data
- Object / restrict — opt out of non-transactional emails; you can also disable specific alert categories from your account page
- Portability — request your data in a portable format
- Withdraw consent — at any time, by deleting your account
8a. Your U.S. state privacy rights
Depending on your state of residence, you may have additional rights under your state’s consumer-privacy law — including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. Subject to your state’s law, these may include the right to confirm whether we process your personal data and to access it; to correct inaccuracies; to delete it; to obtain a portable copy; and to opt out of the “sale” of personal data, “targeted advertising,” or certain “profiling.” We do not sell your personal data, we do not share it for cross-context behavioral or targeted advertising, and we do not use it for profiling that produces legal or similarly significant effects — so for most residents these opt-out rights have no applicable processing to suppress.
Opt-out preference controls. Because we do not sell or share personal data or process it for targeted advertising, browser opt-out preference controls such as Global Privacy Control (GPC) have no applicable processing for us to suppress; we honor the no-sale / no-targeted-advertising posture above for all visitors regardless of signal.
How to exercise / verification. Email info@ratefileai.com. We verify requests against account information on file and respond within the timeframe your state’s law requires (generally 45 days, extendable once where permitted). You may use an authorized agent where your state’s law allows.
Right to appeal. If we decline your request, you may appeal by replying to our decision email; we respond within the period your state’s law requires (typically 45–60 days). If your appeal is denied, you may contact your state Attorney General.
Non-discrimination. We do not discriminate against you for exercising any of these rights.
9. Security
We use industry-standard security measures: TLS everywhere, encrypted-at-rest databases, hashed-not-stored credentials (via Clerk), short-lived authentication tokens, principle-of-least-privilege access controls internally. No system is 100% secure; affected users are notified without undue delay if a breach involving personal information occurs.
10. International transfers
Our servers are located in the European Union (Hetzner — Germany / Finland). If you access the service from outside the EU, your personal information will be transferred to and stored in the EU. We rely on standard contractual clauses and equivalent legal mechanisms where required.
11. Children
RateFileAI is a B2B service intended for licensed insurance professionals. It is not directed at children under 16, and we do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or by prominent notice in the product. The "Last updated" date at the top of this page reflects the current version.
13. Contact
For privacy questions, deletion requests, or any data-rights exercise: