Please read this carefully
TRANSMUTEDOTCOM, Inc. d/b/a Coverflow Privacy Statement
Last Updated: December 22, 2025
Previous privacy statement available here.
Contents
Overview
Our Role as Data Controller and Data Processor
Personal Data We Collect about You
How We Use Your Personal Data
Do We Share Your Personal Data and Why?
How Long Do We Retain Your Personal Data?
Personal Data International Transfers
How Do We Use Cookies and Tracking Technologies?
Your Data Protection Rights
How Do We Protect Your Personal Data?
Can Children Use Our Services?
Updates to this Privacy Statement
Contact Information
Definitions
Overview
This Privacy Statement aims to provide you with sufficient information regarding Coverflow’s (“we,” “us” or “our”) use of your Personal Data when you visit our website, apply for, or use our Services. Our Services include the Policy Analysis by Coverflow products and services and all products and services offered by Coverflow, which consist of AI automation software for insurance brokerages to upload insurance-related documents, extract data, and generate spreadsheets and proposals (including all related applications, widgets, software, tools, and other services provided by us and on which a link to this Privacy Statement is displayed). Our Services process insurance-related data, which may include Personal Data from insurance policies. We do not process Protected Health Information (PHI) as defined under applicable laws such as HIPAA. Our Services employ machine learning and generative AI models provided by third-party AI service providers to process, extract, and analyze insurance policy data. The AI technologies used in our Services are subject to the limitations, capabilities, and potential biases of the underlying AI models, and may occasionally produce inaccurate, incomplete, or unexpected results. We do not use your Personal Data to train or fine-tune our AI models, though our third-party AI providers may process your data in accordance with their own privacy and data handling policies as set forth in our data processing agreements with those providers.
This Privacy Statement complies with applicable data protection and privacy laws in multiple U.S. states, including but not limited to: California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA) and Colorado Artificial Intelligence Act (SB24-205), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), Indiana Consumer Data Protection Act (ICDPA), Iowa Consumer Data Protection Act, Tennessee Consumer Information Protection Act (TCIPA), Texas Data Privacy and Security Act (TDPSA), Florida Information Protection Act (FIPA), Montana Consumer Data Privacy Act (MCDPA), Oregon Consumer Identity Theft Protection Act (OCITPA), Delaware Personal Data Privacy Act (DPDPA), New Hampshire Consumer Expectation of Privacy Act (NHEPA), New Jersey Personal Data Privacy Act (NJPDPA), Kentucky Consumer Data Protection Act (KCDPA), Nebraska Data Privacy Act (NDPA), Rhode Island Data Transparency and Privacy Act (RIDTPA), Maryland Online Data Privacy Act (MODPA), and Minnesota Consumer Data Privacy Act (MCDPA). While this single privacy statement applies globally, certain rights and protections available to you may vary depending on your state of residence. We encourage you to read this Privacy Statement and to use it to help you make informed decisions.
This Privacy Statement does not apply to any third-party websites, services or applications, even if they are accessible through our Site or Services. When you click on links to third-party websites, products, or services, your Personal Data will become subject to the privacy policies and practices of those third parties. We have no responsibility or liability for the content and activities of these linked sites . You should therefore read the privacy notices provided by any third-party offerings.
Certain capitalized terms that are not otherwise defined in this Privacy Statement are explained in Section 14 (“Definitions”) at the end of this Statement.
Our Role as a Data Controller and Data Processor
We are a Data Controller of Personal Data collected and processed when you access our Site, sign up for a product demonstration, send us an email, register with us as a Merchant, interact with us on social media, or provide information directly when you communicate with us, such as by calling or emailing the customer service. This means that we are determining the purposes and means of the processing of Personal Data
We also receive information about individuals indirectly in connection with providing our Services to Merchants. In these cases, we serve as a service provider or data processor. This means that we will access your Personal Data on behalf of our Merchant customers. When we serve as a data processor, we process Personal Data solely in accordance with written instructions from the Merchant. Our processing is limited to the purposes specified by the Merchant and in compliance with their documented lawful basis for processing. We implement appropriate technical and organizational measures to protect Personal Data processed on behalf of Merchants, consistent with SOC 2 Type 1/II certification standards and applicable state and federal security requirements. Given the insurance industry context, we acknowledge that insurance-related data processed through our Services may be subject to the Gramm-Leach-Bliley Act (GLBA) and state insurance data privacy laws. We do not independently enforce GLBA compliance with Merchants. This Privacy Statement does not cover Personal Data for which we act in those capacities. In such cases, the privacy statements published by the Merchant or the payment processor that the individual did business with should be reviewed to learn about how the Merchants or the payment processor have decided to collect, use, or share the individual’s Personal Data.
Personal Data We Collect about You
We may collect Personal Data about you when you visit our Site, create an account through or for use on the Site, use our Services, interact with us on social media, or provide information directly when you communicate with us, such as by calling or emailing customer service.
The types of Personal Data we collect about you may include the following:
Personal data collected from you such as:
Your name and email address;
Any other information you voluntarily provide us through our Services, including data contained in uploaded insurance policies or quotes, such as entity names, addresses, contact information, and other insurance-related details.
Personal data automatically collected such as:
Technical Usage Data. Information such as response time for web pages, download errors, date and time when you used the Site, your IP address, statistics regarding how pages are loaded or viewed, the websites you visited before coming to the Site and other usage and browsing information that may be collected through Cookies. This data is collected solely for Site improvement, security monitoring, and fraud prevention. Technical Usage Data is not used to train, fine-tune, or improve third-party AI models without your explicit consent.
Information from your device. Information about your language settings, IP address, browser ID, device ID, cookie preferences, time zone, operating system, platform, screen resolution and similar information about your device settings, and data that may be collected from cookies or other tracking technologies. Device information is used solely to optimize user experience and is not shared with AI service providers for training purposes.
Insurance Policy Data (for Merchant Users). When you or your Merchant customer uploads insurance policies, quotes, or related documents, we automatically extract and process data contained within those documents, including policyholder names, addresses, coverage types, premium amounts, policy dates, and other insurance-related details. This extraction is performed using OCR (Optical Character Recognition) and AI technologies provided by third-party vendors. Data extracted from uploaded documents is used solely to provide the Services and is not used to train or improve AI models without the Merchant's explicit authorization and separate data use agreement.
Sensitive Personal Information. Depending on the content of uploaded insurance documents and your interactions with our Services, we may process the following categories of Sensitive Personal Information (as defined under state privacy laws):
Financial account information (banking details, credit card numbers if visible in uploaded documents)
Government-issued identifiers (driver's license numbers, passport numbers, Social Security numbers visible in policy documents)
Precise geolocation information
Health information (to the extent included in insurance policies)
Biometric data (facial recognition data from ID documents, if processed)
Information revealing racial or ethnic origin
Information relating to union membership
Precise location data
We minimize collection and processing of Sensitive Personal Information to what is necessary to provide the Services. For Merchants uploading documents containing Sensitive Personal Information, we recommend redacting or removing such information before upload where not essential to the Services requested. We implement enhanced technical and organizational safeguards when processing Sensitive Personal Information, including encryption at rest and in transit, restricted access controls, and audit logging. Under CCPA/CPRA and similar state laws, we may only process certain categories of Sensitive Personal Information with your explicit, opt-in consent. Merchants should obtain appropriate consents from data subjects before uploading documents containing such information.
We do not collect or store payment information, such as credit card details.
How We Use Your Personal Data
We may Process your Personal Data for a variety of reasons that are permitted under data protection laws in the applicable jurisdictions and in accordance with one or more of the follownig lawful bases:
Business Purpose. To provide and improve our Services, provide customer support, process transactions, develop new products, and conduct analytics and aggregated reporting
Compliance with Law. To comply with legal obligations, respond to lawful government requests, defend against legal claims, and maintain records as required by law
Security and Fraud Prevention. To detect, investigate, and prevent fraudulent transactions, security breaches, and other illicit activity
Commercial Interest. To manage our business operations, including hiring and employment, financial planning, and business development
Sensitive Data Processing. For Sensitive Personal Information, we process only when you have provided explicit, informed consent, when necessary to provide requested Services, or when otherwise permitted under applicable law. We may also use Personal Data to contact you regarding products, services, and offers that we believe you may find of interest. Under CCPA/CPRA and most state privacy laws, you have the right to opt out of these marketing communications. You may opt out from receiving marketing communications from us as described in Section 9 (“Your Data Protection Rights”) below.
For Virginia (VCDPA), Colorado (CPA), and similar laws requiring Data Protection Assessments. For processing activities that present significant risk of harm to consumers' rights and freedoms, we have conducted Data Protection Impact Assessments ("DPIA") and maintain documentation of:
Purpose of processing
Nature and scope of data processed
Recipients of personal data
Retention periods
Technical and organizational safeguards implemented
Sensitive Data Limits. For Sensitive Personal Information, we implement purpose limitation and data minimization principles. We will not use Sensitive Personal Information for profiling or automated decision-making without explicit consumer consent and appropriate safeguards, except as necessary to detect fraud or prevent security incidents.
Automated Decision-Making & Profiling. Our AI-assisted data extraction and comparison features may constitute automated decision-making under state privacy laws. See Section 4A below for specific disclosures regarding automated decision-making.
We will request your consent before we use or disclose your Personal Data for a materially different purpose than those set forth in this Privacy Statement. Consent may be obtained by any legally sufficient method. For example, depending on the circumstances and applicable laws, consent may be obtained by providing you with notice and the opportunity to opt-out.
Our use of AI involves third-party providers (such as OpenAI, Anthropic, and Microsoft Azure for OCR). We do not use your data to train AI models, and we have data processing agreements with these providers to ensure your data is not retained or used for training purposes.
4A. Automated Decision-Making & AI Profiling Disclosure
Our Services utilize artificial intelligence and machine learning technologies that may constitute "Automated Decision-Making Technologies" (ADMT) under CPRA and other state privacy laws. Specifically:
Types of Automated Decision-Making:
Data Extraction & Classification. Our AI models automatically extract, classify, and structure insurance policy data into standardized fields and categories. This process involves algorithmic decision-making about what data elements correspond to which policy attributes.
Comparative Analysis. Our Services use AI to compare policies, identify coverage gaps, highlight material differences, and generate recommendations for policy optimization or replacement. These comparisons involve algorithmic analysis that may recommend specific courses of action.
Proposal Generation. AI models assist in generating proposals and recommendations based on extracted and compared data. While these are advisory in nature and do not bind the user, they represent automated decision-making that may influence user choices.
Impact & Disclosures:
For Financial Impact. Insurance-related recommendations generated by our AI systems could have financial implications for insurance brokers, agents, and their customers by influencing policy selection, pricing, and coverage decisions. We therefore disclose that our AI recommendations are generated through automated processes and may not account for all relevant factors.
For Non-Obvious AI Use. When our AI systems generate content, recommendations, or analysis that does not make the use of AI obvious to a reasonable person, we provide clear notice that AI has been involved in generating that content.
Accuracy Limitations. Our AI systems operate based on training data and algorithms that have limitations. AI-generated recommendations and extractions may be inaccurate, incomplete, or based on biased or incomplete training data. We recommend that users review all AI-generated content for accuracy before relying on such content for consequential decisions.
Right to Meaningful Human Review: For substantive decisions influenced by our AI systems' recommendations (including policy replacement or coverage change decisions), you have the right to request meaningful human review by our customer support team or by the relevant insurance professional. To request human review, contact privacy@coverflow.tech.
Opt-Out of Automated Decision-Making: To the extent permitted by law, you may opt out of certain automated decision-making features. However, please note that opting out of automated recommendation features may limit the functionality of our Services. Contact privacy@coverflow.tech to discuss available opt-out options.
Bias and Fairness. We have implemented bias testing and fairness audits to assess whether our AI systems produce disparate outcomes across demographic groups. We maintain audit logs of these assessments and are committed to ongoing monitoring for algorithmic bias. If you believe our AI systems have produced discriminatory or biased results, please contact privacy@coverflow.tech.
How Long Do We Retain Your Personal Data?
We retain Personal Data for as long as needed or permitted in context of the purpose for which it was collected and consistent with applicable law. Personal Data from uploaded insurance documents and user accounts is retained indefinitely until you delete it through our Services or submit a deletion request, after which we will delete it promptly, subject to any legal obligations to retain it (e.g., for litigation, investigations, or regulatory purposes). For such obligations, we may retain data for up to 5 years after resolution or longer if required by a settlement.
To the extent Coverflow serves as a service provider for insurance brokers, agents, or other financial institutions subject to the Gramm-Leach-Bliley Act, we retain certain Personal Data in accordance with GLBA and state insurance privacy law requirements. These requirements may mandate retention of:
Transaction records and account information for 5-7 years (depending on state)
Customer communications for 3-5 years or longer
Compliance documentation and audit records for 3-7 years
Merchants using our Services bear primary responsibility for GLBA compliance determinations. We support Merchant compliance by maintaining appropriate retention schedules and providing data on request for required audits and regulatory examinations.
Personal Data International Transfers
Coverflow is based in the United States and houses all data in the United States. If you access our Services from outside the United States (e.g., the EU), your Personal Data may be transferred to and processed in the United States, where data protection laws may differ. We rely on appropriate safeguards, such as standard contractual clauses, for any such transfers.
How Do We Use Cookies and Tracking Technologies?
When you interact with our Site or open email we send you, we use cookies to recognize you as a user, customize your online experiences and online content, mitigate risk and prevent potential fraud, and promote trust and safety across our Site and Services. We only use cookies and tracking technologies for users who have created an account and agreed to our Terms of Service.
Although most browsers automatically accept cookies, you can change your browser options to stop automatically accepting cookies or to prompt you before accepting cookies. Please note, however, that if you don’t accept cookies, you may not be able to access all portions or features of the Site or the Services or they may not work properly.
We use Cookies to collect your device information, internet activity information, and inferences as described above. Cookies help us to do the following:
Remember your information so you do not have to re-enter it
Track and understand how you use and interact with our online services and emails
Tailor our online services to your preferences
Measure how useful and effective our services and communications are to you
Otherwise manage and enhance our products and services
Do Not Track (DNT) and Global Privacy Control (GPC) are browser settings or signals that allow you to express your preferences regarding online tracking. We honor Do Not Track (DNT) signals and Global Privacy Control (GPC) signals received from your browser. When we detect such a signal, we will treat it as an opt-out request from the sale or sharing of your Personal Data for cross-context behavioral advertising purposes.
Your Data Protection Rights
Depending on your state of residence and applicable laws, you may have the following rights regarding your Personal Data:
Right to Know / Right to Access (CCPA/CPRA, VCDPA, CPA, and most state laws)
You have the right to request that we disclose the categories and specific pieces of Personal Data we have collected about you, including:
• Categories of Personal Data collected
• Sources from which Personal Data was collected
• Business purpose(s) for which we collected the data
• Categories of third parties with whom we shared the data
How to Submit. Contact privacy@coverflow.tech with the subject line "Request to Know" or "Request for Data Access." Include your full name, email address, and account identifier.
Verification. We may request additional information to verify your identity before responding. If we cannot verify your identity with reasonable certainty, we will decline the request.
Timeline. We will respond to verified requests within 45 days or as otherwise required by applicable law. We may extend this period by 45 days if necessary, with notice.Right to Correction / Rectification (CCPA/CPRA, VCDPA, CPA, and most state laws)
You have the right to request correction or deletion of inaccurate Personal Data. We will take reasonable steps to correct inaccurate data upon your request.
How to Submit. Contact privacy@coverflow.tech with the subject line "Request to Correct." Provide the specific data you believe is inaccurate and the correction you are requesting.
Timeline. We will respond within 45 days or as otherwise required by law.Right to Delete / Right to Erasure (CCPA/CPRA, VCDPA, CPA, and most state laws)
You have the right to request deletion of Personal Data we have collected about you, subject to certain exceptions.
Exceptions to Deletion Rights. We may decline to delete Personal Data if deletion would:
• Prevent us from providing the Services you have requested
• Detect, investigate, or prevent fraud or security breaches
• Comply with legal obligations or permit us to defend against legal claims
• Fulfill another purpose for which you provided the data
• Maintain records required by law (including GLBA financial records, litigation holds)
How to Submit. Contact privacy@coverflow.tech with the subject line "Request to Delete."
Verification. We will verify your identity before processing deletion requests.
Timeline. Upon verification, we will delete the requested Personal Data within 30 days, unless exceptions apply.
Note on Account Deletion. Deleting your Coverflow account does not automatically delete all associated data. To request deletion of specific data, use the deletion request process above.Right to Portability (CCPA/CPRA, VCDPA, CPA, and most state laws)
You have the right to obtain a copy of your Personal Data in a portable, machine-readable format (such as CSV) and to direct us to transmit it to another service provider.
Format. We will provide data in a commonly used, machine-readable format.
How to Submit. Contact privacy@coverflow.tech with the subject line "Request for Data Portability."
Timeline. We will respond within 45 days.Right to Opt-Out (CCPA/CPRA, VCDPA, CPA, and most state laws)
Depending on applicable law, you may have rights to opt out of:Sale of Personal Data. Under CCPA/CPRA, you have the right to direct us not to sell your Personal Data. Coverflow does not sell Personal Data and will not use your Personal Data for this purpose without your explicit opt-in consent. If we ever begin selling personal information, we will implement opt-out mechanisms and honor opt-out requests.
Sharing for Cross-Context Behavioral Advertising. Under CCPA/CPRA, you have the right to opt out of sharing your Personal Data for cross-context behavioral advertising. Coverflow does not engage in such sharing. We use personal data solely to provide our Services and do not share it with third-party data brokers or advertisers for behavioral advertising purposes.
Profiling and Automated Decision-Making. To the extent Coverflow uses profiling or automated decision-making that affects you materially, you may have the right to opt out. To exercise this right, or to request human review of automated decisions, contact privacy@coverflow.tech.
Targeted Marketing. You have the right to opt out of receiving marketing and promotional communications. See Section 4 for opt-out mechanisms.
Right to Limit Use and Disclosure of Sensitive Personal Information (CCPA/CPRA)
California residents have the right to limit our use of Sensitive Personal Information (such as precise location, health information, financial information, biometric data) to purposes necessary to provide requested Services.
How to Submit. Contact privacy@coverflow.tech with the subject line "Limit Use of Sensitive Information."Right to Withdraw Consent (CCPA/CPRA, VCDPA, CPA)
If we collected your Personal Data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing that occurred before you withdrew consent.
How to Submit. Contact privacy@coverflow.tech with the subject line "Withdraw Consent" and specify which consent you are withdrawing.Right to Object (CCPA/CPRA, VCDPA, CPA, and most state laws)
You may have the right to object to our processing of your Personal Data, including processing for profiling, targeted advertising, or other specific purposes.
How to Submit. Contact privacy@coverflow.tech with the subject line "Object to Processing."Right to Lodge a Complaint with Regulatory Authorities
Special Rights for California Residents (CCPA/CPRA)
In addition to the rights above, California residents have the following additional rights:Right to Know if Personal Data is Sold or Shared. We disclose that we do not sell or share personal data.
Right to Equal Service and Price. We will not discriminate against you for exercising your privacy rights by:
• Denying you goods or services
• Charging different prices or rates
• Providing different quality of service
• Suggesting you are not entitled to the same serviceAuthorized Agents. You may designate an authorized agent (such as a lawyer, business manager, or family member) to submit requests on your behalf. We will request verification of the agent's authority.
How Do We Protect Your Personal Data?
We maintain technical, physical, and administrative security measures designed to provide reasonable protection for your Personal Data against loss, misuse, unauthorized access, disclosure, and alteration. The security measures include firewalls, data encryption, and information access authorization controls. In addition, we maintain a SOC 2 Type 1 certification.
While we implement substantial safeguards, no security measure is completely impenetrable. You are responsible for:
Maintaining the confidentiality of your password and login credentials
Promptly notifying us of any unauthorized access to your account
Keeping your device and software current with security patches
Not sharing Personal Data with unauthorized third parties
State Insurance Privacy Laws. We comply with state-specific insurance privacy and data protection regulations, including requirements for insurer safeguards, policyholder notices, and data breach reporting to state insurance commissioners.
Can Children Use Our Services?
Our Services are directed exclusively to business users (insurance brokers, agents, and their representatives) who are at least 18 years old. We do not knowingly collect or solicit Personal Data from children under the age of 13 (or the age of majority in the relevant jurisdiction, whichever is higher). If you are under the age of 18, do not use our Services. Our Services are not subject to the Children's Online Privacy Protection Act (COPPA) as they are directed to business users, not children. However, we are committed to complying with COPPA's principles and, if we discover a child under 13 has used our Services, we will promptly notify parents and delete collected information.
Updates to this Privacy Statement
We revise this Privacy Statement from time to time to reflect changes to our business, Services, or applicable laws. The updated Privacy Statement will be posted on our Site with a new "Last updated" date. For material changes that expand our rights to use your Personal Data or otherwise require notice under applicable law (e.g., changes to how we collect, use, or share your Personal Data), we will provide prominent notice on our Site (and, where feasible and required by law, via email to the address associated with your account) at least 30 days before the changes take effect, giving you an opportunity to review them. In such cases, your continued use of our Services after the effective date constitutes your acceptance of the revised Privacy Statement. For non-material changes, the revised Privacy Statement will be effective immediately upon posting.
Contact Information
If you have any questions, comments, or concerns about this Privacy Statement, please contact us at privacy@coverflow.tech.
Definitions
“Affiliate” means Any entity controlled by, controlling, or under common control with Coverflow, including subsidiaries and parent companies.
“Automated Decision-Making Technology” (ADMT) means technology that makes or substantially assists in making decisions that affect individuals, including decisions about their access to financial, educational, employment, healthcare, legal, or other important services or benefits. This includes machine learning models, AI algorithms, and other computational methods that influence consequential decisions.
“Data Controller” means the entity that determines the purposes and means of processing Personal Data. In the B2B context, typically the Merchant (insurance broker or agent).
“Data Processor” means the entity that processes Personal Data on behalf of a Data Controller, following the Controller's instructions and in accordance with a data processing agreement.
“Merchant” means a purchaser and user of Coverflow's Services, typically an insurance broker, agent, or insurance-related business.
“Personal Data” means information that can be associated with an identified or directly or indirectly identifiable natural person. “Personal Data” can include, but is not limited to, name, postal address (including billing and shipping addresses), telephone number, email address, payment card number, other financial account information, account number, date of birth, and government-issued credentials (e.g., driver’s license number, national ID, passport number), and insurance-related details such as entity names, addresses, and contact information from uploaded policies
“Process” means any method or way that we handle Personal Data or sets of Personal Data, whether or not by automated means, such as by recording, categorization, structuring, storage, adaptation or alteration, retrieval, and consultation, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of Personal Data.
“Site” means the Policy Analysis website, mobile apps, official social media platforms, or other online properties through which we offer the Services and which has posted or linked to this Privacy Statement.
“You” means a person or entity accessing Coverflow's Site or using our Services, including both individual users and Merchants.
Any references to “we,” “our,” “us,” or “Coverflow” in this Privacy Statement refer to TRANSMUTEDOTCOM, Inc. and the group of companies that it directly or indirectly controls.



