๐Ÿ”’ Legal

Privacy Policy

We take your health and insurance data seriously. Here's exactly what we collect, why we collect it, and how we protect it.

Effective Date: January 1, 2025  ยท  Last Updated: July 1, 2025
On This Page
โ„น๏ธ
Plain English Summary: CovrMeUp stores your insurance card details securely so you always have them on your phone. We use OpenAI's API to read your card images โ€” OpenAI does not store these images or use them for training. We never sell your data.

1 Overview

CovrMeUp ("we," "our," "us") operates the CovrMeUp mobile application and web platform (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service.

By using CovrMeUp, you agree to the collection and use of information in accordance with this policy. If you do not agree with these terms, please do not use the Service.

CovrMeUp is designed to help users securely store and manage their insurance cards across categories including Health Insurance, Medicare, Medicaid, Dental, Vision, Pharmacy (Rx), Auto, Homeowners, Life, Travel, Business, and Pet Insurance.

2 Data We Collect

2.1 Information You Provide Directly

Data TypeExamplesPurpose
Account InformationFirst name, last name, email address, phone number, passwordAccount creation and authentication
Insurance Card DataMember ID, Policy Number, Group Number, Plan Name, Provider Name, Coverage Dates, RX BIN/PCN, VIN, Beneficiary NameDigital card wallet storage
Card ImagesPhotos of physical insurance cards taken via camera or uploaded from galleryOCR scanning to auto-fill card fields
Expense DataPremium amounts, deductibles, copays, payment dates, frequencyExpense tracking and summary
Location DataZIP/PIN code, stateFinding nearby hospitals, pharmacies, and local insurance resources
Profile PictureUser-uploaded avatar imageProfile personalisation

2.2 Information Collected Automatically

  • Device Information: Device type, operating system version, unique device identifiers
  • Usage Data: Features accessed, pages viewed, actions taken within the app, time and duration of use
  • Log Data: IP address, browser type, referring URL, error logs
  • Session Tokens: JWT authentication tokens stored locally on your device

2.3 Sensitive Health-Related Information

โš ๏ธ
Insurance card data (Member IDs, Medicare/Medicaid numbers, health plan details) may constitute sensitive health information under applicable laws. We apply the highest level of security to this data and never use it for advertising, profiling, or sale to third parties.

3 How We Use Your Data

PurposeData UsedLegal Basis
Provide and maintain the ServiceAccount info, card dataContract performance
Email OTP verification and password resetEmail address, nameContract performance
OCR card scanning via OpenAICard image (temporary)Explicit consent
Expense tracking and summariesExpense entries, card dataContract performance
Location-based servicesZIP code, stateConsent
Security and fraud preventionIP, device info, logsLegitimate interests
Customer supportAccount info, usage dataContract performance
Service improvement and analyticsAnonymised usage dataLegitimate interests
Legal complianceAll data as requiredLegal obligation

4 Data Sharing

โœ…
We do not sell, rent, or trade your personal data to any third party for marketing or advertising purposes. Ever.

We share your data only in the following limited circumstances:

4.1 Service Providers

ProviderPurposeData SharedPrivacy Policy
OpenAICard image OCR and field extractionCard image (not stored โ€” see Section 5)openai.com/privacy
Mail Provider
(Mailgun/SendGrid/SES)
OTP and transactional emailsEmail address, first nameProvider's privacy policy
Cloud Hosting
(Server Provider)
Database and file storageEncrypted data at restProvider's privacy policy
OpenStreetMap / OverpassFinding nearby hospitals and pharmaciesZIP code / coordinates onlyosmfoundation.org
Open-MeteoLocal weather informationCoordinates onlyopen-meteo.com

4.2 Legal Requirements

We may disclose your information if required to do so by law, regulation, court order, or governmental authority, or when we believe disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a lawful request.

4.3 Business Transfers

If CovrMeUp is involved in a merger, acquisition, or asset sale, your data may be transferred. We will notify you via email and/or prominent notice in the app before your data is transferred and subject to a different privacy policy.

4.4 Card Sharing Feature

When you use the "Share Card" feature, you generate a time-limited link (valid 24 hours) that allows the recipient to view specific card details. You control what you share. Shared links expire automatically and cannot be renewed without your action.

5 OpenAI & Card Scanning

๐Ÿ”’ How Card Scanning Works

When you scan an insurance card, your image is sent to OpenAI's GPT-4o Vision API over an encrypted HTTPS connection. OpenAI processes the image and returns the extracted text fields.

  • OpenAI does not store your image after processing (Zero Data Retention policy for API calls)
  • OpenAI does not use your card images for AI model training
  • Images are deleted from OpenAI's servers immediately after the API response
  • We store both your original image and a processed image on our servers for your reference
  • You can delete your scan history at any time from the app

Reference: openai.com/enterprise-privacy

The extracted fields (insurer name, member ID, policy number, etc.) are stored in our database associated with your account. We do not extract or store payment card numbers, CVV codes, or full Social Security Numbers from scanned images.

6 Data Storage & Retention

6.1 Where Data is Stored

Your data is stored on secure servers. All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3.

6.2 How Long We Keep Your Data

Data TypeRetention Period
Account informationUntil account deletion + 30 days
Insurance card dataUntil you delete the card or account
Scan images (original + processed)Until you delete the scan log or account
Expense recordsUntil you delete them or close account
OTP codes10 minutes (auto-expire)
JWT tokens60 minutes (configurable)
Server logs90 days rolling
Anonymised analytics2 years

6.3 Backups

We maintain encrypted database backups for disaster recovery purposes. Backup data is subject to the same privacy protections as production data.

7 Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.3
  • Encryption at rest: All stored data is encrypted using AES-256
  • JWT Authentication: Stateless JSON Web Token authentication with automatic expiry
  • Password hashing: Passwords are hashed using bcrypt (never stored in plaintext)
  • OTP verification: Email-based 6-digit OTP required for account activation and password reset
  • Soft deletion: Deleted cards and accounts are soft-deleted, allowing 30-day recovery
  • Rate limiting: API endpoints are rate-limited to prevent abuse
  • HTTPS only: All connections require HTTPS; HTTP requests are rejected
โš ๏ธ
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security. Please safeguard your login credentials and never share your OTP codes.

8 Your Rights

Depending on your location, you may have the following rights regarding your personal data:

RightDescriptionHow to Exercise
AccessRequest a copy of all data we hold about youEmail privacy@covrmeup.com
CorrectionUpdate inaccurate or incomplete dataProfile settings in the app
DeletionRequest deletion of your account and all associated dataProfile โ†’ Delete Account, or email us
PortabilityReceive your data in a machine-readable formatEmail privacy@covrmeup.com
RestrictionRequest restriction of processing in certain circumstancesEmail privacy@covrmeup.com
ObjectionObject to processing based on legitimate interestsEmail privacy@covrmeup.com
Withdraw ConsentWithdraw consent for OCR scanning at any timeApp settings โ†’ Disable Card Scanning

We will respond to all requests within 30 days. In some cases, we may need to verify your identity before fulfilling a request.

9 Children's Privacy

CovrMeUp is not directed to children under the age of 13 (or 16 in the European Union). We do not knowingly collect personal information from children under these ages.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@covrmeup.com. If we become aware that we have collected personal information from children without verification of parental consent, we will take steps to remove that information from our servers.

10 Cookies & Tracking

Web Platform

Our web-based admin panel uses session cookies for authentication. We use minimal, essential cookies only:

CookiePurposeDuration
covrmeup_sessionAdmin panel authentication session2 hours (configurable)
XSRF-TOKENCross-site request forgery protectionSession

Mobile Application

The mobile app uses local device storage to store your JWT authentication token. No tracking cookies are used in the mobile app. We do not use third-party advertising or analytics SDKs in the app.

11 Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by:

  • Sending an email to the address associated with your account
  • Displaying a prominent notice in the app
  • Updating the "Last Updated" date at the top of this page

Your continued use of the Service after any changes constitutes your acceptance of the new Privacy Policy. We encourage you to review this policy periodically.

12 Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

CovrMeUp Privacy Team

โœ‰๏ธprivacy@covrmeup.com
๐ŸขCovrMeUp Inc., United States
๐ŸŒcovrmeup.com
โฑ๏ธResponse time: within 30 business days