On This Page
1 Overview
CovrMeUp ("we," "our," "us") operates the CovrMeUp mobile application and web platform (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service.
By using CovrMeUp, you agree to the collection and use of information in accordance with this policy. If you do not agree with these terms, please do not use the Service.
CovrMeUp is designed to help users securely store and manage their insurance cards across categories including Health Insurance, Medicare, Medicaid, Dental, Vision, Pharmacy (Rx), Auto, Homeowners, Life, Travel, Business, and Pet Insurance.
2 Data We Collect
2.1 Information You Provide Directly
| Data Type | Examples | Purpose |
|---|---|---|
| Account Information | First name, last name, email address, phone number, password | Account creation and authentication |
| Insurance Card Data | Member ID, Policy Number, Group Number, Plan Name, Provider Name, Coverage Dates, RX BIN/PCN, VIN, Beneficiary Name | Digital card wallet storage |
| Card Images | Photos of physical insurance cards taken via camera or uploaded from gallery | OCR scanning to auto-fill card fields |
| Expense Data | Premium amounts, deductibles, copays, payment dates, frequency | Expense tracking and summary |
| Location Data | ZIP/PIN code, state | Finding nearby hospitals, pharmacies, and local insurance resources |
| Profile Picture | User-uploaded avatar image | Profile personalisation |
2.2 Information Collected Automatically
- Device Information: Device type, operating system version, unique device identifiers
- Usage Data: Features accessed, pages viewed, actions taken within the app, time and duration of use
- Log Data: IP address, browser type, referring URL, error logs
- Session Tokens: JWT authentication tokens stored locally on your device
2.3 Sensitive Health-Related Information
3 How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide and maintain the Service | Account info, card data | Contract performance |
| Email OTP verification and password reset | Email address, name | Contract performance |
| OCR card scanning via OpenAI | Card image (temporary) | Explicit consent |
| Expense tracking and summaries | Expense entries, card data | Contract performance |
| Location-based services | ZIP code, state | Consent |
| Security and fraud prevention | IP, device info, logs | Legitimate interests |
| Customer support | Account info, usage data | Contract performance |
| Service improvement and analytics | Anonymised usage data | Legitimate interests |
| Legal compliance | All data as required | Legal obligation |
4 Data Sharing
We share your data only in the following limited circumstances:
4.1 Service Providers
| Provider | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| OpenAI | Card image OCR and field extraction | Card image (not stored โ see Section 5) | openai.com/privacy |
| Mail Provider (Mailgun/SendGrid/SES) | OTP and transactional emails | Email address, first name | Provider's privacy policy |
| Cloud Hosting (Server Provider) | Database and file storage | Encrypted data at rest | Provider's privacy policy |
| OpenStreetMap / Overpass | Finding nearby hospitals and pharmacies | ZIP code / coordinates only | osmfoundation.org |
| Open-Meteo | Local weather information | Coordinates only | open-meteo.com |
4.2 Legal Requirements
We may disclose your information if required to do so by law, regulation, court order, or governmental authority, or when we believe disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a lawful request.
4.3 Business Transfers
If CovrMeUp is involved in a merger, acquisition, or asset sale, your data may be transferred. We will notify you via email and/or prominent notice in the app before your data is transferred and subject to a different privacy policy.
4.4 Card Sharing Feature
When you use the "Share Card" feature, you generate a time-limited link (valid 24 hours) that allows the recipient to view specific card details. You control what you share. Shared links expire automatically and cannot be renewed without your action.
5 OpenAI & Card Scanning
๐ How Card Scanning Works
When you scan an insurance card, your image is sent to OpenAI's GPT-4o Vision API over an encrypted HTTPS connection. OpenAI processes the image and returns the extracted text fields.
- OpenAI does not store your image after processing (Zero Data Retention policy for API calls)
- OpenAI does not use your card images for AI model training
- Images are deleted from OpenAI's servers immediately after the API response
- We store both your original image and a processed image on our servers for your reference
- You can delete your scan history at any time from the app
Reference: openai.com/enterprise-privacy
The extracted fields (insurer name, member ID, policy number, etc.) are stored in our database associated with your account. We do not extract or store payment card numbers, CVV codes, or full Social Security Numbers from scanned images.
6 Data Storage & Retention
6.1 Where Data is Stored
Your data is stored on secure servers. All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3.
6.2 How Long We Keep Your Data
| Data Type | Retention Period |
|---|---|
| Account information | Until account deletion + 30 days |
| Insurance card data | Until you delete the card or account |
| Scan images (original + processed) | Until you delete the scan log or account |
| Expense records | Until you delete them or close account |
| OTP codes | 10 minutes (auto-expire) |
| JWT tokens | 60 minutes (configurable) |
| Server logs | 90 days rolling |
| Anonymised analytics | 2 years |
6.3 Backups
We maintain encrypted database backups for disaster recovery purposes. Backup data is subject to the same privacy protections as production data.
7 Security
We implement industry-standard security measures to protect your data:
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.3
- Encryption at rest: All stored data is encrypted using AES-256
- JWT Authentication: Stateless JSON Web Token authentication with automatic expiry
- Password hashing: Passwords are hashed using bcrypt (never stored in plaintext)
- OTP verification: Email-based 6-digit OTP required for account activation and password reset
- Soft deletion: Deleted cards and accounts are soft-deleted, allowing 30-day recovery
- Rate limiting: API endpoints are rate-limited to prevent abuse
- HTTPS only: All connections require HTTPS; HTTP requests are rejected
8 Your Rights
Depending on your location, you may have the following rights regarding your personal data:
| Right | Description | How to Exercise |
|---|---|---|
| Access | Request a copy of all data we hold about you | Email privacy@covrmeup.com |
| Correction | Update inaccurate or incomplete data | Profile settings in the app |
| Deletion | Request deletion of your account and all associated data | Profile โ Delete Account, or email us |
| Portability | Receive your data in a machine-readable format | Email privacy@covrmeup.com |
| Restriction | Request restriction of processing in certain circumstances | Email privacy@covrmeup.com |
| Objection | Object to processing based on legitimate interests | Email privacy@covrmeup.com |
| Withdraw Consent | Withdraw consent for OCR scanning at any time | App settings โ Disable Card Scanning |
We will respond to all requests within 30 days. In some cases, we may need to verify your identity before fulfilling a request.
9 Children's Privacy
CovrMeUp is not directed to children under the age of 13 (or 16 in the European Union). We do not knowingly collect personal information from children under these ages.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@covrmeup.com. If we become aware that we have collected personal information from children without verification of parental consent, we will take steps to remove that information from our servers.
11 Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by:
- Sending an email to the address associated with your account
- Displaying a prominent notice in the app
- Updating the "Last Updated" date at the top of this page
Your continued use of the Service after any changes constitutes your acceptance of the new Privacy Policy. We encourage you to review this policy periodically.
12 Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: