📋 Contents
1 Acceptance of Terms
These Terms & Conditions ("Terms") constitute a legally binding agreement between you ("User", "you") and CovrMeUp Inc. ("Company", "we", "us", "our") governing your use of the CovrMeUp mobile application, web application, APIs, and all related services (collectively, the "Service").
By accessing or using the Service in any way — including registering for an account, scanning an insurance card, storing card data, or browsing our website — you acknowledge that you have read, understood, and agree to be bound by these Terms, our Privacy Policy, and our Terms of Use, which are incorporated herein by reference.
2 Definitions
| Term | Meaning |
|---|---|
| Service | The CovrMeUp mobile app (iOS and Android), web application, admin panel, REST APIs, and all associated features |
| Account | A registered user profile with email, password, and JWT authentication credentials |
| Card | A digital representation of an insurance or identity card stored in the Service |
| Card Scan | The process of uploading a card image for AI-powered data extraction using OpenAI GPT-4o Vision |
| Dynamic Fields | Category-specific data fields (e.g. Member ID, Policy Number, RX BIN) configured per insurance type |
| Expense | A monetary entry (premium, copay, deductible) associated with a card and tracked in the Service |
| OCR / AI Extraction | Automated text recognition from card images using OpenAI GPT-4o Vision API |
| PHI | Protected Health Information as defined under HIPAA (45 CFR §164.501) |
| PII | Personally Identifiable Information such as name, date of birth, member ID |
| JWT | JSON Web Token — the authentication mechanism used for API access |
| OTP | One-Time Password sent to your email for account verification and password reset |
| Admin Panel | Web-based administrative interface for managing users, categories, and system settings |
3 Service Description
CovrMeUp is a digital insurance card wallet that allows users to:
3.1 Core Features
- Store Insurance Cards: Digitise and securely store Health, Medicare, Medicaid, Dental, Vision, Pharmacy (Rx), Auto, Homeowners, Life, Travel, Business, and Pet insurance cards
- AI Card Scanning: Upload a photo of a physical insurance card — OpenAI GPT-4o Vision automatically extracts and maps data to the appropriate dynamic fields
- Dynamic Field System: Each insurance category has purpose-built fields (e.g. RX BIN, Member ID, VIN, Policy Number) managed through an admin panel
- Expense Tracking: Log and monitor insurance-related expenses including premiums, deductibles, copays, and other recurring costs by frequency (monthly, annual, one-time, etc.)
- Card Sharing: Generate secure 24-hour share links for individual cards
- Location Services: Enter a zip code and state to find nearby hospitals, pharmacies, state insurance department contacts, and healthcare resources
- OTP Email Verification: All accounts require email verification via a 6-digit one-time password before access is granted
3.2 Supported Insurance Categories
3.3 Platform Availability
The Service is available on iOS, Android (Flutter mobile app), and web browsers (admin panel). API access is available for authorised integrations using JWT Bearer token authentication.
4 Eligibility & Account Registration
4.1 Eligibility Requirements
- You must be at least 18 years of age (or the age of majority in your jurisdiction)
- You must be a legal resident or citizen of the United States or an authorised jurisdiction
- You must have the legal authority to store the insurance card information you upload (your own cards or cards of dependants you are legally authorised to manage)
- You must not be barred from using the Service under applicable law
4.2 Account Registration
To use the Service you must create an account by providing:
- First and last name
- Valid email address (required for OTP verification)
- Phone number (optional)
- Password (minimum 8 characters)
You must verify your email address via OTP before you can log in. You agree to provide accurate, current, and complete information during registration and to keep it updated.
4.3 Account Security
- You are responsible for maintaining the confidentiality of your password and JWT tokens
- You must notify us immediately at security@covrmeup.com if you suspect unauthorised access
- We are not liable for losses arising from your failure to protect your credentials
- Do not share your account, OTP codes, or access tokens with anyone
4.4 One Account Per Person
Each person may only maintain one active account. Creating duplicate accounts, or accounts on behalf of others without explicit authorisation, is prohibited.
5 Subscription & Billing
5.1 Free Tier
CovrMeUp currently offers its core features at no cost. Users may store cards, scan images, and track expenses without payment during any applicable free period.
5.2 Future Paid Plans
We reserve the right to introduce paid subscription tiers in the future. If we do so, we will:
- Provide at least 30 days' advance notice by email before any paid tier begins
- Allow existing users to continue using any previously free features at no cost for a reasonable transition period
- Clearly disclose all pricing, billing cycles, and cancellation policies before purchase
5.3 AI Card Scanning Costs
Card scanning uses the OpenAI GPT-4o Vision API. Any costs associated with AI processing are currently absorbed by CovrMeUp at no charge to the user. We reserve the right to apply usage limits or charges to this feature with 30 days' notice.
5.4 Refunds
If paid features are introduced, refund requests will be evaluated on a case-by-case basis. Digital services rendered are generally non-refundable unless required by applicable consumer protection law.
6 Acceptable Use Policy
6.1 Permitted Use
You may use CovrMeUp solely for lawful, personal use to store and manage your own insurance cards and the cards of dependants you are legally authorised to manage.
6.2 Prohibited Conduct
- Storing, uploading, or sharing fraudulent, forged, or altered insurance cards
- Using the Service to commit insurance fraud or any other criminal offence
- Uploading cards that do not belong to you or that you are not authorised to manage
- Attempting to reverse-engineer, decompile, or disassemble the Service
- Using automated scripts, bots, or scrapers to access the API without authorisation
- Attempting to gain unauthorised access to other users' data or the admin panel
- Transmitting malware, viruses, or any malicious code through the Service
- Circumventing or disabling any security or authentication features (JWT, OTP, CSRF)
- Using the card sharing feature to distribute sensitive data beyond its intended purpose
- Overloading or attacking our servers (DDoS, brute-force attacks)
- Creating accounts using false identities or impersonating others
- Reselling, sublicensing, or commercialising the Service without written consent
6.3 Card Scanning Limitations
- Card images must be of your own legitimate insurance cards
- Maximum file size: 10 MB per image
- Accepted formats: JPEG, PNG, WEBP, BMP
- Do not upload images containing credit card numbers, CVV codes, or banking PINs
- Card scan results are for informational use — always verify extracted data against your physical card
7 User Content & Data Ownership
7.1 Your Data is Yours
You retain full ownership of all insurance card data, field values, expense records, and profile information you submit to the Service ("User Content"). We claim no ownership over your User Content.
7.2 License to Us
By submitting User Content, you grant CovrMeUp a limited, non-exclusive, royalty-free licence to store, process, and display your content solely for the purpose of providing the Service to you. This licence terminates when you delete your account or the relevant content.
7.3 Data Accuracy
You are solely responsible for the accuracy of the data you enter or confirm. AI-extracted field values are suggestions only — always review and correct them before saving a card. We are not liable for decisions made based on inaccurate stored data.
7.4 Data Export
You may request a copy of all your stored data at any time by contacting privacy@covrmeup.com. We will provide your data in a machine-readable format within 30 days.
7.5 Data Deletion
Deleting a card, expense record, or your account initiates a soft-delete. Data is permanently purged from our servers within 30 days, except where retention is required by law.
8 Card Scanning & AI Data Extraction
8.1 How It Works
When you use the Scan Card feature, your image is:
- Uploaded to our servers and saved to
public/card_scans/ - Optionally pre-processed (greyscale, sharpening, deskew) to improve accuracy
- Sent to OpenAI GPT-4o Vision API along with a structured prompt listing your card category's dynamic fields
- Returned as structured JSON with extracted field values mapped to your category's field definitions
- Stored in the scan log (
card_scan_logstable) along with both original and processed image paths
8.2 Both Images Are Stored
The Service stores two versions of each scanned image:
| Version | Description | Use |
|---|---|---|
| Original | Your unmodified uploaded image | Reference / audit trail |
| Processed | Pre-processed version (greyscale, sharpened) | OCR accuracy improvement |
Both images are accessible via secure URLs and are deleted when you delete the scan log or your account.
8.3 AI Accuracy Disclaimer
8.4 Category Auto-Detection
If you do not select a category before scanning, GPT-4o will attempt to auto-detect the card type from the image. The detected category slug is matched against active categories in your database. You may override the detected category at any time.
8.5 Scan History
All scans are logged in your account history with status (pending, success, failed), confidence score, engine used, and matched field values. You may delete individual scan logs at any time.
9 Data Security
9.1 Security Measures
| Layer | Protection |
|---|---|
| Authentication | JWT tokens (HS256, configurable TTL), OTP email verification, session-based admin guard |
| Password Storage | Bcrypt hashing via Laravel's Hash::make() — never stored in plain text |
| Transport | TLS/HTTPS for all API and web traffic |
| CSRF Protection | Laravel CSRF tokens on all web forms; excluded for API routes using JWT |
| Database | Soft deletes, foreign key constraints, parameterised queries (Eloquent ORM) |
| Input Validation | Server-side validation on all API endpoints using Laravel Validator |
| Access Control | Role-based (user/admin) with middleware enforcement on all protected routes |
| Image Storage | Card scan images stored in public/card_scans/ with unguessable filenames |
9.2 Breach Notification
In the event of a data breach affecting your personal information, we will notify you by email within 72 hours of becoming aware of the breach, as required by applicable law.
9.3 No Absolute Guarantee
10 HIPAA & Health Information
10.1 Nature of Stored Data
CovrMeUp stores insurance card metadata such as Member ID, Group Number, Plan Type, RX BIN, and coverage dates. This data is entered by you and reflects what is printed on your physical insurance cards.
10.2 Not a Covered Entity
CovrMeUp is not a HIPAA Covered Entity (healthcare provider, health plan, or healthcare clearinghouse) as defined under 45 CFR §160.103. We are a consumer-facing card storage application.
10.3 Sensitive Health Data Guidance
- Store only information visible on your insurance card face
- Do not enter SSNs, medical record numbers, or diagnosis codes
- Do not use the card sharing feature to share health data with unauthorised parties
- Date of Birth fields are included because they appear on some insurance cards — treat this data with care
11 Third-Party Services
CovrMeUp integrates with the following third-party services. Your use of the Service implies acceptance of their respective terms:
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| OpenAI | GPT-4o Vision card scanning & field extraction | Card images (zero retention) | openai.com/privacy |
| OpenStreetMap / Overpass | Nearby hospitals & pharmacies lookup | Latitude/longitude (no account data) | osmfoundation.org |
| Open-Meteo | Weather data for location screen | Latitude/longitude only | open-meteo.com |
| Zippopotam.us | ZIP code → city/state/coordinates lookup | ZIP code only | zippopotam.us |
| Mail Provider (Mailtrap / Mailgun / SES / Postmark) |
OTP verification emails & notifications | Email address, first name | Varies by provider |
We are not responsible for the practices, content, or availability of any third-party service. Links to third-party sites are provided for convenience only.
12 OpenAI Integration — Data Handling
12.1 Zero Data Retention
Card images sent to OpenAI via the API are subject to OpenAI's zero data retention policy for API calls. This means:
- Images are processed in memory and not stored by OpenAI after the API response
- Your card images are not used to train OpenAI models
- All data is transmitted over TLS encryption
12.2 Model Used
We use gpt-4o (or gpt-4o-mini) with detail: high for accurate field extraction. The model is instructed via a system prompt to return structured JSON only — never to hallucinate, guess, or fabricate field values not visible on the card.
12.3 AI Liability Limitation
We make no warranty regarding the accuracy, completeness, or reliability of AI-extracted data. Insurance decisions should never be made based solely on AI-extracted values without cross-referencing your physical card or contacting your insurance provider directly.
13 Expense Tracking Feature
13.1 What It Does
The expense tracking feature allows you to log insurance-related costs (premiums, deductibles, copays) per card. Each expense entry includes: amount, currency, frequency (one-time, monthly, quarterly, annual, etc.), expense date, due date, and paid status.
13.2 Home Page Summary
The GET /api/home endpoint returns a real-time summary of your monthly and annual insurance expense totals, broken down by category, along with upcoming dues within the next 30 days.
13.3 Financial Disclaimer
13.4 Supported Frequencies
Expenses can be tracked as: one-time daily weekly monthly quarterly semi-annual annual
Monthly and annual totals are computed by normalising all frequencies to a common basis using standard multipliers.
14 Location Services
14.1 Pincode + State Lookup
When you enter a ZIP code and state, the Service retrieves:
- City, county, latitude, longitude, and timezone (via Zippopotam.us)
- Nearby hospitals within 10 km (via OpenStreetMap Overpass API)
- Nearby pharmacies within 5 km (via OpenStreetMap Overpass API)
- Current weather conditions (via Open-Meteo)
- State insurance department contact information
- National healthcare resources and emergency contacts
14.2 Data Caching
Location lookup results are cached for 24 hours to reduce API calls. Cached data is stored on our server and associated with the ZIP code + state combination, not your personal account.
14.3 Accuracy Disclaimer
Hospital, pharmacy, and location data is sourced from community-maintained OpenStreetMap data. This data may be incomplete, outdated, or inaccurate. Always call ahead to confirm facility details before visiting. In an emergency, always call 911.
15 Intellectual Property
15.1 Our Property
All software, code, design, trademarks, trade names, logos, UI/UX, API structure, dynamic field system, admin panel, and documentation comprising CovrMeUp are the exclusive intellectual property of CovrMeUp Inc., protected by US and international copyright, trademark, and other intellectual property laws.
15.2 Restricted Use
You may not:
- Copy, reproduce, or distribute any part of the Service without written permission
- Use the CovrMeUp name, logo, or branding without explicit written consent
- Create derivative works based on the Service's design or functionality
- Reverse-engineer the app, API, or admin panel
15.3 Feedback
Any feedback, suggestions, or ideas you submit to us become our property. We may use them without restriction or compensation to you.
16 Disclaimers
We do not warrant that:
- The Service will be available uninterrupted or error-free at all times
- AI-extracted card data will be 100% accurate or complete
- Location data (hospitals, pharmacies) will be current or accurate
- Expense calculations will meet accounting or tax standards
- The Service will meet every user's specific requirements
- Defects in the Service will be corrected within any specific timeframe
16.1 Not Insurance Advice
CovrMeUp does not provide insurance advice, recommendations, or comparisons. Nothing in the Service constitutes an endorsement of any insurance provider, plan, or product. Always consult a licensed insurance professional.
16.2 Not Medical Advice
Information about hospitals, healthcare resources, or coverage displayed in the Service is for informational purposes only and does not constitute medical advice. Always consult a licensed healthcare professional for medical decisions.
17 Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, CovrMeUp INC. AND ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, AND LICENSORS SHALL NOT BE LIABLE FOR:
- Any indirect, incidental, special, consequential, or punitive damages
- Loss of data, profits, revenue, goodwill, or business opportunities
- Damages arising from your reliance on AI-extracted card data
- Damages arising from inaccurate location, hospital, or pharmacy data
- Damages from unauthorised access to your account due to your own negligence
- Service interruptions, maintenance downtime, or data loss
- Third-party service failures (OpenAI outages, mail provider issues, etc.)
18 Indemnification
You agree to indemnify, defend, and hold harmless CovrMeUp Inc. and its affiliates, officers, directors, employees, and agents from and against any claims, liabilities, damages, losses, costs, or expenses (including reasonable legal fees) arising from:
- Your violation of these Terms & Conditions
- Your violation of any applicable law or regulation
- Your User Content or card data that infringes any third-party right
- Fraudulent, forged, or misrepresented insurance card data you upload
- Your use of the card sharing feature in an unauthorised manner
- Your misuse of the AI card scanning feature
19 Modifications to Terms & Service
19.1 Changes to These Terms
We reserve the right to modify these Terms at any time. We will notify you of material changes by:
- Sending an email to your registered address at least 30 days before changes take effect
- Displaying a banner notification in the app
- Updating the "Last Updated" date at the top of this page
Your continued use of the Service after the effective date of changes constitutes acceptance of the revised Terms.
19.2 Changes to the Service
We reserve the right to:
- Add, modify, or remove features from the Service at any time
- Change the supported insurance categories or dynamic field definitions
- Change the AI scanning engine or provider
- Introduce or modify API rate limits
- Discontinue the Service with 30 days' notice
20 Termination
20.1 Termination by You
You may delete your account at any time from Profile → Settings → Delete Account. Upon deletion:
- Your account is immediately deactivated
- All cards, expenses, and scan logs are soft-deleted
- Permanent purge occurs within 30 days
- Scan images stored on disk are deleted within 7 days
- Email logs and transaction records may be retained for up to 90 days for legal compliance
20.2 Termination by Us
We may suspend or permanently terminate your account immediately and without notice if you:
- Violate these Terms, our Privacy Policy, or Terms of Use
- Engage in insurance fraud or any criminal activity using the Service
- Upload fraudulent, forged, or stolen insurance cards
- Attempt to gain unauthorised access to our systems or other users' data
- Provide false identity or registration information
- Abuse the card scanning, sharing, or location features
20.3 Effect of Termination
Upon termination, your licence to use the Service ends immediately. Sections covering IP, disclaimers, liability limitations, indemnification, and dispute resolution survive termination.
21 Dispute Resolution
21.1 Informal Resolution First
Before filing any formal dispute, you agree to contact us at legal@covrmeup.com to attempt informal resolution. We will try to resolve your concern within 30 days.
21.2 Binding Arbitration
If informal resolution fails, any dispute, claim, or controversy arising out of or relating to these Terms or the Service shall be resolved by binding individual arbitration administered by JAMS (jamsadr.com) under its Streamlined Arbitration Rules, except for claims eligible for small claims court.
- Arbitration shall be conducted in English
- Arbitration may be conducted remotely at either party's request
- The arbitrator's decision is final and binding on both parties
- Costs of arbitration are split equally unless the arbitrator determines otherwise
21.3 Class Action Waiver
YOU AND COVRMEUP EACH WAIVE THE RIGHT TO A JURY TRIAL AND TO PARTICIPATE IN CLASS ACTION LAWSUITS. All disputes must be resolved on an individual basis. You may not consolidate your claims with any other person's claims or participate in any class, collective, or representative proceeding.
21.4 Exceptions
The following are excluded from arbitration and may be brought in court:
- Claims eligible for small claims court in your jurisdiction
- Requests for injunctive or other equitable relief to prevent IP infringement
- Claims arising from violation of the Computer Fraud and Abuse Act
22 Governing Law & Jurisdiction
These Terms shall be governed by and construed in accordance with the laws of the United States of America and the state of incorporation of CovrMeUp Inc., without regard to its conflict of law provisions.
For matters not subject to arbitration, you consent to the exclusive jurisdiction of the federal and state courts located in the United States.
If you access the Service from outside the United States, you are responsible for compliance with local laws. We make no representation that the Service is appropriate or available in all jurisdictions.
23 Miscellaneous
23.1 Entire Agreement
These Terms, together with our Privacy Policy and Terms of Use, constitute the entire agreement between you and CovrMeUp Inc. regarding the Service, superseding all prior agreements.
23.2 Severability
If any provision of these Terms is found unenforceable, the remaining provisions continue in full force and effect. The unenforceable provision shall be modified only to the extent necessary to make it enforceable.
23.3 No Waiver
Our failure to enforce any right or provision does not constitute a waiver of that right or provision. Any waiver must be in writing to be effective.
23.4 Assignment
You may not assign your rights or obligations under these Terms without our written consent. We may assign our rights and obligations without restriction, including in connection with a merger, acquisition, or sale of assets.
23.5 Force Majeure
We shall not be liable for delays or failures in performance resulting from causes beyond our reasonable control, including natural disasters, internet outages, third-party service failures (including OpenAI), government actions, or pandemic-related disruptions.
23.6 Language
These Terms are written in English. Any translations are provided for convenience only. In the event of a conflict between the English version and a translation, the English version controls.
23.7 Electronic Agreements
You agree that your electronic acceptance of these Terms (by clicking "Create Account", scanning a card, or otherwise using the Service) is as legally binding as a physical signature.
24 Contact Us
For questions, concerns, or notices regarding these Terms & Conditions: