Skip to content
Demo. Don’t upload real policies. Accounts aren’t private.

Privacy Policy

Last updated: 2026-08-22 · Drafted for pre-launch review. This document has not yet been reviewed by outside counsel — see docs/LEGAL_REVIEW_REQUIRED.md in the project repository.

Summary

BNIE reads the insurance documents you upload and answers questions about them. This summary is an overview only — the sections below control. Uploaded documents are stored in private, encrypted cloud storage and are not used to train AI models. Answers are generated using a private, isolated language model made available to us through a managed AWS AI service; your document content is processed by that AWS-hosted pipeline in order to generate an answer, but is not sent to any public third-party AI API or to any other AI vendor outside that pipeline. You can delete a document at any time. No system can guarantee absolute security, and this summary does not limit the fuller terms below.

1. Who we are and what this policy covers

This Privacy Policy is issued by BNIE Inc. (“BNIE,” “we,” “us,” or “our”)[TODO: confirm legal entity name and state of incorporation] and describes how we collect, use, disclose, and protect information in connection with the BNIE website, application, and related services (together, the “Service”). It applies to visitors, registered users, and anyone who uploads a document to BNIE, including before creating an account.

This Privacy Policy is part of, and should be read together with, our Terms of Use. Capitalized terms not defined here have the meaning given in the Terms of Use. By using the Service, you acknowledge this Privacy Policy; where the Service asks for your affirmative agreement (for example, at signup), your agreement covers both documents.

Geographic scope. BNIE is designed for, and currently offered only to, individuals in the United States. We do not currently offer the Service outside the United States, do not represent that the Service complies with the laws of any other country, and this Privacy Policy is written against the U.S. legal framework only. If you access the Service from outside the United States, you do so on your own initiative and are responsible for compliance with local law.

2. Information you provide to us

Depending on how you use the Service, you may provide us with:

  • Account information: an email address and password (or, once available, an authentication credential issued by our identity provider), used to create and secure your account.
  • Uploaded documents and their contents: the insurance-related PDF files you upload, which may include declarations pages, full policy documents, renewal notices, endorsements, or other insurance paperwork you choose to submit. We currently accept PDF uploads only.
  • Information contained within your documents: uploaded documents may themselves contain sensitive personal information that you are choosing to give us, such as your name, address, date of birth, policy and account numbers, vehicle identification numbers, driver information, property or household details, coverage limits, deductibles, premiums, and — if you upload correspondence relating to a claim — claim details. We do not ask you to categorize this information before uploading; it is present because it is part of the document.
  • Questions and messages you submit: the questions you type into the chat feature, and any messages you send us through the contact form (name, email, topic, and message body).
  • Communications with us: anything you send to our support or legal contacts.

We do not currently offer any paid subscription, and the Service does not currently collect payment card or billing information. If that changes, this Policy will be updated to describe the payment processor involved before payment collection begins.

3. Information we collect automatically

When you use the Service, we and our service providers automatically collect:

  • Usage and device information — such as pages and features used, timestamps, browser and device type, and general diagnostic information — through Google Analytics (GA4) and, where enabled, Cloudflare’s web analytics beacon. Both are configured to load only when the corresponding measurement ID is present in our deployment, and our GA4 configuration enables IP anonymization. These tools do not currently power any interest-based or cross-site advertising; we do not run ad campaigns and do not use these tools to build advertising profiles.
  • Server and security logs — including IP address, request timestamps, and basic technical metadata — generated as a normal part of operating a web application and used for security, abuse prevention, and troubleshooting.
  • Account activity records — we maintain an internal audit log of account-level events (for example, sign-in, document upload, document deletion, and that a chat question was asked) tied to your account, used for security, support, and to help us detect misuse. This log records that an event happened and basic metadata about it; it does not store the text of your chat questions.
  • Cookies and similar technologies — we use a strictly necessary session cookie to keep you signed in and a short-lived cookie to associate a document you upload before creating an account with the account you later create. We do not currently use third-party advertising or cross-site tracking cookies. Our analytics providers may set their own cookies or use device signals when their scripts load, subject to their own policies.

We do not attempt to precisely geolocate you. Standard web infrastructure (including our analytics and content-delivery providers) may infer an approximate, city- or region-level location from your IP address; we do not use this to build a profile of your movements.

4. Information we derive from your documents

When you upload an insurance document, an automated pipeline reads it and produces a structured, normalized record of what the document contains — for example, the carrier, policy type, effective dates, coverage sections and their limits, deductibles, exclusions, endorsements, and form numbers. From that structured record, we generate additional derived content, such as plain-language explanations, a list of items we think are worth your attention (gaps, unusual terms, or possible cost discussion points), and suggested questions to bring to your agent or carrier.

This derived information is generated automatically and may be incomplete or inaccurate — see our Terms of Use for important limitations on AI-generated content. We treat derived information as part of the record associated with the document it came from: deleting the source document (see Section 7) is intended to delete the derived structured record and observations generated from it, along with the file itself, from our active systems. Two qualifications are important and are addressed further in Section 7: (a) some copies (backups, security logs, or the audit record that a document existed) are retained on a different schedule, and (b) as we build retrieval-augmented search over your documents using a managed vector index, deleting a document is designed to also remove it from that index, but this integration is still being built and verified as of the date of this Policy.

5. How we use information

We use the information described above to:

  • provide the Service, including processing documents you upload and generating summaries, observations, and answers to your questions;
  • create and maintain your account, and authenticate you when you sign in;
  • secure the Service, including detecting, investigating, and preventing fraud, abuse, and unauthorized access;
  • operate, debug, and maintain the reliability of the Service;
  • respond to your questions and provide customer support;
  • understand aggregate usage of the Service so we can improve it;
  • communicate with you about your account and about the Service, including security and legal notices; and
  • comply with legal obligations and enforce our Terms of Use.

We do not use the content of your uploaded documents or your chat questions to train or fine-tune any AI or machine-learning model, whether ours or a provider’s. This is distinct from, and does not mean the same thing as, whether a third-party infrastructure provider ever processes your content — see Section 6, which explains that distinction and describes the provider involved.

We do not sell personal information, and we do not share personal information with third parties for their own cross-context behavioral advertising, as those terms are used under U.S. state privacy law.

6. How BNIE uses AI, and what happens to your data when it does

BNIE uses artificial intelligence and automated systems to extract structure from documents, generate summaries and observations, and answer your questions. Understanding what that involves matters, because “we don’t train AI on your documents” and “no third party ever processes your documents” are not the same statement, and we want to be precise about which one is true.

Our production design routes document processing and question-answering through a managed AI service operated by Amazon Web Services (AWS), using an underlying language model made available through that service. In that design:

  • your document content and questions are transmitted to that managed AI service, running inside our AWS environment, in order to extract information and generate an answer;
  • they are not sent to any public third-party AI API or to any AI vendor outside the private pipeline described here;
  • retrieval is filtered so that a query can only retrieve chunks belonging to your own account, using tenant metadata attached at ingestion; and
  • based on AWS’s published terms governing this service, AWS does not use content you send to it to train the underlying foundation models. We rely on AWS’s representations about its own service for this statement; we encourage you to review AWS’s current documentation if this distinction matters to you, and we will update this section if our processing architecture changes.

Where BNIE is in building this out. As of the date of this Policy, some of the infrastructure described above — specifically, the managed vector search index that will power retrieval-augmented answers over your documents — is still being built. Until it is fully deployed, portions of document processing may run as a deterministic, non-AI simulation for development and testing purposes, and production question- answering may use a simpler rule-based process rather than a live model call. We will update this Policy as that architecture changes, and this section describes our production design and data-handling commitments regardless of which processing mode is active at a given time.

Amazon Web Services is, in this sense, a data processor / service provider that handles your content on our behalf and under contract, not an independent recipient free to use your content for its own purposes. That is a narrower and more accurate statement than simply asserting no third party ever sees your documents, and we think the more precise statement is the more trustworthy one.

7. Data retention and deletion

Account information is retained for as long as your account is active, and for a limited period afterward to allow you to reactivate your account, resolve disputes, and comply with legal and security obligations.

Documents you upload are retained until you delete them or delete your account. Deleting a document through the Service removes the underlying file from our storage and removes the associated metadata and derived structured record (Section 4) from our active document store.

What deletion does not immediately remove. Deleting a document or your account does not instantaneously purge every copy everywhere. In particular:

  • copies may persist for a limited time in encrypted backups and disaster-recovery systems, which are retained on a rolling schedule and are not individually editable;
  • our audit/security log retains a record that a document existed and was deleted (action, timestamp, and file name), because that record is itself a security control; it does not retain the file or the derived policy data after deletion;
  • once the retrieval index described in Section 6 is fully deployed, deleting a document is designed to also remove it from that index, but — consistent with Section 4 — we are not yet in a position to represent that this propagation is fully automated and verified in every deployment configuration; and
  • we may retain limited information where required by law, to resolve disputes, to enforce our agreements, or to protect against fraud and abuse.

Contact-form submissions (your name, email, and message) are retained as part of our internal activity records so we can respond to you and keep a record of the request; they are not used for any purpose other than responding to you and the security/abuse purposes described in Section 3.

We do not currently offer instantaneous, guaranteed permanent erasure across every system (including backups) — no consumer service reasonably can. Where applicable state law gives you a deletion right, see Section 9.

8. Data security

We use administrative, technical, and organizational safeguards designed to protect information you provide, including:

  • encryption of uploaded documents and account data at rest, using customer-managed keys, and encryption in transit using TLS;
  • private cloud storage that blocks public access, with object paths scoped to your account;
  • tenant-isolation controls enforced at the storage, database, and retrieval layers so that, by design, one account’s data is not queryable by another account;
  • security response headers, a content security policy, and standard web-application hardening; and
  • internal audit logging of account and document activity, used to detect and investigate suspicious activity.

Some safeguards described in our internal security documentation — for example, durable rate limiting and automated malware scanning of uploaded files — are still being built out as of the date of this Policy and are not yet fully in production. We do not rely on them being complete when making the representations above; we describe only what is actually implemented.

No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee its absolute security, and you should take care to use a strong, unique password and to keep your account credentials confidential.

9. Your privacy choices and rights

Depending on where you live, applicable state privacy law may give you rights over the personal information we hold about you, which can include the right to:

  • know what personal information we have collected about you and how we’ve used it;
  • request a copy of, or export, your personal information;
  • request correction of inaccurate personal information;
  • request deletion of your personal information, subject to the exceptions in Section 7;
  • opt out of the sale or sharing of personal information, and of targeted advertising, to the extent we engage in those activities; and
  • not be discriminated against for exercising these rights.

We do not represent that we are currently subject to every state comprehensive privacy law, and our obligations depend on factors like the volume of information we process and your state of residence. Regardless, you may submit a request to exercise any of the above by emailing privacy@askbnie.com. We will verify your request using the information associated with your account (typically, confirming control of the email address on file) before acting on it, and we will respond within the time required by applicable law or, where none applies, within a reasonable time.

You can delete individual documents and, where account deletion is available in the product, your account directly from the Service; where account self-deletion is not yet available in the interface, email us and we will process the request manually. See docs/LEGAL_REVIEW_REQUIRED.md for engineering work needed to fully automate rights fulfillment.

California residents

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, “CCPA”), may give you the rights described in Section 9, plus the right to limit the use of sensitive personal information and, where applicable, rights concerning automated decision-making technology. We do not currently sell personal information or share it for cross-context behavioral advertising, and we have not received or acted on any Global Privacy Control signal differently from an opt-out request submitted by email, because we do not currently operate systems that distinguish the two — treat an emailed request under this section the same as a GPC signal. You may designate an authorized agent to submit a request on your behalf; we may require proof of the agent’s authority and separately verify your identity. This Policy has not yet been reviewed for CCPA-specific notice requirements (categories of personal information collected by CCPA category, categories of sources, and categories of third parties to whom information is disclosed for a business purpose, presented as a formal table) — see docs/LEGAL_REVIEW_REQUIRED.md.

10. Children’s privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Because the Service involves insurance and financial information, we also do not intend the Service for use by anyone under 18 without the involvement of a parent, guardian, or the named insured on the relevant policy; our Terms of Use establish a minimum age for creating an account. If we learn that we have collected personal information from a child under 13, we will take steps to delete it.

11. Service providers

We use the following categories of service providers to operate the Service:

  • Cloud infrastructure, storage, and database hosting — Amazon Web Services (AWS).
  • AI / document processing — a private, isolated language model via AWS, as described in Section 6.
  • Authentication — a managed identity provider for real-account authentication.
  • Analytics — Google Analytics (GA4) and, where enabled, Cloudflare web analytics.
  • Security and content delivery — Cloudflare, where used for delivery/edge security.

We do not currently use a separate email-delivery provider, customer-support platform, or payment processor; if we begin using one, we will update this Policy before doing so. Service providers are permitted to use information we share with them only to perform services for us and subject to confidentiality obligations, and we do not authorize them to sell it or use it for their own independent purposes.

12. Changes to this Policy

We may update this Privacy Policy from time to time. If we make a material change, we will update the “Last updated” date above and, where required by law or where the change materially reduces your rights, provide additional notice (such as an email to the address on your account or a prominent notice in the Service) before the change takes effect.

13. Contact us

Questions about this Policy, or requests to exercise a privacy right, can be sent to privacy@askbnie.com. Security reports can be sent to security@askbnie.com. General legal notices can be sent to legal@askbnie.com.

[TODO: add BNIE Inc.’s registered mailing address / registered-agent address here before launch. A privacy policy for a consumer product handling sensitive financial data should identify a physical point of contact; none currently exists in the repository.]