Privacy Policy
Last updated June 15, 2026
CoverCurve helps employers and their brokers compare group healthcare options. To do that we collect a limited amount of personal information about the people who would be covered. This policy explains exactly what we collect, why, who can see it, and how long we keep it. We treat this information as confidential business data and protect it accordingly.
What we collect
From the census you upload, for each person to be covered we collect only:
- First and last name
- Date of birth
- ZIP code
- Gender
- Relationship to the employee (e.g. spouse, child) and, optionally, tobacco use
We also collect the work email and company details of the person who creates a workspace, and basic technical logs (timestamps and IP address for sign-ins and for signed consents).
We do not collect health records, claims, prescriptions, diagnoses, Social Security numbers, or member ID numbers. CoverCurve is for comparing plans, not for processing medical data.
Why we collect it
Premiums are age- and location-rated, so date of birth and ZIP are required to price real plans. Gender and tobacco use are used only when an underwritten quote is requested. We use this data solely to generate your benefit comparisons and to support the broker of record process you initiate, never to sell or advertise.
Who can access it
Access is restricted to your own workspace. Another company can never see your data, and another broker can never see another broker’s clients. A small number of CoverCurve operators may access your data to provide the service (for example, to key in a returned carrier quote). All access requires authentication, travels over HTTPS, and is recorded in an audit log. We use vetted infrastructure providers (Vercel for hosting and file storage, Neon for the database, Resend for email, Anthropic for assisted document extraction) who process data on our behalf under their own security commitments.
How it is protected
Files and database records are encrypted at rest by our cloud providers and in transit via HTTPS. Uploaded files are stored privately with no public links, and uploads are validated and size-limited before they are accepted.
How long we keep it
Original uploaded files (your census spreadsheet, renewal, and quote documents) are automatically deleted after 30 days; the normalized data needed to keep your comparison intact is retained for the life of your workspace. You may request deletion of your data at any time by emailing privacy@covercurve.com, and we will delete it within 30 days unless we are required to retain it.
Contact us
Privacy questions or deletion requests: privacy@covercurve.com
Security issues or vulnerability reports: security@covercurve.com
General support: support@covercurve.com