Effective Date: July 26, 2026 Last Updated: July 26, 2026
1. Introduction
Kubo ("PolicyPurse," "we," "us," or "our") provides a mobile application that helps you store, organize, understand, and act on your insurance policies, warranties, receipts, and related documents (the "App" or "Service"). This Privacy Policy explains what personal information we collect, how we use and share it, the choices you have, and how we protect it.
By creating an account or using the App, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, please do not use the App.
This Policy applies to the App, our website, and any related services we operate that link to it. It does not apply to third-party sites, apps, or services that we do not control, even if accessed through the App.
2. Information We Collect
2.1 Information You Provide Directly
| Category | Examples |
|---|---|
| Account information | Name, email address, phone number (if provided), authentication credentials or social/SSO sign-in tokens |
| Documents you upload | Photos, scans, PDFs, or files of insurance policies, warranties, receipts, manuals, and related documents, including any personal, financial, or coverage details contained within them |
| Household/member information (if you use household sharing) | Names and contact details of household members you invite, and their role/permissions |
| Communications | Messages you send to support, feedback submitted via thumbs up/down on Ask AI answers, survey responses |
| Subscription and payment information | Subscription tier selected, billing cycle, and transaction status. Note: actual payment card details are collected and processed by our payment processor (via RevenueCat and the Apple App Store/Google Play Store); we do not receive or store your full card number |
2.2 Information We Collect Automatically
| Category | Examples |
|---|---|
| Usage and analytics data | Screens viewed, features used, button taps, session duration, crash logs, app version, general engagement patterns |
| Device information | Device type, operating system and version, unique device/advertising identifiers (where permitted), language and locale settings |
| Approximate location | Coarse, IP-derived location (e.g., city/region) used only where relevant to app functionality (e.g., localizing insurance terminology); we do not collect precise GPS location |
2.3 Information Generated by the App (Derived / AI-Processed Data)
| Category | Examples |
|---|---|
| Extracted document fields | Provider/issuer name, document type, policy dates (start, expiry, renewal), coverage limits, excess/deductible amounts, claims contact information, and AI-generated summaries, produced by our OCR and AI extraction pipeline |
| OCR text | Raw text extracted from your uploaded documents, used to power extraction, search, and Ask AI |
| Vector embeddings | Numerical representations of your document content used to power semantic search and Ask AI's retrieval-augmented responses |
| Ask AI conversation history | Your questions, the assistant's answers, which documents were cited, and any thumbs up/down feedback you provide |
| Reminders and Incident/Claims data | Auto-generated reminders and due dates; incident type and checklist progress you create in Incident Mode; Claims Prep packet contents (evidence checklist items, uploaded photos, timeline entries, contacts) |
We treat the content of your uploaded documents, OCR text, and Ask AI conversations as sensitive personal data and apply the safeguards described in Section 6.
2.4 Information We Do Not Intentionally Collect
We do not request or knowingly collect government identification numbers, Social Security numbers, or full payment card numbers directly from you. Where such data happens to appear within a document you upload (e.g., a policy schedule that includes a partial account number), it is stored as part of that document like any other document content, protected under the same security controls described below, and is never independently extracted, tagged, or indexed as a standalone data point.
3. How We Use Your Information
We use the information described above to:
- Provide the core Service — store and organize your documents; run OCR and AI extraction to identify categories, dates, and coverage details; power search, Ask AI, Reminders, Incident Mode, and Claims Prep.
- Personalize and improve the App — tailor Explore tab suggestions, Benefits summaries, and reminder timing to your documents and behavior.
- Communicate with you — send push notifications and (where enabled) emails for reminders, renewal deadlines, incident nudges, product updates, and support responses.
- Maintain security and integrity — detect fraud, abuse, or security incidents; enforce our Terms of Service; debug and maintain reliability.
- Analyze aggregate usage — understand feature adoption and app performance using privacy-safe, consented analytics (see Section 5.1).
- Process payments and manage subscriptions — administer Free, Plus, and Household subscription tiers through our payment infrastructure.
- Comply with legal obligations — respond to lawful requests, enforce agreements, and meet recordkeeping or regulatory requirements.
We do not use the content of your documents, OCR output, or Ask AI conversations for advertising purposes, and we do not sell this information.
3.1 AI Processing — How It Works and Its Limits
- Ask AI is a retrieval-grounded assistant: it answers questions using only your own vault documents (plus general, non-personalized knowledge for definitions or process explanations), and cites the specific document(s) it relied on.
- Document content, OCR text, and chat inputs may be sent to our AI processing provider(s) (currently including OpenAI, operating under our commercial API terms) solely to generate extraction results and Ask AI responses.
- We do not permit our AI providers to use your document content or conversations to train their general-purpose models. Our agreements with AI vendors contractually prohibit this.
- Ask AI is not a substitute for advice from your insurer, a licensed insurance professional, or an attorney. Coverage-related answers include a reminder that final determinations rest with your insurer and policy documents.
4. Legal Bases for Processing (EEA/UK Users)
If you are located in the European Economic Area, United Kingdom, or another jurisdiction requiring a legal basis for processing, we rely on:
- Contractual necessity — to provide the App and features you've requested (e.g., storing documents, generating reminders).
- Consent — for optional analytics tracking (Section 5.1), marketing communications, and any optional data uses we ask you to opt into.
- Legitimate interests — for security, fraud prevention, and product improvement, balanced against your rights.
- Legal obligation — where processing is required to comply with law.
You may withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
5. Sharing of Information
We do not sell your personal information. We share information only in the following circumstances:
5.1 Analytics and Consent
Before any analytics tracking begins, we present an in-app consent dialog describing what is tracked and why. You may decline or later withdraw consent in Settings. When you consent:
- We collect behavioral/usage events (e.g., feature taps, screen views, reminder interactions).
- We do not send raw document text, OCR output, search query strings, or Ask AI question/answer content to our analytics provider. Analytics events are structured to exclude the substance of your documents and conversations.
- Analytics data is processed with EU data residency where applicable.
We do not use Apple's App Tracking Transparency (ATT) prompt because we do not perform cross-app/cross-site ad tracking. This may change if our practices change, in which case we will update this Policy and request consent as required by law.
5.2 Household Sharing
If you enable Household sharing, documents and information you choose to share become visible to other members of your Household group, subject to the permissions you configure. Members you invite will need to accept an invitation; each member's own account information is subject to this Policy.
5.3 Legal, Safety, and Business Transfers
We may disclose information: (a) to comply with a legal obligation, court order, or valid legal process; (b) to protect the rights, property, or safety of PolicyPurse, our users, or the public; (c) in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections; or (d) with your explicit consent for a purpose not otherwise described here.
5.4 No Direct Insurer/Manufacturer Integrations (Current State)
As of this version of the App, we do not transmit your documents or extracted data directly to insurers, manufacturers, or claims-processing third parties. Any future feature enabling direct submission to a third party (e.g., a claims API integration) will be clearly disclosed and will require your affirmative action to use.
6. Data Security
We implement technical and organizational safeguards appropriate to the sensitivity of insurance and financial documents, including:
- Encryption in transit (TLS) and at rest for all documents and extracted data.
- Biometric or PIN app-lock (Face ID/Touch ID/fingerprint or passcode), with configurable auto-lock timeout.
- Access controls limiting internal access to personal data to personnel who need it to operate the Service.
- Data minimization — we avoid retaining full raw OCR text longer than necessary for the features that depend on it (search and Ask AI retrieval).
- Incident response planning — we maintain a documented data breach response process and will notify affected users and, where legally required, regulators, without undue delay in the event of a breach affecting your personal information.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. Please use a strong device passcode and keep your login credentials confidential.
7. Data Retention
| Data Type | Retention Approach |
|---|---|
| Documents and extracted fields | Retained while your account is active and for as long as needed to provide the Service; deleted upon account deletion (subject to Section 7.1) |
| Raw OCR text | Retained only as long as needed to support search/Ask AI; not retained indefinitely beyond product need |
| Chat/Ask AI history | Retained to preserve your conversation history and improve answer quality, until you delete it or delete your account |
| Analytics events | Retained in aggregate/pseudonymized form for a limited period consistent with our analytics provider's retention settings |
| Account information | Retained while your account is active |
7.1 Post-Deletion Retention
After you delete a document, a conversation, or your entire account, we may retain limited data for a reasonable period (typically no longer than [90 days], unless a longer period is required by law) to: back up systems, prevent fraud, resolve disputes, or comply with legal obligations. Backups are purged on our standard rotation schedule.
8. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you.
- Correction — correct inaccurate or incomplete information, including AI-extracted fields (you can also do this directly in-app).
- Deletion — request deletion of a specific document or your entire account and associated data.
- Portability — receive your data in a portable, machine-readable format.
- Restriction/Objection — object to or request restriction of certain processing (e.g., withdraw analytics consent).
- Non-discrimination — we will not discriminate against you (e.g., by degrading Service quality) for exercising these rights.
How to exercise these rights: Use the in-app data/export/delete controls in Settings, or contact us at [privacy contact email]. We will verify your identity before fulfilling requests and will respond within the timeframe required by applicable law (e.g., 30 days under GDPR, 45 days under CCPA/CPRA).
8.1 California Privacy Rights
If you are a California resident, the CCPA/CPRA gives you the rights described above, plus the right to know the categories of personal information collected, disclosed, and (if applicable) "shared" for cross-context behavioral advertising. We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
8.2 European/UK Users
If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority.
8.3 International Data Transfers
Your information may be processed in countries other than your own, including the United States, where our infrastructure and service providers operate. Where required, we rely on appropriate safeguards for such transfers (e.g., Standard Contractual Clauses) and select providers offering regional data residency options (such as EU data residency for analytics) where feasible.
9. Children's Privacy
The App is not directed to, and we do not knowingly collect personal information from, children under the age of 16 (or the relevant age of digital consent in your jurisdiction). If we learn that we have collected personal information from a child without appropriate parental consent, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at [privacy contact email].
10. Third-Party Links and Integrations
The App may surface links to third-party websites (e.g., an insurer's claims portal) or reference third-party benefits (e.g., "travel insurance included with your credit card"). We are not responsible for the privacy practices of third parties, and this Policy does not apply to information you provide directly to them.
11. Push Notifications and Communications Choices
You can manage reminder push notifications, their lead times, and frequency in-app under Settings, and can opt out of non-essential communications at any time. You may not be able to opt out of certain essential service communications (e.g., security alerts, changes to this Policy).
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. If we make material changes, we will notify you via in-app notice, email, or another reasonable method, and update the "Last Updated" date above. Your continued use of the App after changes take effect constitutes acceptance of the revised Policy, to the extent permitted by applicable law.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:
Kubo [Company Address] Email: [privacy contact email] [Data Protection Officer / EU representative, if applicable]
14. Region-Specific Addenda (To Be Completed Prior to Launch)
Depending on your launch markets, consider adding jurisdiction-specific addenda covering:
- EU/UK GDPR Addendum — full Article 13/14 disclosures, DPO contact (if required), international transfer mechanism detail.
- California/US State Privacy Addendum — categories of personal information collected/disclosed in the CCPA-mandated table format, "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information" links if thresholds are met, Colorado/Virginia/Connecticut/Utah state-specific rights if you have users there.
- Insurance-Sector-Specific Disclosures — some jurisdictions regulate "personal financial information" or "nonpublic personal information" collected in connection with insurance (e.g., U.S. state Insurance Data Security Laws modeled on the NAIC Model Law, GLBA-adjacent considerations if applicable to your business model). A licensed attorney should confirm whether these apply given PolicyPurse does not itself underwrite insurance but does process insurance documents.
- App Store Disclosures — ensure this Policy is consistent with your Apple App Store "Privacy Nutrition Label" and Google Play "Data Safety" section submissions, since inconsistencies between store disclosures and this Policy are a common source of platform rejection and regulatory scrutiny.
This document was prepared as a draft starting point and does not constitute legal advice. Please have qualified legal counsel review and finalize this Privacy Policy before publishing it or launching the App in any jurisdiction.