Privacy Policy

Leer en español

What data Cleverio AI handles, in which role, for what, who it is shared with and what rights you have.

Version 1.1 · effective 2026-09-06 · Available in English and Spanish. In case of discrepancy, the English version prevails.

1. Who we are and what this policy covers

Alexander Fregonese, self-employed professional (sole trader) established in Spain, Tax ID (NIF) Y3260770M, trading as "Cleverio AI" ("we", "us"), provides customer relationship management software (a CRM) for life and health insurance agents and agencies in the United States, available at cleverioai.com. Our address is Barcelona, Spain, and our contact email is cleverioai@gmail.com.

This policy applies to three groups of people:

  • Anyone who visits our website or requests access to the service.
  • Anyone who uses the CRM as an agent, administrator or owner of an organization (an agency or an independent agent).
  • The people whose data agencies store in the CRM: their clients, their leads and their agent candidates. If you are one of them, the part that concerns you is summarized in the Privacy Notice for Agency Clients, and your agency is your first point of contact.

We play two different roles, and this policy keeps them apart on purpose. For account data, website data and service usage data we are the controller (the business, in California terms). For the data each agency stores about its own clients we are a processor (a service provider): we handle it only on the agency's instructions and to provide the service to it, as set out in the Data Processing Agreement.

Because we are established in the European Union, the General Data Protection Regulation (GDPR) and Spanish data protection law apply to the data we handle as controller, in addition to the US laws that protect you where you live. Where two laws give you different protections, we apply the one that protects you more.

2. Data we handle as controller

  • Account data: name, email, phone, profile photo, email signature, time zone, language and display preferences, password (stored as a hash, never in clear text) and, if you enable two-step verification, the factors you register.
  • Organization data: name, brand and logo, subscribed plan, seats, your own email domain if you configure one, and the trail of who invites, changes the role of or removes whom.
  • Technical data: IP address, browser type, date and time of each access, server logs and an audit trail of sensitive actions (reading a Social Security number, exporting, deleting a client, connecting an integration).
  • Communications with us: access requests, cancellation requests, support.
  • Billing data: plan, price, history of changes. We do not store card numbers: when we enable a payment gateway, the gateway will store the card and this list will be updated beforehand.

3. Data we handle on behalf of agencies

Each agency decides what it stores about its clients. The CRM is designed for data such as the following, some of which is especially sensitive:

  • Identification and contact details: name, date of birth, sex, address, phone, email, preferred language.
  • Social Security number (SSN) or ITIN and bank details: stored encrypted in the database with a key known only to the server, and every read is logged with who did it and when.
  • Health data: medical conditions, medications, tobacco use, and enrollment form answers (tax household, income, employer coverage, Medicare, Medicaid or CHIP).
  • Policies, beneficiaries, premiums, commissions, payments, documents (contracts, policies, IDs) and the agent's notes.
  • Emails the agent sends to the client from the CRM, if they connect Gmail. The CRM does not read the agent's mailbox: it only stores a copy of what is sent from here. The body is stored encrypted and only decrypted when opened, with a log entry.
  • Consents: when, where and how each person authorized the agency to contact them.

We handle this data solely to provide the service to the agency and on its instructions. We do not use it for anything of our own: no advertising, no profiling, no training of artificial intelligence models, no selling. If you are an agency's client and want to exercise a right over it, your agency is the controller and we help it respond to you.

4. What we use data for, and on what legal basis

  • Providing the service (performance of the contract): making the CRM work, storing what you store, sending the notices you configure and syncing what you connect.
  • Security (our legitimate interest and yours): authenticating users, detecting unauthorized access, throttling automated abuse, keeping the audit trail.
  • Support and service communications (performance of the contract): answering questions, notifying changes, incidents, maintenance or limits reached.
  • Billing and account administration (performance of the contract and legal obligations).
  • Complying with legal obligations and responding to valid requests from authorities (legal obligation).
  • Anything else only with your consent, which you can withdraw at any time.

What we do not do: we do not sell personal data, we do not share it with advertisers, we do not run behavioral advertising, we make no automated decisions with legal effects on anyone, and we do not use agencies' client data to train models.

5. Who we share data with

With the providers we need in order to run the service (subprocessors), each under a contract that binds them to handle data only for what we ask and to protect it. The full list, with what each one receives and where it stores it, is on the Subprocessors page and is updated before any change.

  • Supabase: database, authentication and file storage. Always.
  • Vercel: hosting and running the application. Always.
  • Resend: email delivery (service notices, agency campaigns and payment reminders). When sending email that does not go out through the agent's Gmail.
  • Google: sign in with google, and the agent's gmail and google calendar. Only if the agent connects it; disconnects with one click.
  • Anthropic: the copilot (ai assistant). Only when a question is asked to the Copilot, and only if the platform has the integration enabled.

With public authorities when a law, a court order or a valid legal request requires it, and only to the extent necessary. Where the law allows, we will notify the affected agency.

If the business changes hands (sale, merger or reorganization), data may be transferred to the new owner under the same obligations as this policy. We will give notice before it happens.

We never sell or rent personal data. We never share it with third parties for their own marketing.

6. Data we receive from Google

If you sign in with Google, we receive your name, email and photo to identify you. If you connect Google Calendar, we read and write appointments in your calendar to keep them in sync with the CRM. If you connect Gmail, we send emails from your address using Google's send permission (gmail.send) and store a copy of what is sent in the client's record. We do not read your mailbox or your incoming messages: we do not request any Gmail read permission. Your clients' replies are read in your own Gmail.

Cleverio AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we only use that data to provide the features you have enabled, we do not transfer it to third parties except to provide those features or as required by law, we do not use it for advertising, and no human reads it except with your explicit permission, for security purposes or as required by law.

You can disconnect Google at any time from Integrations. When you do, we delete the access tokens; what was already stored in the CRM (appointments and the emails you sent from here) stays because it is part of the client's record, and you can delete it from the CRM itself. You can also revoke access from your Google account.

7. Artificial intelligence (Copilot)

The Copilot answers questions about your book of business using a model from Anthropic. When you ask it something, we send it a purpose-built summary of your data: names, statuses, amounts, dates and tasks. We never send Social Security numbers, bank details, medical conditions or the body of any email, and we only send what your user is allowed to see.

Anthropic processes that data as a provider under its commercial terms and does not use it to train its models. The Copilot's answers are suggestions: decisions about a client or a policy are always made by a person. If the platform does not have the integration enabled, the Copilot sends nothing outside and says so.

8. Cookies

We use only the cookies needed to keep your session and to protect sign-in with Google. We use no analytics, advertising or third-party cookies. Details are in the Cookie Policy.

9. How we protect data

  • Encryption in transit (HTTPS) across the whole application and in the connection to every provider.
  • Additional column-level encryption for SSNs, bank details and email bodies, with a key that lives only on the server. Decrypting them requires a controlled function that records who and when.
  • Isolation between organizations inside the database itself (row-level security policies): an agency cannot see another agency's data, not even through a mistake of ours.
  • Two-step verification available to every user, and enforceable by the organization.
  • An audit trail of sensitive actions that survives even when what it describes is deleted.
  • Provider keys and encryption keys never reach the browser. Sensitive data is never written to logs or third-party tools.
  • Rate limits and brakes against automated abuse; origin verification on every write.
  • Daily backups by the database provider.

The complete measures are in the annex to the Data Processing Agreement. No system is infallible: if we detect an incident affecting personal data, we will notify the affected agencies without undue delay and, at the latest, within 72 hours of confirming it, with what we know and what we recommend doing, and we will notify the competent authority where the law requires it.

10. How long we keep data

  • Account and organization data: for as long as the account is active.
  • After cancellation or termination: 30 days, so the agency can export its data or reactivate the account. After that we delete it from our active systems. The provider's backups are overwritten in their normal cycle (seven days).
  • Audit trail and technical logs: up to twelve months, with no sensitive data.
  • Consents and unsubscribes: while the agency is active and, after termination, for as long as the law requires to be able to prove them.
  • Anything a law requires us to keep longer (for example, billing records): for that time.

11. Your rights

Depending on where you live, the law gives you rights over your personal data. We honor them for anyone, wherever they live:

  • To know what data we hold about you and receive a copy.
  • To correct inaccurate data.
  • To delete your data, except what the law requires us to keep.
  • To take your data with you in a usable format (agencies have a CSV export inside the CRM).
  • To object to or restrict certain uses, and to withdraw consent where a use is based on it.
  • Not to be discriminated against for exercising your rights.
  • If you live in California (CCPA/CPRA): additionally, the right to opt out of the sale or sharing of your data. We do not sell or share it for advertising purposes, so there is nothing to opt out of; you may still ask us to confirm it.
  • If you live in another state with a privacy law (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida and others): the equivalent rights that law grants you.
  • Under the GDPR: the rights above, plus the right to lodge a complaint with a supervisory authority. Ours is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es).

To exercise them, write to cleverioai@gmail.com. We will ask for the minimum needed to confirm you are who you say you are, and we will respond within one month, or within 45 days where US state law sets that period (extendable once, with notice to you, if the case is complex). You may act through an authorized agent. If you disagree with our response, you may ask us to review it and contact the authority of your state or country.

If you are an agency's client or lead, your data is held by the agency as controller: contact your agency first. If you write to us, we will forward your request to it and help it respond; if you get no answer within a reasonable time, tell us.

12. Industry laws: GLBA and HIPAA

Insurance agencies are financial institutions under the Gramm-Leach-Bliley Act (GLBA). We act as a service provider to those agencies and apply the safeguards the Safeguards Rule requires of service providers: limited access, encryption, change control, monitoring and incident notification.

If an agency is a covered entity or a business associate under HIPAA and needs us to process protected health information, it must sign a Business Associate Agreement (BAA) with us before uploading it. We sign one on request; the procedure is in the Data Processing Agreement.

13. Minors

The service is intended for professionals and does not admit users under 18. Data about minors that appears in the CRM (dependents in an insured household) is entered by the agency as part of managing the policy of their parents or guardians, who are the ones who provide it.

14. Where data lives and international transfers

The database and the files live in the European Union (Ireland, AWS eu-west-1). Because agencies and their clients are in the United States, using the service means their data travels between the United States and the European Union. Some providers process data in the United States (hosting, email delivery, Google, Anthropic): each of them is bound by a contract with the safeguards the GDPR requires for such transfers (standard contractual clauses or the EU-US Data Privacy Framework, as applicable to each provider).

15. Changes to this policy

When we change something material (new uses, new third parties, new retention periods) we will notify the owners of each organization by email and inside the CRM at least 15 days before it takes effect. Minor changes are published here with their new date. Each version carries a number and a date at the top.

16. Contact

Privacy and rights: cleverioai@gmail.com. Support: cleverioai@gmail.com. Security incidents: cleverioai@gmail.com. By mail: Alexander Fregonese, Barcelona, Spain.