In short: Coily helps insurance agencies issue certificates of insurance. We collect the account data you give us (name, work email, sign-in details) and the business records your agency puts into Coily. We use them to run the product — including AI reading of certificate requests — and for nothing else. We do not sell personal information, we do not run advertising or analytics trackers, and we do not use your data to train AI models. Questions or requests: legal@trycoily.com.
Who we are
Coily ("Coily," "we," "us") operates the trycoily.com website, the Coily web application, and the Coily add-ins for Microsoft Outlook and Gmail (together, the "Service"). Coily is operated from the United States.
For questions about this policy or your data, contact legal@trycoily.com.
Our two roles
Coily handles two kinds of data, and our role is different for each:
- Account and service data — the data described in this policy that we collect about you as a user (your name, email, sign-in and usage records). For this data, Coily decides how and why it is processed, and this policy governs.
- Customer Content — the business records your agency puts into Coily: clients and named insureds, policies and their limits and endorsements, certificate holders, certificate requests, and issued certificates. Your agency owns this data and decides why it is processed; Coily processes it only to provide the Service under our agreement with your agency. If you are a client or certificate holder of an agency that uses Coily, contact that agency about its records — we process them on the agency's behalf.
What we collect
- Account data — your name, work email address, role, and organization membership. If you sign in with a password, Supabase (our authentication provider) stores it as a secure hash; we never see or store your plain-text password. If you sign in with Microsoft or Google, we receive your name, email, and profile photo from that provider.
- Profile photo — optional; only if you upload one.
- Customer Content — the records described above, entered by your team, imported by your team, or extracted from certificate requests you ask Coily to read.
- Email content you send to the add-in — when you open the Coily pane on an email (or use the Gmail add-on on a message), the content of that message is sent to Coily to extract the certificate request. This happens only for messages you open the add-in on. Coily has no standing access to your mailbox and does not read other messages.
- Payment data — handled by Stripe. Card details are collected directly by Stripe and never touch our servers; we store only your subscription status, seat count, and Stripe customer reference.
- Usage and security records — an append-only audit log of actions in your workspace (who did what, when, and from which IP address), API and add-in key usage timestamps, and per-organization AI usage metering (token counts and cost, no message content).
- Technical data — session cookies, IP address (used for rate limiting and bot protection), and standard server logs kept by our hosting provider.
- Public demo — if you use the "try it" demo on our landing page, the text you paste is processed to produce the extraction shown to you, and a hashed form of your IP address is kept briefly for rate limiting. Don't paste real client data into the public demo.
We do not collect precise geolocation, biometric data, health records, government ID numbers, or advertising identifiers. We do not use third-party analytics or advertising trackers anywhere on the Service.
Why we use it
- To provide the Service — reading certificate requests, verifying them against policy data, issuing certificates, and keeping your workspace running.
- To secure the Service — authentication (including multi-factor authentication), tenant isolation, rate limiting, bot protection on the public demo, and the audit log your agency relies on.
- To bill — seat-based subscription billing through Stripe.
- To communicate about the Service — transactional email only: account verification, password resets, security notices, and billing notices. We do not currently send marketing email. If we ever do, it will include an unsubscribe link.
- To meter usage — per-organization AI cost tracking, so usage reporting works and pricing stays honest.
AI processing
AI is core to how Coily works, so here is exactly what it does:
- When Coily reads a certificate request, the request text (and, where relevant, policy data needed for verification) is processed by Anthropic's Claude models through Anthropic's commercial API.
- Our agreement with Anthropic includes a zero-data-retention arrangement: Anthropic does not retain the inputs or outputs of these requests, and does not use this data to train its models.
- We also have a signed Business Associate Agreement (BAA) with Anthropic. Today's Service processes no protected health information, so the BAA is a forward-looking safeguard — the AI layer is already HIPAA-eligible if a future product line ever brings health data into scope.
- We do not use your data to train AI models either — not ours, not anyone's.
- Coily's verification engine is designed so that AI output is checked against policy records, and anything ambiguous or unverified is routed to a human at your agency. Coily does not make automated decisions about individuals that have legal effects; issuance decisions belong to your agency and its licensed professionals.
How long we keep it
- Account data — for as long as your account exists. When your organization is deleted, its data is deleted.
- Customer Content — for as long as your agency's workspace exists; it is your agency's business record. Issued certificates and the audit log are kept for the life of the workspace because they are designed to be a durable, tamper-evident record for your agency.
- Technical logs and demo rate-limit records — kept briefly and rotated automatically.
When data is no longer needed, we delete it. You can request deletion of your account data at legal@trycoily.com; requests about Customer Content go to your agency, and we act on the agency's instructions.
Security
We protect data with encryption in transit (TLS) and at rest (AES-256), database row-level isolation so one agency can never read another's data, multi-factor authentication, API secrets stored only as cryptographic hashes, and an append-only audit log. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security — but security is designed into the product, not added on. If a breach affects your data, we will notify you and regulators as required by applicable law.
Your rights and choices
Wherever you live in the United States, we honor the same set of rights over your account data:
- Access — ask what we hold about you.
- Correct — fix inaccurate account data (name and photo are self-service in Settings).
- Delete — ask us to delete your account data.
- Portability — get a copy in a usable format.
- Appeal — if we decline a request, you may appeal and we will explain the outcome.
- No discrimination — exercising these rights never affects your service.
Send requests to legal@trycoily.com. We will verify your identity (normally by confirming control of your account email) and respond within the time required by your state's law — and in any case within 45 days. For Customer Content, we forward the request to your agency or direct you to it, since that data belongs to the agency's records.
Your California privacy rights
California residents have specific rights under the CCPA/CPRA, and we honor them as described above: the right to know, access, correct, and delete personal information, the right to non-discrimination, and the right to use an authorized agent. In the preceding 12 months we have collected the categories of personal information described in "What we collect," for the purposes described in "Why we use it," from you directly, from your use of the Service, and from your sign-in provider if you use one. We have not sold or shared personal information, and we do not sell or share personal information — so there is no "Do Not Sell or Share" opt-out to exercise. We do not use sensitive personal information for purposes that would require a "Limit the Use of My Sensitive Personal Information" link.
Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us data, contact legal@trycoily.com and we will delete it.
Where data is processed
Coily runs on infrastructure in the United States, and your data is stored and processed there. The Service is built for US insurance agencies; if you access it from elsewhere, you understand your data is processed in the US.
Changes to this policy
When we change this policy, we update the date and version at the top and keep the previous versions available on request. For material changes we will notify you by email or an in-product notice before the change takes effect — we will never rely on you happening to re-read this page mid-stream.
Contact us
legal@trycoily.com — all legal, privacy, and rights questions in one place. hello@trycoily.com — everything else.
This policy is provided for transparency and does not constitute legal advice to you. If you are an agency with your own compliance obligations (for example, GLBA safeguards for consumer insurance data), Coily supports them — with encryption, isolation, and audit logging — but your own notices remain your responsibility.
