CoverSmart.ai
Privacy Terms Sign in

Legal

Privacy Policy

This Policy explains what CoverSmart collects, why we use it, when service providers may process it, and the choices available to you.

Effective: September 28, 2026

On this page

  1. 1. Scope
  2. 2. Information we collect
  3. 3. How we use information
  4. 4. Google API data
  5. 5. Disclosure
  6. 6. Retention
  7. 7. Security
  8. 8. Your choices
  9. 9. International processing
  10. 10. Children
  11. 11. Changes
  12. 12. Contact

1. Scope and who we are

CoverSmart.ai is part of AssureGuru.com. CoverSmart ("CoverSmart," "we," "us," or "our") provides software for insurance document processing, policy-data management, quote preparation, workflow automation, and related collaboration tools (the "Services").

This Policy applies to information processed through our websites, applications, APIs, and integrations. If your employer, insurance agency, or another organization provides your account, that organization may separately control information it submits to CoverSmart. Its own privacy notices may also apply.

2. Information we collect

Account and organization information

We may collect your name, business email address, password hash, company, role, account status, profile preferences, and authentication or session information.

Insurance and document information

When authorized users submit documents or records, we may process policy documents, driver license information, names, addresses, dates of birth, vehicle and property details, policy numbers, coverage information, claims-related information, and generated quote files. This information may concern an agency's customers rather than the signed-in user.

Communications and workflow information

We may process support requests, feedback, authorized Gmail messages and attachments, email metadata, drafts, sent messages, WhatsApp workflow submissions, chat content, renewal responses, activity logs, edits, and automation results.

Technical information

We may collect IP address, browser and device information, request timestamps, error and security logs, cookie or session identifiers, and records of how the Services are used. We use essential cookies to authenticate users, protect requests, and maintain sessions.

Connected-service information

If an authorized administrator connects a third-party service, we may receive account identifiers, authorization tokens, file metadata, and content needed to perform the requested integration. The Google-specific practices are described below.

3. How we use information

We use information to:

  • provide, maintain, authenticate, and secure the Services;
  • extract structured information from authorized insurance documents and prepare quotes or comparisons;
  • store, retrieve, edit, synchronize, and share records within the customer's authorized organization;
  • operate requested integrations, communications, and automation workflows;
  • provide support, investigate errors, prevent abuse, and audit activity;
  • improve reliability, usability, and performance using appropriately restricted operational data;
  • comply with law and enforce our agreements.

We do not use customer documents or Google user data for targeted advertising. We do not sell personal information.

4. Google API Services user data

When a customer or authorized administrator connects a Google Account, CoverSmart may request access to Gmail, Google Drive, or Google Sheets only to provide an expressly requested CoverSmart workflow.

Gmail permissions and how we use them

Depending on the enabled workflow, our Google OAuth consent screen may request the following Gmail permissions:

  • Read Gmail (gmail.readonly): read authorized messages and attachments needed to identify, import, and process insurance-related communications and documents.
  • Modify Gmail (gmail.modify): read messages and update labels or message status as needed to organize and track completed workflows.
  • Send email (gmail.send): send messages that an authorized user initiates through CoverSmart.
  • Compose email (gmail.compose): create, update, manage, and send drafts for user-requested communications.
  • Read email metadata (gmail.metadata): read message metadata, such as sender, recipient, subject, date, labels, and headers, without relying on message-body access when metadata is sufficient.

Drive and Sheets permissions may be used to upload, create, read, update, or manage authorized files and spreadsheets for requested document and quote workflows. We access only the Google data needed for the enabled features and do not use Gmail permissions to send messages unless an authorized user or configured workflow directs us to do so.

Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google-authorized data is used only to provide or improve user-facing integration features that are visible and relevant to the user. We do not use it for advertising, sell it, or transfer it to data brokers.

We do not permit people to read Google-authorized content except when necessary to provide support with your affirmative permission, investigate security or abuse, comply with applicable law, or perform internal operations where the data has been aggregated or de-identified as required by Google's Limited Use rules.

OAuth access and refresh tokens are stored only as needed to maintain the authorized connection and must be protected as credentials. You can revoke CoverSmart's Google access at any time from your Google Account connections. Revocation stops future access but does not automatically delete data previously imported into CoverSmart; contact us to request deletion.

5. When information is disclosed

We do not sell personal information and do not share it with third parties for their independent advertising purposes. We may disclose information only as reasonably necessary to:

  • your organization and authorized users: according to account roles and permissions;
  • service providers: such as cloud hosting and object storage, database and cache providers, OpenAI-powered document processing, OnlyOffice document editing, email and communications vendors, and Google APIs when an integration is enabled;
  • external workflows you request: including carrier, property-data, RPA, or callback services initiated by an authorized user;
  • legal and safety purposes: to comply with law, protect rights and safety, or detect fraud and security incidents;
  • business transactions: during a merger, financing, acquisition, reorganization, or sale, subject to appropriate safeguards.

Service providers are permitted to process information only for contracted purposes and are expected to protect it. Their own terms and privacy notices may apply where you directly interact with them.

6. Retention and deletion

We retain information for as long as needed to provide the Services, meet the customer's instructions, maintain security and audit records, resolve disputes, and satisfy legal obligations. Retention varies by data type, account configuration, contractual requirements, and backup cycle.

Temporary local processing files are generally removed after processing. Authorized records and files may remain in databases or object storage until deleted under customer instructions or our retention schedule. Residual copies may remain in protected backups for a limited period and are not returned to active use except for disaster recovery.

7. Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, scoped user roles, secure session cookies, request-forgery protection, logging, and restricted credentials. No transmission or storage system is completely secure, and we cannot guarantee absolute security.

Users must protect their credentials, use accounts only as authorized, and promptly report suspected unauthorized access.

8. Your choices and privacy rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection to certain processing. You may also revoke consent where consent is the basis for processing.

If your account is managed by an employer or insurance organization, please direct record-level requests to that organization first because it may control the data. You may also contact us. We may verify your identity and authority before completing a request, and legal exceptions may apply.

You can manage Google authorization through your Google Account. You can control essential session cookies by signing out or through browser controls, but disabling them may prevent the Services from functioning.

9. International processing

CoverSmart and its providers may process information in countries other than the one where it was collected. Where required, we use contractual or other lawful safeguards for cross-border transfers.

10. Children's privacy

The Services are business tools and are not directed to children under 13. We do not knowingly create accounts for children. Insurance records may contain information about household members or young drivers when submitted by an authorized business user for a legitimate insurance workflow.

11. Changes to this Policy

We may update this Policy as our Services, integrations, or legal obligations change. We will post the revised version here and update the effective date. Where required, we will provide additional notice of material changes.

12. Contact us

For privacy questions, rights requests, or data-deletion requests, contact CoverSmart or AssureGuru using one of the channels below. Please include enough information for us to identify the relevant account and organization, but do not send sensitive insurance documents or credentials.

  • Phone: 888-896-1232
  • Email: alerts@assureguru.com
  • WhatsApp: +1-678-451-1571

© 2026 CoverSmart. All rights reserved.

Privacy Policy Terms & Conditions