1. Overview
This Privacy Policy describes how FinSecureTech ("we", "us") collects, uses, and protects information when you use AI Accident Pilot.
2. Information We Collect
- Account data: name, email, phone, firm name, state, role.
- Client data (PHI): information you upload about your clients, including medical records, accident details, and client identifiers.
- Usage data: IP address, user agent, and event logs for security and auditing.
- Payment data: processed by Razorpay. We do not store full card numbers.
3. How We Use Information
- To provide and operate the Service.
- To generate documents using AI.
- To authenticate users and prevent fraud.
- To comply with legal obligations, including HIPAA.
- To send transactional emails (verification, resets, document-ready notices, receipts).
4. Protected Health Information (PHI)
PHI is encrypted at rest with AES-256-CBC. Access is logged in a dedicated PHI access log. PHI is never used to train AI models and is never shared with third parties except the AI provider strictly for the purpose of generating the requested document, under contractual restrictions.
5. Sharing
We share data only with:
- Together AI — to generate drafts (medical text, no account identifiers beyond what is required for generation).
- Razorpay — to process payments.
- Brevo — to send transactional email.
- Legal authorities — if required by law.
6. Data Retention
Client data is retained for 10 years (3,650 days) by default, in line with PI case lifecycle. You may delete a case at any time (soft delete). Audit logs are retained longer for compliance.
7. Security
- AES-256-CBC encryption of PHI fields
- TLS 1.2+ for data in transit
- PDO prepared statements (no SQL injection)
- CSRF protection on all state-changing requests
- Rate limiting on authentication and contact endpoints
- Audit logs for all user actions
8. Your Rights
You may access, correct, or delete your account data at any time through the app. To request a copy of your data, contact us.
9. Cookies
We use a single session cookie for authentication and CSRF protection. See Cookie Policy.
10. Children
The Service is not intended for children under 18.
11. Changes
We may update this policy. Material changes will be communicated by email or in-app notice.