Trust · Privacy

Minimum-necessary data, explicit boundaries.

Insurf builds tools for coverage decisions. This notice explains how the public insurf.io website, the free cost tools (the benefits audit, savings, COBRA, and renewal-letter comparison pages), the Surely by Insurf ChatGPT app, Inveto, Surely, and the Insurf PA Copilot Chrome extension collect, use, disclose, store, and delete data. Customer agreements and BAAs provide additional workflow-specific terms where applicable.

Public website

What the public site handles.

Hosting
The site runs on Vercel, our hosting provider, which processes requests to serve pages and keeps standard, short-lived operational logs (such as request paths and IP-derived routing data) to run and secure the service.
Analytics
We use Vercel Web Analytics for aggregated page-view, performance, and product-event metrics (for example, that an audit ran and which campaign it came from). Per Vercel's documentation it sets no cookies and does not track visitors across sites. We run no advertising pixels, no Google Analytics, and no cross-site trackers.
Scheduling
Booking time with us opens a Cal.com scheduling embed. The details you enter there (name, email, chosen time) go to Cal.com, our scheduling processor, and to us to hold the meeting.
Email
If you email us (for example support@insurf.io or pilot@insurf.io), we keep the correspondence to respond and follow up.
Recipients
Service providers only: Vercel (hosting, analytics) and Cal.com (scheduling) for the public site. We do not sell personal information and do not share it for advertising.
Free tools

The audit, savings, COBRA, and renewal-letter tools.

  • The COBRA comparison and savings quote services accept ZIP code, ages, and optionally an income figure, tax-household size, and an illustrative care profile. They compute cost math from state-filed public data, return the result, and store nothing: no accounts, no lead rows, no request records. Responses may be cached briefly at the CDN edge, keyed on the request parameters, to keep the tools fast.
  • The ICHRA affordability calculator runs entirely in your browser and calls no backend; the numbers you enter never leave the page.
  • The benefits audit parses any uploaded census file in your browser; the file itself is never uploaded. Each audit run is recorded as a derived, run-level record retained to operate and improve the service: the ages used, the ZIP codes found (with counts), the county priced, team size, the current monthly cost you entered, the computed savings figures, the uploaded file's name, and how you arrived (campaign tags, a Google click id, the referring site's domain, and the page you landed on, when present). Names, birthdates, and every other census column never reach our servers.
  • If you generate the letter that asks your employer to run the audit, one derived event is stored per letter: the county, the age range you select, the page it was generated from (the audit results or a county page), the letter template version, campaign and referral tags including the letter's reference code, and the date. The name and employer you type into the letter stay in your browser and are never sent to us. When an employer later runs the audit from the letter's link, that reference code is stored with the run's arrival details so the two can be matched.
  • Your email address is saved with an audit run only when you choose to share it, to send you the full analysis and follow up. Ask at support@insurf.io and we will delete your run records, subject to security and legal retention needs.
  • The renewal-letter comparison (insurf.io/renewal/letter/compare) never receives a letter: there is no upload, no scan, and no document of any kind, only numbers you type. Each submission is stored as a derived record retained to operate the Georgia Renewal Letter Project and publish its aggregates: the market (small group or individual), the current and renewal monthly premiums you typed and the percentage change between them, your five-digit ZIP code and the county, state, and rating area derived from it, the ages you entered (individual) or the group-size band (small group; the exact head count stays in your browser), whether you reported receiving a premium tax credit, the renewal effective month, the illustrative care profile, the computed figures (the lowest modeled 12-month true cost, its metal tier, its premium and cost-sharing components, the plan count, and the data-snapshot id), how you arrived (the same campaign, click-id, referring-domain, and landing-page fields as the audit), and the time received. Your email address is stored only if you enter it, together with a yes/no flag if you tick the box allowing a reporter to contact you about your renewal; both are optional. We never store or receive a name, an address, a member id, or your carrier: the optional carrier menu is discarded in your browser before anything is saved, and a household income entered to model the credit is used for that computation only and not stored. Aggregates are published only from 25 or more Georgia letters, with any county under 10 letters folded into its rating area; individual records are never published. Ask at support@insurf.io and we will delete your submission, subject to security and legal retention needs.
ChatGPT app

Surely by Insurf, inside ChatGPT.

The Surely by Insurf app is an anonymous, read-only calculator: the same public-data cost math as the free tools, exposed to ChatGPT through our MCP server.

Inputs
The tools accept exactly: a ZIP code, the age of each person to cover, optionally an expected annual household income and tax-household size, an illustrative care profile, optionally medication names, and optionally the COBRA monthly premium printed on an election notice.
Processing
Inputs are processed to compute the estimate and returned. They are never stored (no accounts, no authentication, no lead rows, no request records), never sold, and never used for advertising.
Medications
Medication names are accepted only as drug names for cost math context. Diagnoses, dosages, and member identifiers are neither requested nor wanted, and nothing about the request is kept.
The platform
When you use the app, your conversation happens inside ChatGPT and is handled by OpenAI under your agreement with OpenAI. Our server receives only the tool-call inputs listed above and returns the computed result; we do not see or store the rest of your conversation.
Outputs
Every result is deterministic cost math from state-filed public data and carries its disclaimers and the compensation disclosure: educational figures, not a recommendation, eligibility determination, enrollment, or advice.
Extension scope

What PA Copilot handles.

  • Insurf account and authentication data: the paired user's name, user and organization identifiers, role/access status, extension identifier, and a signed, expiring pairing credential. PA Copilot does not collect a user's CoverMyMeds or Athena password.
  • Authorized CoverMyMeds website and form data: patient and member identifiers, demographics and contact details, coverage, prescriber, medication, diagnosis, questions and options, existing form values, validation state, request context, and workflow or submission status needed to prepare prior authorizations. On an authorized CoverMyMeds page, an unambiguously patient-labeled rendered context may start an Athena prefetch before a request is opened. If an exact request link is present, the cache is also bound to that request; otherwise it remains an opaque patient-context cache until an exact request corroborates and adopts it.
  • Authorized Athena health information and website context: the exact athenaOne host is enabled at extension installation or update. In an authorized NTEC session, the extension may read unambiguously patient-labeled rendered contexts on athenaOne pages and use them to start a read-only Athena API prefetch. The retrieved chart may contain patient demographics, coverage, medications, diagnoses, observations, encounters, finalized notes or documents, practitioners, practice information, and related records needed to prepare a prior authorization.
  • The athenaOne observer also records exact CoverMyMeds request links displayed on authorized pages so they can appear as status-unverified work items. A displayed link alone is not treated as proof that a PA is pending, and an ambiguous or contradictory patient context does not trigger a chart match.
  • Operational data needed to run and protect the service, such as stage and timing events, error categories, verified browser-write status, extension version, and audit events. Diagnostics and logs are designed to avoid patient values where the workflow does not need them.
  • Question-learning data contains a sanitized form schema (such as label, section, control type, required state, option shape, and resolution outcome), not the request code, DOM selector, patient answer, Athena evidence, or patient identifier.
Purpose and processors

How extension data is used and disclosed.

Single purpose
Use patient and PA context on authorized CoverMyMeds and NTEC athenaOne pages to prefetch authorized Athena records, prepare evidence-grounded answers, fill and verify the corresponding CoverMyMeds request, and record workflow status and aggregate operational metrics.
Insurf
The extension sends required request, form, account, and patient context over HTTPS to Insurf's application service. Insurf performs authorization checks, Athena retrieval, deterministic answering, evidence validation, workflow caching, audit recording, and response delivery.
OpenAI
For eligible form questions, Insurf may send OpenAI the exact question and option schema plus selected, patient-bound Athena evidence needed to produce a grounded answer while deterministic matching runs in parallel. A grounded deterministic result supersedes model output. Insurf does not send the extension pairing credential or a CoverMyMeds or Athena password to OpenAI.
Other processors
Athenahealth supplies records authorized by the practice; CoverMyMeds receives values written into the user's active request. Vercel provides application hosting and operational logs, and Neon provides the production database and backups. These services process data only as needed to deliver or secure the workflow.
Learning
Insurf may use an encrypted, sanitized, value-free inventory of request control labels, option labels, input types, required state, validation/dependency structure, and aggregate success or timing data to expand deterministic form support and improve reliability. Entered values, answers, patient identifiers, raw HTML, selectors, and credentials are not placed in that question catalog.
No ads or sale
Insurf does not sell extension user data and does not use or transfer it for advertising, ad personalization, creditworthiness, lending, or another unrelated purpose.
Storage and retention

Where data remains and for how long.

  • On the device, Chrome's extension-local storage holds the expiring Insurf pairing credential and bounded connection, retry, activity, value-free question-schema, and pending HTML-upload metadata. Active-request patient values clear on patient change, tab close, actor change, or explicit clear. A patient context queued for preload may remain in Chrome's extension-session storage through page or tab navigation so the prefetched chart can be reused, but expires after no more than 60 minutes and clears on actor, pairing, permission, or release-target change.
  • For authorized troubleshooting and automation reliability, PA Copilot records the complete sanitized browser-accessible CoverMyMeds rendered DOM and live form state immediately before its first fill, after fill attempts, and when the nurse manually captures the page. These snapshots contain patient and form data. A local gzip-compressed copy remains in Chrome's extension-session storage for no more than 60 minutes. PA Copilot also sends each complete supported snapshot to Insurf over HTTPS in integrity-bound compressed chunks; Insurf verifies its size and integrity, stores it in a tenant-, actor-, and exact-request-bound AES-256-GCM encrypted record, and retains it for no more than 30 days. Authorized same-tenant staff and authorized Insurf support personnel can retrieve it as inert plain text for troubleshooting; it is never rendered as executable HTML or sent to OpenAI, activity logs, or the question catalog. Password and file-input values are redacted. Executable inline-script bodies are replaced with a marker while their credential-scrubbed stable fingerprint and exact byte length remain in the snapshot. Browser-inaccessible cross-origin frames and closed shadow roots cannot be captured. Snapshots above the explicit 8 MiB envelope fail visibly without truncation, while the independently delivered control/question inventory and failure status remain available for diagnosis.
  • To diagnose a missing or incorrect Athena extraction without asking the nurse to reproduce the chart, Insurf may retain for no more than 30 days a bounded support archive of the normalized, patient-bound Athena evidence used by a request. The archive can include structured FHIR paths and values, normalized facts, source and resource-type metadata, collection warnings, and bounded text extracted from finalized clinical documents. A fresh provider pull also contributes a separately AES-256-GCM-encrypted, bounded normalized-FHIR resource corpus containing exact scalar paths and values, including fields the current parser did not recognize. The corpus is bound to the exact tenant, request, and matched patient and available only through the authenticated same-tenant workspace or to authorized Insurf support personnel for the disclosed troubleshooting purpose. Authentication and token values, provider URLs, Binary or Attachment data, and unbounded document files are omitted with explicit markers; per-scalar, per-resource, corpus, continuation, and upstream-index limits are disclosed in the workspace rather than presented as complete.
  • Delivered activity retry metadata is locally bounded to seven days; an undelivered event may be retried for up to 30 days so an accepted workflow event is not silently lost during an outage. Value-free HTML-capture status records (including the request-bound CoverMyMeds code needed for authenticated retry) may also retry locally for up to 30 days and are cleared when the paired user, release target, or CoverMyMeds permission changes. Pending or failed value-free question-schema payloads may remain in Chrome local storage and retry for up to 30 days; once Insurf acknowledges delivery, the schema payload is removed and only value-free synced delivery metadata remains locally for up to seven days.
  • In production, patient-bound Athena workflow and prefetch cache rows are encrypted at rest with authenticated AES-256-GCM encryption, bound to the organization, user, extension session, patient, and an opaque source context or exact request. They expire on a sliding window of no more than 60 minutes; requestless context is reused only after an exact opened request corroborates the same patient.
  • The sanitized question catalog is encrypted at rest and may be retained to improve deterministic support. Separate Inveto workflow, submission, security, audit, and aggregate metrics records are retained as required by the customer agreement, operational security, compliance, and applicable law.
  • Insurf transmits user data using HTTPS. Removing the extension removes its Chrome-managed local data. Privacy and deletion requests may be sent to support@insurf.io or bryan@insurf.io; deletion may be limited where the customer controls the record or retention is required for security, contractual, or legal obligations.
Consent and control

Access is explicit and revocable.

  • Exact CoverMyMeds and athenaOne site access is declared at extension installation or update so patient-context detection and preload are enabled by default. PA Copilot states that it may read unambiguously patient-labeled contexts across authorized CoverMyMeds pages, prefetch those patients for up to 60 minutes, read and change authorized request pages, and transmit complete supported sanitized browser-accessible before/after request HTML to Insurf for encrypted troubleshooting retention of no more than 30 days.
  • The extension is restricted to declared Insurf, CoverMyMeds, and athenaOne origins; it does not request access to all websites. A paired, authorized Insurf account and current server-side authorization are still required after Chrome grants site access.
  • Users can withhold or revoke either exact site permission in Chrome's extension settings or remove the extension. They can clear an active patient from PA Copilot and clear the device-local HTML copies from the HTML viewer; clearing a local copy does not delete an already uploaded encrypted Insurf record, which expires within 30 days or may be handled through the customer-authorized deletion process. Connection data expires or is cleared when the actor or release target changes.
  • PA Copilot may fill and verify supported form controls, select an exact existing saved physician signature when authorized and evidence-bound, and attach a compatible finalized patient document. It does not create a signature, enter a credential, or perform the final Send to Plan action.
Limited use

Use stays tied to the PA workflow.

Insurf's use of information received through Chrome extension permissions complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

  • User data is used or transferred only to provide or improve PA Copilot's disclosed single purpose, to maintain security and reliability, to comply with applicable law, or as otherwise permitted by the Chrome Web Store User Data Policy.
  • Insurf personnel do not routinely read patient content to complete forms. Human access to the encrypted troubleshooting snapshots is limited to authorized same-tenant users and authorized Insurf support personnel acting to provide the disclosed troubleshooting function, investigate security or abuse, comply with law, or perform contract-authorized aggregate and de-identified internal operations.
  • The same limits apply to raw data and to data derived, aggregated, or de-identified from it. A customer agreement or BAA may impose additional restrictions and does not expand the extension's Chrome permissions.
Enterprise carve-out

Provider-facing and enterprise services.

Inveto, Surely product accounts, and other provider-facing or enterprise services (including clinical workflow products) are governed by separate written agreements, including Business Associate Agreements where applicable. This notice does not alter those agreements.

  • Visitors may provide contact details when requesting a demo, support, or diligence materials.
  • Authorized Inveto and Surely users may provide account, role, case, document, plan-selection, usage, security, audit, and diagnostic data needed to deliver those services.
  • Customer data is governed by the signed customer agreement and, where applicable, a BAA. This public notice does not itself authorize production patient-data processing or replace those terms.
  • Insurf uses service data to deliver the requested product, maintain audit history, secure the service, provide support, and create contract-authorized aggregate or de-identified improvements within the applicable data boundary.
Limits

What this page does not do.

  • It does not replace a customer BAA or order form.
  • It does not authorize production PHI processing by itself.
  • It does not claim Safe Harbor or Expert Determination for any specific dataset.
  • It does not change the signed terms that govern a named customer pilot.
  • It does not cover third-party services you use directly (Cal.com, ChatGPT/OpenAI, HealthCare.gov) beyond describing what Insurf receives from them; their own notices govern those services.