Privacy Policy
Operated by myriskmanager.ai LLC
Effective Date: July 18, 2026
Last Updated: July 18, 2026
This Privacy Policy describes how myriskmanager.ai LLC, a Georgia limited liability company ("Company," "we," "us," or "our"), collects, uses, stores, and discloses information when you access or use the myriskmanager.ai web application and related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, do not access or use the Service.
This Privacy Policy is incorporated into and forms part of our Terms of Service. Capitalized terms used but not defined here have the meanings given in the Terms of Service.
1. INFORMATION WE COLLECT
We collect information in three ways: information you provide directly, information generated through your use of the Service, and information from third parties.
1.1 Information You Provide Directly
Account Information. When you create an account, we collect your name, business name, email address, phone number, business address, industry type, and any other information you provide during registration.
Business Information. When you use the Service, you may provide information about your business operations, including employee count, revenue range, physical location details, operational practices, regulatory compliance status, and insurance coverage information.
User Content. You may upload insurance policy documents, insurance quote documents, vendor and contractor certificates of insurance (COIs), inspection photos, compliance records, signed program documents, employee training logs, and other business documents to the Service.
Payment Information. When you subscribe to the Service, payment information is collected and processed directly by Stripe, Inc. We do not receive or store your full credit card number, card verification code, or bank account details. We receive only a payment confirmation and limited transaction metadata from Stripe.
Communications. When you contact us by email or through the Service, we collect the contents of your messages and your contact information.
Agency User Client Data. Agency Users may submit information about their clients, including business profiles, risk assessment responses, and insurance information. Agency Users are responsible for ensuring they have appropriate authorization to submit client data. See Section 9 for Agency User-specific provisions.
1.2 Information Generated Through Your Use of the Service
Usage Data. We collect information about how you interact with the Service, including pages visited, features used, time spent, actions taken, and session data. This data is used for service delivery and security monitoring. Where used for service improvement, it is aggregated and de-identified as described in Section 3.3.
Assessment and Inspection Data. Your responses to Business Risk Snapshot assessments, Location Compliance Inspections, and compliance document discovery conversations are collected and stored to generate your risk scores, reports, and documents.
AI Interaction Data. Your conversations with Reese and Nora, including questions asked and responses received, are stored for service delivery purposes — specifically to maintain conversation context and continuity within your account. Use of this data for service improvement purposes is governed separately by Section 3.3.
Insurance Hub Data. When you use the Insurance Hub, we collect and store the documents you upload and the data generated from them, including insurance quote analyses, vendor certificate of insurance (COI) records and the data extracted from them (such as carrier names, policy numbers, coverage limits, expiration dates, and additional insured status), and coverage gap reports generated by cross-referencing your policy information against your Business Risk Snapshot and other business data. This information is stored to deliver the Insurance Hub features and maintain your records within your account.
Device and Technical Data. We collect standard technical information including IP address, browser type and version, operating system, referring URLs, and device identifiers. This information is used for security monitoring and service optimization.
Log Data. Our servers automatically record information when you access the Service, including access times, pages viewed, and error events.
1.3 Information from Third Parties
Payment Processor. We receive transaction confirmations, subscription status, and limited metadata from Stripe, Inc. in connection with your subscription.
Authentication Providers. If you create an account using a third-party authentication service (such as Google), we receive basic profile information from that provider as permitted by your settings.
2. HOW WE USE YOUR INFORMATION
We use the information we collect for the following purposes. We process personal information only where we have a lawful basis for doing so, as described in the legal basis table below.
Service Delivery. To provide, operate, and maintain the Service, including generating Business Risk Snapshots, Location Compliance Inspection reports, Compliance Documents, Insurance Hub analyses (including policy review, insurance quote analysis, COI management, and coverage gap reporting), and AI-assisted guidance through Reese and Nora.
Account Management. To create and manage your account, process your subscription, communicate with you about your account, and provide customer support.
AI Processing. To process your inputs through our AI systems and generate personalized risk assessments, compliance documents, and recommendations based on your specific business information. All inputs used to generate AI Output — including assessment responses, inspection answers, compliance document discovery conversations, insurance quote documents and vendor certificates of insurance uploaded to the Insurance Hub, and conversations with Reese and Nora — are transmitted to Anthropic’s API. See Section 3 for details.
Safety and Security. To detect, investigate, and prevent fraudulent transactions, unauthorized access, and other illegal or harmful activity. To monitor for security incidents and comply with our breach notification obligations.
Legal Compliance. To comply with applicable laws and regulations, respond to lawful requests from government authorities, and enforce our Terms of Service and other agreements.
Service Improvement. To analyze de-identified, aggregated usage patterns and improve the accuracy and quality of our Service and AI systems. See Section 3.3 for the specific scope of this use and your opt-out rights.
Marketing Communications. To send you product news, feature announcements, and updates about the Service. You may opt out at any time using the unsubscribe link in any such email or by contacting support@myriskmanager.ai.
2.1 Legal Basis for Processing — For Agency Users whose operations involve EU data subjects, and for users in states with applicable privacy frameworks, we process personal information on the following bases:
| Processing Purpose | Legal Basis |
|---|---|
| Account creation and management | Performance of contract |
| Service delivery (assessments, documents, AI guidance) | Performance of contract |
| Payment processing | Performance of contract |
| Security monitoring and fraud prevention | Legitimate interests |
| Breach notification and incident response | Legal obligation |
| Tax and financial record-keeping | Legal obligation |
| Responding to lawful government requests | Legal obligation |
| Service improvement (de-identified, aggregated data) | Legitimate interests |
| Marketing communications | Consent or legitimate interests (existing customers; opt-out available at any time) |
| Analytics cookies | Legitimate interests |
Where we rely on legitimate interests as the legal basis, we have assessed that our legitimate interests are not overridden by your privacy rights. You may object to processing based on legitimate interests by contacting us at support@myriskmanager.ai.
3. AI PROCESSING AND AUTOMATED DECISION-MAKING
3.1 Scope of Anthropic API Processing — All inputs used to generate AI Output through the Service are transmitted to Anthropic’s API. This includes:
- Insurance policy documents uploaded to the Policy Vault
- Insurance quote documents and vendor certificates of insurance (COIs) uploaded to the Insurance Hub
- Your responses to Business Risk Snapshot assessments
- Your responses to Location Compliance Inspection questions
- Your answers during compliance document discovery conversations (including HazCom, Emergency Action Plan, PPE Hazard Assessment, and other compliance programs)
- Your conversations with Reese and Nora
Transmission to Anthropic’s API is necessary for the performance of the Service. By creating an account or entering into a subscription, you acknowledge and agree that your inputs will be processed as described in this Section.
3.2 Anthropic Data Use — As of the Effective Date of this Privacy Policy, Anthropic, PBC does not use data submitted through its API for training its AI models under its standard commercial terms of service, available at anthropic.com/legal/commercial-terms. This means your User Content and conversation data submitted to the Service are not used to train Anthropic’s models.
We cannot guarantee that Anthropic’s policies will remain unchanged. If Anthropic modifies its data use policies in a material way that affects how your data is processed, we will notify you as described in Section 12.
3.3 Our Use of Data for Service Improvement — We may use aggregated, de-identified data derived from Service usage to improve the accuracy and quality of our AI systems and content. This data:
- Is de-identified before use and cannot reasonably be used to identify you or your business
- Is not used to train AI models operated by us or any third party
- Is used only to analyze patterns, identify product improvements, and refine assessment and inspection content
We do not use identifiable User Content for service improvement purposes. You may opt out of this use of your de-identified data by contacting us at support@myriskmanager.ai. Opting out will not affect your access to the Service.
3.4 Automated Decision-Making — The Business Risk Snapshot and Location Compliance Inspection are generated through automated processing of the information you provide. This means:
- Risk scores, category ratings, action items, and inspection findings are produced by AI systems without human review before delivery
- Compliance Documents are generated through automated processing of your discovery conversation responses
- No human reviews AI Output before it is delivered to you
Advisory nature of AI Output. Risk scores and inspection findings are advisory assessments only. They do not constitute binding determinations, regulatory certifications, or professional opinions. They are intended to inform your decisions, not replace them. See Section 6 of our Terms of Service for the full scope of AI Output limitations.
Your rights regarding automated processing. You have the right to:
• Request that we review and address concerns about any AI Output you believe is inaccurate, incomplete, or does not reflect your actual business conditions • Contest the accuracy of any risk score, finding, or recommendation • Provide additional context that should be considered in any assessment
To exercise these rights, contact us at support@myriskmanager.ai with a description of the specific AI Output you wish to have reviewed or contested.
4. HOW WE SHARE YOUR INFORMATION
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We share information only in the following circumstances:
4.1 Service Providers (Sub-Processors) — We share information with third-party service providers that help us operate the Service. These providers are contractually obligated to use your information only to provide services to us and in accordance with this Privacy Policy.
| Sub-Processor | Category | Purpose |
|---|---|---|
| Anthropic, PBC | AI Model Provider | Processes User Content and conversation data to generate AI Output |
| Stripe, Inc. | Payment Processor | Processes subscription payments |
| Base44, Inc. | Infrastructure | Hosts the Service and stores data |
| Resend (resend.com) | Communications | Delivers transactional emails and notifications |
We will update this table when we add or change sub-processors. For Agency Users requesting a Data Processing Addendum, current sub-processor details will be provided in that agreement.
4.2 Agency Users — If you are an SMB User whose information has been submitted to the Service by an Agency User on your behalf, the Agency User has access to your risk assessments, inspection reports, compliance document status, and other information generated through the Service in connection with your account. This access is governed by your relationship with the Agency User and their obligations under our Terms of Service.
4.3 Legal Requirements — We may disclose your information if required to do so by law or in response to valid legal process, including subpoenas, court orders, or government requests. We will notify you of such requests where permitted by law.
4.4 Protection of Rights — We may disclose information where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of the Company, our users, or the public, including to prevent fraud or security threats.
4.5 Business Transfers — If the Company is involved in a merger, acquisition, asset sale, or similar business transaction involving the transfer of personal information, we will provide notice before, or as soon as practicable after, any such transfer takes effect. Notice will be sent to the email address associated with your account and posted prominently within the Service.
If you do not consent to the transfer of your personal information to the acquiring entity, you may request deletion of your personal information prior to the transfer date by contacting us at support@myriskmanager.ai. Requests received less than 7 days before a transfer date may not be processed before the transfer occurs, in which case you may direct your request to the acquiring entity.
Under the CCPA, the transfer of personal information in a business transaction may constitute a "sale" or "share" under certain circumstances. We will provide required disclosures in any transfer notice.
4.6 With Your Consent — We may share your information with third parties when you have given us explicit consent to do so.
4.7 Third-Party Information in Insurance Hub Documents — When you upload vendor or contractor certificates of insurance or other third-party insurance documents to the Insurance Hub, we process the information in those documents — including carrier names, policy numbers, coverage limits, expiration dates, and additional insured status — solely to provide the Insurance Hub features to you. We do not use this information for any purpose other than delivering the Service. We do not sell or share third-party information contained in uploaded documents. Third parties whose information appears in documents you upload have no direct contractual relationship with myriskmanager.ai. If you are a third party whose information has been submitted to the Service by one of our users, contact us at support@myriskmanager.ai to request access, correction, or deletion of your information.
5. DATA RETENTION
We retain your information for the periods described below. After the applicable retention period, information is securely deleted or de-identified.
Data Export. You may request a copy of your data by contacting us at support@myriskmanager.ai. We will provide your data in a portable format within 30 days of your request. We encourage you to request your data before terminating your account if you wish to retain it.
Legal Hold. We may retain information beyond the periods above if required to comply with legal obligations, resolve active disputes, or enforce our agreements.
| Data Category | Retention Period | Voluntary Cancellation | Termination for Cause |
|---|---|---|---|
| Account and profile information | Duration of account | Retained while your account exists; deleted within 30 days of written request | Deleted 30 days after termination |
| Business assessment and inspection data | Duration of account | Retained while your account exists; deleted within 30 days of written request | Deleted 30 days after termination |
| User Content (uploaded documents) | Duration of account | Retained while your account exists; export and download rights preserved | Deleted 30 days after termination |
| Compliance Documents (generated) | Duration of account | Retained while your account exists; export and download rights preserved | Deleted 30 days after termination |
| AI interaction data (Reese/Nora conversations) | Duration of account | Retained while your account exists; deleted within 30 days of written request | Deleted 30 days after termination |
| Agency User client data | Duration of Agency account | Deleted 30 days after termination | Deleted 30 days after termination |
| Free Tier AI Output | Retained while account is active; account hibernated after 12 months of inactivity | Accessible while account is active; after 12 months of inactivity the account is hibernated. One reactivation is permitted; a second 12-month period of inactivity results in deletion with 30 days’ notice | N/A |
| Insurance Hub Data (COI records, quote analyses, coverage gap reports) | Duration of account | Retained while your account exists; export rights preserved; third-party data deleted upon written request to support@myriskmanager.ai | Deleted 30 days after termination |
| Payment and transaction records | 7 years | Retained for legal and tax compliance | Retained for legal and tax compliance |
| Security and access logs | 12 months | Compressed and archived; deleted at end of retention period | Compressed and archived; deleted at end of retention period |
| De-identified, aggregated data | Indefinite | Re-identification is prohibited; this data cannot be used to identify you | Re-identification is prohibited; this data cannot be used to identify you |
6. DATA SECURITY
We implement commercially reasonable technical and organizational security measures to protect your information from unauthorized access, disclosure, alteration, and destruction. These measures include:
- Encryption of data in transit using TLS
- Encryption of data at rest
- Access controls limiting employee access to user data on a need-to-know basis
- Regular security monitoring and logging
- Secure authentication requirements for account access
We conduct periodic reviews of our security practices as the Service evolves and as threats change. We require sub-processors that handle personal information to maintain appropriate security standards and, where practicable, conduct or review security assessments of such providers. Our security practices are designed to be consistent with the FTC Safeguards Rule (16 CFR Part 314) with respect to customer financial information processed through the Service.
No method of electronic transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials and for notifying us promptly if you suspect unauthorized access.
7. DATA BREACH NOTIFICATION
In the event of a security breach involving your personal information, we will notify you at the email address associated with your account in the most expedient time possible, consistent with the legitimate needs of law enforcement, as required by applicable law including Georgia's data breach notification statute (O.C.G.A. § 10-1-912) and the laws of other applicable states.
Breach notifications will describe:
- The nature and scope of the breach
- The categories of personal information involved
- Steps we are taking to address the breach and prevent recurrence
- Steps you can take to protect yourself
To report a suspected security incident involving your account, contact us immediately at support@myriskmanager.ai.
8. YOUR PRIVACY RIGHTS
8.1 All Users — Regardless of your location, you have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information, subject to our retention obligations
- Export: Request a portable copy of your data by contacting support@myriskmanager.ai (provided within 30 days)
- Object to Legitimate Interests Processing: Object to processing based on legitimate interests, including service improvement use of de-identified data (Section 3.3)
- Contest Automated Decisions: Request human review of AI Output or contest the accuracy of any risk score, finding, or recommendation (Section 3.4)
- Opt-out of Marketing: Opt out of marketing communications at any time using the unsubscribe link in any marketing email or by contacting support@myriskmanager.ai
8.2 California Residents (CCPA/CPRA) — If you are a California resident, you have the following additional rights, which we honor whether or not the thresholds of the California Consumer Privacy Act (as amended by the California Privacy Rights Act) apply to us:
- Right to Know: The right to know what personal information we collect, use, disclose, and sell or share
- Right to Delete: The right to request deletion of personal information we have collected
- Right to Correct: The right to request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: We do not sell personal information and do not share personal information for cross-context behavioral advertising
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information beyond what is necessary to provide the Service
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
To submit a CCPA request, contact us at support@myriskmanager.ai. We will respond within 45 days as required by law.
8.3 Residents of States with Applicable Privacy Laws — Residents of states with comprehensive consumer privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Tennessee, Minnesota, Maryland, Montana, Oregon, Delaware, New Hampshire, New Jersey, Nebraska, Iowa, Indiana, Kentucky, Rhode Island, and other states with comprehensive consumer privacy laws in effect — have, to the extent those laws apply to our processing, rights similar to those described above, including rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising and profiling that produces legal or similarly significant effects.
Regarding profiling: our Business Risk Snapshot produces a scored assessment that may influence business decisions, including insurance-related decisions made by Agency Users on behalf of their clients. You have the right to opt out of profiling used for decisions that produce significant effects. To exercise this right, contact us at support@myriskmanager.ai. Note that opting out of risk scoring will substantially limit your ability to use the core features of the Service. This limitation is not a penalty for exercising your privacy rights but is a necessary consequence of the fact that risk scoring is the core function of the Service and cannot be provided without automated processing of your assessment data.
8.4 How to Submit a Request — To exercise any of the rights described above, contact us at:
- Email: support@myriskmanager.ai
- Mail: myriskmanager.ai LLC, 11175 Cicero Drive, Alpharetta, GA 30022
We will verify your identity before processing your request. We will respond within the timeframe required by applicable law — generally 30-45 days, with the possibility of a single extension where permitted.
9. AGENCY USER AND CLIENT DATA
9.1 Agency User Responsibilities — Agency Users who submit client data to the Service are responsible for:
- Obtaining all necessary consents and authorizations from clients before submitting their information
- Ensuring their use of the Service complies with applicable privacy laws and professional obligations
- Providing their clients with appropriate notice that their information is processed through the Service, including transmission to Anthropic’s API for AI analysis
- Maintaining appropriate records of client consents
9.2 Client Data Requests — If you are a client of an Agency User and wish to access, correct, or delete information submitted about you through the Service, contact the Agency User directly. We will cooperate with Agency Users in responding to such requests.
9.3 Data Processing Addendum — Agency Users requiring a Data Processing Addendum — including those whose operations involve EU data subjects, CCPA-covered data, or other data processing frameworks — should contact support@myriskmanager.ai. Agency Users with EU data subject clients must execute a DPA before submitting such data to the Service.
10. COOKIES AND TRACKING
10.1 Cookies We Use — We use the following types of cookies and similar technologies:
Essential Cookies. Required for the Service to function. These include session authentication cookies, security tokens, and preference settings. These cannot be disabled without preventing use of the Service.
Analytics Cookies. Used to understand how users interact with the Service, including which features are used most and where users encounter difficulty. This data is aggregated and de-identified. Users are informed of analytics cookies via an informational notice banner.
No Advertising Cookies. We do not use cookies for advertising, retargeting, or cross-site tracking. We do not share cookie data with advertising networks.
Do Not Track and Global Privacy Control. Because we do not sell or share personal information and do not track users across third-party websites or over time, the Service does not respond to browser "Do Not Track" signals or the Global Privacy Control, which are designed to opt users out of those practices. We will update this disclosure if our practices change.
10.2 Your Cookie Choices — You may configure non-essential cookie preferences by contacting us at support@myriskmanager.ai. You may also configure your browser to refuse or delete cookies. Note that disabling essential cookies will prevent you from using the Service.
11. CHILDREN'S PRIVACY
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected information from a child under 18, contact us at support@myriskmanager.ai and we will delete the information promptly.
12. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Sending an email to the address associated with your account at least 14 days before the change takes effect
- Displaying a prominent notice within the Service
The updated Privacy Policy will be effective on the date stated at the top of the document. Your continued use of the Service after that date, or your continued subscription without cancellation, constitutes your acceptance of the updated policy. If you do not agree with a material change, you may cancel your subscription before the effective date.
13. INTERNATIONAL DATA TRANSFERS
The Service is operated in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
The Service is not specifically offered to individuals or businesses in the European Union. The EU General Data Protection Regulation (GDPR) does not currently apply to our operations, as the Company does not have an establishment in the EU, does not specifically target EU residents, and does not monitor the behavior of EU residents within the EU. If this changes in the future, we will update this Policy and implement appropriate safeguards before offering the Service to EU residents.
Agency Users with clients who are EU data subjects must execute a Data Processing Addendum before submitting such data to the Service. Contact support@myriskmanager.ai to request a DPA. Where a DPA is executed, we process the covered personal data as a processor acting on the Agency User’s documented instructions. We will implement appropriate safeguards for cross-border transfers as required by applicable law.
14. THIRD-PARTY LINKS AND SERVICES
The Service may contain links to third-party websites or services, including links to Safety Data Sheet databases, regulatory agency websites, and vendor resources. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party services you access through the Service.
15. PRIVACY COMPLIANCE PROGRAM
We maintain an internal privacy compliance program that includes periodic review of our data collection and processing practices, designation of a responsible contact for privacy matters, and ongoing assessment of our practices against applicable legal requirements. We monitor developments in AI-specific regulation, including requirements applicable to automated decision-making systems used in insurance and compliance contexts, and will update our practices as applicable requirements develop.
AI Regulatory Compliance. We monitor developments in AI-specific laws, including Colorado’s Automated Decision-Making Technology Act (SB 26-189), which repeals and replaces the Colorado Artificial Intelligence Act (SB 24-205) effective January 1, 2027. If and to the extent any such law applies to the Service, we will provide the required notices, plain-language explanations of adverse consequential decisions, and rights to meaningful human review and correction of inaccurate personal data. Section 3.4 describes how you can contest AI Output and correct personal data today.
Questions about our privacy practices or this Policy should be directed to the contact information in Section 16.
16. CONTACT INFORMATION
For questions about this Privacy Policy or our data practices, contact us at:
General Privacy Inquiries and Rights Requests. support@myriskmanager.ai
Security Incidents and Breach Reports. support@myriskmanager.ai
Data Processing Addendum Requests. support@myriskmanager.ai
Mail. myriskmanager.ai LLC, 11175 Cicero Drive, Alpharetta, GA 30022
This Privacy Policy was last updated on July 18, 2026. Previous versions are available upon request.