This policy explains what information Casewave, Inc. ("Casewave," "we") collects, how we use and protect it, and the choices you have. It covers the Casewave agent application, the Client Portal, and casewave.life.
1. Who we are in relation to your information
Casewave provides software to licensed life-insurance agents. That creates two different roles:
- For information about an agent's clients — policies, servicing requests, client details — Casewave is a service provider to your insurance agent. Your agent controls that data; we process it on the agent's behalf to provide the service.
- For agents' own account information and for visitors to our website, Casewave decides how the information is used, and this policy describes those uses.
If you are an agent's client and want to exercise choices about your information, Section 10 explains how requests are routed.
2. What our systems are not designed to collect
Casewave is deliberately built not to collect or store Social Security numbers, bank account or routing numbers, driver's license or other government ID numbers, or health information — there are no database fields for these categories in our systems. We also do not store executed (signed) documents. When a servicing task needs information like this, it is entered directly in DocuSign, the e-signature system of record — Casewave holds the envelope's status and identifiers only. Free-text fields warn against entering these numbers, and Social Security and financial account number patterns are automatically masked before storage.
3. Information we collect
From agents: account and contact details, and professional licensing information (such as NPN, agency identifiers, licensed states, and errors-and-omissions details).
From agents about their clients: information agents import or enter to service their book — names, contact details, dates of birth, addresses, policy details, and beneficiary information.
From clients directly: information you provide in intake forms, portal activity, and chat messages. Chat and note fields warn against entering sensitive numbers, and Social Security and financial account number patterns are automatically masked before storage.
Automatically: device and usage information and service logs. We do not use session-replay tools, and error telemetry is designed to strip personal information. Cookie information is in Section 12's cookie disclosure below.
From service providers: authentication events from Clerk, billing status from Stripe, and envelope status events from DocuSign.
What we specifically do not collect: our systems are not designed to collect or store Social Security numbers, bank account or routing numbers, government ID numbers, or health information — see Section 2. That information is collected only in DocuSign.
4. Categories of personal information
Described using the vocabulary many state privacy laws use:
| Category | Collected? | Notes |
|---|---|---|
| Identifiers (name, email, phone, address) | Yes | Agents and clients |
| Customer records | Yes | Policy and servicing records |
| Professional information | Yes | Agent licensing details |
| Commercial information | Yes | Subscription and billing status (via Stripe) |
| Internet activity | Yes | Usage and device data, logs |
| Sensitive personal information | Limited | Dates of birth and intake details are collected and protected as described in Section 8. Social Security numbers, financial account numbers, government IDs, and health information are not stored (Section 2) |
| Inferences | No | None beyond providing service functionality |
5. How we use information
To provide and operate the service; to automate servicing tasks; to route documents for e-signature; to provide AI assistance (Section 6); to bill agents; for security, fraud prevention, and auditing; for support; and to monitor, troubleshoot, and improve the service; and to comply with law.
What we do not use your information for: we do not sell it, do not use it for advertising, do not use it to train general-purpose AI models, and do not create data products, benchmarks, or industry reports from it — including in de-identified or aggregated form.
6. AI processing
Conversations in the service may be processed by AI model providers to generate responses. Anthropic is our AI model provider. Under Anthropic's commercial terms, Anthropic may not train its models on this data, and the data is processed under Anthropic's Data Processing Addendum, which limits processing to providing the service and imposes confidentiality obligations. To keep conversations useful over time, the service maintains summaries of them.
7. When we disclose information
- Subprocessors — the vendors that help us run the service, listed with their purposes on our public Subprocessor page. We keep that page current and notify agents of changes by email.
- Your agent — clients' information is, by design, available to the agent who services them.
- Legal process — when required by law, subpoena, or court order.
- Business transfers — if Casewave is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this policy's commitments.
- With consent — any other sharing happens only if you agree to it.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We use no advertising trackers.
8. Security
We maintain a written information security program. Our program includes:
- The most sensitive categories are protected by absence: our systems are not designed to store Social Security numbers, bank account details, government IDs, or health information — no database fields for them exist (Section 2).
- Industry-standard TLS encrypts data in transit; our database provider encrypts data at rest.
- Dates of birth, agent notes, policy numbers, and intake records are individually encrypted at the field level; the unencrypted versions of these fields have been removed.
- Tenant isolation is enforced by the database itself and fails closed — a misconfiguration produces an error, not someone else's data.
- Sensitive reads and writes are recorded in an append-only audit log.
- Payments are handled by Stripe on Stripe-hosted pages; card details never touch Casewave's systems.
No method of transmission or storage is 100% secure, and we do not promise otherwise. If a security event affects your information, we will act under our incident-response plan and applicable law — and for agents, under the 24-hour notice commitment in the Agent Terms.
9. Retention and deletion
- While you use the service: we keep the information needed to provide it.
- After an account closes: a 90-day grace period (a reactivation window), then deletion.
- How deletion works: deletion is implemented by cryptographic erasure — we destroy the encryption keys, which renders the encrypted data unrecoverable, including in backups.
- Audit records are retained for 7 years.
- Servicing message history is retained as an immutable record, consistent with insurance-record-keeping expectations. This means a deletion request is honored for your other information, but messages that document servicing work may be retained where records must be kept to comply with legal obligations.
10. Your rights and choices
We offer everyone — agents and clients — the ability to request access to, correction of, and deletion of their information, as a matter of practice, regardless of where you live.
How requests are routed: for information your agent controls, your request goes to your agent as the controller of that data, and Casewave executes it on the agent's instruction. If your agent is unresponsive or no longer uses Casewave, contact us at [email protected] and we will handle the request directly.
We verify identity before acting on a request, and we aim to respond within 45 days.
Email choices: servicing and transactional email is part of the service. If we ever send marketing email, it will include an unsubscribe link.
11. Children
The service is not directed to anyone under 18, and accounts are adult-only (the Client Portal requires an 18+ representation at sign-in). Beneficiary records may include information about minors entered by adults as part of ordinary insurance servicing; that information is protected like all client data and is never sold.
12. Cookies; state-specific disclosures; where we operate
Cookies. The service uses strictly necessary cookies only: authentication/session cookies (Clerk), security cookies (such as CSRF and bot protection on our signup form), and preference storage. We do not use advertising or analytics cookies, so there is no cookie banner to click through.
Do Not Track and Global Privacy Control. We do not track users across third-party sites or over time, and we do not sell or share personal information — so there is nothing for a Do Not Track or Global Privacy Control signal to opt out of. We treat every user as though such a signal were present.
State disclosures. Casewave is currently below the thresholds at which most state comprehensive privacy laws apply to a business of our size; we offer the rights in Section 10 voluntarily and by contract rather than claiming any particular statute applies. As we grow into those laws' scope, this section will carry the state-specific disclosures they require.
US only. The service is offered in the United States and is not directed to persons in the EU or UK.
13. Changes to this policy
We will post changes here with a new effective date and a changelog. For material changes we will give at least 30 days' notice by email and in the app.
