Aicopack

Legal

Privacy Policy

Last updated October 5, 2026

Aicopack gives licensed insurance producers and real estate agents a verified page, a QR intake, and the tools to run the business behind it. This policy explains what we collect, what we do with it, and what we never do with it.

We never sell your data, to anyone, ever.

Who this covers

Our customer is the licensed insurance producer, real estate agent, or agency that holds an Aicopack account. We also process information about that account holder’s own clients and prospects, which they enter or which those people submit through the account holder’s page. We act on the account holder’s instructions with respect to that information.

What we collect

  • Account information. Your name, email address and password hash; billing details are held by our payment processor, not by us.
  • Identity check. If you verify your identity, the check is run by Stripe Identity. We keep the result, not your ID document.
  • Business records you enter. Your public profile and licences, clients, companies, contacts, calls and booking hours.
  • What your clients submit. When someone uses your QR intake, books a call on your page, or sends you their details from it: their contact details, the coverage or service they ask about, and any note they write. Details a client sends go only to that agent. We never sell them or use them for anything else.
  • Workforce survey answers. If you survey a group’s employees, each person’s five answers (age range, doctor visits, a major medical event, prescriptions, who they cover). Their email is used only to deliver the link; the answers are stored with no email or invitation attached, and results are shown only in aggregate once enough people have answered.
  • Visits to your page, as counts. How many people opened your page, checked a licence, booked a call, sent their details or saved your pass, per day. We also count how each visit arrived (your QR code, your link, your card, a wallet pass, your email signature, your video background), the US state it came from (from our hosting provider’s coarse location, never finer than the state and never the address), the kind of device (phone, tablet or computer) and the hour. These are counts only. We keep no record of any one visitor: no IP address is stored, no cookie follows anyone across sites, there is no session recording and no fingerprinting. A repeat visit from the same connection on the same day is dropped before it is counted. A person appears in your records only when they send you their details or you add them. The by-source, by-state, by-device and by-hour counts are deleted after 13 months; the plain daily totals stay with your account. We also combine these counts across all accounts as totals, to see how Aicopack is used; only totals, never an individual agent, visitor or client.
  • Email you send. For mail sent from Aicopack, who it went to, when, and whether it was opened or a link was clicked, plus simple counts about the message (its length, how many links, whether your signature was on it). We do not keep the message itself, and we do not receive, read or store incoming email. We combine these as statistics across all accounts (for example, the open rate of morning emails) to learn what makes email work better; only totals are used, never an individual address, message or client.

Google account data, and our Limited Use commitment

Connecting a Google account is optional. Aicopack works without it: outbound mail is sent through our own provider instead. We do not read your inbox.

If you do connect one, we request only these scopes and use them only as described:

  • gmail.send: to send mail you initiate in Aicopack from your own address rather than ours, so your client sees a message from you.
  • gmail.settings.basic: only when you click “Install to Gmail”, to write your Aicopack email signature into your Gmail send-as settings. We change nothing else.
  • userinfo.email: to show you which account is connected and to send from the right one when you connect more than one.
  • calendar.events: a separate, optional connection that adds the calls booked through Aicopack to your Google Calendar, and updates or removes them when they change. We do not read your other events.
Limited Use. Aicopack’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the features described above; we do not transfer it to others except as needed to provide those features, for security purposes, or to comply with applicable law; we do not use it for advertising; we do not sell it; and we do not use it to develop, train or improve any generalised artificial intelligence or machine learning model. No human at Aicopack reads your mail except where you specifically ask us to investigate a problem, or where we are required to for security or by law.

AI

Aicopack does not send your data, or your clients’ data, to any AI provider, and does not use it to train any model.

You can choose to connect your own AI assistant (for example Claude or ChatGPT) to your account from Account → Connections. A connected assistant can use the same tools you have in the app (clients, calls and calendar, your public page, automations, companies, surveys and proposals) with your permissions, but not sign-in, billing, the identity check or your verify link, and what its provider does with that data is governed by your own agreement with that provider. Information received from Google APIs is never made available to a connected assistant. You can revoke an assistant at any time, and its access ends immediately.

Service providers who process this data for us

  • Cloudflare: hosting, application database and key storage.
  • Stripe: subscription billing and the optional identity check. Card details and ID documents go to Stripe, never to us.
  • Resend: sending mail when you have not connected your own account.

How your Google credentials are stored

Access and refresh tokens are held in Cloudflare’s encrypted key store, separately from the application database, and are never shown in the interface or written to our logs. When you disconnect an account we revoke the token with Google first and then delete our copy, so access ends at both ends rather than only ours. You can also revoke Aicopack yourself at any time from your Google account permissions page.

Retention and deletion

Records you create stay until you delete them or close your account. When you delete a client, we keep only a one-way coded form of their email address (it can’t be turned back into the address) with their email opt-out and the dates of recent automated emails (about 13 months), so if they are ever added again their unsubscribe is still honoured and they aren’t emailed more often than the limits allow. Disconnecting a Google account ends sending from it, and calendar updates, immediately and deletes the stored credentials. You can delete your account from Account settings: it is permanently deleted, with its data, 14 days later, and you can cancel any time before then. You can also ask us to delete it at [email protected].

Sharing

We never sell or rent personal information, to anyone, ever, and we do not share it for advertising. We disclose it only to the providers listed above, to someone you direct us to send it to (including an AI assistant you connect), or where we are legally required to.

Your choices

You can connect or disconnect a Google account or an AI assistant at any time, export a copy of your data from Account settings, delete records you have entered, and delete your account. Depending on where you live you may have additional rights over your personal information; write to us and we will honour them.

Contact

Questions about this policy: [email protected].

Aicopack is a product of TentaPack LLC, Chicago, IL, USA. Reach us at the email above.