Privacy Policy
Last Updated: July 4, 2026
1. Introduction & Scope
XactaClaim is operated by XactaClaim LLC, a U.S.-based software company located at 50 Adams St., Ste 152, Milton, MA 02186, United States. XactaClaim provides claim documentation, communication, and workflow software for claim professionals and their teams.
Customers retain ownership of the claim files, documents, photos, notes, client information, communications, and other content they upload or create in XactaClaim. XactaClaim does not claim ownership of Customer Content. We process Customer Content only to provide, secure, support, maintain, and improve the service, comply with law, and as otherwise described in these Terms and our Privacy Policy. Authorized workspace users control what they upload and share through the platform.
XactaClaim is not an insurance carrier, law firm, public adjusting firm, or licensed claims provider. XactaClaim does not provide legal advice, insurance advice, public adjusting services, claim valuation opinions, or claim outcome guarantees.
For business, privacy, or support questions, contact XactaClaim at hello@xactaclaim.com.
We may process account information, workspace and team information, claim details, client contact information, uploaded documents and photos, notes, communications, portal activity, agreements and signature metadata, voicemail and call metadata when voice features are enabled, billing information through Stripe, support messages, usage logs, device and browser data, cookies and analytics preferences, and AI analysis inputs and outputs.
XactaClaim ("we", "our", or "us") respects your privacy and is committed to protecting it through our compliance with this policy. This policy describes the types of information we may collect from you or that you may provide when you visit the XactaClaim website and use our application (the "Service") and our practices for collecting, using, maintaining, protecting, and disclosing that information.
If you do not agree with our policies and practices, your choice is not to use our Service.
2. The Role of XactaClaim (Data Processor)
For the majority of the data processed within our system—such as the personal, property, and financial information of your clients (the claimants)—you, the public adjusting firm or attorney, act as the Data Controller. XactaClaim acts strictly as a Data Processor.
You represent and warrant that you hold the legal right and have obtained explicit, informed consent from your clients to upload their sensitive data into a third-party cloud environment for AI processing and analysis. We are not liable for your failure to secure such consent.
2A. Customer Data Ownership
Customers retain ownership of the claim files, documents, photos, notes, client information, communications, and other content they upload or create in XactaClaim. XactaClaim does not claim ownership of Customer Content. We process Customer Content only to provide, secure, support, maintain, and improve the service, comply with law, and as otherwise described in our Terms of Service and this Privacy Policy. Authorized workspace users control what they upload and share through the platform.
3. Information We Process
We collect several types of information from and about users of our Service, including:
- Account Information: Your name, email address, brokerage or agency name, phone number, workspace role, and billing contact details. On Premium workspaces, optional workspace branding assets such as logos and brand colors may be stored and displayed to verified client portal users and on generated XactaClaim reports.
- Workspace and Team Information: Agency or workspace name, workspace membership, user roles, invite status, seat counts, workspace settings, and related team administration metadata.
- Claim Data: Claim identifiers and workflow metadata; client or insured name; property address (including structured address fields where provided); client phone and email; date of loss; insurer and assigned adjuster fields; policy PDFs, estimates, photos, documents, and other files you or your clients upload (uploaded files may contain additional sensitive identifiers if you include them, such as account numbers or tax identifiers—we do not require those fields); client tasks and action items; adjusting logs; portal uploads; notification preferences; SMS/MMS and email consent status and related contact snapshots; portal PIN and phone access code verification metadata; and audit or timeline history events associated with claim workflows. On Premium workspaces, embedded images may be extracted from estimate PDFs for staff review before selected images are saved to damage photos.
- Agreements and Signatures: When the client portal agreement workflow is enabled, we may store agreement titles, body text, status (pending or signed), created and signed timestamps, captured signature data, and related agreement PDF or file metadata (such as file name, storage path, and size) on the claim record.
- Internal Claim Notes: Staff-only notes on claim files, including author, note type, body text, source (web or mobile companion API), created and updated timestamps, and archived status. Internal notes are not exposed through the client portal.
- AI Analysis Inputs and Outputs: When you use AI-assisted or automated analysis, summarization, drafting, or Q&A features in the Service, we may process inputs such as documents, images, audio, transcripts, truncated internal note excerpts, task descriptions, timeline or communication summaries, document metadata, structured claim context, and prompts or questions you submit. We may store or display outputs on claim records, in workspace views, or in transient session state, such as structured analysis results, summaries, classifications, generated text, cached AI outputs, model and generation metadata (including timestamps and model identifiers), and analysis status or error metadata when processing fails. See section 3D for how AI processing works.
- Device and Browser Data: IP address, browser type, operating system, device category, approximate locale or timezone signals available from the browser, referrer or page path metadata for optional analytics (when you opt in), and similar technical data collected through normal web or mobile app requests, Firebase Auth sessions, Stripe checkout flows, and essential cookies or local storage described in section 3E and our Cookie Policy.
- Cookies and Analytics Preferences: Your cookie and similar-technology category choices (including optional usage analytics opt-in or opt-out; marketing is not currently used), preference version, and acceptance or update timestamps stored in browser local storage; theme and similar UI preferences; and, when you opt in and this deployment has analytics enabled, aggregated usage or page-view signals sent to analytics providers such as Firebase/Google Analytics (route path only—not query strings, form fields, or claim content). See section 3E and our Cookie Policy.
- Usage Logs: Metadata about how workspaces use the Service, such as feature usage counters, fair-use category usage and monthly limits, billing and webhook audit summaries, security and operational logs, Platform Admin audit events for internal operator actions, AI error diagnostics, and other server-side activity records needed to operate, secure, bill, and support the platform. These logs are generally not claim document content, but may include identifiers such as workspace, user, claim, or provider event IDs.
- Support Messages: Information you send when contacting us for help—for example by email to hello@xactaclaim.com or through contact pages that open your email client—including your name, email address, agency name, message content, and any attachments you choose to include. We use this information to respond to inquiries, provide customer support, and maintain records of support interactions where appropriate.
3A. Client Portal Users
Client portal users are PIN-based participants on a specific claim file through a web browser. They are not necessarily registered Firebase or staff application users, and there is no separate client mobile application. When portal access is enabled, clients may view claim-related portal content, complete action items, upload documents, sign agreements when that beta workflow is enabled, and provide or update SMS/MMS and email notification preferences. Internal claim notes and AI Claim Briefs are not visible to portal users.
Portal authentication uses a claim-specific PIN and is re-verified with our servers. Portal sessions may use browser session storage for convenience as described in section 3F below.
3B. Telephony, SMS/MMS, Email, and Voicemail Data
If your workspace enables messaging and voice features, we may process phone numbers, SMS/MMS message content and metadata (sender/recipient numbers, timestamps, delivery status from carriers), STOP/HELP/START and similar opt-out or help keywords, SMS/MMS and email notification preference selections, SMS/MMS consent status, email consent status, and contact snapshots used to evaluate consent and opt-out state, and document or photo uploads submitted through the client portal or inbound MMS.
When voice or voicemail features are enabled, we may also process call and voicemail metadata such as caller phone number, call or recording identifiers from Twilio, IVR menu selections, match or routing status, voicemail audio storage references, transcription status and text, AI-generated voicemail summaries or urgency labels, and portal PIN or phone access code verification events (for verification only—we do not send PINs in SMS portal-link messages).
These features are powered by third-party providers including Google Firebase and Google Cloud (hosting, authentication, and storage), Stripe (billing), Twilio (messaging and voice when configured), Resend (email when configured), and AI service providers such as Google Gemini when you use analysis features.
You are responsible for obtaining any required consent from clients/claimants for SMS/MMS messaging, phone calls, voicemail recording, and transcription in your jurisdiction. Message frequency varies. Message and data rates may apply.
If a recipient replies STOP or a similar opt-out keyword, we log the request and rely on Twilio/carrier opt-out processing. Users must not continue sending claim-related SMS to recipients who have opted out. Recipients may reply HELP for help or contact hello@xactaclaim.com. See also our SMS Consent & Messaging Disclosures.
Transcription may be delayed, incomplete, or inaccurate. Staff should review recordings and transcripts before taking action.
Inbound email replies from clients are not automatically captured in the timeline unless manually added or handled by a specific supported workflow. SMS/MMS and voicemail capture depend on workspace configuration, consent, opt-out state, and provider availability. Delivery and receipt may be affected by carriers, email providers, consent status, and configuration.
3C. Billing, Subscriptions, and Entitlements
We may process subscription tier and status, billing interval, claim credit balances, booster purchases, extra-seat counts, Stripe customer and subscription identifiers, invoice and payment event metadata, and related entitlement or fair-use information to manage plan access, workspace limits, customer support, fraud prevention, and billing operations. Payment card numbers and card security codes are collected and processed by Stripe and are not stored by XactaClaim. Stripe may also retain billing name, address, and payment method details according to its own policies.
3D. Artificial Intelligence (AI) — Processing & Data
XactaClaim includes AI-assisted features that may help summarize claim information, review uploaded policy documents, compare estimates, analyze photos, or generate workflow suggestions. When a user chooses to use these features, relevant Customer Content may be processed by third-party AI service providers to return the requested output. AI outputs are for workflow assistance only and may be incomplete or inaccurate. Users are responsible for reviewing all AI outputs before relying on them. We do not use Customer Content to train XactaClaim-owned foundation models.
When you enable or use AI-assisted features on an eligible plan, XactaClaim may process claim-related inputs through server-side workspace APIs using third-party AI service providers (for example, Google Gemini and related Google AI services). AI processing is generally initiated by authorized staff actions in the web workspace or mobile companion—not automatically for every uploaded file unless you request analysis or a supported workflow triggers it.
Depending on the feature, inputs may include documents, images, audio, transcripts, structured claim fields, truncated internal note excerpts, task descriptions, timeline or communication summaries, document metadata, saved analysis summaries, and prompts or questions you submit. Source files and recordings are not necessarily transmitted in full for every feature; we may send excerpts, metadata, or summarized context instead.
Outputs may be stored on claim records, shown in workspace views, or held in transient session state. Most AI-generated claim insights and assistant responses are staff-only and are not shown in the client portal. AI-assisted features (such as Claim Copilot, Morning Brief, and AI Claim Brief) are assistive tools only—they are not legal, insurance, engineering, public adjusting, or coverage advice.
We configure enterprise-oriented AI API access where available. Under those arrangements, provider policies generally restrict use of customer content to provide the service—not to train public foundational models. Provider retention, subprocessors, and security constraints are described further in our Security Policy.
AI output may be incomplete, inaccurate, outdated, or omit critical details. You are responsible for independently reviewing outputs before relying on them or sharing them with clients, carriers, or other parties. The mobile companion does not store AI provider API keys on the device and does not call third-party AI providers directly.
Related disclosures: Terms of Service — Artificial Intelligence (AI) and Security Policy — Artificial Intelligence (AI).
3E. Cookies and Similar Technologies
We use essential cookies and local storage needed for sign-in, security, session management, and basic preferences. Optional usage analytics runs only when you opt in through cookie preferences and this deployment has analytics enabled. We do not currently use advertising cookies. For details, see our Cookie Policy.
3F. Children
XactaClaim is a business tool for adjusters and claim teams. It is not intended for use by children under 13, and we do not knowingly collect personal information directly from children.
3G. Browser and Session Storage
The Service uses browser storage technologies for different purposes:
- Staff authentication: Firebase Auth and related browser storage or cookies needed to keep staff users signed in.
- Client portal session restore: When a client successfully verifies a portal PIN, the browser may store minimal session data in
sessionStoragefor that claim, including the claim or portal identifier, PIN, and authentication timestamp. This data expires after approximately twelve (12) hours, is re-verified with our servers before portal claim data is shown, and does not store claim payloads, documents, tasks, notification preferences, or staff Firebase tokens. - Registration and legal acknowledgement: Selected registration plan choice, pending legal acceptance, and related flow state may use session storage during sign-up.
- Preferences: Theme, saved cookie and analytics preference choices, and related UI settings may use local storage or similar browser storage.
See our Cookie Policy for more detail.
3H. Staff Mobile Companion
XactaClaim mobile is a staff companion app for eligible Pro and Premium workspaces. Client access remains through the secure web PIN portal. Mobile features require an active workspace, verified staff account, and supported role permissions. The mobile app is for authorized workspace staff only — not for clients. There is no separate client mobile application.
Mobile access is subject to the same workspace role, plan entitlement, email verification, and account-status checks as the web application, in addition to mobile app version and release capabilities. Offline mode is not currently supported; mobile use requires network connectivity.
Depending on your role, plan, and app release, the mobile companion may access and process workspace data such as:
- Claim records: Claim identifiers, client and property information, phase/status, and related claim metadata visible to your role.
- Files and photos: Document and photo metadata, uploads, and damage photo information where implemented.
- Internal Claim Notes: Staff-only notes including author, note type, body, source (including
mobile), created/updated timestamps, and archived status. These notes are not exposed through the client portal. - Tasks and work queue: Task descriptions, status, ownership, and due dates where supported on mobile.
- Communications metadata/content: Timeline events, SMS/MMS/email metadata, voicemail or call summary references where available to your workspace and role.
- AI-generated outputs: Including summaries, briefs, and other cached or generated analysis results produced server-side when requested from mobile.
When you request AI features from the mobile companion, processing occurs as described in section 3D. Server-side processing may use claim context such as truncated internal note excerpts, task descriptions, file metadata, saved analysis summaries, photo analysis outputs, timeline events, and voicemail or call summaries when available.
Staff mobile sessions use Firebase-authenticated staff accounts. You are responsible for device-level security, including OS lock screens, avoiding shared devices for sensitive claim work, and promptly reporting suspected account or device compromise to your workspace administrator and hello@xactaclaim.com.
4. How We Use and Process Information
Customers retain ownership of the claim files, documents, photos, notes, client information, communications, and other content they upload or create in XactaClaim. XactaClaim does not claim ownership of Customer Content. We process Customer Content only to provide, secure, support, maintain, and improve the service, comply with law, and as otherwise described in our Terms of Service and this Privacy Policy. Authorized workspace users control what they upload and share through the platform.
We use information that we collect about you or that you provide to us:
- To operate, maintain, and provide the features and functionality of the Service.
- To process and analyze documents, images, communications (including voicemail transcripts), and structured claim context via our proprietary systems and trusted third-party AI models (for example, Google Gemini). AI-assisted features (such as Claim Copilot, Morning Brief, and AI Claim Brief) may use claim records, truncated internal note excerpts, task descriptions, document metadata, saved analysis summaries, photo analysis outputs, and timeline, call, or voicemail summaries. Source files and recordings are not necessarily transmitted in full for every AI feature.
- To manage your account, process billing, and carry out our obligations arising from any contracts entered into between you and us.
- To analyze usage trends to improve the platform's stability and feature set.
5. Disclosure of Your Information
We do NOT sell your personal information or your clients' claim data. We may disclose aggregated information about our users without restriction. We may disclose personal information that we collect or you provide as described in this privacy policy:
We use cloud infrastructure and service providers to host, secure, operate, and support XactaClaim. These providers may process Customer Content or related metadata only as needed to provide their services to XactaClaim. Examples may include hosting, database, storage, authentication, payment processing, email, SMS/MMS, voice, analytics, and AI service providers.
- To Sub-processors: We use trusted third parties to run the infrastructure (Google Cloud/Firebase), process payments (Stripe), handle telecommunications (Twilio), send email (Resend), and process AI tasks (Google Gemini and related Google AI services). These third parties are strictly bound by data processing agreements.
- For Legal Compliance: To comply with any court order, law, or legal process, including to respond to any government or regulatory request.
- To Protect Rights: If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of XactaClaim, our customers, or others.
6. Security and AI Constraints
We have implemented rigorous, industry-standard measures designed to secure your personal information from accidental loss and from unauthorized access. For detailed information, please review our Security Policy.
However, we cannot guarantee that malicious third parties will not bypass those measures. We are not liable for breaches of infrastructure outside of our direct, negligent control.
7. Data Requests, Export, Deletion, and Retention
You may contact us to request access, export, correction, or deletion of account or workspace data associated with your subscription. Email us and include your agency name, account email, and the scope of your request. We will verify ownership and respond within a reasonable period. Some data may be retained where required or permitted for security, legal compliance, billing, fraud prevention, audit logs, backup continuity, or dispute resolution. Workspace administrators remain responsible for managing client and claim records in their workspace and for responding to their own clients as applicable. Deletion is not instantaneous when backups, archives, or provider-side records exist.
When you use Delete login account from Profile settings, we remove your Firebase Authentication login and your user profile document (users/{uid}). This removes your ability to sign in and your personal account record in our application database. This is a login-level action — not full workspace or data deletion.
Canceling a paid subscription is separate from deleting your login account. Canceling stops future billing or changes plan access through Stripe. It does not delete your login, workspace, claim files, documents, notes, reports, uploaded files, or client portal records.
Deleting your login account does not cancel Stripe billing, delete Stripe customer or subscription records, or automatically delete your agency/workspace, claims, documents, uploaded PDFs or other files, timelines, internal claim notes, tasks, client updates, SMS/MMS or voice communication records, AI analyses (including AI Claim Brief outputs), demand letters, or other workspace data. That data may remain for teammates, operational continuity, or records retention unless a separate full workspace deletion request is completed through support.
If your workspace has active, trialing, or past-due paid billing, you must manage or cancel billing from the Billing page or Stripe Billing Portal before deleting your login account.
If you are the sole workspace owner, deleting your login account removes your access and user profile only. The workspace, claims, and files remain until you contact support for workspace closure, ownership transfer, or full workspace deletion.
Stripe and other payment providers may retain billing records (customers, subscriptions, invoices, charges, and related metadata) according to their own policies and legal obligations. We do not delete Stripe customers, invoices, charges, or provider-side billing history when you delete your login account.
We may retain security, audit, legal, abuse-prevention, and operational logs where required by law or legitimate business need. Backups and disaster-recovery copies may persist for a limited period before being overwritten.
Export any records you need before deleting your login account. If you are the workspace owner and need full deletion of agency data, contact hello@xactaclaim.com. We will verify ownership and scope before processing deletion requests.
8. Privacy Laws and Applicable Frameworks
Depending on the customer's location, industry, and use of the service, privacy and data protection obligations may apply to Customer Content, including U.S. state privacy laws, insurance-related privacy and security obligations, consumer protection laws, SMS/MMS rules, and other applicable requirements. Customers are responsible for determining how these laws apply to their use of XactaClaim and their own clients. XactaClaim provides the service as a software provider and processes Customer Content as described in this Privacy Policy and our Terms of Service.
9. Changes to Our Privacy Policy
It is our policy to post any changes we make to our privacy policy on this page. If we make material changes to how we treat our users' personal information, we will notify you by email to the email address specified in your account.