ClaimStation
HomeSign inTrust Center
Home/Legal/Privacy
Legal

Privacy Policy

How ClaimStation collects, uses, stores, and protects data, including our Limited Use commitments for Gmail data under the Google API Services User Data Policy.

Effective September 23, 2026v2.314 min read

On this page

01Who is in scope02What we collect03How we use your information04Privileged content & the AI scanner05Sub-processors06How long we keep data07Your rights and choices08Security09Children10Changes to this policy11Your California privacy rights12Contact

Overview

What changed on September 23, 2026

We checked this policy against what ClaimStation actually does and corrected it. The product did not change; the description did:

  • The list of outside companies that handle your data is now complete. We added Google's Gemini API (it reads connected email to file and draft), Microsoft (Outlook), Vapi and Twilio (the phone line), Zoom (meetings) and RoofGrid LLC (roof report review), and we list the map and public-records services that receive a property address. We removed DocuSeal and Logflare, which ClaimStation no longer sends data to, and narrowed Anthropic to roof images and Sentry to error reports, each only when turned on.
  • Deleting an account and exporting data are done by ClaimStation staff on written request. There is no delete or export button in the product. We no longer promise automatic deletion at 30 or 90 days.
  • A deleted claim is hidden, not erased. Claims and their audit trail are kept.
  • Audit logs are kept with no automatic deletion. We no longer say 18 months.
  • The privacy filter for attorney and custody-app email now covers the history import as well as new mail.

ClaimStation ("ClaimStation," "we," "us," "our") provides claim management software to licensed public adjusters and their authorized firm members. This Privacy Policy explains what information we collect, how we use it, who we share it with, how we protect it, and the choices you have. By using ClaimStation you agree to the practices described here.

We are a Florida company. The product is operated by Nations Public Adjusting, Inc.. Questions about this policy can go to privacy@claim-station.com.

01Who is in scope#

This policy applies to:

  • Operators, public adjusters, adjusters-in-training, and firm support staff who hold ClaimStation user accounts.
  • Insureds & contacts, homeowners, business owners, contractors, carriers, and other parties whose information operators enter into ClaimStation in the course of representing a claim.
  • Visitors, anyone browsing our public marketing pages.

02What we collect#

Information operators provide directly

  • Account info, name, email, phone, password (hashed), license number, license state.
  • Claim records, file numbers, claim numbers, policy numbers, dates of loss, perils, loss addresses, fee percentages, settlement amounts.
  • Contact records, names, addresses, emails, phone numbers, and roles (insured, co-insured, attorney, contractor, mortgagee, carrier adjuster, etc.).
  • Documents you upload, photos, contracts, policy PDFs, carrier letters, engineer reports, estimates, settlement breakdowns.
  • Notes and correspondence drafts you author or that we draft on your behalf for your review.

Information collected when you connect Gmail

If you connect your Gmail account through our integrations, we receive only the OAuth tokens and message data permitted by the scopes you grant. The scopes we currently request are:

  • https://www.googleapis.com/auth/gmail.readonly, read-only access to your Gmail messages, attachments, and labels. Used to scan inbound carrier and client emails and surface them as claim correspondence.
  • https://www.googleapis.com/auth/gmail.compose, create draft messages in your Gmail account. Used to place reply drafts in your Gmail Drafts folder, when you ask for one or when a carrier message needs a reply, for your review and sending. We never send a message from your Gmail account; you send every one yourself.
  • openid and userinfo.email, your Google account email, used only to confirm which inbox is connected.

The text of connected mail is processed by Google's Gemini API to file each message to the right claim and to write reply drafts. Mail from a listed attorney or custody-app address never reaches Gemini (see "Privileged content" below). When you first connect, ClaimStation also imports the sender, recipients, subject and date of the last two years of mail (not the Promotions or Social tabs), without the message text. It fetches the text later only for messages filed to a claim or when you open a message. The history import does not send mail to Gemini.

Information collected when you connect Outlook

If you connect a Microsoft Outlook or Microsoft 365 mailbox, we request Mail.Read and Mail.ReadWrite (Microsoft has no draft-only permission), plus User.Read, offline_access and sign-in identity. We use them only to read carrier and client mail and to place reply drafts in your Drafts folder. We never send from your mailbox. Outlook mail goes through the same privilege filter and the same Gemini processing as Gmail.

Information collected by the phone line

If your firm turns on the ClaimStation phone line, we collect what callers tell it: the caller's phone number, a transcript and summary of the call, a recording if the call was recorded, and the claim details the caller gives, such as name, email, loss address and date of loss.

Limited Use Disclosure

ClaimStation's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Gmail data only to provide the user-facing features described above: filing mail to the right claim, the claim correspondence inbox, pulling dates and facts from carrier letters into the claim, claim summaries, and reply drafts.
  • We do not use Gmail data to serve advertisements.
  • We do not transfer Gmail data to third parties except as necessary to provide the features, or as required by law. The main such transfer is to Google's own Gemini API, which reads message text to file and draft (see "Sub-processors" below).
  • Humans (including ClaimStation employees) do not read your Gmail data except (i) with your explicit consent, (ii) to investigate abuse or a security incident, (iii) to comply with applicable law, or (iv) where the data is aggregated and anonymized for internal operations.
  • We do not use Gmail data to develop, improve, or train generalized or generative artificial-intelligence or machine-learning models.

Information collected automatically

  • Standard server logs, IP address, browser/device type, pages visited, timestamps. Used for security, debugging, and abuse detection. Retained 30 days unless tied to an active investigation.
  • Cookies and similar, session cookies for authentication, CSRF tokens, theme preferences. We do not use third-party advertising cookies.

03How we use your information#

  • To provide, maintain, and operate the ClaimStation product.
  • To draft documents (letters, demands, settlement summaries) at your direction.
  • To classify inbound carrier emails into the correct claim record.
  • To compute statutory deadlines and surface them in your dashboard.
  • To send you transactional product email (sign-in links, deadline alerts, onboarding, billing).
  • To investigate abuse, fraud, security incidents, and policy violations.
  • To comply with legal obligations and respond to lawful requests.

04Privileged content & the AI scanner#

ClaimStation checks the sender of every message against a privilege filter before it reaches the AI. This applies to new mail and to the history import, for Gmail and Outlook alike. Mail from a listed custody-app or family-court domain is discarded. Mail from a listed attorney domain is recorded by sender, recipients, subject and date only; its body is not stored and never reaches the AI. Mail you send to a listed address is not imported at all.

The filter works from a list. Every firm starts with a default list of attorney and custody-app domains, and firm users cannot turn it off. Mail from an address that is not on the list is treated as ordinary mail, so contact support to add the domains your firm deals with.

05Sub-processors#

ClaimStation uses the companies below to run parts of the product. Each one gets only the data its job needs. Some are used only when a feature is connected or turned on, as the last column says.

CompanyWhat it receives and whyWhen
Vercel, Inc.Hosts the application and the roof measuring service, so every page and request passes through it.Always
Supabase, Inc.Stores the database, uploaded files and sign-in accounts: all account, claim, contact and correspondence data.Always
Google LLC (Gemini API)The AI behind ClaimStation. It receives the text of connected Gmail and Outlook mail (except mail stopped by the privilege filter) to file each message to a claim and draft replies, plus the claim details, notes and documents for letters, summaries and data extraction, and the words spoken on phone line calls so it can answer the caller.Always
Google LLC (Gmail API and Cloud Pub/Sub)Gmail API: reads your mail and places drafts, under the scopes above. Cloud Pub/Sub: tells us a connected mailbox has new mail. The notice carries the mailbox address and a change number, not the message.When you connect Gmail
Microsoft CorporationMicrosoft Graph reads your Outlook mail and places drafts, under the permissions above.When you connect Outlook
Resend, Inc.Sends ClaimStation's own email: sign-in links, alerts, signing requests and reminders, meeting invites and messages you send from ClaimStation. It receives each recipient's address and the message. It also receives mail sent to our support address.Always
Stripe, Inc.Subscription billing: the firm's billing contact and payment details. Card numbers go to Stripe, not to us.Always
VapiRuns the phone line: answers and places calls, turns speech into text and text into speech (through its speech provider, Deepgram), and records calls where the call is recorded. It receives the call audio, the caller's phone number, the transcript and the spoken replies.When a firm turns on the phone line
Twilio Inc.Sends text messages from the phone line, such as the link to sign a new claim's agreement. It receives the caller's phone number and the text.When a firm turns on phone line texting
Zoom Video Communications, Inc.Hosts meetings you schedule from a claim. It receives the meeting title, agenda and time, and the audio and video of the people who join. Cloud recording is off.When you schedule a Zoom meeting
RoofGrid LLCTraces and reviews roof reports. When you order one, it receives the property address, claim number, customer name and your name, and sends the reviewed report back.When you order a roof report
Anthropic PBCCan read aerial and street images of a property to help measure its roof. It receives the images only: no email, notes or documents.Only when turned on
Functional Software, Inc. (Sentry)Error reports: the page or request that failed and technical details of the failure.Only when turned on

Address and map lookups

To find a property, measure its roof and look up weather and parcel records, ClaimStation sends a property's address or map coordinates, and nothing else about the claim or the people on it, to map and public-records services. These include Google Maps Platform (maps, place search, Street View and Solar), Mapbox, OpenStreetMap's Nominatim, the U.S. Census geocoder, the National Weather Service, Iowa State University's weather archive, Esri ArcGIS, and county property and GIS servers.

06How long we keep data#

  • Account data is kept while the account is open. There is no delete button in the product. To delete an account, email support@claim-station.com. ClaimStation staff handle it by hand and finish within 30 days of a verified written request: they remove the person's sign-in and profile details and disconnect their mailboxes. See /data-deletion for what stays.
  • Claim records are kept for the life of the firm's account, because they are the firm's claim file. A firm owner or admin can delete a claim. A deleted claim disappears from every list and screen, but the record and its audit trail are kept. ClaimStation never permanently erases a claim, and nothing deletes claims automatically. There is no restore button; to bring a deleted claim back, ask support.
  • Imported email is kept. Disconnecting Gmail or Outlook stops new imports but does not remove mail already imported. Mail filed to a claim is part of that claim's file and is kept with it. To have other imported mail removed, email support; staff handle it by hand within 30 days of a verified written request.
  • Audit logs are kept, with no automatic deletion. No user can edit or delete an audit entry.
  • Server / network logs, 30 days unless tied to an active investigation.

07Your rights and choices#

  • Access & export, email support@claim-station.com to ask for a copy of your data. There is no self-serve export. ClaimStation staff prepare the copy by hand and send it within 30 days of a verified written request.
  • Correction, edit account, claim, and contact information directly in the product.
  • Deletion, ask us to delete your account by emailing support@claim-station.com. Staff handle it by hand within 30 days of a verified written request. The steps and what we keep are at /data-deletion.
  • Disconnect Gmail or Outlook, at any time from Settings → Integrations. For Gmail we ask Google to revoke our access and delete the stored credential; for Outlook we clear the stored credential. Mail already imported stays, as described above.
  • California residents, see "Your California privacy rights" below.
  • EU / UK residents, ClaimStation is a US service primarily serving US public adjusters. We do not target EU residents and do not knowingly process EU personal data. Contact us if you believe we hold your data in error.

08Security#

See our security overview for the controls we operate, including encryption at rest and in transit, AES-256-GCM encryption of OAuth refresh tokens, Postgres row-level security on every table, audit logging on every claim mutation, and the principle of least privilege for our team.

09Children#

ClaimStation is a B2B product for licensed adults. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.

10Changes to this policy#

We will update this policy as the product changes. Material changes will be posted here with a new effective date and, when appropriate, notified to operators by email. Continued use of ClaimStation after a change constitutes acceptance of the revised policy.

11Your California privacy rights#

California residents may request to know what personal information we have collected, request deletion, or opt out of "sale" or "sharing" (we do neither). Submit requests to privacy@claim-station.com. We will not discriminate against you for exercising these rights.

12Contact#

ClaimStation
c/o Nations Public Adjusting, Inc.
517 5th Ave, Suite 206E
Indialantic, FL 32903
Email: privacy@claim-station.com

ClaimStation
AboutContactPrivacyTermsSecurityRefundData DeletionGmailSupport