Privacy Policy
We handle personal information in two roles: as a controller for our website and business contacts, and as a processor acting on our customers' instructions for claim file data. This policy explains both.
Last updated: 14 August 2026
Legal status of this page
This policy is a binding commitment about how we actually handle personal information, and we intend it to be relied on - unlike the informational content elsewhere on this site. It does not, however, form part of any commercial agreement, alter a signed contract, or create rights beyond those applicable privacy law already gives you. Customers with a signed Data Processing Addendum are governed by that document where it differs from this page.
01Two different roles
Hesper AI handles personal information in two distinct capacities, and the rules differ for each. Read the one that applies to you.
| Website and business contacts | Claim file data | |
|---|---|---|
| Whose data | Visitors, prospects, people who request a demo or subscribe | Claimants, insureds, witnesses, providers and vendors in our customers' claim files |
| Our role | Controller / business - we decide the purposes | Processor / service provider - we act only on our customer's instructions |
| Governed by | This policy | Our customer's own privacy notice, plus our Data Processing Addendum |
| Who to contact about your rights | Us, at privacy@gethesperai.com | The insurance company or administrator handling your claim. We will forward requests to them. |
If you are a claimant or policyholder and want to know what an insurer holds about you, contact that insurer directly. We process claim data only on their instructions and cannot act on your request without them. If you contact us, we will pass your request to our customer within five business days and tell you we have done so.
This policy is published by Hesper PN, Inc., a Delaware corporation doing business as Hesper AI, of 680 2nd Street, San Francisco, CA 94107.
02Information we collect as a controller
You give it to us
Name, work email address, phone number, company name, job title, and anything you choose to include in a message when you request a demo, contact us, subscribe to our newsletter, apply for a role or register for an account.
We collect it automatically
IP address, browser and device type, operating system, referring URL, pages viewed, and dates and times of access. We use cookies and similar technologies for essential site function and for analytics.
Account and usage data
For platform users: account identifiers, authentication events, API usage metadata, request identifiers, timestamps, feature usage and audit logs. We use this to operate, secure and support the Services and to bill accurately.
03How we use it
- to provide, maintain, secure and improve the Services
- to respond to enquiries, demo requests and support tickets
- to send service, security and administrative messages
- to send marketing communications where permitted - you can unsubscribe at any time
- to process payments and manage our customer relationships
- to detect, investigate and prevent fraud, abuse and security incidents
- to comply with legal obligations and enforce our terms
Where the GDPR or UK GDPR applies, our lawful bases are performance of a contract, our legitimate interests in operating and marketing a B2B service, your consent where required, and compliance with legal obligations.
We do not sell or share personal information as those terms are defined by the California Consumer Privacy Act, and we have not done so in the preceding twelve months. We do not use personal information for cross-context behavioural advertising.
04Claim file data we process for customers
When an insurance organisation uses Hesper, it submits claim files to us for analysis. These can contain identifiers, claim and policy details, loss descriptions, financial information, photographs, recorded statements and correspondence. In bodily-injury, workers' compensation and disability claims they routinely contain medical bills, treatment records and diagnoses.
What we do with it
We ingest, extract, index, analyse and correlate the claim file, and we generate investigation output - findings, fraud indicators, evidence summaries, narratives and referral documentation. We do this only on our customer's documented instructions and only to provide the Services to them.
Where it is stored, and for how long
Claim file data and investigation output are stored in our systems, and are retained for the duration of the customer's subscription term unless the customer instructs us otherwise in writing.
A customer may at any time instruct us to apply a shorter retention period, to delete identified data, or to hold data for longer than the term - for example to match their own claim-file record-retention schedule. We give effect to that instruction within 30 days, subject only to a legal requirement or a litigation hold.
When a subscription ends, the customer has 30 days to export their data. We then delete it from production systems within 60 days, and from backups within a further 90 days, except where law or a litigation hold requires us to keep it - in which case we isolate it, keep only what is required, and continue to protect it until deletion is permitted. We certify deletion in writing on request.
Data is hosted in the United States on Amazon Web Services unless a customer's order form specifies otherwise.
Sensitive information
We treat medical, mental-health, substance-use, genetic and biometric information, government identifiers and financial account numbers as sensitive, and apply heightened access controls to them, whether or not HIPAA applies. Where our processing makes us a HIPAA business associate, a Business Associate Agreement governs. We do not use sensitive information to infer characteristics about anyone.
05We do not train AI models on your data
We do not use claim file data, personal information or investigation output to train, fine-tune, retrain or evaluate any machine-learning model that is available to anyone other than the customer it came from. This is a binding contractual commitment, not a policy preference.
We flow the same prohibition down to every AI subprocessor by contract, and we disable training, improvement-retention and human-review-for-improvement features wherever a provider offers them. Our subprocessor page states the data-retention posture of each AI provider we use.
Where a customer's order form provides for tuning specific to that customer, the resulting artefacts stay logically segregated to their tenant and are never exposed to anyone else.
We generate aggregated, de-identified statistics about how the Services perform. Before we do, we strip all direct and indirect identifiers of any customer, claimant, insured, provider or other person, and all claim and policy numbers, and we aggregate across customers so no individual customer is identifiable. We do not publish statistics identifying a customer without their written consent.
07Security
We encrypt data in transit using TLS 1.2 or higher and at rest using AES-256. We enforce multi-factor authentication for all personnel access to production, grant access on a least-privilege basis, log access to claim file data, segregate customer tenants, run automated vulnerability scanning, and commission an independent penetration test annually.
We have completed a SOC 2 Type I examination. The report is available to customers and prospects under NDA.
Full detail is on our security page. No system is perfectly secure, and we do not claim otherwise.
If we confirm a security incident affecting customer data, we notify the affected customer within 48 hours and give them what they need to meet their own regulatory notification deadlines. To report a vulnerability, write to security@gethesperai.com - we acknowledge within two business days.
08Your rights
United States
Depending on your state, you may have the right to know what personal information we hold, to access a copy, to correct it, to delete it, to opt out of sale, sharing or targeted advertising, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. We do not sell or share personal information, and we do not conduct targeted advertising.
Europe and the United Kingdom
If you are in the EEA, UK or Switzerland you may have the right to access, rectify, erase, restrict or object to processing, to data portability, to withdraw consent, and to lodge a complaint with your supervisory authority.
How to exercise them
Write to privacy@gethesperai.com. We will verify your identity and respond within 30 days, or within the period your law requires. You may use an authorised agent where the law permits.
For claim file data, contact the insurer or administrator handling your claim. We will forward your request to them within five business days. Insurance regulation and open fraud investigations may permit or require them to defer or deny certain requests - that decision is theirs, not ours.
09International transfers
Customer claim data is stored and processed in the United States by default. Where our personnel outside the United States need access for support, engineering or security, that access is subject to the same least-privilege controls, logging and confidentiality obligations, and customers may require on their order form that access to unmasked claim data be restricted to United States personnel.
Where we transfer personal data out of the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful mechanism, and we provide the information customers need to complete a transfer impact assessment.
11Children
The Services are for insurance organisations and are not directed to children. We do not knowingly collect personal information from anyone under 18 through our website or account registration. Claim files submitted by our customers may contain information about minors - for example a child injured in an accident. We process that information only as our customer instructs, and treat it as sensitive.
12Changes
We may update this policy. We will post the updated version here with a revised date. For material changes affecting customers, we will give at least 30 days' notice to the contact on file. Previous versions are available on request.
13Contact
Privacy and data rights: privacy@gethesperai.com. Security: security@gethesperai.com. Legal: legal@gethesperai.com.
Hesper PN, Inc. (d/b/a Hesper AI), 680 2nd Street, San Francisco, CA 94107, United States.
Customers should also read our Data Processing Addendum, subprocessor list and security documentation.