ContentsClaims LLC · Last updated April 10, 2026
ContentsClaims LLC, a Nevada limited liability company, 401 Ryland Street, Ste 200-A, Reno, NV 89502. Privacy Officer: privacy@contentsclaims.com.
This Privacy Policy describes how ContentsClaims LLC collects, uses, stores, shares, and protects your personal information in connection with the contentsclaims.com website and all related services (the "Service"). By using the Service, you agree to the practices described in this Policy. If you do not agree, discontinue use of the Service.
Information You Provide Directly: Name, email address, phone number, mailing address, property address, insurance policy information, and account login credentials (username and password for the ContentsClaims platform — not your email provider credentials).
Email Account Credentials: When you connect an email account, you provide either: (a) an app-specific password generated by your email provider (Gmail, Yahoo, AOL, iCloud), which is a limited-purpose credential separate from your main account password; or (b) a Microsoft OAuth2 authorization token (for Outlook/Hotmail/Live). We do not receive or store your primary email account password under any circumstances. App-specific passwords are stored in encrypted form for the duration of the scan session only — see §7 for retention details. OAuth2 tokens are stored securely and can be revoked at any time through your email provider's account settings.
Email Content — Purchase Records Only: When you connect an email account, our systems access and temporarily process emails identified as order confirmations, purchase receipts, invoices, and warranty documents. We do not access personal correspondence, banking statements, medical information, legal communications, or any other non-purchase email content. Emails that are processed for classification but found not to contain purchase information are not retained. Our access is read-only and limited to a discrete scan session you initiate; we do not conduct ongoing or background monitoring of your inbox.
AI Processing of Email Data — PII Disclosure: Purchase-related email content identified by our systems is transmitted to third-party AI API providers for structuring and analysis to generate your claim inventory. ContentsClaims may use any AI provider at its discretion — including but not limited to OpenAI, Anthropic, Google, open-source or self-hosted models, or other providers — and may change providers at any time. These providers receive the full text content of purchase emails — such as order confirmations and receipts — which may contain personally identifiable information including your name, billing address, shipping address, and email address embedded in those purchase records. AI providers do not receive your email login credentials or primary account password. ContentsClaims works to obtain appropriate data processing agreements or contractual protections with AI API providers; where such agreements are not yet finalized, ContentsClaims implements alternative safeguards or restricts the data transmitted. Each provider's data handling is governed by its own published privacy policy and API usage terms. ContentsClaims does not independently control or warrant any AI provider's internal data retention or usage practices beyond what they publicly disclose. ContentsClaims does not use your personal information or email content to train, fine-tune, or improve any AI model, whether proprietary or third-party, and does not sell or license your data for AI training purposes. By using the Service, you acknowledge and consent to the transmission of purchase email content, which may contain personally identifiable information, to AI API providers as necessary to generate your claim documentation.
Payment Information: Payment card details are collected and processed exclusively by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. ContentsClaims does not store full card numbers, CVV codes, or complete cardholder data on our systems. We retain billing records (transaction amounts, dates, status, and last-four card digits) for accounting, dispute resolution, and legal compliance purposes.
Usage and Device Data: IP addresses, browser type and version, operating system, device identifiers, pages visited, session duration, referring URLs, and clickstream data are automatically collected when you visit or use the Service.
IP Address and Geolocation: We collect your IP address automatically upon each visit to the Service, including before you create an account. We use IP addresses to infer approximate geographic location (city and region level — not street-level or GPS-level precision) through a third-party geolocation service (ip-api.com). IP addresses are personal information under applicable law. Geolocation data derived from IP addresses is used for: fraud prevention, regulatory compliance verification (confirming U.S.-based access), platform security, and aggregate analytics. We do not collect device GPS location.
Phone Numbers — SMS Consent: If you provide a mobile phone number, you consent to receive text messages as described in our Terms of Service §2. If you register as an Adjuster Partner and check the SMS consent box, you additionally consent to fire incident alerts and adjuster-program notifications as described in our Terms of Service §2.
ContentsClaims uses the information we collect for the following purposes:
What We Use: We use cookies and similar tracking technologies for: authentication (session tokens), payment processing (Stripe fraud detection), analytics (usage patterns), and user preferences. See our Cookie Policy for the full cookie inventory and opt-out instructions.
Global Privacy Control (GPC): ContentsClaims honors the Global Privacy Control (GPC) browser signal for California residents and other users in jurisdictions recognizing GPC. We treat a valid GPC signal as a request to opt out of the sale or sharing of your personal information, consistent with CPRA requirements. Note that GPC opt-out applies to data sale and sharing for cross-context behavioral advertising — it does not disable cookies required for account security or payment processing.
Do Not Track: The World Wide Web Consortium (W3C) has not established universal standards for browser-level Do Not Track (DNT) signals distinct from GPC. ContentsClaims honors GPC as described above but does not separately respond to legacy DNT signals.
Third-Party Cookies: Stripe (payment fraud detection), Google Analytics (usage analytics), and ip-api.com (IP geolocation) may process data subject to their respective privacy policies. See our Cookie Policy for details.
ContentsClaims does not sell your personal information to third parties. We do not share personal information for cross-context behavioral advertising. We share information only as described below:
Service Providers and Processors: We share data with vendors that help us operate the Service. Current categories of service providers include: cloud hosting and storage (Render, AWS), payment processing (Stripe), AI processing APIs (third-party AI providers receive purchase email content which may include PII as described in §1 — providers may change at our discretion), SMS delivery (Twilio, for users who have consented to SMS), IP geolocation (ip-api.com), and direct mail fulfillment (Lob, for physical postcard delivery to property owners — not requiring user consent under applicable law). ContentsClaims does not currently maintain formal data processing agreements with all vendors. We work to obtain appropriate agreements where feasible; where we cannot, we implement alternative safeguards or discontinue that vendor for processing personal information.
Your Adjuster, Attorney, or Insurer: If you share a Generated Report with your public adjuster, attorney, or insurance carrier through the Service, we transmit the report and associated documentation as directed by you. You control this sharing.
Adjuster Partner Platform Activity: If you use the Service as a licensed Adjuster Partner, we log your platform activity (logins, report generation, client account access, fire feed views, referral activity) for compliance, security, and service quality purposes. This activity data may be reviewed by ContentsClaims in connection with regulatory inquiries, legal proceedings, or partner program compliance. Adjuster activity logs are retained for a minimum of 3 years.
Legal Process: We disclose personal information in response to valid legal process — including subpoenas, court orders, civil investigative demands, and government requests that we are legally compelled to honor. To the extent permitted by law and not prohibited by the terms of the legal process, we will endeavor to notify you before complying with a government request for your personal information. We will comply with all valid, legally issued process; however, we will review requests for legal sufficiency and may challenge overbroad demands.
Imminent Harm Disclosure: ContentsClaims may disclose personal information without prior legal process only when we have a reasonable, documented, good-faith belief that immediate disclosure to law enforcement is necessary to prevent imminent harm to the life or safety of a person. We will document the specific basis for any such disclosure. All other disclosures to law enforcement, insurance fraud bureaus, or government agencies require valid legal process.
Insurance Fraud Cooperation: ContentsClaims cooperates with law enforcement and regulatory authorities in response to valid legal process. If ContentsClaims identifies activity that reasonably suggests insurance fraud, we reserve the right to: (a) suspend the involved account, (b) preserve relevant records, and (c) comply with any applicable legal obligations. ContentsClaims does not proactively report users to insurers, fraud bureaus, or law enforcement absent valid legal process or an imminent harm situation as described above.
Business Transfers: If ContentsClaims is involved in a merger, acquisition, sale of all or substantially all assets, bankruptcy, or reorganization, your information may be transferred as part of that transaction. We will provide notice before your personal information is transferred and before it becomes subject to a materially different privacy policy.
Aggregate and De-Identified Data: We may share de-identified, aggregated statistics about Service usage and claim documentation patterns with business partners, investors, or the public for business and research purposes. This data cannot reasonably be used to identify any individual user.
ContentsClaims may use de-identified data derived from user interactions to improve the Service, train and refine our internal machine learning models, develop new features, and conduct research. De-identification is performed by removing all direct identifiers (name, email address, account ID, IP address, property address) and applying technical safeguards to prevent re-identification, consistent with the standards of 45 C.F.R. §164.514(b) (the HIPAA Safe Harbor methodology) or equivalent technical standards.
ContentsClaims will not re-identify de-identified data or attempt to link it back to any individual. ContentsClaims retains full ownership of all models, insights, and derivative works created from de-identified aggregate data.
You may opt out of having your de-identified data used for AI model improvement by submitting a written request to privacy@contentsclaims.com with the subject line "AI Training Opt-Out." We honor opt-out requests within 30 days. Opting out does not affect your ability to use the Service. Data already incorporated into aggregated statistical models prior to your opt-out request cannot be reversed.
The following table describes the categories of personal information ContentsClaims collects, the sources, business purposes for collection, and categories of third parties with whom we share or disclose it. ContentsClaims does not sell personal information as defined by the CCPA/CPRA. ContentsClaims does not share personal information for cross-context behavioral advertising.
| Category | Source | Business Purpose | Disclosed To |
|---|---|---|---|
| Identifiers (name, email address, account ID, phone number) | Directly from you | Account management, service delivery, communications, fraud prevention | Service providers, law enforcement (legal process) |
| Personal Records (mailing address, property address, insurance policy info) | Directly from you | Service delivery, account management | Service providers, adjuster/attorney (at your direction) |
| Financial Data (payment records, billing amounts, claim values) | Directly from you; Stripe | Payment processing, billing records, fee calculation | Stripe; accounting vendors |
| Sensitive: Account Credentials (app-specific passwords, OAuth tokens) | Directly from you via email provider | Email scanning for claim documentation — deleted post-scan | Not shared; processed internally only; deleted per §7 |
| Email Content (purchase receipts, order confirmations only) | Your connected email account | Generating claim documentation reports | Third-party AI API providers — purchase email content transmitted for AI processing may include PII embedded in purchase records (name, address, email); provider may change; see §1 |
| Internet/Network Activity (IP address, pages visited, session data, browser info) | Automatically collected | Security, fraud prevention, analytics, geolocation inference | IP geolocation processor (ip-api.com); analytics providers |
| Geolocation (city/region inferred from IP — not precise GPS) | Inferred from IP address via ip-api.com | Fraud prevention, regulatory compliance, security | ip-api.com (processor); not shared with others |
| Professional Information (adjuster license, company, referral activity) | Directly from Adjuster Partners | Partner program management, fraud prevention, compliance | Service providers; law enforcement (legal process) |
| Inferences (claim size estimates, usage patterns, risk signals) | Internal systems | Service improvement, fraud detection, de-identified AI training | Not shared in identifiable form |
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We will treat any personal information we collect as subject to a do-not-sell request unless you have separately consented to such use.
Email Credentials: App-specific passwords are deleted from active systems upon scan completion, session timeout, or your request — in no event more than 72 hours after scan commencement. Encrypted backup systems purge credentials on a rolling 30-day schedule. OAuth tokens persist until you revoke them via your email provider or request deletion from ContentsClaims.
Email Content and Extracted Purchase Data: Raw email content is not retained after the extraction process completes. Extracted purchase data (item descriptions, prices, dates, merchants) is retained as part of your Generated Report for up to 24 months following your last active use of the Service, or until you request deletion, whichever occurs first, subject to legal hold obligations.
Generated Reports: Reports are retained for 24 months following your last active use or your deletion request, whichever is earlier, subject to legal holds.
Payment Records: Billing and payment records are retained for 7 years for accounting and legal compliance purposes.
IP and Visitor Logs: IP address logs and associated geolocation data are retained for 12 months for security, fraud prevention, and analytics purposes, then deleted from active systems. Backup copies may persist for up to 30 days on the standard backup purge cycle.
Adjuster Activity Logs: Platform activity logs for Adjuster Partners are retained for a minimum of 3 years for compliance and regulatory purposes.
Legal Holds: If ContentsClaims receives a subpoena, court order, regulatory demand, or has a reasonable basis to believe litigation or investigation may be imminent, ContentsClaims will implement a legal hold on all relevant data. A legal hold overrides the standard retention schedules above and remains in effect for the duration of the legal matter plus one year, or as otherwise ordered by a court. If a legal hold is in effect on your account and you request deletion, ContentsClaims will notify you of the hold and preserve your data until the hold is released. After the hold is released, your data will be deleted within 30 days per the standard schedule.
Backup Systems: Backup copies of data may persist in disaster recovery systems for up to 30 days following deletion from active systems. This window is necessary for data integrity and does not extend ContentsClaims' obligations under this Policy for service delivery purposes.
De-Identified and Aggregated Data: We retain the right to retain de-identified or aggregated data indefinitely for research, analytics, and AI model improvement, provided it cannot reasonably identify any individual.
ContentsClaims implements technical, administrative, and physical safeguards designed to protect the personal information we collect from unauthorized access, disclosure, alteration, and loss. Our current security practices include:
ContentsClaims is not SOC 2 certified. Our security practices are designed to be appropriate to the sensitivity of the data we handle, but we do not represent that we have obtained any specific third-party security certification. No security system is impenetrable. We cannot guarantee the security of our systems against all possible attack vectors. See our Terms of Service §9 for the liability limitations that apply in the event of a security incident.
Notification Obligation: In the event of a security incident that compromises the confidentiality, integrity, or availability of your personal information in a manner triggering notification obligations under applicable state or federal law, ContentsClaims will notify affected users as required by law. Notification will be provided via email to the address on file and/or via a prominent notice on our website, within the timeframes required by applicable law.
Notification Contents: Where required and permitted by law, our breach notification will include: (a) a description of the nature of the incident; (b) the categories and approximate volume of information involved; (c) steps we are taking to investigate and remediate; and (d) recommended steps you can take to protect yourself.
Liability Limitation: Compliance with breach notification obligations does not expand ContentsClaims' liability beyond the caps and limitations set forth in Section 9 of our Terms of Service, incorporated herein by reference. ContentsClaims' fulfillment of its notification obligations constitutes its complete obligation with respect to informing affected individuals, and does not create any additional duty to provide identity theft services, credit monitoring, or compensation beyond the liability cap.
Access and Portability: You may request a copy of the personal information we hold about you. We will provide this information in a structured, commonly used, machine-readable format where technically feasible.
Correction: You may request that we correct inaccurate personal information in our records.
Deletion: You may request deletion of your personal information. We will fulfill deletion requests subject to: (a) legal retention obligations (including 7-year billing records and 3-year adjuster activity logs); (b) active legal holds; and (c) the 30-day backup purge cycle. We will confirm completion of deletion requests within 45 days.
Opt-Out of Marketing Communications: You may opt out of marketing emails at any time by clicking "unsubscribe" in any marketing email or contacting support@contentsclaims.com. Opting out of marketing does not affect transactional or security-related communications.
SMS Opt-Out: You may opt out of SMS messages at any time by replying STOP to any text message from ContentsClaims or by contacting support@contentsclaims.com. Adjuster Partners who opt out of SMS fire alerts will continue to receive essential account security messages.
AI Training Opt-Out: You may opt out of having your de-identified data used to improve ContentsClaims' AI systems by contacting privacy@contentsclaims.com with subject line "AI Training Opt-Out." See §5 for details.
CCPA/CPRA Rights (California Residents): California residents have the right to: (1) know what personal information we collect, how we use it, and with whom we share it; (2) request deletion of personal information we collected directly from you, subject to legal retention exceptions; (3) correct inaccurate personal information we hold about you; (4) opt out of the sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising); (5) limit the use and disclosure of sensitive personal information (including email content and account credentials) to the purpose for which it was collected; and (6) non-discrimination for exercising these rights. To exercise CCPA/CPRA rights, you or your authorized agent (with written authorization or valid power of attorney) may submit a verifiable consumer request to privacy@contentsclaims.com or by certified mail to ContentsClaims LLC, 401 Ryland Street, Ste 200-A, Reno, NV 89502. We will respond to verifiable requests within 45 days, with one possible 45-day extension for complex requests (we will notify you of any extension). If we deny your request, you may appeal by contacting privacy@contentsclaims.com with subject line "Privacy Rights Appeal" within 45 days of receiving our denial. We will respond to appeals within 60 days.
Sensitive Personal Information (CPRA): Under CPRA, the following information we collect is classified as sensitive personal information: account log-in credentials (email app-specific passwords and OAuth tokens). We use sensitive personal information only for the purpose of providing the Service — specifically, to access your email account for purchase data extraction. We do not use sensitive personal information for inferring characteristics about you, for advertising, or for any purpose beyond what is necessary to provide the requested service. You have the right to direct ContentsClaims to limit its use of your sensitive personal information to this service provision purpose.
Do Not Sell or Share: ContentsClaims does not sell personal information. ContentsClaims does not share personal information for cross-context behavioral advertising. To submit a formal Do Not Sell or Share request, contact privacy@contentsclaims.com with subject line "Do Not Sell/Share Request." We honor GPC signals as described in §3.
Residents of the following states have privacy rights under their respective state laws. To exercise any of these rights, contact privacy@contentsclaims.com with your state of residence and the right(s) you wish to exercise. We will respond as required by applicable law.
| State | Law | Key Rights Available |
|---|---|---|
| Virginia | VCDPA | Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling |
| Colorado | CPA | Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling; universal opt-out honored |
| Connecticut | CTDPA | Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling |
| Texas | TDPSA | Access, correction, deletion, portability, opt-out of sale/targeted advertising |
| Montana | MCDPA | Access, correction, deletion, portability, opt-out of sale/profiling |
| Oregon | OCPA | Access, correction, deletion, portability, opt-out of sale/targeted advertising |
| Delaware | DPDPA | Access, correction, deletion, portability, opt-out of sale/targeted advertising |
| Nevada | NRS 603A | Opt-out of sale of covered information (we do not currently sell covered information) |
ContentsClaims does not sell personal information and does not share personal information for cross-context behavioral advertising under any applicable state law definition. Universal opt-out signals (including GPC) are honored for applicable states.
Under Nevada Revised Statutes Chapter 603A, Nevada residents may opt out of the sale of certain covered information. ContentsClaims does not currently sell covered information as defined by Nevada law. If our data practices change in a way that would constitute a sale under NRS 603A, we will notify Nevada residents and provide an opt-out mechanism before any such sale occurs. To place yourself on our do-not-sell list for future changes, contact privacy@contentsclaims.com with subject line "Nevada Privacy Rights."
ContentsClaims does not knowingly collect personal information from children under 13 years of age. The Service is intended only for users 18 years of age or older. If we become aware that we have inadvertently collected personal information from a child under 13, we will take prompt steps to delete such information. If you are a parent or guardian and believe your child has provided us with personal information, contact privacy@contentsclaims.com immediately.
ContentsClaims is based in the United States and processes all data in the United States. If you access the Service from outside the U.S., your information will be transferred to, processed, and stored in the United States. U.S. privacy laws may differ from the laws of your home jurisdiction. By using the Service, you consent to the transfer, processing, and storage of your information in the United States. ContentsClaims does not currently offer services to European Union residents and does not have a GDPR compliance program; EU residents should not use this Service.
The Service may contain links to third-party websites or services. ContentsClaims does not control and is not responsible for the privacy practices, content, or security of any third-party site. ContentsClaims expressly disclaims all liability for the privacy or security practices of third parties. Please review the privacy policies of each third-party site or service before providing personal information.
ContentsClaims may update this Privacy Policy from time to time. Material changes will be communicated by posting the updated Policy on this page with a revised "Last Updated" date and by sending notice to the email address on your account. For changes that materially alter how we collect or use sensitive personal information (including email credentials), we will request your affirmative re-consent before the change takes effect as to your data. Your continued use of the Service after the effective date of a non-sensitive update constitutes your acceptance of the updated Policy.
Privacy Officer — ContentsClaims LLC
401 Ryland Street, Ste 200-A, Reno, NV 89502
privacy@contentsclaims.com · support@contentsclaims.com