Draft for pre-launch review
Privacy
This prototype uses fictional data. The launch policy must identify the legal entity, controller address, rights contact, and selected processors.
Information and purpose
At launch, accounts will store email and access information. Drafts support agreed preparation and review work. Data is not sold or automatically linked with insurance services.
Translation and external providers
AI translation requires separate consent after disclosure of the processor, country, retention, and training use. Without this configuration, no text is sent to a provider.
Retention and your rights
Applicants must be able to access and receive their data and request changes or deletion subject to applicable requirements. Backups need a published retention period. Deleting a draft does not instantly erase every backup.
Data protection
Before launch: HTTPS, access controls, encrypted drafts, separate encryption keys, administrator MFA, recovery tests, and tests preventing cross-account cache exposure.
No advertising trackers. Drafts and test files are encrypted in the database. Pending device copies are optional for personal devices, encrypted in IndexedDB, and expire after 24 hours. They are cleared after successful saves or website sign-out. Use fictional data only.