Privacy Policy
OneUp Insurance
Last updated: June 9, 2026
1. Who We Are
OneUp Insurance is an AI-powered insurance assistant that helps you
manage your insurance policies, premiums, renewals, and claims in one
place. This Privacy Policy explains what data we collect, how we use
it, and the choices you have.
2. Information We Collect
OneUp Insurance collects the following information to provide our
services:
- Phone number — used as your account
identifier and for one-time-password authentication.
- Name — displayed in your profile and used
to personalise the assistant's responses.
- Insurance policy data — when you connect
an insurer (e.g. ACKO, Tata AIA, LIC, SBI Life, Ageas Federal,
Edelweiss, Royal Sundaram), we fetch your policies, premiums,
claims, and policy documents through that insurer's API on your
behalf.
- Chat messages — the text you send to the
insurance assistant, used to generate responses.
- Uploaded documents — policy PDFs, health
cards, claim docs, or any insurance-related files you upload
voluntarily for analysis and storage.
- Contacts — a limited, on-device check
— if you use the option to forward claim documents to OneUp
over WhatsApp, the app checks your device contacts on your device
to see whether OneUp's WhatsApp number is already saved. This
check happens entirely on your device. We do not upload, store,
or transmit your contacts to our servers, and we do not read any
contact other than to look for that one number.
3. Information We Do Not Collect
- We do not collect device location.
- We do not collect advertising identifiers.
- We do not use tracking, analytics, or cross-app tracking SDKs.
- We do not read your messages, your photo library, or your
browsing history. Our only use of your contacts is the limited,
on-device check described in section 2, which never leaves your
device.
4. How We Use Your Information
Your chat messages and uploaded documents are sent to AI providers
— Google Gemini and DeepSeek (accessed via OpenRouter) — for
AI processing so the assistant can understand your requests and
generate responses. Your data is not used to train any AI model. Both
providers operate under terms that prohibit using customer inputs for
model training.
When you connect an insurer, the login credentials and one-time
passwords you enter are used only to sign in to that insurer on your
behalf. We do not store your insurer passwords, PINs, or
OTPs — they are used for that single sign-in and then
discarded. So that you do not have to sign in again every time, we store
only the session token that the insurer issues after a successful login.
That session token lets us fetch your policies, premium status, and
claim status on your behalf; it expires over time and is renewed the
next time you connect. You can clear all stored insurer sessions at any
time by disconnecting an insurer or deleting your account.
5. Document Storage & Security
- Documents are stored on Amazon Web Services (AWS) S3, encrypted
at rest with AES-256.
- All data in transit is encrypted via HTTPS/TLS.
- Each document is stored under a user-specific path. Only you
can access your documents.
- No human at OneUp Insurance ever views, reads, or has access to
your documents. They are processed only programmatically.
6. Third-Party Processors
We do not sell, rent, or share your personal information for
marketing or advertising. The third-party services that process your
data on our behalf are:
- Google Gemini API (Google LLC) — powers
the assistant's responses. Inputs are not used to train Google's
models.
- OpenRouter, used to access the DeepSeek model
— powers selected AI capabilities. Inputs are not retained
for training.
- Insurer APIs (ACKO, Tata AIA, LIC, SBI Life,
Ageas Federal, Edelweiss, Royal Sundaram, etc.) —
contacted on your behalf when you connect an insurer, to fetch
your policies, premium status, claim status, and policy
documents.
- Amazon Web Services (AWS) — hosts our
application servers and stores uploaded documents on S3.
- Amazon SES (AWS) — delivers any service
emails we send to you.
7. Account Security
- Authentication uses one-time passwords (OTP) sent to your phone
number, with a short expiry.
- Session tokens are stored on your device using platform-level
encrypted storage.
8. Data Deletion & Retention
You can permanently delete your account and all associated data at
any time from Me > Delete Account. This removes your profile,
uploaded documents, insurer connections, and chat history within 48
hours. Server logs are kept for up to 30 days for debugging and
security, then automatically purged.
9. Children's Privacy
OneUp Insurance is not intended for children under 18. We do not
knowingly collect personal information from anyone under 18. If you
believe a child has provided us with personal information, please
contact us and we will delete it promptly.
10. Your Rights
- Access your personal data within the app.
- Delete your account and all associated data.
- Withdraw consent by deleting your account at any time.
- Request an export of your data by contacting us at
[email protected].
11. Regulatory Note (India)
OneUp Insurance is a personal-management tool. We are not registered
with the Insurance Regulatory and Development Authority of India
(IRDAI) as a broker, agent, web aggregator, or insurance marketing
firm, and we do not sell, advise on, or intermediate insurance
products. Use of OneUp Insurance does not constitute an insurance
contract or advisory engagement.
12. Contact Us
If you have questions about this privacy policy, please contact us
at [email protected].