kerlo

Privacy Policy

Version 1.0 — last updated 26 September 2026

Kerlo reads your health insurance policy and tells you what it covers. This page explains what data we process, why, who it is shared with, how long it is kept, and how you stay in control of it.

Insurance documents can reveal information about your health. We process them only with your explicit consent, which you can withdraw at any time.

1. Who is responsible for your data

The data controller is Maison MV LLC, a limited liability company organized under the laws of the State of Wyoming (United States), registered under number 2026-001942978, with its address at 30 N Gould St, Ste R, Sheridan, WY 82801, United States.

We are established outside the European Union but offer Kerlo to people who live there, so the General Data Protection Regulation (GDPR) applies in full to what we do (Article 3(2)).

Our representative in the European Union (Article 27 GDPR), whom you can contact about your data: being appointed; in the meantime, write to privacy@kerlo.app.

For any question about your data: privacy@kerlo.app.

2. What we process

CategoryContentSource
AccountIdentifier, email address, sign-in method (Apple, Google or email link)You, through the provider you choose
ProfileDisplay name, country of residence, nationality, currency, language, time zone, household member profilesYou
Insurance documentsThe PDF or photos of your policy. Kept on your phone; on our servers only while being readYou
CoverageRates, limits, deductibles, general exclusions and conditions, each with the quote and page it came from. Never your name, address, member number or a medical exclusion specific to youAutomated reading of your document, then your confirmation
Care and reimbursementsCare category, provider, amounts, dates, country, receipts, optional notes. Only on your phoneYou
EstimatesThe simulations you save and their result. Only on your phoneComputed on your device from your coverage
SubscriptionSubscription status, plan, trial period, renewal datesApp Store or Google Play, through RevenueCat
Technical logsError and document-access events, without contentAutomatic

Your care never leaves your phone. The treatments, reimbursements, receipts and estimates you save are never sent to our servers: we cannot access them. Your phone's backup (iCloud or Google) can keep them when you change device, and you can export them at any time. Signing out or uninstalling erases them; the app reminds you and offers the export first.

We never ask for a diagnosis or any medical information. The claim notes field warns against entering any. We use no analytics SDK and no advertising network.

3. Why we process it, and on what basis

PurposeLegal basis
Creating and maintaining your account, providing the servicePerformance of our contract with you (GDPR Art. 6(1)(b))
Reading your insurance policy and extracting your benefitsYour explicit consent (GDPR Art. 6(1)(a) and 9(2)(a))
Estimating what a treatment would cost youPerformance of the contract
Saving your care and estimates on your phoneYour explicit consent (GDPR Art. 6(1)(a) and 9(2)(a)), asked separately before the first save
Managing the subscription and the trialPerformance of the contract
Securing the service, preventing abuse, fixing failuresOur legitimate interest in running a reliable service
Answering your support requestsPerformance of the contract
Meeting our accounting and legal obligationsLegal obligation

Consent to reading your policy

Before your first upload, a screen states what is sent, to whom, why, and how long it is kept. Reading starts only once you agree. That agreement is stored with its date and version.

You can withdraw it at any time from Profile then Privacy. Withdrawal stops any new reading. It does not retroactively delete benefits already recorded: to do that, delete the policy or your account.

4. Who else can access your data

We sell no data and share none for advertising. We rely on the processors below, each under a data processing agreement.

ProcessorRoleData involvedHosting location
SupabaseDatabase, authentication, temporary document storage, server functionsAccount, profile, your coverage terms; your documents while they are readEuropean Union (Ireland)
AnthropicAutomated reading of your insurance documentThe document you upload, only while it is being readUnited States
RevenueCatSubscription and trial managementAccount identifier, subscription statusUnited States
Apple and GoogleApp distribution and subscription billingPayment data, which we never seePer the app store

The document is sent to Anthropic by our server function: the app never calls the model provider directly. Anthropic acts as our processor under its Data Processing Addendum, part of its commercial terms, which includes the European Commission's standard contractual clauses. It does not use your data to train its models and deletes it from its systems within 30 days at most.

Our reading instructions forbid copying your name, address, date of birth, member number or any personal medical information: only the policy terms are extracted. A reading that contains any is never cached.

5. Where your data lives

Your account, profile and policy terms are hosted in the European Union; your care stays on your phone. As our company is established in the United States, our team may access them from there, only to run the service and answer your requests. Reading a document involves a one-off transfer to the United States, covered by the European Commission's standard contractual clauses.

If you live outside the European Union, your data still sits in Europe. Some national laws require a different location; we do not claim to satisfy all of them, and will tell you if this changes for your country.

6. How long we keep it

DataRetention
Account, profile, coverage termsAs long as your account exists
Care, reimbursements, receipts, estimatesOn your phone only, until you delete them, sign out or remove the app
Insurance documents on our serversDeleted as soon as reading ends; your copy stays on your phone
Raw model output from a readingNever kept after a successful reading; on failure, only error messages, without content
Cached reading result (policy terms only, no personal data), so an identical document is not read twice30 days maximum
Data processed by Anthropic30 days maximum, in its systems
Files from a failed upload7 days maximum
Technical logs without content7 days at most
After account deletionImmediate cascading erasure; our host's encrypted backups expire within 7 days
Accounting records for the subscriptionThe statutory retention period

7. Your rights

You have the right to access, rectify, erase, restrict, object to and port your data, and to withdraw your consent at any time.

These rights remain available even after your subscription ends. To exercise them: privacy@kerlo.app. If our answer does not satisfy you, you may lodge a complaint with the French data protection authority, cnil.fr, or with the authority of your country of residence.

8. How we protect your data

9. Children

Kerlo is for adults. We do not knowingly create accounts for anyone under 18. A household member profile may concern a child; in that case the account holder enters and manages that information under their own responsibility.

10. Changes

Any change to this policy is published here with a new date. If the change concerns how your documents are read, we tell you in the app and ask for your consent again.