PolicyChat Life
Privacy Policy
Effective September 21, 2026.
This policy explains what PolicyChat Life ("PolicyChat", "we", "us") collects when you use policychat.com, talk to Sage, or apply for life insurance through us, why we collect it, who sees it, and the choices you have. It is written to match how the site actually works. If something here is unclear, email hello@policychat.com.
Who we are
PolicyChat Life is a life insurance agency. Sage is our assistant: it sizes coverage, asks a few health questions, estimates a rate class and a price, and can issue a dated pre-qualification. Our licensed agents take it from there and place the policy with a carrier. We are not a carrier, and we are not a lead network.
What we collect
The conversation
What you type or say to Sage is sent to our servers so Sage can answer. During a life insurance conversation that usually includes:
- About you: age or birth month, ZIP code and state, sex where a carrier prices by it.
- What the policy should do: income to replace, a mortgage, children, final expenses; the coverage amount and term you land on.
- Health screen: tobacco or nicotine use, health conditions and medications you mention, and your build (height and weight).
- Contact details, only when you give them: first name, phone number, email address, and a preferred call time. Sage shows an estimate before asking for any of these, and you can see your price without providing them.
Your health answers are sent to our servers to price your estimate. Your browser also keeps your chat session in its local storage so the conversation can resume if you reload: the messages, including anything you typed about your health, and the profile Sage has built, with the health and underwriting fields removed from that profile. It stays in your browser only. It is cleared when you start over, when it ages out, or when you clear the site's data in your browser settings.
The pre-qualification
If you save a pre-qualification, we store the answers behind it together with a random token and an expiry date, and give you a link. Anyone with the link can open it, so treat it like a document. You can ask us to revoke it at any time.
The application
When you apply, the apply page sends your chosen next step, name, phone or email, preferred call time, the non-health profile from your conversation, and your pre-qualification to our agents. Your health answers from the conversation are used only to prepare your application.
Cookies and browser storage
We set first-party cookies only. None of them are shared with advertising networks, and none of them contain your name, contact details, or health answers. Each is set once and never overwritten.
| Cookie | What it holds | Why | Lifetime |
|---|---|---|---|
pc_session | A random session ID | Ties the pages you visit, the chat, and any form you submit to one visit so we can fix errors and measure the funnel | 1 year |
pc_sid | A random ID | Lets a result (an estimate, an application) be matched back to the visit that produced it | 1 year |
pc_vid | A random visitor ID | Tells us whether people who found us once come back | 90 days |
pc_zip | The approximate location our hosting provider derives from your IP address: ZIP, city, state, and coordinates. Set only for visitors in the United States | So Sage can skip asking for your ZIP | 1 year |
pc_entry | The first page you landed on and when | Shows which pages bring people in | 1 year |
pc_arrival_tid | Campaign parameters from the link you arrived on (utm tags, ad click IDs) and the referring page. Set only when you arrive from such a link | Campaign attribution | 30 days |
Your browser also keeps a few things locally: your light or dark theme choice, a question you typed on the home page before the chat opened, your chat session (described above), a copy of your non-health profile that lets an application or estimate page pick up where the chat left off, and a short log of recent page events. You can clear these in your browser settings.
Site analytics and logs
Our pages send small event beacons to our servers (page and error events, which buttons were clicked, whether you arrived from an AI assistant). Our hosting provider adds an approximate location derived from your IP address (postal code, region, country, city, network) to those events. We keep a one-way hash of your IP address with those events and with your consent record, not the address itself. We may also use Cloudflare Web Analytics and Google Analytics 4 for aggregate traffic measurement, and Cloudflare Turnstile on the chat to tell people from bots.
Why we use it
- To size your coverage, estimate the rate class you would likely be offered, and price it.
- To issue, save, and later resume a pre-qualification.
- To connect you, when you ask, with one of our licensed agents, the carrier we place your policy with, or an instant-decision partner when that is the better fit.
- To answer your questions, fix errors, and improve Sage.
- To meet insurance record-keeping and consent-logging obligations.
Underwriting records: prescription history, MIB, and driving record
Sage never pulls records about you. If you go forward with an application, the carrier (or an underwriting service acting for it) may ask for your separate written authorization to check:
- Prescription history from pharmacy-benefit and prescription databases.
- MIB, the Medical Information Bureau consumer file that life insurers share coded underwriting information through.
- Motor vehicle record (MVR) from your state's licensing agency.
- Identity and, where a carrier uses it, other public-record or consumer-report data.
Those checks happen only after you give that explicit authorization, it is shown to you before you sign it, and the results go to the carrier that requested them. Our agent may see the outcome to help you with the application. Nothing in a Sage conversation is a substitute for, or triggers, that authorization.
Who we share it with
- Carriers and underwriting partners, to quote, underwrite, and issue a policy you apply for. This includes the carriers we are appointed with and instant-decision partners we route some applicants to when you choose that path.
- Our licensed agents, who pick up the conversation where Sage left off.
- Service providers that run the site for us: web hosting and edge delivery, the servers Sage runs on, the language-model provider that powers Sage's replies, email delivery, bot protection, and analytics. They process data on our instructions.
- Legal and safety: when required by law, a regulator, or to protect people or the service.
We do not sell your information to a lead network, and we do not share it with other agencies or marketers for their own use. Your details go to a carrier or an agent only when you choose to move forward.
Calls, texts, and email (TCPA)
We contact you only with your consent. On the apply page, that consent is a checkbox you tick yourself; it allows a PolicyChat licensed agent to reach you at the number or email you gave, including by automated means. Consent is not a condition of buying anything. To withdraw it, tell the agent or email hello@policychat.com at any time. We keep a record of the consent you gave and when.
How long we keep it
- Conversations, estimates, and pre-qualifications: retained while your pre-qualification is active and for as long as needed to service an application. A pre-qualification stops being usable on the expiry date shown on it, or sooner if you ask us to revoke it. You can ask us to delete any of it at hello@policychat.com.
- Applications and consent records: for as long as needed to service your application and to meet insurance record-keeping obligations. You can ask us to delete what the law allows us to delete.
- Site events: kept as individual events keyed to your session and visitor IDs and the approximate location above, without your name, phone number, or email address.
Security
Traffic between your browser and our site is encrypted in transit. Access to conversations, applications, and consent records is limited to the people and systems that need it. No method of transmission or storage is completely secure, and we cannot promise otherwise; if we learn of a breach affecting you, we will notify you as the law requires.
Your privacy rights
If you live in California, the CCPA/CPRA gives you the right to know what we hold about you, to delete it, to correct it, to opt out of sale or sharing (we do neither), and not to be treated differently for exercising those rights. Residents of other states with privacy laws have similar rights. Certain insurance information is also governed by state insurance privacy laws; where those give you additional rights, we honor them.
To make a request, email hello@policychat.com with the subject line "Privacy request." We will confirm it is you, and respond within the time your state's law allows. You can also use an authorized agent; we may ask for proof that you gave them permission.
Children
The site and Sage are for adults. We do not knowingly collect information from anyone under 18. If you believe a minor has given us information, email us and we will delete it.
Changes
When we change this policy we update the effective date at the top of this page. If a change materially affects how we use information you have already given us, we will tell you before it takes effect.
Contact
PolicyChat Life, hello@policychat.com. Our licensing details are on the licensing page; the terms that govern the site are at Terms of Use.