Cessions

Privacy Policy

Last updated: August 13, 2026 · Cessions is in private preview

This policy explains what data Cessions processes, how connected data sources are used, who our sub-processors are, how long we keep data, and your rights. It applies to the Cessions private-preview platform and this website. Pilot participants are additionally covered by the confidentiality and data-processing terms agreed for their pilot, which control in the event of any conflict.

1. Information we process

  • Access-request information submitted through the Request Private Preview form (name, work email, company, role, use case) — used only to evaluate and respond to your request. Not sold, and not shared with third parties for marketing.
  • Account & authentication data for invited pilot users (email, authentication identifiers).
  • Customer content — the insurance/reinsurance documents you upload or connect, and the structured data and work products Cessions derives from them. Stored in private, organization-scoped storage.
  • Operational logs — audit records of privileged actions, and error/performance telemetry used to operate the service.

2. Connected data sources (Google & Microsoft)

If your organization connects a Google Drive or Microsoft 365 source, Cessions reads documents from that source on your behalf, using your own authorization:

  • We request read-only provider scopes (Google drive.readonly, Microsoft Files.Read.All) — never write, delete, or send permissions. These are broad provider read scopes; Cessions further restricts practical access through approved-source configuration and application-level authorization, so the app reads only the specific sources you approve, not everything the provider scope would technically allow.
  • We read only the documents needed to provide the reinsurance-workflow features you use, and we use that content only to provide those features to you — never to train generative models, never for advertising, and never sold or shared for unrelated purposes.
  • OAuth tokens are encrypted at rest with a dedicated key and are used solely to read on your behalf. You can disconnect a connection, or revoke the grant directly with Google/Microsoft, at any time; we then stop accessing that source.
  • Google Limited Use: Cessions' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. How we use information

To provide, secure, and operate the platform: ingesting and structuring documents, generating source-cited draft work products for professional human review, delivering reviewed outputs, maintaining an audit trail, and responding to support requests. AI processing is performed to generate drafts you request; your content is not used to train third-party foundation models.

4. Sub-processors

We use a small set of vetted service providers to run the platform, each processing data only to provide its service to us. Formal data-processing agreements are being executed as part of commercial readiness; where a DPA is not yet in place we operate under the provider’s standard terms and will confirm contractual data-protection status before accepting real customer confidential data:

  • Supabase — database, authentication, file storage (US region)
  • Vercel — application hosting
  • Anthropic — AI processing of the content needed to generate the drafts you request
  • Resend — transactional email
  • Inngest — background job processing
  • Sentry — error monitoring
  • DocuSign — e-signature, only when you send a document for signature

Google and Microsoft, when you connect them, act as your data source under your own authorization rather than as our sub-processors. Pilot customers receive advance notice of material changes to this list under their pilot terms.

5. Retention & deletion

We keep customer content for the duration of your pilot and delete or return it after termination in line with your pilot terms, except where retention is required by law. You can request deletion of your access-request information at any time by contacting us. Disconnecting a Google/Microsoft source stops further access immediately.

6. Security

Tenant isolation is enforced both in the application authorization layer (a capability + scope model) and at the database data plane (client roles have no direct table access; all reads and writes go through a server that enforces scope). Data is encrypted in transit (TLS) and at rest; connector credentials are encrypted with a dedicated key. We apply least-privilege access, log privileged actions, and rate-limit public endpoints. See our security overview.

7. Your rights & contact

Depending on your location you may have rights to access, correct, delete, or restrict processing of your personal data. Pilot customers exercise data-subject requests through their organization's administrator; we assist as processor under the pilot terms. To make a request or ask a question, contact us through the request form.

A complete general-availability privacy policy is being finalized with counsel and will supersede this preview policy. This page reflects the platform as deployed in private preview.