Privacy Policy

Your policy is private by design.

FinePrintCheck is designed to minimize the personal information we collect and retain. We do not sell personal information, and we do not retain copies of uploaded policies or generated reports in our application database or persistent application storage as part of the normal analysis workflow.

Effective date: September 18, 2026

1. Scope of this Privacy Policy

This Privacy Policy explains how FinePrintCheck handles information when you visit the website, purchase an analysis, submit a U.S. health insurance policy for analysis, or contact us.

FinePrintCheck is designed, offered, and marketed exclusively for the United States market and for the analysis of U.S. health insurance policy documents.

2. Who operates FinePrintCheck

FinePrintCheck is operated by:

Luca Milanesi

Sole trader (enskild näringsidkare)

Sweden

Privacy questions may be sent to fineprintcheck-general-support-requests@fineprintcheck.app.

3. Information we process

Depending on how you use the Service, FinePrintCheck may process the following categories of information:

  • the insurance policy document that you voluntarily submit for analysis;
  • information contained in that document, which may include personal, insurance, health-related, financial, membership, or other sensitive information;
  • limited payment and transaction metadata necessary to verify that an analysis was purchased;
  • operational information such as entitlement status, retry count, transaction identifiers, analysis status, timestamps, rate-limit information, and non-sensitive error categories;
  • technical information generated in connection with operating and securing the website and Service; and
  • information you voluntarily provide if you contact us for support.

4. Policy selection and upload

Selecting a policy PDF in your browser does not by itself send the document to FinePrintCheck application storage.

The selected file is initially kept in the browser so that you can review your selection and complete payment.

After payment has been confirmed and you choose to start the analysis, the policy document is transmitted to the analysis infrastructure for the purpose of performing the analysis you requested.

5. Uploaded policies and generated reports

FinePrintCheck does not retain a copy of your uploaded policy or generated report in its application database or persistent application storage as part of the normal analysis workflow.

Your policy is processed through infrastructure used to perform the requested analysis. Temporary or service-level processing may occur within third-party infrastructure as necessary to provide, secure, monitor, and operate the Service.

The completed report is returned to your browser and made available for download. You are responsible for downloading and retaining any report you wish to keep.

FinePrintCheck does not guarantee that a report can be recovered after your analysis session has ended.

6. Artificial-intelligence processing

FinePrintCheck uses Microsoft Azure and Microsoft Foundry services to perform automated analysis.

Information submitted for analysis may therefore be processed by Microsoft infrastructure for the purpose of providing, securing, monitoring, and operating those services.

FinePrintCheck does not authorize submitted policy contents to be used for advertising or marketing.

FinePrintCheck does not use uploaded policy documents or generated reports to train its own artificial-intelligence model.

Service providers may process or retain information in accordance with their applicable service configuration, security mechanisms, abuse-monitoring processes, contractual commitments, and retention practices.

7. Payments

Payments are processed by Stripe. FinePrintCheck does not receive or store your full payment-card number or card security code in its application database.

FinePrintCheck receives and retains limited transaction information needed to verify payment, create an analysis entitlement, prevent duplicate use, investigate billing issues, operate the Service, and maintain appropriate business records.

Stripe processes payment information under its own terms and privacy practices.

8. Operational and security information

FinePrintCheck maintains limited operational records necessary to run and protect the Service.

These records may include payment identifiers, entitlement identifiers and status, amount and currency, retry counts, analysis state, timestamps, security and rate-limit events, non-sensitive error categories, and administrative audit information.

These operational records are designed not to contain the contents of your insurance policy or generated report.

9. How we use information

We use information only as reasonably necessary to:

  • provide the analysis you purchased;
  • verify payment and create the corresponding entitlement;
  • generate and deliver the report;
  • provide technical and customer support;
  • detect fraud, abuse, security incidents, and misuse;
  • diagnose technical failures and operate the Service;
  • maintain necessary transaction and business records; and
  • comply with applicable legal obligations.

10. What we do not do

FinePrintCheck does not:

  • sell uploaded insurance policy contents;
  • sell generated analysis reports;
  • sell or rent customer email addresses or contact lists for third-party marketing;
  • use uploaded policy contents to build advertising profiles;
  • use uploaded policy contents for targeted advertising; or
  • automatically enroll purchasers in a marketing newsletter.

11. Service providers

FinePrintCheck relies on service providers to operate the Service. These may include providers for payment processing, application hosting, database and server functionality, cloud infrastructure, security, and artificial-intelligence processing.

Our current architecture includes services provided by Stripe, Lovable and associated application infrastructure, and Microsoft Azure / Microsoft Foundry.

These providers process information for their respective functions subject to their contracts, configurations, security controls, and applicable privacy practices.

12. Data retention

FinePrintCheck follows a data-minimization approach.

Uploaded policy documents and generated reports are not intentionally retained in FinePrintCheck application database or persistent application storage as part of the normal analysis workflow.

Limited transaction, entitlement, security, audit, and operational records may be retained for as long as reasonably necessary for payment verification, fraud prevention, security, accounting, dispute handling, legal compliance, and operation of the Service.

Third-party service providers may maintain information or technical logs according to their applicable service configuration, contractual commitments, security processes, and retention practices.

13. Security

FinePrintCheck uses technical and organizational measures intended to reduce unauthorized access, misuse, disclosure, or alteration of information.

These measures include restricted server-side credentials, payment verification, short-lived analysis authorization, entitlement controls, rate limiting, transport encryption, and access controls appropriate to the Service architecture.

No internet service or method of electronic processing can guarantee absolute security.

14. Health information and HIPAA

Insurance policy documents may contain health-related or other sensitive information.

FinePrintCheck is an independent consumer service. It is not a health plan, healthcare provider, healthcare clearinghouse, insurance carrier, or representative of any such entity.

FinePrintCheck is not offered by or on behalf of a healthcare provider, health plan, or other HIPAA covered entity.

The applicability of HIPAA depends on the circumstances and relationships involved. Information voluntarily provided to an independent consumer service is not necessarily protected by HIPAA merely because it concerns health or insurance.

Other federal or state privacy, security, consumer-protection, and breach-notification laws may apply regardless of whether HIPAA applies.

15. U.S. privacy rights

Depending on your state of residence and the applicability of particular laws, you may have rights concerning certain personal information, which may include rights to request access, correction, deletion, or information about how personal information is processed.

These rights are subject to the scope, definitions, exceptions, thresholds, and verification requirements of applicable law.

FinePrintCheck does not waive any privacy right that cannot lawfully be waived.

Privacy requests may be sent to the contact address below.

16. International processing

FinePrintCheck is operated from Sweden and uses service providers and cloud infrastructure that may process information in the United States, Sweden, other parts of the European Economic Area, or other locations depending on service configuration and provider infrastructure.

By using the Service, information may therefore be processed outside the U.S. state in which you reside.

17. Children's privacy

The Service is not directed to children under 13.

FinePrintCheck does not knowingly solicit children under 13 to purchase or use the Service.

If you believe a child has provided personal information to FinePrintCheck in violation of applicable law, contact us so the matter can be reviewed.

18. Security incidents and breach notification

If FinePrintCheck becomes aware of a security incident involving information processed through the Service, we will investigate and take reasonable measures appropriate to the circumstances.

Where notification to affected individuals, regulators, or other parties is required by applicable law, FinePrintCheck will provide notification in accordance with those legal requirements.

19. Changes to this Privacy Policy

FinePrintCheck may update this Privacy Policy as the Service, technology, providers, or applicable legal requirements change.

The current version will be published on this page together with its effective date.

20. Contact

Privacy questions or requests may be sent to:

fineprintcheck-general-support-requests@fineprintcheck.app

Do not send insurance policy documents, medical information, member identification numbers, or other sensitive health information by ordinary email.