Stoa

Legal

Privacy Policy

Last updated: August 1, 2026

This Privacy Policy explains how Stoa ("Stoa", "we", "us") collects, uses, shares, and protects information when you use the Stoa website and Service. By using the Service, you agree to the practices described here.

1. Information we collect

Account and contact information — name, work email, company, and any message you submit through our contact form or a request for a coverage report.

Assessment information — the description of your AI systems and organization you provide in the Assessment questionnaire: archetypes, routing answers, and configuration parameters. This is generally business and technical information about how your systems operate, not personal data about your customers or employees, unless you choose to include it.

Behavioral testing data — if you run behavioral testing against your AI agents, the probe results and evidence generated by that testing.

Usage data — first-party, self-hosted analytics on how the Assessment and site are used (for example, when a wizard is started, a question is answered, or a coverage cell is viewed). We do not use third-party advertising trackers.

Device and log data — IP address, browser type, and timestamps, collected automatically as part of operating the Service.

2. How we use information

To generate your Assessment, coverage report, and any specimen policy documents.

To follow up on your submission, prepare for a placement conversation, and provide brokerage services.

To operate, secure, and improve the Service.

To communicate with you about your account, report, or support requests.

To comply with legal obligations.

3. How we share information

We do not sell your personal information. We share it only as follows:

Service providers — infrastructure and data-storage providers (including Upstash Redis) and transactional email providers (including Resend), who process data on our behalf to operate the Service.

Carriers and markets — when you engage us for placement, information necessary to obtain terms is shared with underwriters and markets on your behalf, with your knowledge.

Legal and safety — when required by law or to protect the rights, property, or safety of Stoa or our users.

Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

4. Data retention

We retain your information for as long as needed to provide the Service and pursue a placement, then for the period required to meet legal, accounting, or security obligations. [TODO: specific retention schedule to be confirmed.] You can request deletion as described below.

5. Security

We use technical and organizational measures, including encryption in transit and access controls, to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

6. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, or port your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at ved@stoa.insure.

7. International users

We are based in the United States and process data there. If you access the Service from outside the U.S., your information may be transferred to and processed in the U.S.

8. Children

The Service is not intended for anyone under 18, and we do not knowingly collect personal information from children.

9. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above.

10. Contact us

Questions about this Policy or your data? Reach us at ved@stoa.insure.

[TODO: entity name, jurisdiction of incorporation, and registered address to be added here]

This is an initial privacy policy provided for transparency and is not legal advice. It should be reviewed by counsel before being relied upon for compliance in any specific jurisdiction.