Privacy Statement

Last Updated: February 14, 2026

Litmus Holdings, Inc. ("Litmus," "we," "our," or "us") operating under the brands Litmus™ and Litmus Risk™ is committed to protecting your privacy. This Privacy Statement explains how we collect, use, share, and safeguard your personal information when you access our website, use our platform, or engage with our services. It also outlines additional rights granted to California residents under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).


1. INTRODUCTION


1.1 Who We Are. Litmus is a fee-only, no-commission insurance advisory platform helping individuals and families optimize their property and casualty coverage. We do not sell insurance, adjust claims, represent carriers or earn commissions.


1.2 Scope of This Statement. This Privacy Statement applies to personal information and uploaded content collected from users of the Litmus website, platform, and subscription-based services. It supplements—but does not override—the Subscriber Master Services Agreements, which govern service-specific data practices.


1.3 Updates. We may update this Privacy Statement from time to time. We will provide sixty (60) days' advance notice for general changes and ninety (90) days' notice for material changes affecting your rights or data usage.


2. INFORMATION WE COLLECT


2.1 Information You Provide.

We collect the following when you interact with our platform:

  • Contact Details: Name, email, phone, mailing address

  • Property Information: Address(es), features, risk factors

  • Insurance Data: Policy details, claims history, coverage terms

  • Billing Information: Subscription payment data (processed via secure third parties)

  • Account Credentials: Login, preferences, usage history

  • Driver's License Numbers: For identity verification and policy management

  • Claims Documents: May contain sensitive information including social security numbers, medical information, and other personal details


2.2 Automatically Collected Data.

We may collect:

  • IP address, browser type, OS, device ID

  • Usage metrics (pages visited, features used, timestamps)

  • Cookies and analytics data for performance and personalization

  • Technical logs for diagnostics and security


2.2.1 Third-Party Data Integrations.

With your authorization, we may collect insurance policy information through third-party integration services that connect to your insurance carrier accounts. These integrations allow automated policy ingestion without manual document upload. 


2.3 How We Use Your Information.

  • Service Delivery: Policy reviews, renewal alerts, and coverage analysis

  • AI-Powered Features: Policy ingestion, automated recommendations, coverage analysis, and other AI-driven insights

  • Claims Support: Tiered support as governed by the Subscriber Master Services Agreements

  • Operations: Account management, billing, support services

  • Improvements: Platform optimization using anonymized and aggregated data

  • Product Development: Anonymized and aggregated data may be used to improve AI tools and platform functionality


3. UPLOADED DOCUMENTS & DATA HANDLING


3.1 Document Uploads. Subscribers may upload policies, appraisals, or claims files for analysis. By uploading, you confirm that you have the right to share the files and that they do not infringe on third-party rights. Users acknowledge that uploaded documents may contain sensitive personal information and are responsible for ensuring they have the right to share such information with Litmus.


3.2 Data Storage & Security.

  • Encryption: All documents are encrypted in transit and at rest

  • Access Controls: Only authorized Litmus personnel can access files

  • Cloud Hosting: Secure providers under confidentiality contracts

  • Security Reviews: Ongoing audits and updates


3.3 Retention Policy.

  • Active accounts: Data retained during the subscription

  • After cancellation: Retained for 30 days, then deleted

  • Legal holds: Retained longer if required

  • Early deletion: Available upon request, subject to compliance requirements

  • Backups: Data backups are deleted in accordance with the same 30-day retention period


3.4 Content Management. Users may manage or delete uploaded files via the dashboard or by contacting support. Deleting files may affect advisory outcomes.


4. INFORMATION SHARING


4.1 No Sharing with Carriers. We do not share your data with insurance carriers, agents, or brokers without your express written consent.


4.2 Trusted Service Providers. 

We may share limited data with partners who assist with:

  • Payment processing

  • Hosting and infrastructure

  • AI and machine learning services

  • Policy data integration services

  • Customer relationship management

  • Customer support tools

  • Analytics (anonymized)

  • Legal, audit, or compliance services

All partners are bound by confidentiality and data protection agreements.


4.3 Legal & Regulatory Disclosures. 

We may disclose your information to:

  • Comply with subpoenas or legal orders

  • Prevent fraud or harm

  • Protect our legal rights

  • Fulfill regulatory obligations in the insurance industry


4.4 Enterprise Advisor Data Sharing. If you access the Services through an Enterprise Advisor (such as a financial planning firm or professional advisor), certain information about your use of the Services and your insurance data may be shared with your Enterprise Advisor to facilitate their advisory services to you.


5. DATA SECURITY


5.1 Our Security Program.

We maintain a layered cybersecurity framework that includes:

  • Industry-standard encryption

  • Role-based access controls with MFA

  • Network firewalls and monitoring

  • Security awareness training for employees

  • Regular security assessments and updates


5.2 Breach Notification. In the event of a data breach affecting your information, we will notify you without undue delay and, where feasible, within seventy-two (72) hours in accordance with applicable law and our contractual obligations.


5.3 Limitations. No security system is foolproof. While we implement best-in-class measures, we cannot guarantee absolute protection against every threat.


5.4 Call Recording. Conversations with our live representatives may be recorded for quality assurance, training, and service improvement purposes. You will be notified at the beginning of any recorded call.


6. CHILDREN'S PRIVACY


Our platform is intended for users 18 and older. We do not knowingly collect data from children. If we become aware of such data, we will delete it promptly.


7. YOUR RIGHTS & CHOICES


7.1 Account Management. You can access and update your information via your account or by contacting support@litmusrisk.com.


7.2 Deletion Requests. You may request deletion of personal data. We will respond within 30 days, subject to applicable retention requirements and our 30-day post-cancellation policy.


7.3 Communication Preferences.

  • Marketing: You can opt out of promotional emails

  • Service Messages: You will still receive important billing and platform alerts

  • Cookie Settings: Manage cookies through your browser or in-platform settings


7.4 California Privacy Rights.

If you are a California resident, you have rights under CCPA and CPRA including:

  • The right to know what personal data we collect

  • The right to request deletion or correction

  • The right to limit use of sensitive data

  • The right to non-discrimination

  • The right to opt out of sale (not applicable—we do not sell data)

To exercise these rights, email: privacy@litmusrisk.com with "California Privacy Request" in the subject line.


8. INTERNATIONAL USE

By using our Services outside the U.S., you consent to the processing and storage of your personal data in the United States. 


9. COOKIES & ANALYTICS

We use cookies and similar tracking technologies to operate and improve our Services. Categories include:

  • Essential Cookies: Required for login, security, and core platform functionality.

  • Analytics Cookies: To improve features, measure engagement and understand usage patterns.

  • Preference Cookies: To remember your settings and preferences

You can manage cookies via browser settings or within the platform. Disabling certain cookies may affect platform functionality.


9.1 AI Features And Automated Decision-Making.

Our Services utilize artificial intelligence and machine learning features powered by third-party providers. AI Features are used for:

  • Policy document ingestion and analysis

  • Automated coverage recommendations

  • Risk assessment and gap analysis

  • Interactive queries and responses

You are solely responsible for reviewing and validating all AI-generated outputs and recommendations. AI outputs may be inaccurate or incomplete. We strongly recommend verifying all AI-generated information before making insurance decisions. AI Features are provided for informational and advisory purposes only and do not constitute professional advice.


9.2 Data Used for AI Improvement. We may use anonymized and aggregated customer data to improve our AI tools and platform functionality. 


10. DISCLAIMERS

  • We provide non-legal, educational advisory only. We do not give legal, tax, or financial advice.

  • We do not handle or file claims, nor guarantee their outcome.

  • We do not sell insurance, adjust claims, represent carriers or earn commissions.

  • AI-generated recommendations are based on the data you provide and may contain errors or inaccuracies.

  • We are not responsible for decisions made by insurance carriers or the outcomes of insurance claims.

  • Service uptime targets are 99.5%, but availability is not guaranteed.


11. CONTACT & DISPUTE INFORMATION

For legal rights, arbitration, and governing law, please refer to our Master Services Agreements.


Contact: Litmus Holdings, Inc. Privacy Officer 1230 Rosecrans Ave., Suite 300

Manhattan Beach, CA 90266 Email: privacy@litmusrisk.com Support: support@litmusrisk.com Legal: legal@litmusrisk.com


12. UPDATES & EFFECTIVE DATE

We encourage you to review this Statement periodically. Changes will be communicated with adequate advance notice.

By using our Services, you acknowledge that you have read and understood this Privacy Statement. For subscribers, your use is also subject to the Terms of Use and the applicable Master Services Agreements.

Ready to Transform Your Insurance Experience?

Join thousands who trust Litmus to protect their assets with clarity, confidence, and expert guidance.

Insurance doesnt have to feel uncertain. Litmus helps you navigate complexity with clarity, empathy, and expertise transforming risk management into a source of confidence and peace of mind

© 2024 Litmus Holdings, Inc. All rights reserved. Litmus™ and Litmus Risk™ are trademarks of Litmus Holdings, Inc.


CA P&C License #6017185 / CA Adjuster License #2N60154


© 2024 Litmus Holdings, Inc. All rights reserved. Litmus™ and Litmus Risk™ are trademarks of Litmus Holdings, Inc.



CA P&C License #6017185 / CA Adjuster License #2N60154