Privacy
Privacy policy
Effective 16 September 2026
Slipstream is a placement workspace used by insurance brokers and carriers. The data in it belongs to the firms placing a risk; we process it to run the service and for nothing else. This policy says what we collect, why, who else handles it, how long it is kept, and what you can ask us to do with it.
It is written by us, in plain language, for a private beta. It will be reviewed by counsel and replaced by a negotiated agreement with each firm before any live client data is handled. Where it says “we”, it means Slipstream; where it says “you”, it means a person using the product or this website.
01What we collect
Account data. Your work email address, the name you give us, the firm you belong to and which side of a placement it sits on, and your notification preference. There are no passwords: you sign in with a one-time link sent to your email.
Placement data. Everything a firm puts into a placement room — the submission and other filed documents, the slip’s terms, every move in a negotiation, quotes, conditions, bind orders, endorsements, the expiring terms of a renewal, and the assistant proposals and concerns with the human decisions on them. This data is entered by the firms and is theirs. It routinely contains information about the insured, which is a business rather than a person, and may incidentally contain personal data of the insured’s people where a submission includes it.
The trail. An append-only record of who did what in a placement and when: the actor, whether they were a person or an assistant, the firm they acted for, the action and a hash chained to the previous entry. It is part of the placement record and cannot be edited or deleted, by anyone, including us.
Operational data. Whether and when you opened a room, which is private to you; server request logs with paths, timings and IP addresses, kept by our hosting provider for a short window; and error reports.
On this website. If you request pilot access, what you type into that form. Nothing else: there is no analytics script, no advertising pixel and no session recording anywhere on the site or in the product.
02Why we process it
To provide the service to the firms using it — that is the only purpose. In the language of data protection law, we process account data to perform our agreement with you and your firm, and placement data on the instructions of the firms that own it. We rely on our legitimate interest in running a secure service for the operational data above.
We do not sell data, share it with advertisers, or use it to build anything other than the service the firms have asked for. Submissions and negotiations are never used to train a model — ours or anybody else’s.
03The assistants
Two AI assistants read a submission and draft or review terms. They run on Anthropic’s API on a paid workspace, whose terms do not use prompts or outputs to train models. What they produce is a proposal; only a person at the firm it was drafted for can approve it, and the database enforces that rather than the interface. The provider and model that read a given submission are written to that submission’s own audit row, so the answer to “which model saw this” is in the record.
04Who else handles it
Six providers process some part of the data on our behalf. They are named, with what each one sees, on the security page: Supabase (database, authentication and file storage, on AWS in the United States), Vercel (hosting), Liveblocks (the live slip and presence), Anthropic (document reading and the assistants), Resend (sign-in and notification email) and Tally (the pilot request form on this website only). We will tell firms before adding one.
Everything is hosted in the United States. There is no EU-resident deployment. If your firm’s data cannot leave the EEA, say so early and we will tell you plainly that we are not ready for that.
05Who can see it
Access is granted per placement room, never per organisation. A firm sees the rooms it was invited to and nothing else; a market never sees another market’s terms. The one read that reaches past a room is the names of the people at your own firm, so that a firm can see who is in it. These rules are enforced in the database and are asserted on every build. Within a room, the counterparty sees your actions as part of the shared record, which is the point of the product; it does not see whether or when you opened the room.
We can see the data in the course of operating the service — support, debugging, and incident response — and for no other reason. Our administrative access is logged by our providers, and the mechanisms that stop an assistant committing a term stop us too.
06How long we keep it
For the life of the placement and the account. A placement record is kept because it is a record: a firm may need to show, years later, what was agreed and by whom. The filed documents can be removed on a firm’s request. The trail and the negotiation record cannot be deleted — that is a property of the design and it is stated plainly on the governance page. Where deletion of a value is ever required, the honest form is redaction, which we would scope with the firm rather than switch on.
Server request logs are kept by our hosting provider for a short rolling window and are not retained by us beyond it.
07Your rights and how to use them
You can see and correct your own account data on the settings page, switch notification email off there, and sign out of every device. A firm placing a risk can export the whole placement as one self-contained file at any time, without asking us.
Depending on where you are, you may have rights to access, correct, port, restrict or object to processing of personal data about you, and to complain to a supervisory authority. Write to mhk127@rutgers.edu and we will answer within thirty days. Where a request concerns placement data owned by a firm, we will refer it to that firm, because the data is theirs and the decision is theirs.
08Cookies
The product sets the cookies needed to keep you signed in and nothing else. They are first-party, marked HttpOnly and Secure, and are refreshed on each navigation. This website sets none. There is no consent banner because there is nothing to consent to.
09Security
Every connection is encrypted in transit and the data is encrypted at rest by the providers that hold it. Sign-in is by one-time link, so there is no password to be phished or leaked. What is in place, and what is not yet — SOC 2, a third-party penetration test, EU residency — is listed on the security page, and a vulnerability can be reported to the address below.
10Children, changes and contact
The product is for people working at insurance firms and is not directed at anyone under eighteen. We will post changes to this policy here with a new effective date, and tell firms directly about any change that affects how their data is handled.
Questions and requests go to mhk127@rutgers.edu. A founder reads that inbox.