Privacy Policy

Effective date: June 4, 2026

Mule Digital LLCoperates the Nest platform (“Nest,” “we,” “us,” or “our”), an all-in-one CRM, AI writing assistant, license tracker, document vault, and scheduling tool built for licensed insurance agents and IMOs (independent marketing organizations). This policy explains what personal information we collect, how we use it, and your rights.

Two roles. For information about your own account and use of Nest (your name, email, agency, billing, and license records), we act as a controller. For the personal information you upload about your clients and contacts, you are the controller (or “business”) and we act as your processor(or “service provider”), handling that data only on your instructions to provide the Service — see our Data Processing Addendum. This policy primarily describes the information we handle as a controller.

1. Information we collect

Information you give us directly

  • Account information:name, email address, and password when you sign up. Authentication is handled by Clerk; we do not store passwords.
  • Agency and license information:home state, agency name, NPN (National Producer Number), resident and non-resident license data you enter or sync via NIPR.
  • Client and contact data:names, phone numbers, email addresses, and notes you add to your contacts and leads inside Nest.
  • Documents and voice memos:files you upload to the document vault and voice recordings you create in the app. Files are stored on Vercel Blob; voice memos are transcribed by OpenAI Whisper and then deleted from temporary storage.
  • Payment information:billing is handled by Stripe. We receive a confirmation and customer ID from Stripe; we do not store your card number or bank details.

Information from third-party services you connect

  • Google Calendar:if you connect Google Calendar, we request read/write access to your calendar events to enable two-way sync. We store your OAuth access and refresh tokens, encrypted at rest (AES-256-GCM). We do not read, store, or share the content of calendar events beyond what is necessary to display and sync them inside Nest. You can disconnect Google at any time in Settings → Integrations.
  • LinkedIn:if you connect LinkedIn, we request the following permissions via LinkedIn’s OpenID Connect:
    • openid, profile:your LinkedIn member id, name, and profile photo, used to display your identity inside Nest and to attribute posts.
    • email:your LinkedIn email address, used to link your LinkedIn account to your Nest account.
    • w_member_social:the ability to publish posts to LinkedIn on your behalf, used only when you explicitly click “Publish” inside the Nest social scheduling tool.
    We store your LinkedIn OAuth tokens encrypted at rest. We never read your LinkedIn feed, messages, connections, or any data beyond the profile fields above. You can disconnect LinkedIn at any time in Settings → Integrations, which revokes our access and deletes your stored tokens.
  • NIPR:if you enable license sync, we query the National Insurance Producer Registry using your NPN to retrieve your public license and appointment records. We cache this data in your account to power the Licensing dashboard.

Information collected automatically

  • Usage data:page views and feature interactions, collected via Vercel Web Analytics. No third-party cookies; no cross-site tracking.
  • Server logs:IP address, user agent, and request timestamps for security monitoring. Retained for 30 days.

2. How we use your information

  • To provide, maintain, and improve the Nest platform.
  • To publish content to LinkedIn, Google Calendar, or other connected services when you explicitly request it.
  • To send transactional emails (email verification, billing receipts, cert renewal reminders). We use Resend for delivery; we do not send marketing emails without your consent.
  • To enforce our Terms of Service and prevent fraud or abuse.
  • To comply with legal obligations (e.g., state insurance regulations, IRS).

We do not sell your personal information. We do not use your data to train AI models.

3. How we share your information

We share your information only with the sub-processors necessary to operate Nest:

  • Clerk:identity and authentication.
  • Neon:PostgreSQL database hosting.
  • Vercel:application hosting, Blob storage, and analytics.
  • Stripe:payment processing.
  • Resend:transactional email delivery.
  • OpenAI:voice transcription (Whisper). Audio is sent to OpenAI for transcription and not retained by OpenAI per their zero data retention API agreement.
  • Google:AI text generation for the AI Studio’s drafting and assistant features, accessed via the Vercel AI Gateway. Prompts are processed to generate output for you and are not used to train Google’s models.
  • LinkedIn:when you publish a post, the post content is transmitted to LinkedIn via their API.

Each sub-processor is bound by a data processing agreement. We do not share your data with insurance carriers, lead vendors, or advertising networks.

4. Data retention

We retain your account data for as long as your account is active. If you close your account, we delete your personal information within 30 days, except where we are required to retain records for legal or regulatory compliance (e.g., commission audit trails). Voice memo transcripts are deleted from temporary storage immediately after transcription.

5. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate information.
  • Request deletion of your account and associated data.
  • Receive a portable copy of your data (export is available in-product as CSV).
  • Disconnect any third-party integration (Google, LinkedIn) at any time.
  • Opt out of analytics collection by enabling “Do Not Track” in your browser.

To exercise any of these rights, email hello@nestannuity.comwith the subject line “Privacy Request.” We verify your identity and respond within the time required by applicable law (generally within 45 days). If your clients’ personal information is involved, we will refer the request to the relevant agency customer (the controller of that data).

6. Your U.S. state privacy rights

Residents of states with comprehensive privacy laws — including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing list of others — have rights to know/access, correct, delete, and obtain a portable copy of their personal information, and to opt out of “sale” or “sharing” of personal information and certain targeted advertising and profiling.

  • We do not sell your personal informationand do not “share” it for cross-context behavioral advertising, as those terms are defined under California and other state laws.
  • No discrimination. We will not deny service, charge a different price, or provide a different quality of service because you exercised a privacy right.
  • Authorized agents. You may use an authorized agent to submit a request; we may require verification.
  • Appeals. Where state law provides an appeal right (e.g., Virginia, Colorado, Connecticut), you may appeal a denied request by replying to our decision; we will respond within the period required by law.

Submit requests to hello@nestannuity.comwith the subject “Privacy Request.” The categories of personal information we collect, the purposes, and the parties we disclose to are described in Sections 1–3 above.

7. Financial and insurance information

Because Nest serves insurance professionals, some information may relate to insurance and financial matters and may be subject to laws such as the Gramm-Leach-Bliley Act (GLBA) and state insurance data-security and privacy rules (including frameworks based on the NAIC Insurance Data Security Model Law). We maintain administrative, technical, and physical safeguards designed to protect this information, and we limit its use to operating the Service and as permitted by law. Your clients’ nonpublic personal information that you upload is handled as a processor under our Data Processing Addendum; you remain responsible for your own GLBA and state-law privacy obligations to your clients.

8. Cookies and tracking

We use strictly necessary first-party cookies set by us and by our authentication and payment providers (Clerk and Stripe) to keep you signed in and to process payments. We use Vercel Web Analytics for privacy-friendly, aggregate usage measurement. We do not use third-party advertising cookies and do not engage in cross-site tracking.

9. Security

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). OAuth tokens and connected-integration credentials are encrypted at the application layer before storage. Access is role-scoped and org-scoped, reads and writes to the document vault are logged, and cross-organization access is not possible by design. We conduct security reviews and follow responsible-disclosure practices. No system is perfectly secure, and we cannot guarantee absolute security.

10. Data breach notification

If we become aware of a breach of security affecting your personal information, we will notify affected users and, where required, regulators and your agency customer, without undue delay and within the timeframes required by applicable state breach-notification laws. Where we act as a processor of your clients’ data, we will notify the relevant agency customer so it can meet its own notification obligations.

11. Automated processing and AI

Nest’s AI features generate drafts and suggestions to assist you; they do not make legally or similarly significant decisions about consumers on their own, and every output is subject to your review and action before use. We do not use your data or your clients’ data to train third-party foundation models.

12. Children

Nest is intended for licensed insurance professionals. We do not knowingly collect information from anyone under 18. If you believe a minor has created an account, contact us and we will delete it promptly.

13. Changes to this policy

We will post any changes to this page and update the effective date above. For material changes, we will notify you by email at least 14 days before they take effect.

14. Contact

Questions or privacy requests:
Mule Digital LLCNest
[PRINCIPAL ADDRESS]
hello@nestannuity.com