Privacy Policy
Last updated: September 16, 2026
Who we are
Benefits Studio (“we,” “us”) provides software that lets insurance brokers and HR teams turn employee benefits documents into published benefits websites, with an AI assistant (“Benny”) that answers questions using only those documents. This policy explains what information we collect, how we use it, and the choices you have. Questions? Email legal@benefitsstudio.com or use our contact form.
If you’re an employee visiting a benefits portal
Benefits portals are public web pages. You do not create an account, and we do not ask you for your name, email, or health information. When you use the site we collect only:
- Standard web logs and page-view counts (which pages are visited, not who visited them).
- A random session cookie, and your IP address, used to prevent abuse of the AI assistant (rate limiting) and to keep the site secure. Your IP address is kept only briefly for that purpose and is not used to identify you personally.
- The questions typed to Benny, stored with that random session ID so the employer’s benefits team can see what topics people ask about. To generate an answer, your question and excerpts of the employer’s plan documents are processed by Anthropic (our AI provider) via API; Anthropic does not use this data to train its models. Don’t include personal details (like your name, member ID, or health conditions) in questions — Benny doesn’t need them and can’t access any personal records anyway.
- If you use the “contact your benefits team” form, the name (optional), reply-to email, and message you enter are emailed to your employer’s benefits team through our email delivery provider (Resend) and are not stored by us.
Portal analytics (PostHog) count page views and feature use in aggregate. They do not include the text of your questions, and we do not use session recording or automatic click capture on benefits portals.
If you’re a broker or HR administrator
We collect:
- Account information — your email, password (stored hashed, never readable by us), and company name. If you sign in with Google, we receive your email from Google.
- Content you upload — benefits plan documents (SBCs, plan summaries, formularies), branding assets, announcements, and contact directories. These are plan-level documents; please don’t upload documents containing individual employees’ personal or health information.
- Billing information — handled by Stripe. We never see or store your card number.
- Usage data — logs and product analytics (PostHog) about how the admin app is used, to keep it working and improve it. In the admin app this can include session recordings of your screen interactions; text you type into forms is masked. We also keep a contact record for you in our email platform (Loops) so we can send account and onboarding emails.
How we use information
- To provide the service: host portals, extract plan facts from documents for your review, and answer employee questions from those documents.
- To process payments and manage subscriptions.
- To send transactional emails (account confirmation, password resets, billing and usage notifications) and onboarding or product-update emails to account holders. You can unsubscribe from the onboarding and product-update emails at any time; account, security, and billing notices continue while you have an account.
- To monitor performance, prevent abuse, and improve the product.
We do not sell personal information, and we do not use your uploaded documents to train AI models.
Service providers
We rely on a small set of processors to run the service: Supabase (database, file storage, authentication), Vercel (web hosting), Stripe (payments), Anthropic (AI document processing and the Benny assistant), Voyage AI (document search indexing), Cloudflare (domain, DNS, and the Turnstile bot check on our forms), Google (optional sign-in), PostHog (product analytics and error tracking), Loops (account, onboarding, and product emails to administrators), and Resend (delivery of contact-form messages, and of error alerts to our own team). Each receives only what it needs to perform its function; PostHog, Loops, and Resend never receive your uploaded documents or the questions employees ask Benny. Our AI providers process uploaded documents and Benny questions via API and do not use that data to train their models — see Anthropic’s privacy policy and Voyage AI’s privacy policy for how they handle data they process.
Retention & deletion
Account data and uploaded content are kept while your subscription is active. If a trial or subscription ends, portal data is retained for 90 days and then deleted. You can request deletion of your account and data at any time by emailing us; we’ll complete it within 30 days, except records we’re legally required to keep (like billing records).
Security
Documents are stored in private storage accessible only through short-lived signed links; data is encrypted in transit and at rest; each customer’s data is isolated at the database layer. No method of storage or transmission is 100% secure, but we design for defense in depth.
Your rights
Depending on where you live (for example, California or the EU), you may have rights to access, correct, export, or delete your personal information. Email legal@benefitsstudio.com (or use our contact form) and we’ll honor these requests regardless of where you’re located.
Children
Benefits Studio is a workplace tool and is not directed at children under 16. We don’t knowingly collect their information.
Changes
If we make material changes to this policy, we’ll update the date above and notify account holders by email. Continued use after changes means you accept the updated policy.