Privacy Policy
Last updated: July 2026
Overview
Milan Audit (“Milan Audit,” “we,” “us”) is a tool that reviews completed property insurance estimates and returns a structured audit: missing scope, QA issues, supplement opportunities, and a confidence score. This policy explains what information we collect, how we use it, and how it’s shared with the third-party services Milan Audit depends on to work.
Information we collect
Account information: your email address and any name you provide at signup, and your organization’s name.
Uploaded estimates: the PDF files you upload for audit, and the text and data extracted from them (line items, trades, quantities, pricing, and whatever claim information the document itself contains, such as a policyholder’s name, property address, phone number, or policy/claim number). Claim-header fields like these are redacted before the estimate is sent to OpenAI; see below.
Audit results: the findings, scores, and summaries Milan Audit generates from your uploaded estimates.
Billing information: handled directly by our payment processor, Stripe. We do not store your card number ourselves.
How estimate data is processed, and what an AI model sees
Auditing an estimate requires sending its contents to a large language model (currently OpenAI’s API) for the parts of the review that require judgment rather than a fixed rule. Before that happens, Milan Audit runs an automated redaction pass over the estimate’s text that strips recognized claim-header fields: the policyholder’s name, property address, phone number, and policy/claim number, replacing them with a placeholder before anything is sent externally. This is a real, pattern-based mechanism, not a guarantee: it’s calibrated on conventional estimate header formats and, like any automated text-processing step, will not catch every possible variation.
Per OpenAI’s own published policy as of this writing, data submitted through their API is not used to train their models, and API inputs/outputs are retained for up to 30 days for abuse-monitoring purposes before being deleted, unless a longer period is legally required. We do not currently hold a Zero Data Retention agreement with OpenAI. If that changes, this policy will be updated to reflect it.
How we use your information
To provide the audit service itself: extracting, analyzing, and scoring your uploaded estimates, and showing you the results. To operate your account and organization, including enforcing plan limits. To process payments through Stripe. To maintain and improve the reliability of the service. We do not sell your data, and we do not use your uploaded estimates to train any AI model.
Where your data is stored
Application data (accounts, organizations, uploaded files, audit results) is stored with Supabase, using database-level access controls (Row Level Security) that scope every read and write to your own organization. Another customer’s data is not visible to your account, and vice versa, enforced at the database layer rather than solely in application code.
Data retention and deletion
We retain your account and estimate data for as long as your account is active, so you can access your audit history. If you’d like your account and associated data deleted, contact us at the email below and we’ll process the request.
Third-party service providers
Milan Audit relies on the following providers to operate: Supabase (database, authentication, file storage), OpenAI (AI-assisted audit reasoning, with redaction applied first as described above), Stripe (payment processing), and our application hosting providers. Each processes data under its own privacy terms in addition to this policy.
Children's privacy
Milan Audit is a business tool intended for insurance professionals and is not directed at, or knowingly used to collect information from, children.
Changes to this policy
We’ll update the date at the top of this page when this policy changes. If a change is material, we’ll make a reasonable effort to notify account holders directly.
Contact
Questions about this policy, or requests regarding your data, can be sent to [add a contact email before publishing].