Privacy Policy
This Privacy Policy explains what IBC Tool collects, how we use it, where it lives, and the choices you have. We have written it to be readable. Where the legal precision matters, we have kept the precision. Where it doesn't, we have kept the prose.
IBC Tool is operated by {{LEGAL_ENTITY_NAME}} ("we," "us"), reachable at privacy@ibctool.app and at {{CONTACT_ADDRESS}}.
1. What we collect
Account information
When you create an account we collect your email address and a cryptographic hash of the password you choose (we never store the password itself). You may optionally provide a display name and timezone. If you join the waitlist before sign-ups open, we keep your email and waitlist status until you become a full account or ask us to delete it.
Insurance and financial data you enter
IBC Tool exists to track whole-life policies and the loans, payments, and budget allocations that flow through them. To do that, we store the data you enter or upload, including:
- Policy details — policy number, carrier, issue date, named owner, insured, and beneficiary, premium amounts and frequency, death benefit, and Paid-Up Additions targets.
- Periodic snapshots — cash value, available loan amount, accrued loan interest, dividend amounts, and the dates you recorded them on.
- Loan and PUA history — amounts, dates, repayment schedules, payment splits between principal and interest, and the strategy you tagged each loan with.
- Budget categories and allocations — the envelopes you set up against your available loan amount.
- Documents you upload — PDFs of policy contracts and annual statements, stored as files alongside the policy they belong to. To save you typing, the contents of annual statements are parsed by an AI provider (see section 5) and used to populate snapshot fields like cash value and available loan amount; you can review and correct anything before saving.
Third-party connections you authorize
IBC Tool can connect to outside services that you opt into — for example, a financial-account aggregator that imports transactions you can match to your account, or a budgeting tool that lets us read envelope-style allocations on your behalf. The brand of each service is shown to you in the app at the moment you authorize the connection.
When you opt in, we store any identifiers and access tokens we need to keep the connection alive, encrypted at rest where applicable. Your credentials at the third-party service stay with that service; we never see them. We use the data the connection returns only for its specified purpose — running the integration in your account — and never to train AI models or for any other use.
Some connections are still in development. We will not enable an integration on your account, or read or send any data through it, until the corresponding feature is live and described in this policy.
You can disconnect any integration at any time. When you do, we delete the corresponding tokens and provider identifiers from our systems.
Service-level data
We retain authentication sessions and password-reset tokens to keep you signed in and to let you recover your account. Application logs may record IP address and request metadata for the limited purpose of operating and securing the service.
2. What we don't collect
IBC Tool does not load behavioral analytics platforms, advertising-attribution pixels, session-replay scripts, or any other tools that track users across pages or sessions. We do not sell or share your data for advertising. If that ever changes, we will say so here before it happens.
3. How we use it
We use the data above to:
- Operate the service — show your policies, run the calculations that produce ALA, render snapshots, render budgets.
- Authenticate you and let you reset a forgotten password.
- Communicate about the service — outages, security notices, and material changes to these policies.
- Diagnose and fix problems, including looking at your data when you report a bug or ask for help, or when a serious incident requires it.
- Comply with legal obligations and protect the service from abuse.
4. Where it lives
IBC Tool's application servers and primary database are hosted in the United States. Uploaded documents are kept in object storage with our cloud storage provider. Customer data is encrypted at rest. Connections between you and IBC Tool, and between IBC Tool and our service providers, use TLS in transit.
5. Service providers
We rely on third-party service providers to host the application, store uploaded documents, and parse the contents of annual statements you upload (so cash value, available loan amount, and similar fields can be populated automatically rather than re-typed). Each receives only the data needed for its role and is bound by contractual confidentiality and security obligations. We do not permit service providers to use your data to train AI models or for any purpose other than delivering their service to us. If you'd like a current list of named sub-processors, email privacy@ibctool.app and we will share it. We will give notice on this page before any change that materially affects how your data is handled.
Integrations that you authorize yourself are described under "Third-party connections you authorize" in section 1.
6. Cookies and local storage
IBC Tool uses one category of client-side state: an authentication token, kept in your browser so you stay signed in between visits. We do not use marketing cookies, advertising cookies, or analytics cookies. A cookie banner is therefore not required today; if we add anything that would require one, we will add the banner first.
7. Children
IBC Tool is for users 18 and older. We do not knowingly collect personal information from minors; if you believe one has provided us information, contact us and we will delete it.
8. Your rights
You can ask us to:
- Access a copy of the data we hold about you.
- Correct data that is wrong. Most fields are also editable in the app.
- Delete your account and the data associated with it.
- Export your account data in a portable format.
- Withdraw consent for any optional integration you have connected.
You can delete your account at any time from the settings page in the app; the flow re-confirms your email and password and removes your data immediately. For access, correction, export, or anything else listed here, email privacy@ibctool.app and we will respond within thirty days. Self-serve data export is on the roadmap. Depending on where you live, additional rights may apply under the laws of your jurisdiction (for example, the GDPR in the EU/UK or the CCPA/CPRA in California). We honor those rights regardless of where your account is hosted, and we honor Global Privacy Control signals from your browser as a request to opt out of any sale or sharing of personal information.
9. Security
We hash passwords with bcrypt. Password-reset tokens are short-lived (fifteen minutes) and bound to your password salt, so resetting a password invalidates any outstanding reset link. Third-party access tokens you authorize are encrypted at rest. All traffic to and from IBC Tool is served over TLS. No system is perfectly secure, but we treat your insurance and financial data as data we'd want a serious provider to treat ours.
If we discover a security incident that affects your account data, we will notify you within thirty days of confirming the incident — sooner where law requires — and report to the relevant authorities on the timelines those authorities require.
10. Retention
While your account is active, we retain the data needed to operate it. When you delete your account, we remove your data from our primary database immediately and from object storage within minutes via a background purge job, with the exceptions described in our Data Retention Policy. Backups age out on the schedule maintained by our hosting providers.
11. Changes to this policy
We may update this policy as the product changes. Material changes will be communicated by email and in-app notice. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the service after a material change means you accept the updated policy.
12. Contact
Questions, complaints, or requests under section 8 can go to privacy@ibctool.app. Postal mail reaches us at {{LEGAL_ENTITY_NAME}}, {{CONTACT_ADDRESS}}.