Privacy policy
Version of 10.10.2026 · Draft before legal review.
What this is about
duvet shows your insurance in one place: you upload your policies, the app reads out the facts, shows costs and deadlines and will later remind you of cancellation dates. This statement says which data we process for that, where, for how long, and what your rights are.
Jannis Keller runs duvet and is responsible for processing your data. Contact: hello@duvet.one. This text is a draft and is reviewed by legal counsel before the app is published.
Which data we process
Your account: the email address you sign in with, your language and your settings. We store no password.
About you: your date of birth and postcode, which you give after signing in. They are only used to show in the app what applies to you, and go neither to insurers nor to the AI service.
Your documents: the policies you upload as PDF or photos. Insurance policies contain sensitive personal data, for example about your health insurance. We treat them accordingly.
The facts read from them: insurer, line, premium, term, deadlines, Franchise and Selbstbehalt, sums insured and exclusions, with the page they appear on.
What you enter yourself: your answers behind the coverage check, that is whether you rent or own your home, whether you have a car, a motorbike or pets, whether you often travel abroad and who insures you against accidents: your employer, your health insurer or the unemployment insurance (Suva). And what you record on a policy: a premium increase, a paid claim, a sold vehicle or a notice you sent, each with its date. The answers do not go to the AI service; what you record on a policy reaches the Agent with that policy's facts.
Your chats: the questions you ask the Agent and its answers.
If you allow notifications on your iPhone: the device token Apple issues for them. It is deleted when you sign out.
If you sign in with Apple: a token Apple issues for it, stored encrypted. It serves only to end your Sign in with Apple when you delete your account, and is deleted with the account.
Technical logs without personal data: time, status and internal ids, never email addresses, names, file names or document contents.
A security log of important steps such as sign-ins, uploads, opening and deleting documents, consents, exports and deleting the account: each with the time, your user id and internal ids, and instead of your IP address only a code made from it with a secret key.
Feedback: what you write or dictate to us in Settings goes to our team by email, with your user id, the app version, your language and your email address for the reply. The app stores none of it; the team's mailbox is currently at Google (Gmail). We delete these emails after twelve months. Deleting your account does not delete them automatically: the team then receives your user id and deletes your feedback within 30 days.
How the AI reads your policies and answers questions
So that the app can show the facts, an AI service reads each uploaded document once and returns the facts to us in a fixed form. Only the pages of your own document are sent, nothing else from your account. You see what was read in the app and confirm or correct it.
When you ask the Agent a question, the question, the last messages of that chat and the facts of your policies (without policy numbers) go to the same service, together with passages from the insurers' public conditions. Your email address, your date of birth and your original documents are not sent.
This service is Claude, an AI model by Anthropic that we use through Amazon Bedrock. Amazon Web Services processes the data for it on our behalf in Stockholm (Sweden, EU). Anthropic does not receive the content, and it is not used to train models.
In test versions, reading and the Agent run directly at Anthropic PBC instead, processed in the USA, under a data processing agreement with the standard contractual clauses and the Swiss addendum. There, Anthropic does not use the data to train models and does not retain the inputs and outputs of the models we use by default. A test version says so on Home and before you agree.
Both happen only with your agreement, which you give after signing in, when uploading or in the Agent, and can withdraw in Settings at any time. After a withdrawal, no new uploads, no new readings and no questions are possible; facts already read stay until you delete them.
We keep the service's raw answer for 90 days for troubleshooting, then delete it. The checked facts stay with your policy.
Anonymised comparison figures
Anonymised facts from policies feed into comparison figures and market analyses, never with your name, never individually, only in groups of at least 20 similar policies. This setting is on by default and can be switched off in Settings.
Where your data is and who processes it
Your data is stored in Switzerland: database and files are kept at Supabase in Zurich, encrypted in transit and at rest. It is also processed in the EU: the app servers run at Fly.io in Frankfurt (Germany); reading policies, the Agent and sending our emails run at Amazon Web Services in Stockholm (Sweden).
These providers are involved:
Supabase (Zurich, Switzerland): database and files.
Fly.io (Frankfurt, Germany): the app servers every request from the app passes through.
Amazon Web Services (Stockholm, Sweden): reading policies and the Agent's answers with Claude through Amazon Bedrock, and sending the emails with sign-in codes and reminders, your feedback to our team (your text, your user id and your email address for the reply) and the notices asking the team to delete the feedback of a deleted account.
Apple (worldwide, including the USA): distributing the app, notifications on your iPhone and, if you use it, Sign in with Apple.
Google (USA and EU), only if you sign in with Google: Google confirms your email address to us.
Google Gmail (USA and EU): our team's mailbox, where your feedback and emails to our addresses arrive.
Spaceship (USA): manages our domain duvet.one and forwards emails to our addresses to that mailbox.
Contracts oblige these providers to protect your data; where such a contract is still missing, we conclude it before publication.
No advertising, no sharing with third parties for their own purposes, no trackers in the app.
How long we keep data
Your documents, the facts read from them and your chats with the Agent stay until you delete them or your account. Deleting a document removes the file and every fact read from it at once. Deleting the account deletes everything at once, except feedback emails (see above); usage counters and security log entries lose your user id at once and stay until their period ends. Where database backups exist, they are deleted after seven days at most; by then, deleted data is gone from them too. Technical logs are deleted after 30 days, security log entries after 12 months, usage counters without content after 24 months.
Your rights
You can ask at any time what data we hold, have it corrected or deleted, withdraw your agreements, and export your data (Settings, “Export my data”). Write to us at hello@duvet.one.