← Back to home

Privacy Policy

Last updated: July 3, 2026

OSOK Life LLC ("we," "us," "our") operates the OSOK Life platform. This Privacy Policy describes what information we collect, how we use it, how we protect it, and your rights regarding your data.

1. Information We Collect

When you use OSOK Life, we collect:

2. Information We Do NOT Collect

3. How We Use Your Information

Your information is used to:

4. Data Storage and Security

For a plain-language walkthrough of how we protect your data — including what encryption we use and what end-to-end encryption actually means — see our Security page.

In plain terms, here is the complete honest picture: the identity information we hold about you is your email and a yes/no veteran flag. Your sensitive numbers (SSN, date of birth, VA file number) are stripped before saving and never reach our database. Your conversations, drafts, and uploads are encrypted and readable only by you. Your financial data never leaves your browser. Your passwords belong to Clerk and your card numbers belong to Stripe — we never see either. The most sensitive thing OSOK typically holds is your own work, encrypted, under your own account.

5. Third-Party Services

The Service integrates with the following third-party services. When you use these integrations, their respective privacy policies also apply:

We only request the minimum permissions needed to provide each feature. We do not request or use permissions beyond what is necessary.

6. OTC and Shopping Features

The Smart Shopper tool provides general shopping guidance using AI. OSOK Life is not affiliated with any insurance company, pharmacy, or benefit card provider (including but not limited to CVS, Walgreens, Humana, UnitedHealthcare, Aetna, or any other entity). Coverage and eligibility information is general guidance only. We do not access, store, or process your insurance information, benefit card numbers, or health plan details.

7. Data Deletion

You have the right to delete your data:

8. Cookies and Local Storage

The Service uses:

8a. Abuse Prevention

Some parts of the Service — currently bug reporting — cost us money each time they are used, and they have been targeted with automated junk submissions. To keep those features working and free, we collect a small amount of technical information when you use them. Here is exactly what that means, in plain terms.

Your IP address. When you submit a bug report, your IP address is transformed using a keyed cryptographic hash (HMAC-SHA256) and only the result is stored. We do not keep the address itself. We want to be straightforward rather than reassuring here: this is not anonymisation. An IP address has a small enough range of possible values that anyone holding both our key and our database could test addresses against the stored values. What the hash actually protects against is a database copy on its own being readable, and it means nobody browsing our records ever sees an address. The keyed hash lets us notice that several submissions came from the same network without keeping a record of which network that is.

A random identifier for your browser. We set a cookie containing a random value that we generate. It is not derived from anything about your device, and we do not use browser fingerprinting of any kind — no canvas, WebGL, audio, font, or hardware inspection. Clearing your cookies replaces it with a new value, and we treat that as normal rather than as something to defeat. This cookie is first-party only and is never shared with, or readable by, any other site.

Your account activity on the Service. How many reports you have filed, when, and whether any were held for review.

What we do with it. We use it to spot repeated abuse of these features, to limit how often reports can be submitted, and — rarely, and by a human decision — to temporarily pause reporting from an account or a network. We do not use any of it for advertising, we do not sell it, and we do not share it with data brokers.

What it cannot do. This information describes accounts, networks and browsers. It does not identify a person, and we do not treat it as if it does. A single network is often shared by an entire household, a barracks, a school, a library, or thousands of mobile customers at once. Two accounts appearing on one network tells us nothing about who is using them.

How long we keep it. The network and browser identifiers attached to a report are erased after 90 days. Records of abuse decisions are kept for one year. Decisions made by a human — pausing an account, restricting a network — are kept indefinitely, because if a restriction is still in effect we need to be able to explain why it exists. Erasing this information never deletes the report you wrote; it only removes the technical details attached to it.

If you are affected. If bug reporting is unavailable to you and you believe that is a mistake, contact support. We would rather hear from you than have you assume the Service is broken.

9. Children's Privacy

The Service is not intended for users under the age of 13. We do not knowingly collect information from children under 13. If we become aware that we have collected personal information from a child under 13, we will delete it promptly.

10. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information.

11. Changes to This Policy

We may update this Privacy Policy at any time. Material changes will be communicated through the Service. Continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact

For privacy-related questions, data deletion requests, or concerns, reach out via the Feedback button in the app or contact OSOK Life LLC at the address on file with the California Secretary of State.