This Privacy Policy explains how Sakred Health ("Sakred," "we," "us," or "our") collects, uses, shares, and protects information in connection with the Sakred Agents — our internal customer relationship management (CRM) and sales-automation application, together with related websites and mobile applications (collectively, the "Service").
1. Information we collect
- User (agent/staff) account information — name, email address, phone number, role, and login credentials for the users we authorize to use the Service.
- Prospect and client data — information our agents capture or import about the people they serve, such as name, phone number, email, mailing address, date of birth, and notes relevant to insurance eligibility and coverage.
- Health- and insurance-related information — limited coverage, eligibility, and policy details needed to quote and service insurance products. Where this constitutes protected health information, we handle it under the safeguards described in Section 8.
- Communications — the content and metadata of SMS/text messages, emails, and calls sent or received through the Service, including timestamps, recordings where applicable, and delivery status.
- Calendar and booking data — appointments, availability, and related details when calendar integrations are connected.
- Usage and device data — log data, IP address, device type, push-notification tokens, and interactions with the Service, collected to operate and secure the product.
2. How we use information
- To provide, operate, maintain, and secure the Service for our agents and staff;
- To quote, sell, and service insurance products, and to follow up with the people our agents serve;
- To send and receive the SMS, email, and calls that our agents initiate or automate;
- To power AI features such as lead prioritization, message drafting, conversation summaries, and triage;
- To schedule appointments and sync calendars;
- To provide internal support and send service-related notices, including push notifications;
- To comply with legal, regulatory, and insurance-licensing obligations, and to prevent fraud and abuse.
3. AI processing
The Service uses artificial intelligence to draft messages, summarize conversations, prioritize leads, triage email, and propose appointment times. All of this inference runs on Amazon Bedrock, inside our own AWS account, using Anthropic Claude models, under contractual terms (including, where health information is involved, a Business Associate Agreement). Amazon Bedrock does not retain prompts or responses after a request is served, does not use them to train or improve any model, and does not share them with the model provider.
We do not route any Service data through consumer AI products, model aggregators, model hubs, or third-party AI gateways, and we do not use your data — raw, aggregated, anonymized, or derived — to train, fine-tune, or improve our own or any third party's foundational or generalized AI/ML models. We do not sell your data.
4. How we share information
We do not sell personal information. We share it only as needed to run the Service and provide insurance products:
- Service providers — messaging carriers and platforms (e.g., Telnyx, Twilio), cloud hosting and database providers, email providers, and AI infrastructure providers, each processing data on our behalf under contract.
- Insurance carriers and partners — when needed to quote, place, or service a policy the individual requests.
- Integrations you connect — such as Google (Gmail and Calendar), only to provide the features you enable.
- Legal and safety — when required by law or regulation, or to protect the rights, property, or safety of Sakred, our clients, or others.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
5. SMS / text messaging
The Service sends and receives text messages as part of our agents' outreach. Recipients may opt out at any time by replying STOP, which stops further messages and updates the contact's status; reply HELP for assistance. Message and data rates may apply. Messaging follows applicable carrier requirements and telemarketing/consent laws (including the TCPA and A2P 10DLC rules). Consent to receive messages is never shared with third parties for their own marketing.
6. Google user data
Connecting a Google account is optional. If you connect one, Sakred accesses Gmail and/or Google Calendar data only to provide the inbox triage, reply drafting, and calendar/scheduling features you enable. You can disconnect Google access at any time from within the Service or from your Google account settings; disconnecting stops all further access.
Limited Use
Sakred's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data and AI/ML
We do not use, transfer, or sell Google user data — raw, aggregated, anonymized, or derived — to develop, improve, or train generalized or foundational artificial intelligence or machine learning models. Where a feature applies AI to Google user data, that processing happens only on Amazon Bedrock as described in section 3, under terms that prohibit retention and model training, and only to produce the output shown to the user who connected the account. Specifically:
- Google Calendar — the AI scheduling assistant receives only free/busy time ranges, converted into a list of open appointment times. Event titles, descriptions, locations, attendees, and guest details are never sent to any AI model.
- Gmail — for users who enable the AI email inbox, message content from that user's own synced threads is used to produce a triage label and a suggested reply for that same user to review, edit, or discard.
No Google user data is used to train models, build profiles, serve advertising, or produce any output outside the connecting user's own account.
7. Data retention
We retain personal information for as long as it is needed to provide the Service and service insurance policies, and thereafter as required to comply with legal, regulatory, and recordkeeping obligations, resolve disputes, and enforce agreements. Individuals may request access to or deletion of their information as described below.
8. Security & health information
We use administrative, technical, and organizational safeguards designed to protect information, including encryption in transit, access controls, and restricted internal access limited to authorized agents and staff. Where the Service handles protected health information, we apply safeguards consistent with the Health Insurance Portability and Accountability Act (HIPAA) and enter into Business Associate Agreements with vendors that process such information on our behalf. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing. To exercise a right, or to ask a question about how your information is handled, email team@sakredhealth.com and we will respond in accordance with applicable law.
10. Children
The Service is intended for business use by our authorized agents and staff and is not directed to children under 16. We do not knowingly collect personal information from children.
11. International users
The Service is operated in the United States. If you access it from outside the U.S., you understand your information may be processed in the U.S. and other countries with different data-protection laws.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, through additional notice.
13. Contact us
Questions or requests regarding this Policy or your data:
Sakred Health · team@sakredhealth.com
This document is provided as a general template and does not constitute legal advice. Have counsel review it against Sakred's specific data practices and jurisdictions (e.g., HIPAA, TCPA/A2P 10DLC, state insurance-privacy and CCPA/CPRA requirements) before relying on it.