Brella

[ PRIVACY POLICY ]

What we take, and why we take it.

A plain reading of every piece of information Brella collects, where it goes, and how long it stays. No hedging, and nothing described more flatteringly than it works.

The short version

  • There is no analytics script, advertising pixel or third-party tracker anywhere on this site. You can confirm that in your browser’s network tab.

  • We never sell, rent or trade personal information, and we do not build advertising profiles.

  • We collect what you type into our forms, because we cannot get you priced on a risk nobody has described to us.

  • We record the IP address and browser of public form submissions so a real enquiry can be told apart from a fake one — and we erase it automatically after 90 days.

  • AI helps us draft and read. It never sends anything to an insurance carrier, and it never decides anything about your policy. A person does that.

  • Want a copy of your data, or want it gone? Email hello@brellapartners.com and a human will handle it.

This summary is here so the document gets read. It is a summary — the full text below is what governs.

Effective July 30, 2026

01

Who we are

Brella Partners LLC is a commercial insurance brokerage based in Houston, Texas, licensed by the Texas Department of Insurance. This policy covers brellapartners.com, the onboarding wizard, Brella OS (the platform our agency clients run their book on) and the policyholder portal.

Where you are a customer of an insurance agency that uses Brella OS, that agency decides what to collect from you and why; we hold and process that information on their behalf, and this policy describes how we do it.

Questions about anything below go to hello@brellapartners.com. A person reads that inbox.

02

What we collect, and why

Almost everything we hold is something you typed into a form, because you wanted a quote. Insurance is priced on specifics, so the specifics are what we ask for. Here is the whole list, and the honest reason for each.

What we take

Why we take it

Your business — name, industry, years trading, headcount, revenue band

These are the inputs underwriters actually rate on. A submission without them is a guess, and a guess gets you a worse price.

Where you operate — primary state, any additional states, whether you own or lease your location

Insurance is regulated state by state, and a property form for an owner is a different form from a tenant’s. This decides which markets can even quote you.

Your current program — existing coverages, current carrier, current premium, renewal date

We cannot tell you whether you are being overcharged without knowing what you pay today. The renewal date tells us when we have to move.

What you want covered, and your notes about it

Tells us which markets to approach and what to argue for. Free-text notes are read by a person on our team.

Your contact details — name, email, phone, best time to reach you, how you found us

So we can send you the answer. "How you found us" tells us which channels are worth keeping; it is never used to target you with advertising.

Property details in onboarding — address, year built, construction, roof, occupancy, values

These are the literal rating inputs on a commercial property policy. Some of them we pre-fill for you from public and licensed property data so you do not have to look them up.

Documents you upload — loss runs, current policies, financials, and anything else you attach

They go onto your file so an underwriter sees a real submission rather than a form with blanks. Stored in access-controlled storage, not on the public web.

The IP address and browser of a public form submission

So a genuine enquiry can be told apart from a fake or duplicate one. It is read from the request on our server — you cannot set it, and neither can anyone pretending to be you. It is erased automatically after 90 days.

Account credentials, if you have a Brella OS or portal login

Your email identifies the account. Your password is stored only as a scrypt hash — we cannot read it, and we cannot tell you what it is if you forget it.

Blog post view counts

A single number on each post that goes up by one. It is not linked to you, and we do not store who read what.

03

What we don’t do

Most privacy policies are long because of everything the company is doing to you. This section is the useful one.

  • We do not sell, rent or trade personal information. There is no arrangement under which anyone pays us for data about you.

  • We do not run analytics or advertising trackers. There is no Google Analytics, no Meta pixel, no Segment, Mixpanel, PostHog, Amplitude or Hotjar on this site — no script of that kind is loaded at all.

  • We do not build advertising or behavioural profiles, and we do not track you across other websites.

  • We do not use your data to train anybody’s AI model. See the AI section below for what we do send, and to whom.

  • We do not email you marketing you did not ask for. If you filled in a quote form, expect a human to reply about that quote.

04

Cookies and what’s stored in your browser

Four things, and you can see all of them in your browser’s developer tools. None of them are advertising or analytics cookies.

Stored item

What it does

chakra-ui-color-mode

Remembers whether you chose light or dark. Written only when you use the toggle.

brella-onboarding-v1

Saves your place in the onboarding wizard, so refreshing the page does not throw away twenty properties of typing. It lives in your browser, not on our servers, until you actually submit.

brella_admin_token and brella_portal_token

Your signed-in session for Brella OS and for the policyholder portal. Signing out removes them.

A session cookie from our authentication system

Set when you sign in, so you stay signed in. Strictly necessary for the thing you just asked to do.

Why there’s no cookie banner

Every item above is either something you asked for (staying signed in, not losing your work) or a preference you set yourself. We set nothing for advertising, nothing for analytics, and nothing that follows you to another site — so there is no tracking consent for a banner to collect.

05

One thing your browser sends to Google

The typefaces on this site are served by Google Fonts. That means your browser fetches them from Google’s servers directly, and Google therefore sees your IP address and which page requested them. We do not send Google anything else, and we get nothing back about you.

We are telling you because it is the one third-party request this site makes from your browser, and most sites that use Google Fonts never mention it. Self-hosting the fonts would remove it, and it is on our list.

06

Who else touches your data

We are a small company standing on other people’s infrastructure. These are the services that can see some part of your data in order to do their job. We do not pay any of them for data about you, and none of them are advertising networks.

Provider

What they do, and what they see

Vercel

Hosting, the API, file storage for uploaded documents, and scheduled jobs. Anything you send to us passes through their infrastructure.

Neon

The Postgres database. Everything we store at rest lives here.

Resend

Sends transactional email — invitations, password resets, notifications. Sees the recipient address and the contents of that message.

Anthropic

The AI features. Sees only the specific text we send for one task, described in the next section.

RealEstateAPI

Address autocomplete and property pre-fill in the onboarding wizard. Sees the address you are typing.

Esri / ArcGIS

Location risk data for a property. Sees the property location.

FEMA, the US Census Bureau and geoplatform.gov

Flood and hazard data, geocoding, and aerial imagery for a property. Sees the property location.

Google or Microsoft

Only if you choose "Sign in with Google" or "Sign in with Microsoft" — and only the identity you approve at their screen. If you sign in with an email and password, neither is involved.

And the insurance markets themselves

We are a broker. To get you a quote we send your submission to insurance carriers, wholesalers and managing general agents — that is the entire job you hired us for. What those markets do with a submission is governed by their own terms, not ours. If you would rather we did not approach a particular market, tell us and we won’t.

07

Exactly how AI is used

AI is genuinely useful in this business and genuinely oversold, so here is the specific version rather than the brochure one.

  • The API key lives only on our server. The model is never called from your browser, and your data is never handed to it client-side.

  • What it does: suggests a match when your answer to a dropdown is close but not exact; explains what a question in the wizard is actually asking; drafts questionnaires for an agency; reads an uploaded document to check it looks like the thing it was uploaded for; drafts the narrative for a mid-term policy change; and answers questions about your own file, read-only.

  • What it never does: it never sends anything to an insurance carrier. It never binds, changes or cancels coverage. It never makes a decision about your policy on its own. Every one of those is a person’s action.

  • Document checking is advisory. When the model is not confident, it returns nothing rather than guessing — a wrong confident answer is worse than no answer.

  • Under our AI provider’s API terms, what we send is not used to train their models.

  • If the AI is unavailable or unconfigured, the feature switches off and says so. It never quietly falls back to a guess.

The rule behind all of it

AI drafts; a human sends. Nothing generated by a model reaches a carrier, a customer or a policy without a person reading it and choosing to act.

08

How your data is kept apart from everyone else’s

Brella OS is used by many insurance agencies, and each of them has customers. Keeping one agency’s book invisible to another is the single most important thing the software does.

Separation is enforced in software: every record carries the id of the organisation that owns it, every database query is scoped to the organisation on your session, and a session for one workspace cannot render another’s — it is refused rather than filtered.

Said plainly

That is logical separation inside a shared database, not a separate database per customer. We are telling you which one it is, because "your data is fully isolated" is a sentence that gets written a lot and means very different things.

09

Security, and what we are not claiming

  • Passwords are stored as scrypt hashes. We cannot read them, recover them, or tell them to you.

  • Sessions are cryptographically signed and expire on their own.

  • Third-party API keys stay on the server and are never shipped to your browser.

  • Uploaded documents go to access-controlled storage rather than a public URL.

  • Everything is served over HTTPS.

  • Public forms are rate-limited, so an automated client cannot sit there guessing at reference codes.

What we haven’t got

We have not completed a SOC 2, ISO 27001 or any comparable third-party security audit, and we are not going to imply otherwise by listing security features and letting you assume. No system is perfectly secure. If we complete an audit, this paragraph will say so and will name it.

10

How long we keep things

What

How long

The IP address and browser on a public submission

90 days, then blanked automatically by a job that runs every day. This is enforced in code, not by someone remembering.

Your quote, application, policy file and its documents

For as long as we are your broker, and afterwards for as long as insurance recordkeeping obligations require us to be able to reconstruct what was placed, for whom, and when.

Your account

Until you or your organisation’s owner closes it, or you ask us to delete it.

The honest caveat

The 90-day purge above is the only automatic deletion we currently run. Everything else is deleted on request or by manual review — there is no background job quietly ageing out your file, and we would rather tell you that than let the phrase "retention policy" do work it hasn’t earned.

11

Your choices, and how to use them

Depending on where you live, you may have the right to see the personal information we hold about you, correct it, delete it, get a portable copy, or object to some uses. We will honour those requests regardless of whether the law where you live compels us to.

  • Email hello@brellapartners.com and say what you want. We will ask you to verify who you are first, because handing your file to somebody claiming to be you is the worse failure.

  • We do not sell personal information, so there is no "do not sell" opt-out to operate — there is nothing to opt out of.

  • If we cannot delete something because an insurance recordkeeping obligation requires us to keep it, we will tell you which record and why, rather than refusing in the abstract.

Not yet self-service

There is no export or delete button in the product today. It is a real email to a real person, usually answered within a few business days. When we build the button, this section will change.

12

Children

Brella is a service for businesses and the people who run them. It is not directed at children, we do not knowingly collect information from anyone under 16, and if we discover we have, we will delete it.

13

Changes to this policy

When this policy changes we update the effective date at the top. If a change materially affects what we collect or who we share it with, we will email account holders rather than relying on you to re-read the page.

14

Contact

Brella Partners LLC, Houston, Texas. Email hello@brellapartners.com for anything in this policy, including a request to see or delete your data.

Anything here that reads as evasive is a bug — tell us and we’ll fix the wording. hello@brellapartners.com

Read the Terms of Service