Legal
Privacy Policy
This policy describes how Nemus Insights collects, uses, and shares information when you visit our websites or use the employer, broker, and member portals.
Last updated: September 3, 2026
Who this covers
Nemus Insights provides a health and benefits platform for self-funded employers, their brokers, and the employees and dependents those employers enroll. This policy applies to:
- Visitors to nemusinsights.com and related marketing pages
- Employer and broker administrators who sign in to manage a book or a plan
- Members who use the employee portal, chat, screenings, and related tools
Information we collect
We collect the following categories of information:
- Account data. Name, email, role, company association, and authentication credentials needed to sign you in.
- Plan and claims data. Eligibility rosters, medical and pharmacy claims, plan documents, and related records that an employer or their TPA provides so we can operate the service. This can include protected health information (PHI).
- Chat and session data. Questions you ask the health advocate, research chat, and operational agents, plus the scoped context our backend attaches to a turn.
- Device and usage data. Browser type, pages viewed, approximate location from IP, and logs we use for security and reliability.
- Cookies. Session and preference cookies required to keep you signed in and to run the site. We do not use advertising cookies to sell your data.
How we use it
- Provide, maintain, and secure the platform
- Authenticate users and enforce role-based access
- Show employers and brokers population analytics — not an employee's private chat
- Answer member questions about their own coverage and claims
- Detect abuse, debug outages, and improve the product
- Respond to support and privacy requests
How we share information
We do not sell personal information. We share data only as needed to run the service:
- Xano is our HIPAA-compliant backend and system of record.
- Microsoft Azure hosts the research and customer-facing conversation agents.
- Hosting, email, and similar vendors that process data on our instructions under contract.
- When the law requires it, or to protect the rights, safety, and security of Nemus Insights, our customers, or others.
Protected health information
PHI stays in our HIPAA-compliant backend. Agents receive only the context that backend authorizes for that session. Research chat does not receive claims or identifiers. For how that split works, see our HIPAA Compliance page. A signed Business Associate Agreement, not this policy, is what governs PHI between Nemus Insights and a covered customer.
Retention and security
We keep account and plan data for as long as the customer relationship requires and as needed for legal, security, and accounting records. We use encryption in transit and at rest, role-scoped APIs, and access controls. No method of transmission or storage is perfectly secure.
Your choices
Depending on your role and applicable law, you may request access to, correction of, or deletion of personal information we hold about you. Members typically work through their employer for roster and claims corrections. Administrators can update much of their account data in the product.
To make a request, use our contact form. We may need to verify your identity and your relationship to the employer before we act.
Children
The marketing site and portals are not directed at children under 13. We do not knowingly collect personal information from children under 13 through the public site. Dependent records that an employer uploads are handled as part of that customer's plan data under our customer agreement and, where applicable, a BAA.
Changes
We may update this policy as the product or the law changes. The “Last updated” date at the top will change when we do. Material changes will be posted on this page.
Contact
Privacy questions and requests go through Contact us. This page is a description of our practices. It is not legal advice and does not replace a signed customer agreement or BAA.