Legal

Privacy Policy

This policy describes how Nemus Insights collects, uses, and shares information when you visit our websites or use the employer, broker, and member portals.

Last updated: September 3, 2026

Who this covers

Nemus Insights provides a health and benefits platform for self-funded employers, their brokers, and the employees and dependents those employers enroll. This policy applies to:

  • Visitors to nemusinsights.com and related marketing pages
  • Employer and broker administrators who sign in to manage a book or a plan
  • Members who use the employee portal, chat, screenings, and related tools

Information we collect

We collect the following categories of information:

  • Account data. Name, email, role, company association, and authentication credentials needed to sign you in.
  • Plan and claims data. Eligibility rosters, medical and pharmacy claims, plan documents, and related records that an employer or their TPA provides so we can operate the service. This can include protected health information (PHI).
  • Chat and session data. Questions you ask the health advocate, research chat, and operational agents, plus the scoped context our backend attaches to a turn.
  • Device and usage data. Browser type, pages viewed, approximate location from IP, and logs we use for security and reliability.
  • Cookies. Session and preference cookies required to keep you signed in and to run the site. We do not use advertising cookies to sell your data.

How we use it

  • Provide, maintain, and secure the platform
  • Authenticate users and enforce role-based access
  • Show employers and brokers population analytics — not an employee's private chat
  • Answer member questions about their own coverage and claims
  • Detect abuse, debug outages, and improve the product
  • Respond to support and privacy requests

How we share information

We do not sell personal information. We share data only as needed to run the service:

  • Xano is our HIPAA-compliant backend and system of record.
  • Microsoft Azure hosts the research and customer-facing conversation agents.
  • Hosting, email, and similar vendors that process data on our instructions under contract.
  • When the law requires it, or to protect the rights, safety, and security of Nemus Insights, our customers, or others.

Protected health information

PHI stays in our HIPAA-compliant backend. Agents receive only the context that backend authorizes for that session. Research chat does not receive claims or identifiers. For how that split works, see our HIPAA Compliance page. A signed Business Associate Agreement, not this policy, is what governs PHI between Nemus Insights and a covered customer.

Retention and security

We keep account and plan data for as long as the customer relationship requires and as needed for legal, security, and accounting records. We use encryption in transit and at rest, role-scoped APIs, and access controls. No method of transmission or storage is perfectly secure.

Your choices

Depending on your role and applicable law, you may request access to, correction of, or deletion of personal information we hold about you. Members typically work through their employer for roster and claims corrections. Administrators can update much of their account data in the product.

To make a request, use our contact form. We may need to verify your identity and your relationship to the employer before we act.

Children

The marketing site and portals are not directed at children under 13. We do not knowingly collect personal information from children under 13 through the public site. Dependent records that an employer uploads are handled as part of that customer's plan data under our customer agreement and, where applicable, a BAA.

Changes

We may update this policy as the product or the law changes. The “Last updated” date at the top will change when we do. Material changes will be posted on this page.

Contact

Privacy questions and requests go through Contact us. This page is a description of our practices. It is not legal advice and does not replace a signed customer agreement or BAA.