Who this covers
Lossworth has two kinds of people in it. Customers are the restoration firms and public adjusters who hold an account. The insured is the property owner whose contents appear in a claim — they usually have no account here at all.
For customer account data, Lossworth is the controller. For the contents of a claim, the customer is the controller and Lossworth is a processor acting on their instructions. If you are an insured and want to know what is held about you, ask the firm handling your claim first; we will support them in answering.
What is stored
- Account. Email address, display name, the organisation you belong to, and your role in it. Passwords are never stored — sign-in is by emailed link, Apple or Google. With Apple you may share your address or use a private Apple relay address.
- Claims. Insured name, loss address, carrier, claim and policy numbers, date of loss, peril, and the line items and rooms you enter or correct.
- Photographs. Images uploaded against a claim, in a private storage bucket. They are never public, and links to them are short-lived and signed.
- Exports. A record of each export: when, by whom, how many rows, and the totals. This is an audit trail and is not deleted when a line item changes.
- Billing. Stripe holds the card. Lossworth stores only the customer and subscription identifiers, the plan, and the status.
There is no advertising, no third-party analytics beacon, and no sale or sharing of personal information. Nothing in a claim is used to train a general-purpose model.
Photo analysis
When photo analysis is enabled on your deployment, the images you analyse are sent to Anthropic's API to draft line items. The model is asked only to identify — description, category, quantity, apparent age and condition. It is never asked for and never given authority over a valuation; every figure in the product is computed by Lossworth's own server-side engine. Anthropic does not train on data submitted through its commercial API. If the feature is switched off, no image ever leaves Lossworth's own infrastructure.
Who can see a claim
Only members of the organisation that owns it. Access is enforced in the database by row-level security, not merely in the interface, so a claim cannot be reached by guessing a URL or by calling the API with another firm's identifiers. Remove a member from your crew and their access ends immediately; the claims stay with the firm.
Lossworth staff do not read claim contents as a matter of course. Access for support or incident response is by exception, logged, and only with the customer's request or where required to keep the service running.
Processors we rely on
- Supabase — database, authentication, file storage.
- Vercel — application hosting.
- Stripe — payments and card details.
- Anthropic — photo analysis, when enabled.
How long it is kept
Claim data is kept for as long as the organisation keeps its account, because a claim can be reopened years later. Delete a claim and its rows, photographs and stored files are removed. Delete the account and everything the organisation holds is removed, along with the storage objects behind it; export records are removed with the claim they belong to. Backups age out on their own schedule, within thirty days.
Your choices
You can export a claim as CSV at any time, correct any field in the product, and delete a claim or the whole account yourself from the billing page. Depending on where you live you may also have rights of access, correction, deletion, portability and objection; exercise them by writing to the address below and we will respond within thirty days.
Security
Data is encrypted in transit and at rest. The photo bucket is private. Tenant isolation is enforced by database policy. We do not claim a certification we have not obtained: Lossworth holds no SOC 2 report today, and this page will say so until it does.
Children
Lossworth is a business tool and is not directed at anyone under 18. We do not knowingly collect information from children.
Changes and contact
Material changes will be announced in the product before they take effect. Questions, requests, or a report of something that looks wrong: privacy@lossworth.com.
See also the terms of service.