Privacy

Privacy Policy

How Keel Benefits Inc. collects, uses, shares, and protects information when you use our benefits enrollment platform and related services.

GDPR · CCPA · State Privacy Laws Consumer health data · WA MHMD · NV SB 370
Effective:August 11, 2026
Last updated:August 11, 2026
Version:v2026-08-11
Questions:corp@keelbenefits.com

1. About this policy and who we are

Keel Benefits Inc. ("Keel," "we," "us," or "our") provides a broker-branded benefits platform. Brokers and employers use Keel to run open enrollment; the employees they sponsor use Keel to compare plans, model costs, ask questions, and submit their elections. This Privacy Policy describes how we handle information when you visit our website at keelbenefits.com (the "Site"), when you use the Keel application at app.keelbenefits.com or at a broker- or employer-branded subdomain of keelbenefits.com (the "Platform"), and when you otherwise interact with Keel.

Keel is based in the United States and our infrastructure is hosted in the United States. References to "you" in this policy include site visitors, broker users, employer administrators, and plan participants — the employees and dependents whose information we process in connection with the Platform.

For most of what we do with plan participant information, we act on the instructions of our customer — the broker or employer that sponsors the benefits program. That customer decides what data reaches us and why. Where you have a question we cannot answer without their direction, we will route it to them.

2. Information we collect

2.1 Information you give us directly

  • Account and contact information: name, work email address, phone number, employer or brokerage name, and job title.
  • Sign-in credentials: depending on how you sign in, a password, a passkey registered to your device, an authenticator-app secret, or a one-time code we send to your email address or phone.
  • Billing contact information: the billing contact and address we need to invoice a customer organization. Keel does not take card payments and does not process payments through the Platform.
  • Sales and support communications: the contents of messages you send us, meetings you book with us, and any files you choose to share.
  • Survey and feedback information: answers to optional surveys and feedback you submit through the Platform.
  • Documents you upload to Claim Advocate: if you use that service, the medical bill you upload and, if you add it, the explanation of benefits your plan sent you. This is consumer health data and Section 3.6 governs it.

2.2 Information we receive about plan participants

When a broker or employer engages Keel, they direct us to receive information about the employees and dependents they sponsor. This usually arrives through a connection to their HR or payroll system, or by direct upload. It may include:

  • Identifiers: legal name, date of birth, home address, personal email address, phone number, employee identifier, and — because benefits administration systems and carriers match people on it — Social Security number.
  • Employment information: hire date, employment status, work location, job classification, occupational class, salary, and pay frequency.
  • Personal characteristics your employer's HR system holds and passes to us, such as gender, ethnicity, marital status, and student or disability status.
  • Household information: dependent names, dates of birth, relationships, and, where a carrier requires it, dependent identifiers.
  • Eligibility and election information: current and historical benefit elections, coverage tiers, contribution and deduction amounts, and effective dates.
  • Your answers to the benefits questionnaire and your conversations with Amanda. Some of this is consumer health data. Section 3 describes it separately, and you should read that section.

2.3 Information from connected systems

  • HR and payroll systems connected through Finch, our HR-connectivity provider. These send us employee, dependent, and compensation records, and — where your employer asks us to — receive benefit deduction amounts back from us after enrollment closes.
  • Plan documents that brokers and employers upload. These are carrier product documents about plans, not records about people.

Keel does not connect to insurance carriers, and we do not receive information from them. Keel does not use an external single sign-on provider, so we receive no profile data from one.

2.4 Information we collect automatically

  • Device and connection data: IP address, browser type and version, operating system, device identifier, language preference, and referring URL.
  • Usage data: pages and screens viewed, features used, links clicked, time spent, and error logs.
  • Cookies: we use a small number of strictly necessary cookies to operate the Platform, plus measured analytics cookies to understand usage. We do not use advertising cookies. See Section 10.5.

3. Consumer health data

This is the section to read if you are an employee using Keel to choose a plan.

Keel does not receive a feed of claims files, explanations of benefits, prescription records, or diagnoses. No carrier, health plan, pharmacy benefit manager, third-party administrator, provider, employer, or broker sends us any of that about you. We do not accept it from them, our customer agreements forbid sending it to us, and we may delete it without notice if it arrives anyway.

There is one exception, and it exists only because you ask for it. If you use Claim Advocate, you can give us a medical bill of your own — and, if you have it, the explanation of benefits your plan sent you for that same care — so that we can read it back to you and check it for errors. That is you handing us a document about your own care, on your own initiative, for a service you chose. It is never a feed from anyone else. Section 3.6 is our account of that data, and it is the only route by which a bill or an explanation of benefits reaches Keel.

Choosing a health plan also means telling us something about your health situation, and some of what you tell us is consumer health data under Washington's My Health My Data Act, Nevada's SB 370, and similar state laws. This section is our account of that data. It applies in addition to the rest of this policy, and it controls where the two conflict.

3.1 What we treat as consumer health data

  • Your answers to the benefits questionnaire. These are the questions Keel asks to size your coverage — for example, whether you have other health coverage, whether you or a spouse are enrolled in a health flexible spending account elsewhere, whether you have used tobacco in the past twelve months, whether someone else claims you as a tax dependent, your household income range, how much of an unexpected bill you could absorb, and how you would want coverage to behave in a low-need year.
  • What you tell Amanda. Anything about your health, your family's health, expected care, or expected costs that you volunteer in a chat, a text message, an email, a voice call, or a video session — for example, "we're expecting a baby in September," "I need orthodontia covered," or "I take a specialty drug." Amanda does not ask you for a diagnosis, and you never have to give one, but what you say is stored in the conversation transcript.
  • The structured summary Amanda keeps about you — a short digest of your open questions, your stated preferences, and any life events you mentioned, so you don't have to repeat yourself when you switch from chat to a call.
  • Anything you upload to Claim Advocate, and what we read out of it. If you use that service, this means the medical bill you upload, the explanation of benefits you upload with it if you have one, the individual charges and codes we extract from them, the findings we produce, and any draft appeal letter we prepare for you. A medical bill names the care you received, so this is the most sensitive category on this list. Section 3.6 describes it in full.

3.2 Where it comes from

All of it comes directly from you, in the Platform — including anything you upload to Claim Advocate, which only you can put there. We do not buy consumer health data, we do not infer it from third-party sources, and we do not receive it from carriers, pharmacies, or providers.

3.3 What we use it for

We use consumer health data to produce benefits guidance for you — plan comparisons, cost estimates, eligibility results, a plan recommendation, and answers to the questions you ask.

If you use Claim Advocate, we use what you upload there for one further purpose, and only that one: to review that bill for you — reading it back in plain language, checking its charges against published coding rules and against the cost-sharing terms of the plan you are enrolled in, and preparing a draft appeal for you to send. We do not use it for the guidance above. Those are the two purposes, and that is the whole list. Specifically:

  • We do not sell consumer health data. We have never sold it and we will not sell it. Under Washington law, selling it would require your signed, specific authorization; we do not seek one.
  • We do not use it for advertising, and we do not share it for cross-context behavioral advertising.
  • We do not use it to train general-purpose AI models, and our AI provider is contractually barred from doing so with what we send.
  • We do not use it to set your premium, to underwrite anything, or to make any decision about your employment. Keel does not underwrite, and your answers do not go to your employer's HR file.
  • We do not use geofencing around health facilities. Keel operates no such technology.

3.4 Who can see it

  • You. Your answers and your conversation history are visible to you in the Platform.
  • Your broker and the employer administrators who run your benefits program. They can see your questionnaire answers and the structured summary described above in the Platform's employee view, because they are the people who support you through enrollment and correct your enrollment when something is wrong. This is a real disclosure and we would rather you know about it than not. They cannot see anything from Claim Advocate — not the bill, not the explanation of benefits, not the charges we extract, not the findings, not the draft appeal, and not the conversation you have with Amanda about it. Section 3.6 states the one count they do see.
  • Our subprocessors, listed in Section 7, strictly to run the features you are using: Anthropic (the language model behind Amanda), Deepgram (speech-to-text when you use the microphone), Vapi (voice calls), Tavus (video sessions), Twilio (SMS delivery), and Amazon Web Services (hosting and encryption). Each is bound by contract to process the data only to provide its service to us.
  • A small number of authorized Keel staff. Our support and engineering staff can reach consumer health data where their job requires it, under access controls and audit logging. For Claim Advocate specifically, a Keel reviewer may open your bill and the findings to check that our analysis was correct — Section 3.6 explains why, and what that reviewer has to do to get in.
  • No one else. We do not share consumer health data with carriers, data brokers, advertisers, or analytics vendors. Keel has no corporate affiliates that receive it.

3.5 Your consent, and how to withdraw it

Where the law requires your consent before we collect consumer health data, we ask for it in the Platform — before the questionnaire or your first conversation with Amanda begins, and separately from any other agreement you are asked to accept.

Not every question is optional, and we would rather be straight with you about which is which:

  • A few questions are required to work out what you are eligible for: whether you have other health coverage, whether you or a spouse have a health flexible spending account at another employer, whether someone else claims you as a tax dependent, and whether you have used tobacco. Tax rules and plan rules turn on these four answers, and our eligibility engine will not produce a result without them. If you would rather not answer them here, we cannot show you an eligibility result, and your broker or employer administrator will need to enroll you another way.
  • The rest are optional. The questions about your household income range, how much of an unexpected bill you could absorb, and how you would want coverage to behave in a low-need year exist only to sharpen your recommendation. Skip them and you can still compare plans and still enroll — the recommendation is simply less tailored.
  • Talking to Amanda is entirely optional. You can compare plans and complete your enrollment without ever starting a conversation.

You may withdraw your consent at any time, and you may ask us to delete your consumer health data. Withdrawal is prospective: it stops further collection and use. Deletion removes your questionnaire answers, your conversation transcripts, and the summary derived from them, and we will pass the deletion request on to the subprocessors listed in Section 3.4 that hold any of it. If you withdraw or delete, Amanda loses the context behind any guidance she has already given, so we may no longer be able to show you a personalized recommendation — your elections and your coverage are unaffected.

To withdraw consent, request deletion, or ask what consumer health data we hold about you, email corp@keelbenefits.com. We will confirm your identity using information we already hold, and we will respond within the timeframe the applicable law requires. We will not discriminate against you for exercising any of these rights.

3.6 Claim Advocate: your medical bills

Claim Advocate is optional and you start it yourself. Nobody enrolls you, your employer does not assign it to you, and your broker does not administer it. If you never open it, nothing in this subsection applies to you.

What we take. The itemized bill you upload; the explanation of benefits your plan sent you for that care, if you choose to add it; the individual charges, codes, dates, and provider details we read out of those documents; the findings we produce; any draft appeal we prepare; and the conversation you have with Amanda about that bill. We ask for the explanation of benefits because it tells us what your plan actually paid, which is what lets us check the bill against your coverage. It is optional and you can use the service without it.

Where it comes from. Only from you. We do not request or accept your bills, claims, or explanations of benefits from your employer, your broker, a carrier, a plan, a third-party administrator, a pharmacy benefit manager, or a provider, and we never will. If a service like this ever needed a feed from one of them, we would have to ask you first, in a separate consent, and this policy would change before it happened.

What we do with it. We review that bill for you and nothing else. We do not use it to produce your plan recommendation, we do not fold it into the summary Amanda keeps about you, we do not use it to set anyone's premium, and we do not use it to train AI models. We do not sell it. We do not send it to your carrier or your provider — every appeal we draft is yours to send.

Who can see it. You. Our AI provider, which processes the document to extract and explain it under a contract that bars any other use. And a small number of authorized Keel staff who review cases to check that our findings were right — that reviewer has to re-verify their identity before the case will open to them, and every open is written to our audit log. That review is how we know whether the service is accurate enough to keep offering. Your employer, your broker, your carrier, and your provider see none of it.

The one thing your employer does see. We may tell your employer how many of their people used Claim Advocate over a period of time. It is a count and nothing more — no names, no bills, no findings, no amounts — and we withhold it when the number is small enough that it could point at an individual. We tell you this because a count is still information about you, even when it carries none of your content.

Your consent. We ask for your explicit permission inside the Platform before any document you upload is analyzed, and nothing you upload reaches our AI provider before you give it. That request is separate from the Terms of Service and from the consent described in Section 3.5, and it tells you about the Keel review described above before you agree to it.

Deleting it. You can delete a case and everything in it from inside the Platform — the documents you uploaded, the extracted charges, the findings, any draft appeal, and the related conversation. We also delete a resolved case automatically on the schedule in Section 8. Deletion here is a real erasure across our systems, not a hidden flag; the one limit is that a copy inside an encrypted backup ages out on the backup's own schedule rather than vanishing the moment you press the button.

4. How we use information

  • To run the Platform. Enrollment, plan comparison, cost modeling, recommendations, eligibility, question answering, and generating the election and export files a broker submits to a benefits administration system.
  • To personalize guidance. To tailor plan comparisons and recommendations to the individual plan participant.
  • To communicate. Service notices, enrollment reminders, security alerts, billing notices, and — where you have opted in — product updates.
  • To support customers. To answer support requests and troubleshoot problems.
  • To protect Keel, our customers, and the public. To detect and prevent fraud, abuse, unauthorized access, and other security or integrity issues.
  • To improve the Platform. To debug, to measure performance, and to build new features. Where we can do that with aggregated or de-identified data, we do.
  • To comply with law. To meet legal obligations, respond to lawful requests, and enforce our agreements.

We do not sell personal information, we do not use plan participant information for advertising, and we do not share it for cross-context behavioral advertising.

5. How we use AI (Amanda)

Amanda is Keel's AI counselor. She talks with plan participants over web chat, SMS, email, voice, and video, and her reasoning is powered by large language models from Anthropic, PBC (Claude).

  • Anthropic is contractually prohibited from using data we send through the Platform to train its models.
  • Keel does not train external models on customer data. Where we evaluate internal models, we use de-identified or synthetic data unless a customer has expressly authorized otherwise.
  • When you speak to Amanda, your audio is transcribed — by Deepgram in the chat window, or by our voice provider Vapi on a phone call. We store the transcript, not the audio.
  • Video sessions are not recorded. Amanda's video enrollment sessions run with recording disabled at the provider. We keep the text transcript of the conversation.
  • Conversation transcripts are stored with the message content encrypted, and they are purged on the schedule in Section 8.
  • Amanda's recommendations are decision support. They are based on the data your organization shares with us and on what you tell her, they can be wrong, and they do not replace the judgment of your broker or a licensed professional. You can always elect a plan other than the one she recommends.
  • If you use Claim Advocate, Amanda reads your bill and explains it, and the checks she runs against published coding rules and your plan's cost-sharing terms are decision support in the same way. A finding can be wrong. It is not medical, legal, or billing advice, it is not a coverage determination, and it is no guarantee that a bill contains an error or that an appeal will change what you owe. You decide what to send and when.

6. How we share information

6.1 With your broker, your employer, and the systems they direct us to

Keel captures elections; it does not transmit them to carriers. At the close of enrollment, Keel produces a submission report and per-carrier export files. Your broker and an employer administrator review and approve them, and the broker uploads them into the employer's benefits administration system — most often Employee Navigator — or a carrier's own portal. That system, not Keel, transmits enrollment to the carriers and drives payroll deductions.

Keel has no direct connection to any insurance carrier. We do not send enrollment, eligibility, or premium files to carriers, and we do not submit evidence-of-insurability applications on your behalf.

Where your employer asks us to, we write benefit deduction amounts back to their payroll system through Finch.

Nothing from Claim Advocate is shared under this section. A bill you upload, the findings from it, and any draft appeal never appear in a submission report, an export file, a payroll write-back, or anything else your broker or employer receives. Section 3.6 governs that data, and it controls over this section.

6.2 With our subprocessors

We engage a small number of vendors to operate the Platform on our behalf. They are bound by contracts requiring them to protect information consistent with this policy and to use it only to provide their service to us. The current list is in Section 7.

6.3 For legal reasons

We may disclose information if we believe in good faith that doing so is necessary to comply with applicable law, regulation, legal process, or a lawful governmental request; to enforce our agreements; or to detect, prevent, or address fraud, security, or technical issues. Where law permits, we will give a customer notice and an opportunity to seek a protective order before responding to compulsory legal process directed at that customer's data.

6.4 In a business transaction

If Keel is involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of service to another provider, information may be transferred as part of that transaction. Any acquirer remains bound by the commitments in this policy — including those in Section 3 — for information collected before the transfer, and we will use commercially reasonable efforts to notify customers of any material change in how their information is handled.

6.5 With your consent

We will share information for any other purpose we disclose to you at the time we collect it, or with your consent.

7. Subprocessors

The list below identifies every subprocessor that may process personal information on our behalf as of the effective date of this policy. We update this list when we add or remove a subprocessor, and we give customers advance notice of a new subprocessor as our customer agreements require.

SubprocessorFunctionLocation
Amazon Web Services, Inc.Cloud infrastructure, database, file storage, encryption key managementUnited States
Amazon SES (Amazon Web Services, Inc.)Email delivery and receipt — our only email transportUnited States
Anthropic, PBCLarge language model reasoning behind Amanda (Claude)United States
Deepgram, Inc.Speech-to-text for the in-app microphoneUnited States
Vapi, Inc.Voice agent orchestration for phone and web voice callsUnited States
Tavus, Inc.Video avatar for Amanda's video enrollment sessionsUnited States
Twilio Inc.SMS delivery and phone numbers — text messages and login codes onlyUnited States
Finch (Tilt 49, Inc.)HR and payroll connectivity — census sync and deduction write-backUnited States
Cloudflare, Inc.DNS for customer subdomains onlyUnited States
Functional Software, Inc. (Sentry)Error monitoring — enabled in our pre-release environments only, with sensitive fields scrubbed before sendUnited States

Customers can request the current list, with the processing detail their agreements require, at corp@keelbenefits.com.

8. Data retention

We state below what our systems actually do. Where we have not yet fixed a retention period, we say so rather than name one we do not enforce.

  • Conversations with Amanda: the full transcript is purged seven (7) days after the last message in that conversation, once its content has been folded into the encrypted summary described in Section 3.1. Every purge is recorded in our audit log. The summary is kept for as long as you are an active participant in your employer's benefits program, so Amanda has continuity across channels; you can have it deleted under Section 3.5.
  • Video sessions: not recorded. There is no video to retain.
  • Raw call audio held by our voice provider: we have not yet fixed this retention setting with the provider, and we will not name a period we do not enforce. The Keel platform stores the transcript, not the audio. Ask us at the contact address in Section 14 for the current configuration.
  • Claim Advocate cases: the documents you uploaded, the charges we extracted, the findings, and any draft appeal are purged ninety (90) days after the case is resolved, together with the raw files in storage. Every purge is recorded in our audit log. You do not have to wait for that — you can delete a case yourself at any time from inside the Platform, as described in Section 3.6.
  • Census, eligibility, and election records: retained while your employer's benefits program is active on the Platform. When a customer leaves Keel, their tenant is archived, held for a thirty (30) day cooling-off period, and then permanently purged — database records and stored files together. The purge is irreversible.
  • Business contact, billing, and marketing records: retained for as long as the relationship is active and for the period our tax and audit obligations require. We have not published a single fixed window for these records.
  • Aggregated and de-identified data: may be retained indefinitely, provided it cannot reasonably be re-associated with an individual.

Where a specific record must be kept longer to comply with law or to resolve a dispute, we keep it for that purpose and no other.

9. Security

We would rather describe our security accurately than impressively. Here is where it stands.

  • In transit: traffic to and from the Platform is encrypted with TLS.
  • At rest: our databases and file storage are encrypted at rest.
  • Field-level encryption: on top of that, the most sensitive identifiers get a second layer, encrypted individually under a managed key: Social Security number, date of birth, personal email address, home address, and phone number — for employees and dependents alike. The content of AI conversation transcripts and the structured summary described in Section 3.1 are also encrypted this way.
  • What is not field-level encrypted: your benefits questionnaire answers are not currently under field-level encryption. They sit in our encrypted-at-rest database, protected by tenant isolation and access controls, but they do not yet carry the extra layer the identifiers above carry. We are closing that gap, and we would rather tell you now than imply a protection that is not there.
  • Access: access to production data is limited to the personnel who need it, requires multi-factor authentication, and is logged.
  • Tenant isolation: each customer's data is partitioned, and the AI retrieval layer is partitioned per customer as well, so one customer's data cannot surface in another's conversation.
  • Logging: sensitive fields are scrubbed before anything reaches our logs or our error monitoring.
  • Incident response: we maintain an incident response process and will notify affected customers and individuals as the applicable law and our customer agreements require.

No security measure is perfect. If you believe your account, or any account at Keel, may have been compromised, contact corp@keelbenefits.com without delay.

10. Your privacy rights and choices

10.1 If you are an employee or dependent

Your employer or broker decides what information about you reaches Keel and why. You can exercise your privacy rights through them, and they may direct us to act. You can also come to us directly using the contact details in Section 14 — we will verify who you are and either handle the request or route it to your employer or broker and support them in answering it.

For your questionnaire answers and your conversations with Amanda, you can come straight to us: see Section 3.5.

10.2 California (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to ask us to (i) disclose the categories and specific pieces of personal information we hold about you, (ii) delete personal information we have collected, (iii) correct inaccurate personal information, and (iv) limit the use and disclosure of sensitive personal information. You have the right not to be discriminated against for exercising these rights.

We do not sell personal information, we do not share personal information for cross-context behavioral advertising, and we do not knowingly process the personal information of consumers under sixteen (16) years of age.

To exercise a right, email corp@keelbenefits.com. We will verify your request against information we already hold and may need to ask for more to confirm your identity. You may use an authorized agent, who must provide written authorization we can verify.

10.3 Washington, Nevada, and other US states

Washington residents (My Health My Data Act) and Nevada residents (SB 370) have specific rights in their consumer health data — to know what we collect and who receives it, to withdraw consent, and to have it deleted. Section 3 is written to serve those rights; Section 3.5 tells you how to use them. Washington's law also gives residents a private right of action.

Residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with comprehensive privacy laws have rights similar to those in Section 10.2. To exercise them, follow the process there.

10.4 European Economic Area, the United Kingdom, and Switzerland

If you are in the EEA, the UK, or Switzerland and the General Data Protection Regulation, UK GDPR, or the Swiss Federal Act on Data Protection applies to our processing, you have the right to access, rectify, erase, restrict, port, or object to our processing of your personal data, and you may lodge a complaint with your local supervisory authority. Where Keel acts as a processor for a customer, direct your request to that customer first. Where Keel acts as a controller, contact us at corp@keelbenefits.com.

10.5 Cookie choices

Most browsers let you control cookies in their settings. If you block cookies, some Platform features may not work as expected. We do not respond to "Do Not Track" browser signals, because no industry standard for them has been established.

10.6 Marketing email choices

You can opt out of marketing email by following the unsubscribe instructions in any marketing message, or by contacting corp@keelbenefits.com. We will still send the transactional and service messages needed to operate the Platform and run your enrollment.

11. International data transfers

Keel is based in the United States and our infrastructure is hosted in the United States. If you access the Platform from outside the United States, your information will be transferred to, stored in, and processed in the United States. Where we transfer personal data from the EEA, the UK, or Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses, the UK Addendum, and the Swiss Addendum, as applicable, supported by the additional safeguards described in our security documentation (available on request).

12. Children

The Platform is not directed to children under sixteen (16), and we do not knowingly collect personal information directly from them. Information about a dependent child — a name, a date of birth, a relationship — reaches us from the employer or broker so the child can be enrolled in coverage, and is handled under our agreement with that customer and under this policy.

13. Changes to this policy

We may update this policy from time to time. Each version carries a version string (this one is v2026-08-11) and a "Last updated" date. If we make a material change — in particular, any change to Section 3 — we will post the updated policy at this URL, update the version, and notify customers in writing or through the Platform. Where the law requires your fresh consent for a new use of consumer health data, we will ask for it before that use begins, not by quietly amending this page.

14. How to contact us

Questions about this policy, or about how we handle your information:

Keel Benefits Inc.
corp@keelbenefits.com