Formevra — Secure Client Intake & Form Exchange

Privacy Policy

Last updated: July 12, 2026

1. Overview

Formevra ("the Service") is a secure client intake and form exchange platform used by insurance agents to request sensitive billing details from clients. This Privacy Policy describes how we collect, use, protect, and dispose of your information when you use the Service.

2. Zero-Persistence Data Model

Your payment details are never permanently stored. Routing and account numbers are encrypted and automatically purged as soon as they are successfully uploaded to your carrier's application.

We employ a Zero-Persistence architecture. Sensitive payment data (bank routing numbers and account numbers) is encrypted using AES-256-GCM encryption immediately upon submission and stored only as an ephemeral, encrypted blob. The encrypted data is permanently purged from our systems the moment the assigned agent reveals it for use in your insurance application. No raw account or routing numbers are retained in any database, log, or backup.

3. Information We Collect

  • Identity verification: Your first name, last name, and date of birth (used only to verify your identity before granting access to the form).
  • Billing information: Your billing phone number, billing address, and the name on your bank account.
  • Payment details: Bank name, account type, routing number, and account number — collected temporarily and encrypted, then purged (see Section 2).
  • Usage metadata: IP addresses and timestamps are logged for security audit purposes only. No payment details are ever included in audit logs.

4. How Your Information Is Used

Your information is used solely for the purpose of processing your health insurance application. Specifically:

  • Identity verification to prevent unauthorized access to the payment form.
  • Securely transmitting payment details to your assigned insurance agent.
  • Entering payment information into your carrier's insurance application.
  • Security auditing and compliance record-keeping (no sensitive data included).

We never sell, rent, or share your information with third parties for marketing purposes.

5. Data Security

AES-256-GCM Encryption

Encryption for all sensitive data in transit and at rest.

MFA-Gated Access

Agents must verify via email-based MFA before viewing any payment details.

Automatic Purging

Data is purged immediately upon agent viewing — no retention.

Immutable Audit Logs

All access attempts are logged with IP, timestamp, and agent identity.

Security measures include brute-force protection (automatic lockout after repeated failed verification attempts), real-time security alerting to administrators, and role-based access controls ensuring only the assigned agent can access your submission.

6. Data Retention

Payment details (routing and account numbers): Purged immediately upon agent viewing. Zero retention.

Non-sensitive metadata (names, phone, address, bank name): Retained for the duration of the active request and for compliance audit purposes, then may be deleted at the agent's or administrator's discretion.

Audit logs: Retained indefinitely for security and compliance purposes. Audit logs never contain full payment details.

7. Your Rights

You have the right to request information about how your data is being handled, request deletion of non-essential records, and withdraw consent for data processing at any time by contacting your insurance agent. If you believe your data has been mishandled, you may also contact the portal administrator.

8. Contact

For questions about this Privacy Policy or your data, please contact your assigned insurance agent or theFormevra administrator.