Eric Brown Insurance
Privacy policy
Effective 7 September 2026
This policy covers the operations tracker at ericbrown.strongsidestrategy.com (the “tool”). The tool is a private, internal application used by Eric Brown Insurance, a final expense and Medicare insurance agency, and by a small number of staff the owner approves. It is not offered to the public and has no customers or consumer users. It is operated on behalf of Eric Brown Insurance by Strongside Strategy.
What the tool collects
The tool holds three kinds of information.
- Account information. When a staff member signs in with Google, the tool receives their name, email address and profile picture from Google. When they sign in with an emailed link, the tool receives their email address. This is used only to identify who is signed in and to record who made a change. Sign-in is limited to addresses the owner has approved.
- Google Calendar events (owner only, optional). The owner can connect one of their Google Calendars from Settings. This asks Google for read-only calendar access (the
calendar.readonlyscope). The tool reads upcoming event titles, times and locations so they can be shown next to the day's tasks. Events are fetched from Google when a page loads, held in memory for at most a couple of minutes, and never written to the database. The refresh token that allows this access is stored encrypted. - Business records entered by staff. Carrier appointments, contract statuses and steps, carrier contacts, notes, links, recurring outreach schedules, projects, the owner's reminder settings and an activity log of changes. Sign-in details for carrier portals are stored encrypted and every reveal is logged. Direct-mail reporting stores counts only. By design the tool holds no names or addresses of policyholders, prospects or mail recipients.
How it is used
- To run the tool: show each person their work, keep carrier and project records, and open recurring tasks on schedule.
- To show the owner's schedule alongside their tasks, which is the only use of Google Calendar data.
- To send email reminders and a daily summary to the addresses the owner chooses in Settings.
- To draft the daily summary and answer questions about the tool's own records using an AI model. Only business records held in the tool are sent for this. Google account details and Google Calendar data are never sent to the AI model.
The tool does not use any data for advertising, does not build profiles, and does not sell or rent data to anyone.
Google user data
The tool's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Google Calendar data is used only to display the owner's events inside the tool. It is not used for any other purpose.
- Google Calendar data is not stored in the database, not transferred to anyone else, and not used to train or improve any model, including the AI features described above.
- No person reads Google user data except the signed-in staff member looking at their own screen, unless the owner asks for support, it is needed for security, or the law requires it.
- Access can be withdrawn at any time by disconnecting the calendar in Settings, which deletes the stored token immediately, or from the owner's Google Account permissions page.
Who else handles data
The tool runs on a small number of service providers, each of which processes data only to provide its service:
- Supabase hosts the database and sign-in, in a data centre in the eastern United States.
- Vercel hosts the application.
- Resend delivers reminder and summary emails.
- Anthropic provides the AI model for the daily summary and questions. It receives business records only, never Google data.
- Google provides sign-in and, if connected, calendar access.
Beyond these providers, data is not shared with any third party.
How it is protected
- All traffic is encrypted in transit.
- Google tokens, carrier portal passwords and calendar feed addresses are encrypted at rest with a key that is not stored in the database.
- Every database table is protected by row-level security, so only approved staff can read records and only the owner can change settings and the sign-in list.
- Reveals of stored sign-in details are recorded in the activity log.
Retention and deletion
- Google Calendar tokens are deleted the moment the owner disconnects the calendar in Settings.
- When the owner removes a staff member from the sign-in list, that person can no longer access the tool. Their account record can be deleted on request.
- Business records are kept for as long as Eric Brown Insurance needs them to run the agency.
- To ask for your data to be corrected or deleted, email services@strongsidestrategy.com.
Changes to this policy
If the tool starts collecting or using data differently, this page will be updated and the effective date above will change. Because the tool is used by a handful of known people, they will also be told directly.
Contact
Questions about this policy or about the tool go to services@strongsidestrategy.com.