About this policy
Max Thruput LLC, operating as MaxThruput ("we," "us," or "our"), provides software that helps commercial insurance teams organize incoming information, review documents, and manage follow-up. This policy covers our public website and MaxThruput Renewal Intake, our connected email and document workflow application. Questions or privacy requests can be sent to info@maxthruput.com.
Access to the application is currently limited to authorized demonstrations and pilots. Public website examples are illustrative. A separate agreement may govern a customer's use of the service and our processing of information on that customer's behalf.
Information we receive
- Contact information: your name, business contact details, and information you choose to include when contacting us.
- Workflow information: documents and email you submit or authorize us to process, including sender and recipient addresses, subject lines, message content, attachments, thread identifiers, timestamps, and extracted fields. These materials may contain personal or business information.
- Connected-account information: your authorized email address, granted permissions, and access and refresh tokens used to maintain the connection. For an enabled Microsoft 365 connection, this can also include your organization identifier and the account, mailbox, site, or file identifiers needed for the authorized workflow. We do not collect your Google or Microsoft password.
- Operational information: review decisions, processing status, audit events, error information, and technical connection information used to operate and protect the service.
Our website hosting provider may process IP addresses, browser and device information, requested URLs, and security logs when you visit. The website's contact links open your email application; they do not upload documents to MaxThruput.
Gmail access and how we use it
When you connect Gmail, Google asks you to authorize access. The current integration requests permission to read Gmail messages and settings and to send email on your behalf. The read permission is broader than the messages selected by our configured workflow: we use configured mailbox, sender, subject, and thread filters to select relevant work. We use account details to verify the connected mailbox; message content and attachments to organize submissions, extract fields, and associate replies with work; and message identifiers and timestamps to track processing and avoid duplicate actions.
Sending is a separate capability used for authorized, human-reviewed workflow messages. Connecting a mailbox does not itself send email. A stored refresh token allows the application to renew its connection without asking you to sign in for every poll. Google or you may revoke that access.
Microsoft 365 email and documents
If a Microsoft 365 connection is offered, enabled for your client environment, and authorized by you or your organization, the same privacy safeguards in this policy apply to the information processed through that connection. This policy does not itself enable a connection or promise that a particular Microsoft 365 feature is available.
The agreed workflow may include Outlook or Exchange Online email and attachments, or selected documents from OneDrive or SharePoint, including Word, Excel, PowerPoint, and PDF files. Information processed may include message content, sender and recipient details, subjects, timestamps, attachments, file content, filenames, authors, modification dates, and identifiers used to associate the information with the correct account or work item. We use this information to organize work, extract and review fields, prepare authorized outputs, and track relevant activity.
The connection's permissions and approved resource scope must be established before activation. Access may operate on behalf of a signed-in user or through organization-approved application access, depending on the agreed setup. Microsoft or your organization's administrator controls the relevant consent and access settings. We request access needed for the agreed features; email access does not itself authorize access to OneDrive or SharePoint. Broader provider permissions, where needed, must be disclosed during setup and constrained through the approved resource and workflow configuration.
Sending email, changing source documents, or writing files back to Microsoft 365 requires a separately enabled, authorized workflow and the applicable review controls. Merely connecting an account does not authorize these actions. Information may be processed by our hosting, document-extraction, or AI service providers for the authorized features described below. We do not sell Microsoft 365 user data, use it for advertising or data brokerage, or use it to train generalized AI or machine learning models. Staff access is limited to the specific access you authorize, necessary security investigations, or legal requirements.
Document processing and AI
We use information to provide the requested workflow, prepare structured fields and reviewable drafts, support users, and maintain security and reliability. Processing can use deterministic rules and, where enabled for the workflow, Amazon Textract for document extraction and AI-assisted interpretation for bounded review tasks. Relevant content is processed by the service required for the enabled feature. Outputs can be incomplete or wrong and require human review.
We do not use Google user data to train or develop generalized AI or machine learning models. We do not sell Google user data or use it for advertising, ad targeting, data brokerage, or creditworthiness decisions.
Providers, sharing, and human access
We use Cloudflare to deliver and protect the public website, Google to provide the Gmail connection, Microsoft for any enabled Microsoft 365 connection, and Amazon Web Services to host and process application information. Service providers may process information as needed to provide the features you authorize and operate and secure the service. Workflow information is made available to the authorized users working on that workflow. Outgoing email or exports disclose the selected information to the recipients you authorize.
Our personnel do not read your Google user data unless you affirmatively agree to their viewing specific messages, documents, or other data; access is necessary for security purposes, such as investigating a bug or abuse; access is required by applicable law; or the information is aggregated and used for internal operations as permitted by applicable law and Google's Limited Use requirements. Routine support, debugging, or product improvement does not by itself authorize access to individual messages or documents outside those exceptions.
We do not transfer Google user data for unrelated purposes. Transfers in a merger or asset sale require your prior explicit consent where Google's policy requires it.
MaxThruput's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. These restrictions also apply to information derived from Google user data.
Storage, retention, and security
Application information is stored in our AWS environment, currently in the United States. Hosting and communications providers may process technical information in other locations. We use access controls, encrypted connections, and managed storage and credential services to protect information. No system can guarantee absolute security.
Retention is determined by the category of information, the authorized purpose, the applicable demonstration or pilot scope, and any contractual or legal requirements. There is no single automatic deletion period for all records:
- Workflow records: source email copies, attachments, extracted fields, review decisions, and exports are retained for the authorized workflow and applicable recordkeeping needs. Closing a task, ending a demonstration, or reaching an extraction or review expiry does not itself delete these records.
- Connection credentials: stored authorization tokens and other connection credentials support the authorized email or document connection. Revocation is subject to the provider's token and session controls; stored credential copies require a separate removal step.
- Audit, security, and backup records: these can have different retention periods from active workflow records. An applicable legal hold or necessary security or audit retention may delay deletion. Backup copies may remain until the applicable backup retention period ends.
For a client pilot involving real information, retention and deletion requirements must be established in the pilot scope before that information is submitted. Connecting a mailbox does not authorize indefinite retention for unrelated purposes.
Your choices and requests
You can stop granting future Google access by removing MaxThruput from your Google Account connections. Revocation stops future authorized access; it does not automatically erase information already processed. Contact info@maxthruput.com to request disconnection, deletion of stored credentials or workflow information, or access to or correction of your information. We may verify your identity and authority before acting. If an organization supplied your information, we may coordinate the request with that organization.
For an enabled Microsoft 365 connection, access can be revoked through the applicable Microsoft account or organization settings; organization-managed permissions may require action by your Microsoft 365 administrator. You can also contact us to request that MaxThruput stop the connection. Revocation and disconnection do not automatically delete copies already processed or guarantee instant invalidation of every existing provider session.
Deletion is handled through a reviewed request. Identify the account or workflow concerned and whether you want the connection removed, stored information deleted, or both. We assess the relevant source copies, derived fields, exports, and credentials, along with any retention requirements. We will explain the scope and timing of the response and any information that must be retained, subject to applicable law. Deleting MaxThruput-held information does not delete originals in Gmail, Outlook or Exchange Online, OneDrive, or SharePoint, or copies already delivered to an authorized recipient or external service.
Depending on where you live, applicable law may give you additional privacy rights. Contact us to exercise them or raise a concern. Do not send passwords, full identity documents, or other unnecessary sensitive information in your request.
Website cookies, children, and updates
The public website does not include advertising trackers or a marketing analytics script added by MaxThruput. Hosting and security services may use technical logs or mechanisms necessary to deliver and protect the site. External links are governed by the destination's policies.
Our service is intended for business users and is not directed to children under 13. If you believe a child has provided personal information, contact us. We will post updates to this policy with a revised date and provide additional notice or obtain consent when required, including before using Google data for a new purpose.