Skip to main content

    Privacy Policy

    Livmor Inc.

    Last Updated: August 17, 2026

    Livmor Inc. (“Livmor,” “we,” “us,” or “our”) operates the LivmorIQ Medicare Agent Platform, a platform used by licensed Medicare agents and agencies (“Agent Customers”) to research and compare Medicare plans and manage their own clients. With a Medicare beneficiary’s explicit authorization, LivmorIQ can also connect to that beneficiary’s official Medicare account through the Centers for Medicare & Medicaid Services (“CMS”) Blue Button API to help their agent serve them more directly.

    This Privacy Policy explains what information we collect, how we use and protect it, with whom we share it, your rights with respect to it, and how to contact us with questions.

    In this Policy, ‘you’ refers to an Agent Customer, unless a section specifically addresses Medicare beneficiaries.

    By using Livmor, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use Livmor.

    1. Information We Collect

    1.1 Information We Collect From Agent Customers

    We collect information about Agent Customers, including:

    • •Name, email address, and contact information;
    • •Professional information, such as license or National Producer Number and agency affiliation;
    • •Account credentials and subscription/billing information; and
    • •Usage information about how the Agent Customer uses Livmor’s research and business-management tools.

    1.2 Client Information Agents Provide

    An Agent Customer may enter or upload information about their own clients so we can help that customer research plans, compare options, or manage their book of business. Where this information constitutes PHI, we process it as a subcontractor business associate under the Agent Customer’s (or their agency’s) HIPAA business associate obligations, consistent with Section 7 of the Livmor Terms of Service, and we do not use it to independently contact the beneficiary or share it with any other Agent Customer.

    1.3 Information Obtained Through the CMS Blue Button API

    If a Medicare beneficiary separately authorizes an agent to access their Medicare account, we retrieve the following information directly from CMS through the Blue Button API, based on the specific scopes the beneficiary approves:

    • •Medicare patient information – name, date of birth, sex, and county/ZIP of residence;
    • •Medicare coverage – Part A, B, C, and D enrollment and plan details; and
    • •Medicare claims – medical and prescription drug claims, including diagnoses, services received, medications, treating providers, and associated costs (“Blue Button Data”).

    We never receive or store a beneficiary’s Medicare.gov username or password; CMS authenticates the beneficiary directly through its own secure sign-in process.

    1.4 Information Collected Automatically

    When Livmor is used, we may automatically collect certain technical information, including IP address and general geographic location; browser type, operating system, and device information; pages visited and navigation paths; and necessary session cookies (see Section 9). This automatically collected information does not include PHI and is used for security, analytics, and improving the platform.

    1.5 Information We Do Not Collect

    We do not collect financial account numbers, credit or debit card information, or biometric data through Livmor.

    2. How We Use Your Information

    2.1 Agent Customer Accounts

    We use Agent Customer information to operate their accounts and subscriptions, provide support, and maintain and improve Livmor’s plan-research and business-management tools.

    2.2 Client Information Agents Provide

    We use client information an Agent Customer provides solely to help that specific agent research plans, generate comparisons, and manage their own book of business. We do not use it to market to that client directly, to build profiles for other agents, or for any purpose the agent did not direct.

    2.3 Blue Button Data

    We make a beneficiary’s Blue Button Data available to their connected agent solely to help that agent assist them. We do not use Blue Button Data to market unrelated products or services, and we do not use it to independently contact the beneficiary outside their relationship with their agent, except as described in this Policy. An agent’s use of Blue Button Data in connection with outreach or enrollment activity remains subject to CMS’s Medicare Communications and Marketing Guidelines, including any applicable Third-Party Marketing Organization (TPMO) requirements described in the Livmor Terms of Service.

    2.4 Non-PHI Technical Data

    Automatically collected technical data may be used to operate, maintain, and improve Livmor, detect and prevent fraud, security incidents, and misuse, and analyze aggregate usage trends.

    3. How We Share Your Information

    3.1 Client Information Agents Provide

    Client information an agent enters or uploads into Livmor is used only by and for that agent. We do not share it with other Agent Customers, sell it, or use it for our own independent marketing. It may be shared and disclosed as described in this Policy, but otherwise stays within that agent’s own use of the platform.

    3.2 Sharing Through the CMS Blue Button Connection

    Blue Button Data is shared only with the specific agent a beneficiary authorized when they connected their Medicare account. We do not share Blue Button Data with any other agent, agency, or third party for marketing or enrollment purposes without the beneficiary’s separate, specific consent.

    Our handling of Blue Button Data is subject to CMS’s Blue Button API Terms of Service, which prohibit us from disclosing Medicare information to any other individual or third party without the beneficiary’s specific, explicit consent.

    3.3 Service Providers

    We may share limited information with third-party vendors and service providers who assist us in operating Livmor (e.g., cloud hosting providers, analytics providers, IT security vendors). These providers are contractually obligated to use information only as directed by Livmor, maintain safeguards appropriate to the sensitivity of the information involved, and not use or disclose your information for their own independent purposes. We do not permit our service providers to access PHI or Blue Button Data except to the limited extent necessary to perform services on our behalf.

    3.4 Legal Requirements and Safety

    We may disclose information if we believe in good faith that such disclosure is necessary to comply with applicable law, regulation, or legal process; protect the rights, property, or safety of Livmor, our users, or the public; or detect, investigate, or prevent fraud or illegal activity.

    3.5 Business Transfers

    If Livmor undergoes a merger, acquisition, sale of assets, or similar corporate transaction, information may be transferred as part of that transaction. If we are involved in a business transfer, we will notify affected Agent Customers, and Medicare beneficiaries through their agent, by email and/or a notice on our platform before your information is transferred and becomes subject to a different privacy policy, except where the transaction is subject to a confidentiality obligation that limits pre-closing notice, in which case we will notify you as soon as practicable. Any successor or acquiring entity will remain bound to handle Blue Button Data consistent with CMS’s Blue Button API Terms of Service and this Policy, or will provide you with prior notice and an opportunity to object as required by law.

    3.6 No Sale of Personal Information

    Livmor does not sell, rent, or trade personal information to any third party for that third party’s own marketing or commercial purposes.

    4. De-Identified and Aggregated Data

    We may create de-identified or aggregated data from the information we collect by removing or altering information so it can no longer reasonably be used to identify you. We may use de-identified or aggregated data, without further restriction, for purposes such as improving Livmor.

    Because Medicare and health data can be detailed, in some cases even de-identified or aggregated data could potentially be used to identify individuals with specific medical conditions or other personal attributes, especially within small populations. We take steps designed to reduce this risk but cannot eliminate it entirely.

    5. Data Retention

    5.1 Agent Customer Accounts

    We retain Agent Customer account information for as long as the agent maintains a Livmor subscription, and for a reasonable period afterward to comply with legal, tax, contractual, and business obligations.

    5.2 Client Information Agents Provide

    We retain client information an agent provides for as long as that agent’s Livmor account remains active and the information remains useful for the purpose the agent provided it, consistent with our obligations as a HIPAA subcontractor business associate under the Livmor Terms of Service. If an agent’s account is closed, we handle this information as described in Section 5.4.

    5.3 Blue Button Data

    Livmor’s Blue Button feature is designed to give a beneficiary’s agent ongoing access to their Medicare information to assist them over time, and we store Blue Button Data in encrypted, access-controlled systems for as long as the connection with that agent remains active, consistent with our role as a subcontractor business associate under the agent’s (or their agency’s) HIPAA business associate obligations.

    5.4 Retention Generally, and Dormant or Closed Accounts

    Non-PHI personal information is retained for as long as necessary to fulfill the purposes described in this Policy, comply with our legal obligations, and resolve disputes. In general, we retain this information for the duration of an Agent Customer’s active Livmor account plus 24 months afterward. If a Livmor account becomes inactive or is closed, we retain information for 24 months following the date of inactivity or closure and then take reasonable steps to delete or de-identify it, except where we are required or permitted to retain it longer. For example, records containing PHI like Medicare Advantage/Part D information are retained as required by CMS (currently 10 years) and records containing information relevant to an actual or anticipated legal claim, audit, or regulatory inquiry are retained until that matter is resolved.

    6. What Happens When You Revoke Blue Button Access

    A beneficiary may revoke their Blue Button connection at any time by disconnecting their Medicare account at Medicare.gov or emailing their request to us at privacy@livmor.ai. When a beneficiary revokes access:

    • •We immediately stop retrieving any further Blue Button Data on their behalf;
    • •Their agent loses access to any newly-arriving data; and
    • •Blue Button Data we already retrieved is, by default, retained so their agent can continue assisting them with matters already discussed, unless they tell us otherwise.

    If a beneficiary wants previously retrieved Blue Button Data deleted as well, they may request that at the time of disconnecting or at any later point by contacting their agent or us. If the request is made to us directly, we will promptly notify the agent and proceed at the agent’s direction, consistent with our role as a subcontractor business associate. We will delete it except where we are required to retain it to comply with law, resolve a dispute, or satisfy record-keeping obligations under our agreement with the agent. Because Blue Button Data is retrieved directly from CMS, we are not able to correct it ourselves; a beneficiary who believes their Medicare information is inaccurate should contact CMS or their plan directly, and any resulting update will be reflected the next time we retrieve data under an active connection.

    7. How We Protect Your Information, and Cookies

    We implement administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction, including encryption of data in transit (TLS) and at rest, access controls based on role and need, regular security assessments and monitoring, and employee training on privacy and data security practices. No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security. See Section 10 below for information about how we respond to and notify you of security incidents.

    Livmor uses only cookies necessary for the platform to function – for example, to keep an Agent Customer securely signed in. We do not use marketing or cross-site advertising cookies on Livmor, and we do not use advertising or cross-site tracking cookies in connection with Blue Button Data or any client information.

    8. Your Privacy Rights

    8.1 General Privacy Rights

    If you are a Medicare beneficiary whose information is processed through Livmor you may exercise your privacy rights either through your agent directly or by contacting us using the information at the end of this Policy; we will coordinate with your agent as needed. For requests involving protected health information, we will notify your agent and proceed consistent with our role as a subcontractor business associate. To the extent required by applicable state or federal law, you may have the right to know what personal information we have collected about you and how it is used and shared; access a copy of your personal information; request correction of inaccurate personal information; request deletion of your personal information, subject to certain exceptions; opt out of certain uses or disclosures of your personal information; and not be discriminated against for exercising your privacy rights. We will respond to verifiable requests within the timeframes required by applicable law, and if we deny a request, we will explain why and, where required by law, tell you how to appeal. If you believe your protected health information has been used or disclosed improperly, you also have the right to file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, without fear of retaliation.

    8.2 Sensitive Personal Information

    The health and claims information within Blue Button Data is “Sensitive Personal Information” under California law and “sensitive data” under other state privacy laws.

    We already limit our use of this information to the purposes necessary to provide the Services as described in this Policy. We do not use it to infer characteristics about a beneficiary, for cross-context behavioral advertising, or for any purpose beyond what this Policy describes.

    Where required by law, a beneficiary has the right to direct us to further limit our use and disclosure of their sensitive personal information to only those purposes. Because we already limit our use in this way by default, exercising this right will generally not change how we handle the information.

    9. Children’s Privacy

    Livmor is designed for use by licensed adult Medicare agents and the adult Medicare beneficiaries they serve. We do not knowingly collect personal information from individuals under the age of 18. If you believe a minor has provided us with personal information, please contact us and we will take steps to remove it.

    10. Data Security Incidents and Breach Notification

    If a security incident compromises the confidentiality, integrity, or availability of information, we will notify our Agent Customers and any other parties as required by applicable law. Where required, our notice will describe what happened, the categories of information involved, and steps affected individuals can take to protect themselves. Where a breach involves protected health information for which Livmor acts as a business associate, we will notify the affected Agent Customer or agency without unreasonable delay and in no event later than 30 days after discovery, consistent with the HIPAA Breach Notification Rule, so that they may in turn notify affected individuals as required.

    11. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make a material change, we will update the “Last Updated” date above and post it on our website and, at least 30 days before the change takes effect, notify affected Agent Customers by email and/or a notice on our platform, and notify Medicare beneficiaries through their agent, describing what has changed. What constitutes a material change will be determined in our sole discretion. Your continued use of Livmor after an update constitutes acceptance of the revised Policy.

    12. Contact Us

    If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, or if you wish to exercise your privacy rights, please contact us at:

    Livmor Inc.
    Attn: Privacy Officer
    500 SW 116 Ave.
    Portland, OR 97225-5937
    Email: privacy@livmor.ai

    13. Interpretation

    In the event of a conflict between this Privacy Policy and the Livmor Terms of Service with respect to privacy matters, this Privacy Policy controls. This Policy does not create or imply any contractual or other legal rights beyond those required by applicable law.

    Privacy Actions

    Exercise your data privacy rights

    Request to Download Your Data