Restoria AI Privacy Policy

Last Updated: July 14, 2026

Effective Date: July 14, 2026

Version 3.5


On this page17 sections

INTRODUCTION

Restoria AI, Inc. ("Restoria AI," "Company," "we," "us," or "our") respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use our AI-powered insurance claims management platform and related services (collectively, the "Service").

This Privacy Policy applies to information we collect through:

By using the Service, you consent to the practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.

1. INFORMATION WE COLLECT

We collect information in several ways: directly from you, automatically when you use the Service, and from third parties.

1.1 Information You Provide Directly

Account Information:

Payment Information:

User Content: You may upload, submit, or create content through the Service, including:

Information About Third Parties: Your User Content may contain personal information about third parties, including:

You are responsible for ensuring you have appropriate authorization to submit third-party personal information to the Service.

Communications:

Website Resource Requests:

When you request a downloadable guide, checklist, spreadsheet, or similar resource, we collect and process:

We normalize your email address and transform it with a versioned HMAC-SHA-256 digest using a dedicated secret. Cloudflare KV stores that keyed pseudonymous recipient digest, not the raw email address, in short processing-lease records, resource-request audit records, and 24-hour recipient-and-resource cooldown records. Processing leases use a distinct key for each attempt and expire after 10 minutes. Before contacting Turnstile, we also transform the request IP address with the same keyed method and a separate purpose label. Cloudflare KV stores that keyed IP digest with a request-window start and count for no more than 120 seconds. The application evaluates a limit of eight requests per 60-second window. Because Cloudflare KV is eventually consistent, this short-lived request budget is a permissive abuse-control signal rather than a hard global cap. A temporary failure of the short request-budget backstop may be tolerated, but the gated resource is not delivered if Restoria cannot read and write the required marketing-consent audit record before provider enrollment.

We do not store the raw email address, raw IP address, Turnstile token, or HMAC secret in these Cloudflare KV resource-request records. For transactional delivery, the raw email address is held in application memory only long enough to ask Resend to deliver the resource. When you request a gated resource, the application also sends the raw address to Resend's contact system as described below. The raw IP address is held in memory only for Turnstile verification and keyed rate-control calculation.

Each resource form requires a checked subscription to receive up to two Restoria emails per month with practical Florida public adjuster resources and product updates. The resource is available only after that subscription is activated. When you submit the form, we record the consent version, exact scope, source page category, resource, timestamp, keyed recipient digest, and provider status in Cloudflare KV before asking Resend to create or update the marketing contact. The KV consent record does not contain your raw email address. Resend stores the raw email address as a marketing contact and records its subscription to the dedicated Restoria field-notes topic. An existing global unsubscribe remains in effect and is not silently reversed. If you previously opted out of only the Restoria field-notes topic but are not globally unsubscribed, submitting a new resource request with the required box checked opts that topic back in; replaying a successfully completed older request does not. A recognized Global Privacy Control signal prevents marketing enrollment; because the subscription is required, the gated resource is not delivered in those cases. You may unsubscribe at any time.

After the required subscription is activated, Restoria issues a download link that expires after seven days. The link contains the selected resource identifier, random submission identifier, Resend contact identifier, expiration time, and HMAC signature; it does not contain your email address. The signed contact identifier lets the download route verify the current global and field-notes topic subscription states directly with Resend without depending on Cloudflare KV replication for first-download authorization. Each download request rechecks the signed entitlement, Global Privacy Control signal, and current Resend subscription state before serving the static resource. Missing, expired, altered, mismatched, opted-out, unsubscribed, deleted-contact, and GPC requests are denied. If Resend cannot confirm the required state, the download fails closed until verification is available. A keyed short-window Cloudflare KV budget limits repeated download attempts; failure of that abuse-control backstop does not bypass the signed entitlement or live subscription checks.

1.2 Information Collected Automatically

When you access the Service, we automatically collect:

Device and Browser Information:

Usage Information:

Log Data:

Location Information:

Cookies and Similar Technologies: See Section 5 for detailed information about our use of cookies.

On the public Website, analytics and website-marketing technologies are enabled by default unless you turn them off through the persistent privacy control in the footer. The Website may use Google Analytics and PostHog for analytics and Apollo's website visitor tracker for marketing as described in Section 5. A recognized Global Privacy Control signal keeps both categories off. Necessary privacy-choice storage and security technologies may operate regardless of these settings.

The authenticated application uses PostHog product analytics and session replay to understand feature use and diagnose problems. This application collection is not controlled by the public Website footer setting and does not currently include an in-application analytics opt-out. PostHog may receive identified account and organization information, application routes, page content, DOM changes, clicks and other interactions, performance and error diagnostics, and non-password form input values. Password fields and authentication or security secrets are excluded or redacted as described in Sections 3.3 and 5.4.

1.3 Information from Third Parties

Authentication Providers: If you authenticate using a third-party service (e.g., Google), we receive basic profile information (name, email) from that provider.

Payment Processors: Our payment processor (Polar Software Inc.) provides us with limited transaction information (transaction ID, last four digits of card, billing address) to confirm payments.

AI Service Providers: Our AI provider (OpenAI) may provide us with usage metrics and error reports related to AI processing.

1.4 Categories of Personal Information Collected

For purposes of privacy laws, we collect the following categories of personal information:

Category Examples Collected
Identifiers Name, email, IP address, account ID Yes
Customer Records Name, address, phone, payment info Yes
Commercial Information Subscription history, usage records Yes
Internet Activity Browsing history, interactions with Service Yes
Geolocation Approximate location from IP Yes
Professional Information License number, business info Yes
Inferences Preferences, usage patterns Yes
Sensitive Personal Information Account credentials Yes

2. HOW WE USE YOUR INFORMATION

We use personal information for the following purposes:

2.1 Providing and Improving the Service

2.2 Communications

The requested resource and its transactional inbox copy are available only after the required marketing subscription is activated. Restoria may then send up to two emails per month with practical Florida public adjuster resources and product updates. You may unsubscribe at any time. If the required box is unchecked, GPC is enabled, an existing global unsubscribe applies, or enrollment fails, the resource is not delivered.

2.3 Security and Compliance

2.4 Legal Bases for Processing

We process personal information based on:


3. HOW WE SHARE YOUR INFORMATION

3.1 We Do Not Sell Your Personal Information

We do not sell your personal information as "sale" is defined under the California Consumer Privacy Act (CCPA), Nevada law, or other applicable privacy laws. We do not receive monetary or other valuable consideration in exchange for your personal information.

3.2 We May Share Personal Information Through Optional Apollo Visitor Tracking

IMPORTANT DISCLOSURE REQUIRED BY CALIFORNIA LAW:

Under the California Privacy Rights Act (CPRA), "sharing" personal information for "cross-context behavioral advertising" is a separate category from "selling." Unless a Website visitor disables the Marketing category or sends a recognized Global Privacy Control signal, Apollo's website visitor tracker may associate Website activity with business or account information for sales intelligence and marketing. We conservatively treat this disclosure to Apollo as potential "sharing" and provide opt-out controls.

What This Means:

Categories of Information Shared for Cross-Context Behavioral Advertising:

Third Parties Receiving Shared Information:

Your Right to Opt Out: You have the right to opt out of this sharing. See Section 5.5 for cookie controls and Section 9.5 for the "Do Not Share My Personal Information" link.

3.3 Service Providers

We disclose information to third-party vendors that support the Service. We treat service-provider processing as distinct from sale or sharing where applicable. The Apollo disclosure described in Section 3.2 is separately treated as potential sharing and remains subject to the Website's Marketing setting, persistent opt-out control, and recognized Global Privacy Control signals.

Service Provider Purpose Data Disclosed
OpenAI AI processing Chat prompts, document content
Google Cloud Platform Cloud infrastructure, storage All Service data
Cloudflare, Inc. Website hosting, KV audit and cooldown storage, marketing-consent evidence, short-window request budgeting, and Turnstile bot verification Keyed pseudonymous recipient and IP digests, requested resource, email-request and consent audit fields, request-budget count and timestamps; raw IP address and security signals processed for bot verification but not stored in resource-request records
Clerk Authentication Account credentials, email
Polar Software Inc. Merchant of Record / Payments Billing information, subscription status, IP address
DocuSeal Electronic Signatures Document contents, signer IP address, email, name, audit trail data
MongoDB Atlas Database hosting Application data
Resend Required resource-subscription management, transactional resource-email delivery, current-subscription verification for gated downloads, and 24-hour provider idempotency Email address, contact identifier, marketing topic subscription, requested resource title and download link, keyed recipient digest and resource identifier in the idempotency key, and delivery metadata
Google Analytics Default-on Website analytics subject to the persistent Analytics setting and GPC Page and explicitly sent usage-event information, device and browser information, IP-derived technical information, and analytics identifiers; Google Signals and ad-personalization features are disabled
PostHog Website analytics subject to the Website Analytics setting and GPC; authenticated-application product analytics and session replay without an in-application opt-out On the Website: automatically captured and Restoria-defined events, manually recorded page views and page leaves, performance and browser diagnostics, event properties, page content, DOM changes, interactions, and non-password form inputs. In the authenticated application: identified user and organization properties, normalized application routes, Restoria-defined and automatically captured events, performance and error diagnostics, page content, DOM changes, interactions, and non-password form inputs. The application records anonymous, normalized public-intake page views without the public slug. Both surfaces filter passwords and authentication or security secrets, mask password inputs, and do not record replay request headers or bodies; specifically tagged content may also be masked or blocked.
Apollo.io Default-on website visitor tracking subject to the persistent Marketing setting and GPC Website visits, referring page, browser or device information, IP-derived technical information, tracker identifiers, and any business or account association made by Apollo; treated as potential sharing as described in Section 3.2

All service providers are bound by contracts requiring them to:

3.4 AI Processing Disclosure

When you use AI features:

We do NOT use your confidential claim data to train AI models without your explicit consent.

3.5 Business Transfers

If Restoria AI is involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred. We will notify you and inform you of choices you may have.

3.6 Legal Requirements

We may disclose information if required by law or in good faith belief that disclosure is necessary to:

3.7 With Your Consent

We may share information when you direct us to or provide explicit consent.

3.8 Aggregated and De-Identified Data

We may share aggregated or de-identified data that cannot reasonably identify you for industry analysis, research, and marketing.

3.9 Google Workspace and External API Data

If you choose to connect your Google account or Microsoft account to the Service, we will access your email data solely to provide the Service's automated claims organization and communication tracking features. Restoria AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use your email data to serve ads, and human access to your email data is strictly limited to resolving technical support issues with your explicit permission, investigating security abuse, or as required by law.


4. ARTIFICIAL INTELLIGENCE AND AUTOMATED PROCESSING

4.1 How We Use AI

The Service uses artificial intelligence to provide administrative and drafting support only, including:

Important: The Service cannot and does not determine coverage, value claims, or make professional adjusting decisions. AI outputs require your professional review.

4.2 AI Provider

Our AI features are powered by OpenAI models. Your inputs are transmitted to OpenAI for processing in accordance with our contractual agreement.

4.3 AI Data Handling

We do NOT:

We DO:

4.4 Automated Decision-Making

The Service uses automated processing for document extraction, classification, and draft generation. We do not make automated decisions with legal or significant effects without human oversight. All AI outputs require your review before professional use.

4.5 Human Review

You may request human review of AI outputs by contacting [email protected].


5. COOKIES AND TRACKING TECHNOLOGIES

5.1 What Are Cookies and Similar Technologies?

Cookies are small text files placed on your device when you visit a website. Similar technologies include local storage and provider-issued browser identifiers. We use these technologies to operate the Service, remember privacy choices, perform analytics, and support website visitor tracking, subject to the settings and opt-out controls described below.

5.2 Types of Cookies We Use

Strictly Necessary Cookies (Cannot be disabled):

Cookie Purpose Duration
**session Session management Session
**clerk_* Authentication Session/Persistent
csrf_token Security Session
restoria_consent_v1 (local storage) Remembers analytics and marketing privacy choices Until changed or browser storage is deleted

Functional Cookies (Can be disabled):

Cookie Purpose Duration
preferences Display settings 1 year
locale Language preference 1 year

Website Analytics Technologies (Enabled by default; can be disabled with the Website control):

Storage Provider Purpose Duration
_ga Google Analytics Distinguishes analytics users Up to 2 years
_ga_* Google Analytics Maintains analytics session state Up to 2 years
ph_<project-key>_posthog (cookie or local storage) PostHog Maintains the Website analytics identifier and state Provider- and configuration-controlled

The authenticated application may also use PostHog browser storage to maintain product-analytics identity and session state. That application use is not controlled by the Website Analytics setting.

Marketing Technologies (Enabled by default; can be disabled; treated as potential "Sharing" under CCPA/CPRA):

Storage Provider Purpose Duration
Apollo tracker identifiers and browser storage Apollo.io Website visitor tracking, business or account matching, sales intelligence, and marketing Provider- and configuration-controlled

5.3 How the Configurable Website Technologies Operate

When Analytics is enabled:

When Marketing is enabled, Apollo's website visitor tracker may process Website visits, referring page, technical identifiers, and browser or device information and may associate a visit with a business or account. As explained in Section 3.2, we treat this disclosure as potential "sharing" and provide opt-out controls.

Turning off a category updates the saved privacy choice, disables the applicable vendor interfaces, removes accessible vendor scripts and related first-party browser storage, and reloads the page so already-loaded tracker code is no longer active. A recognized GPC signal keeps both categories disabled. Existing saved choices remain in effect on later visits.

5.4 Authenticated Application Analytics

The authenticated application uses PostHog with automatic interaction capture, performance and error diagnostics, Restoria-defined product events, and session replay enabled. We identify signed-in users and associate their events with their organization. Collection may include application routes, visible page and interface text, DOM changes, clicks and other interactions, and unmasked non-password input values, including customer-provided information entered into forms. On the same application surface, public intake page views are recorded under a normalized route using a fresh anonymous identity, without the public intake slug or a previously signed-in user's identity.

Passwords remain masked. Fields or regions specifically marked by Restoria for masking or blocking are omitted or obscured, and replay request headers and bodies are not recorded. Before events are sent, we redact properties and URL parameters identified as passwords, authorization values, cookies, credentials, authentication tokens, API or private keys, signatures, Turnstile responses, and other security secrets. Ordinary product metrics such as token counts and non-secret fields remain available for analytics.

The public Website footer Analytics setting and GPC handling described above apply to the public Website, not authenticated-application product analytics. We do not currently provide an end-user analytics opt-out inside the authenticated application.

5.5 Your Cookie Choices

Persistent Website Control: Use the "Do Not Share My Personal Information" button in the Website footer to turn Analytics or Marketing off or on at any time. The Website does not display a first-visit privacy banner.

Browser Settings: Block or delete cookies and local storage in your browser.

Opt-Out Links:

Global Privacy Control (GPC): We honor GPC signals by keeping both optional categories off.

"Do Not Share" Link: Click in our website footer.


6. DATA RETENTION

6.1 Retention Periods

Data Type Retention Period
Account Information Account duration + 3 years
User Content Account duration + 30-day export period
Chat History Account duration + 30-day export period
Payment Records 7 years (legal requirement)
Usage Logs 2 years
Support Communications 3 years
Resource Request Audit Records 365 days after the most recent request or email attempt
Recipient and Resource Cooldown Records 24 hours after provider acceptance
Resource Request Processing Leases 10 minutes after the request attempt
Keyed IP Request-Budget Records No more than 120 seconds
Marketing Consent Audit Records Up to two years after each resource request, unless deletion is required earlier or a verified deletion request applies
Resend Marketing Contact Until unsubscribe, verified deletion request, or account-level retention requirements apply

Resource-request audit records contain the versioned keyed recipient digest and the request, verification, provider-acceptance, and failure fields described in Section 1.1. Each final audit-record write has a 365-day expiration. A distinct keyed processing lease is written before each provider attempt and expires after 10 minutes; it prevents an unresolved attempt from being submitted again while its outcome is unknown without rewriting the final audit key in the same request. Provider acceptance also creates a keyed recipient-and-resource cooldown record for 24 hours. Acceptance means Resend accepted the request; it is not a guarantee that the destination mailbox delivered the message. Before Turnstile, the application evaluates the keyed IP digest against a KV request-budget record containing only the request-window start and count. That record expires no more than 120 seconds after it is written. Because Cloudflare KV is eventually consistent, simultaneous request-budget, audit, lease, or cooldown reads and writes may not always be immediately visible; the permissive request budget, Turnstile, processing leases, recipient cooldown, and provider idempotency provide complementary controls. A temporary request-budget or post-delivery audit outage may be tolerated as described above, but a resource is not released unless Restoria can first persist and confirm the required marketing-consent state.

These Cloudflare KV resource-request records do not contain the raw email address, raw IP address, Turnstile token, or HMAC secret. For a gated resource, the raw email address is held in application memory long enough for Restoria to activate the required Resend topic subscription and submit the transactional resource message. Resend processes and may retain message-delivery, idempotency, contact, and topic-subscription data under our provider configuration, contract, and applicable law.

Marketing-consent audit records contain the keyed recipient digest and the version, scope, source, resource, timestamp, topic, Resend contact identifier, and provider outcome described in Section 1.1. They are written before provider enrollment and retained while the subscription remains active and as reasonably needed to document consent. Resend retains the raw marketing contact address and topic state. A verified privacy request can be used to request deletion where applicable; an unsubscribe stops marketing delivery and gated-download access but may not immediately erase the minimum consent and suppression evidence needed to honor that choice.

6.2 Upon Account Termination

(a) Export Period: You have 30 days to export your data.

(b) Deletion: After 30 days, User Content is deleted from active systems.

(c) Backups: Backup copies deleted within 90 days.

6.3 Compliance Hold Option

IMPORTANT FOR PUBLIC ADJUSTERS:

Many states require claim record retention for 5-7 years:

Your Options:

  1. Export Before Termination: Download all required records. You are solely responsible for statutory compliance.

  2. Compliance Hold: Request read-only archive access after termination for statutory retention periods. Contact: [email protected]

Restoria AI is not responsible for your compliance with record retention laws.

6.4 Legal Holds

We may retain data longer for litigation, investigations, or legal compliance.


7. DATA SECURITY

7.1 Security Measures

Technical Safeguards:

Administrative Safeguards:

7.2 GLBA Safeguards

Public adjusters handle "Non-Public Personal Information" (NPI) under GLBA. Restoria AI maintains safeguards designed to support applicable obligations under 16 CFR Part 314 (FTC Safeguards Rule), including:

7.3 Security Incidents

If a security incident affects your personal information, we will:

7.4 Your Role

Help protect your information by:

7.5 No Absolute Guarantee

No security method is 100% secure. We cannot guarantee absolute security.


8. YOUR PRIVACY RIGHTS

8.1 General Rights

All users may:

8.2 Additional Rights by Location

See Sections 9-11 for state-specific rights.

8.3 How to Exercise Rights

8.4 Verification

We verify identity before fulfilling certain requests.

8.5 Response Timing

8.6 Appeals

If denied, email [email protected] with subject "Privacy Appeal." You may also contact your state attorney general.


9. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)

This section applies to California residents.

9.1 Applicability

The CCPA/CPRA grants California residents specific privacy rights. Note: The B2B exemption expired January 1, 2023—business contact information is now covered.

9.2 Your California Rights

Right Description
Right to Know Categories and specific pieces of PI collected
Right to Delete Request deletion of PI
Right to Correct Request correction of inaccurate PI
Right to Opt-Out of Sale We do NOT sell PI
Right to Opt-Out of Sharing Opt out of sharing for cross-context behavioral advertising
Right to Limit Sensitive PI We only use sensitive PI as needed for Service
Right to Non-Discrimination No penalty for exercising rights

9.3 Sale vs. Sharing — Critical Distinction

Practice Do We Do This? Your Rights
SELL personal information NO N/A
SHARE for cross-context behavioral advertising POTENTIALLY through Apollo unless Marketing is disabled or GPC is recognized You can opt out

9.4 Disclosure Table

Category Collected Disclosed to Providers Sold Shared
Identifiers Potentially through Apollo unless Marketing is disabled
Customer Records
Commercial Info
Internet Activity Potentially through Apollo unless Marketing is disabled
Geolocation
Professional Info Potentially if Apollo makes a business or account association
Inferences
Sensitive PI

9.5 How to Opt Out of Sharing

  1. Footer Link: Click "Do Not Share My Personal Information"
  2. Global Privacy Control: Enable GPC in your browser (we honor it automatically)
  3. Privacy Choices: Turn off Marketing (you may also turn off Analytics independently)
  4. Email: [email protected] with subject "Opt-Out of Sharing"

9.6 Submitting Requests

9.7 Authorized Agents

California residents may use authorized agents with signed written permission.

9.8 Financial Incentives

We do not offer financial incentives for PI collection or deletion.

9.9 Shine the Light

We do not disclose PI to third parties for their direct marketing.


10. NEVADA PRIVACY RIGHTS

10.1 Nevada Residents

Nevada law (NRS 603A) provides opt-out rights for sales. We do not sell personal information.

10.2 Opt-Out Request

Submit to [email protected] with subject "Nevada Opt-Out Request." Response within 60 days.

10.3 Nevada Security

We comply with NRS 603A security requirements including encryption and breach notification for our Nevada users.


11. OTHER STATE PRIVACY RIGHTS

11.1 States with Privacy Laws

State Effective Key Rights GPC Required
Virginia Jan 2023 Access, correct, delete, opt-out No
Colorado Jul 2023 Access, correct, delete, opt-out Yes
Connecticut Jul 2023 Access, correct, delete, opt-out Yes
Utah Dec 2023 Access, delete, opt-out No
Texas Jul 2024 Access, correct, delete, opt-out Yes (Jan 2025)
Oregon Jul 2024 Access, correct, delete, opt-out Yes (Jan 2026)
Montana Oct 2024 Access, correct, delete, opt-out Yes
Delaware Jan 2025 Access, correct, delete, opt-out Yes
Iowa Jan 2025 Access, delete, opt-out No
Tennessee Jul 2025 Access, correct, delete, opt-out No

11.2 Global Privacy Control

We honor GPC signals for all states requiring universal opt-out recognition.

11.3 Exercising Rights

Email [email protected] with your state and request.

11.4 Appeals

If denied, appeal to [email protected]. You may also contact your state attorney general.


12. DO NOT TRACK SIGNALS

12.1 Browser DNT

We do not respond to browser "Do Not Track" signals due to lack of uniform standard.

12.2 Global Privacy Control (GPC)

We DO honor GPC signals. When detected, we:


13. CHILDREN'S PRIVACY

13.1 Age Restriction

The Service is for business use by licensed professionals and not directed to anyone under 18.

13.2 No Collection from Children

We do not knowingly collect information from children under 13 (COPPA) or under 18.

13.3 Parental Contact

If you believe a child has provided information, contact [email protected] immediately.


14. INTERNATIONAL USERS

14.1 US Only

The Service is intended for United States use only.

14.2 Data Location

All data is processed and stored in the United States.

14.3 International Access

If accessing from outside the US, your data will be transferred to the US. By using the Service, you consent to this transfer.


This Privacy Policy does not apply to third-party websites or services. Review their privacy policies separately.


16. CHANGES TO THIS PRIVACY POLICY

16.1 Updates

We may update this Privacy Policy for changes in practices, services, laws, or best practices.

16.2 Notification

For material changes:

16.3 Acceptance

Continued use after changes constitutes acceptance.


17. CONTACT US

Restoria AI, Inc.

Privacy Team: [email protected]

Phone: 646-234-2277

Mailing Address: Restoria AI, Inc. Attn: Privacy Team 1207 Delaware Ave #1021 Wilmington, DE 19806

Other Contacts:


SUMMARY OF PRIVACY PRACTICES

Practice Our Approach
Sell Personal Information NO
Share for Cross-Context Advertising POTENTIALLY through Apollo unless Marketing is disabled or GPC is recognizedYou can opt out
Honor GPC Signals YES
Train AI on Confidential Data NO (without consent)
Google API Limited Use Compliance YES
Provide Data Access YES
Allow Deletion YES
Offer Compliance Hold YES
Encrypt Data YES (HTTPS/TLS in transit; provider-managed encryption at rest)
GLBA Safeguards YES (safeguards designed to support applicable 16 CFR Part 314 obligations)
Breach Notification YES (per state law)

Restoria AI, Inc.

A Delaware Corporation

© 2026 Restoria AI, Inc. All rights reserved.

Analytics and website-marketing technologies are enabled by default. Turn either category off below at any time. A Global Privacy Control signal automatically keeps both categories off.