Cookie & Data Policy
Controller: BrokerFish Ltd, Brighton Place Lot U0213–U0215, Jalan Bahasa, 87000 Wilayah Persekutuan Labuan, Malaysia.
Contact: [email protected]
Last updated: 10 September 2026
1. Cookies & browser storage we use
You can browse and compare plans without accepting non-essential cookies. We ask for your consent before setting anything that isn’t strictly necessary, and you can change your choice at any time using the Cookie settings link in the footer.
| Name | Purpose | Category | Set when | Retention |
|---|---|---|---|---|
bf_consent | Remembers your cookie choice so we can honour it | Strictly necessary | You choose Accept or Reject | Up to 6 months |
authjs.session-token, authjs.csrf-token, authjs.callback-url | Keep a signed-in administrator logged in and protect the login form (CSRF) | Strictly necessary | Only for BrokerFish staff using the admin console | Session |
bf_introducer | Remembers the referral link you arrived through, so your enquiry is handled correctly | Referral (consent required) | You arrive via a referral link and accept non-essential cookies | Up to 90 days |
_ga, _ga_<id> | Google Analytics — measures how the site is used, in aggregate | Analytics (consent required) | Only after you accept non-essential cookies | Up to ~2 years (Google) |
twk_*, TawkConnectionTime | Tawk.to — the live-chat widget in the corner of every page. Its cookies keep a chat session connected and remember a returning chat visitor | Functional — live chat (third party) | The page loads (the chat widget is part of every page) | Session to ~6 months (Tawk.to) |
bf-test-mode-unlocked | Remembers a tester entered the internal preview password (not a cookie — session storage) | Functional | Only on the internal /test preview | Cleared when the tab closes |
We do not use advertising or marketing trackers, and we do not sell your data. Google Analytics and the referral cookie load only after you accept; if you reject, they are not set (and any existing ones are cleared).
Live chat. The chat widget is provided by Tawk.to, a third party, so you can reach a human from any page. It sets the functional cookies listed above to keep a conversation connected; we do not use it to track you across other sites. If you prefer not to use it, simply don’t open the chat — or email us instead at [email protected].
We also keep simple, anonymous first-party counters (page views and funnel steps) to see which parts of the site are used. These store nothing on your device, use no identifiers, and cannot follow you anywhere — which is why they don’t need a cookie or your consent.
2. Personal & health data (applications)
Comparing plans needs no personal data. If you choose to submit an application, we collect the details on the form — your identity and contact information, the plan you chose, your signature, any dependants’ details, and the insurer’s medical questionnaire answers and any medical documents you upload. Medical information is special-category data and is collected only to prepare and place your insurance application.
Your application is emailed to BrokerFish and provided to the insurer you selected so it can be placed. It is stored on our hosting (Render) and in email (Google Workspace). We share it with the insurer you chose and those service providers — not with advertisers.
3. AI assistants and connectors
BrokerFish can be connected to an AI assistant such as ChatGPT, Claude, Perplexity or Gemini, and also answers questions directly at navigator.brokerfish.com/ask. What follows applies when you use BrokerFish that way. How it works and how to add it is a separate page.
What we receive. Only what is needed to rate a plan: date of birth, sex, country of residence, nationality, the same details for anyone else being covered, and the cover options chosen — currency, payment frequency, excess, and which benefits you want included. If you ask an adviser to contact you, we also receive the name, email address and any phone number you give, with the question you want answered.
One question about medical history, and only as a multiple choice. The assistant may also pass on your answer to the same medical-history question this site asks every visitor, chosen from a set of fixed answers — for example, whether there is nothing to work around, a stable and well-managed condition, a past condition you have been clear of for some time, or something else. It is optional, it is always one of those fixed answers and never a description of any condition, and it prices nothing: it decides which insurers are worth showing you, pointing you towards the ones more likely to accept that kind of medical history, because we know from placing cover which insurers have taken it before. We use it for that and nothing else. It is not stored, it is not attached to any quote we keep, and it is not passed to an insurer. It is guidance, not a promise — whether a condition is accepted, excluded, loaded or declined is the insurer’s decision, made on their own health questions once you apply.
What we never receive. Beyond that one multiple-choice answer, we do not accept health or medical information through an AI assistant — no conditions, medications, treatment history, height or weight. There is no field for any of it, and anything of that kind sent to us anyway is discarded rather than stored, with the response saying so. We never ask you to describe a condition in a chat. We ask for no address, no passport or national identity number, and no payment details.
The insurer’s own health questions are asked in one place only: on BrokerFish’s application form, after you have chosen a plan and decided to apply. They are covered by section 2 above, not by this section. If what we accept through an assistant ever goes beyond the details listed here, this notice will say so, and will say why, before it happens.
What we keep, and for how long. We do not store the conversation. Prices are computed when you ask and are not retained against you. Two things do create a record: if you ask for an application link, we store that link — it contains the details you gave, so the form can be filled in for you — for 90 days, after which it is deleted automatically and the link stops working; and if you ask an adviser to contact you, we keep the details and question you gave as an enquiry, handled exactly as an enquiry made through this website.
What the assistant’s operator sees. Your conversation is with the assistant, not with us. Whatever you type is handled by that operator under its own privacy policy — OpenAI, Anthropic, Perplexity, Google or another — and we have no access to it and no control over it. We receive only the details the assistant passes to our tools in order to get a price; we cannot see the rest of the conversation. It is a further reason not to type anything about anyone’s health into a chat.
Which assistant sent you. A link an assistant hands you may identify the assistant it came from, so we can tell which channels are useful. That record identifies the channel, not you.
BrokerFish’s own assistant. At /ask we answer using the Claude API, supplied by Anthropic. The conversation is held in memory for your session and at most one hour afterwards, is not written to a database, and is not used to train any model. Closing the page ends it.
4. Your rights
You can ask to access, correct, or erase your data, object to or restrict processing, or withdraw consent. Contact [email protected]. Because your application is passed to an insurer, you may also need to contact that insurer about the copy they hold.
For any question about this policy or your data, contact [email protected].