Last updated 24 September 2026
This service is built to need as little about you as possible. There is no account, no sign-in and no advertising. What follows is exactly what is collected, by which part of the service, and why.
vhishongkong.com and the MCP server at mcp.vhishongkong.com are operated by Instly Technologies Co., Ltd. (Thailand, registration 0105567135903). Contact: mo@instlytechnologies.com.
To price plans the site uses the details you give Nomi: age, sex as the premium schedules rate it, whether you smoke, room preference and deductible preference. These are used to calculate premiums and are not, on their own, capable of identifying you. They are not stored against a name unless you later ask to be contacted.
Your messages to Nomi are sent to Google's Gemini model on Vertex AI to generate a reply. Do not type medical details, identity document numbers or payment details into the chat. Nomi does not need them and is built not to ask.
The site keeps a few things in your own browser using local storage: your shortlist, whether the assistant panel is open, and whether you have seen the swipe explainer. This stays on your device, is not sent to us and is not shared with anyone. There are no advertising cookies and no third-party analytics.
If, and only if, you ask to be contacted or to have your shortlist sent to you, we store: your name, the phone number or email address you gave, which you preferred to be contacted on, the plans you saved, the quote details above, and a reference number. This is passed to a licensed adviser so they can contact you.
Health details are never stored on an enquiry. If you mention a condition in a note, it is removed automatically before the enquiry is saved, and the adviser asks you directly instead.
If you asked for follow-up messages, we keep the thread of those messages so later ones make sense. Reply STOP, or unsubscribe, and it stops.
Agents connect to mcp.vhishongkong.com without signing in. For each call we log the date and time, which tool was called, the arguments it was given (an age, a plan certification number, an insurer name and the like), the calling IP address, the client's user agent string, how long the call took and whether it succeeded.
This exists to enforce the rate limit, to spot abuse, and to know which tools people actually use. The open tier's tools are read-only and carry no personal data. The only tool that handles personal data is create_lead, which needs no key but only runs when a person has given a name and a way to reach them and asked to be contacted, and it follows the adviser section above.
If you request an API key, we store the name, work email, company and description of intended use that you supply, so the key can be issued, its quota managed and its holder contacted. The key itself is stored only as a hash and cannot be recovered from us.
Nothing is sold, and nothing is shared with insurers for marketing.
Enquiries are kept while the enquiry is open and afterwards as a record of the introduction, until you ask us to delete them. MCP usage records are kept while the service runs, for the operational reasons above. Ask and we will delete what relates to you.
Email mo@instlytechnologies.com to see what is held about you, to correct it, or to have it deleted. Clearing your browser data removes everything the site stored locally.
This service is for adults arranging their own or their family's cover and is not directed at anyone under 18.
If this policy changes, the date above changes with it.