Skip to content

your privacy is top priority

Privacy Policy

How we collect, use, protect, and share your information, and the rights you have over it.

Effective 2026-07 · Version 2026-07

Is this covered by HIPAA?

No. VA Disability Pro is a direct-to-consumer software service. We are not a HIPAA covered entity or business associate, and HIPAA does not govern the information you give us. Rather than claim “HIPAA compliance,” we tell you plainly that we protect your health-related information with the strong safeguards described below, and that we are subject to the Federal Trade Commission Act and the FTC’s Health Breach Notification Rule (16 CFR Part 318).

How we handle your data with AI

We use AI (Amazon Bedrock) to read the documents you upload and to draft your claim materials. We want you to understand exactly what happens to your information when AI is involved:

  • Processed, not retained: when the AI analyzes a document or writes a draft, your information is sent to the model only to produce that result and is not kept by the AI afterward. We do not enable the optional logging that would record the prompts and responses, so your health information is not written to any AI log.
  • Never used to train AI: your information is not used to train or improve any AI model, not ours and not the model provider’s.
  • You stay in control of what’s stored: the documents you upload and the drafts the AI creates are saved only in your own account, encrypted, and readable by no other user. You can delete them, and your whole account, at any time (see deletion, below); when you do, your copies are erased.
  • Veteran-consented counselor access (VDP-1382): if you choose to share your claim with an organization’s accredited counselor (an action you initiate and can revoke at any time), that counselor can view and prepare the records you have shared, and we process your data for that purpose. Every such access is recorded to a tamper-evident audit log; it exists only while your consent is active, and revoking it immediately ends the counselor’s access.
  • Interview transcripts are transient: when you use the practice C&P interview, the conversation is sent to the AI to generate the next question or feedback and is not stored as a separate record beyond your account.

As noted above, we are not a HIPAA covered entity, so HIPAA does not apply to us and we do not claim to comply with it. Instead, the points above are our plain, honest commitment about how your data is handled, backed by the safeguards described throughout this policy.

What Data We Collect

  • Identifiers / account: email, name, contact details, and account credentials.
  • Veteran profile: legal name, date of birth, mailing address, phone, the last 4 digits of your SSN, and your VA file number.
  • Health & claim data (sensitive): the conditions and symptoms you log, and medical or service documents you upload.
  • AI-generated drafts created from your inputs.
  • Payment: processed by Stripe. We do not store your full card number.
  • Usage & device: analytics, device/browser data, and cookies used to run and improve the Service.

We collect this from you directly (and usage data automatically). The last-4 SSN, VA file number, and health data are sensitive personal information.

How We Use Your Data

  • To provide the Service and generate your drafts (via AI).
  • To process your subscription and provide support.
  • To secure, maintain, and improve the Service.
  • To meet legal obligations and enforce our Terms.

We do not use your sensitive or health information to infer characteristics, for advertising, or for any purpose other than providing the Service to you.

Service Providers We Share With (Subprocessors)

We share data only with vendors who help us run the Service, under contract and only as needed:

  • Amazon Web Services, hosting, storage, and the AI (Amazon Bedrock) that analyzes documents and generates drafts.
  • Stripe, subscription payments.
  • Error/usage monitoring, with sensitive fields scrubbed before they leave the app.

These vendors and contractors are bound by the same commitments. Every service provider that handles your information does so only to perform services for us, under a written contract that requires them to protect it and holds them to the same restrictions on use and disclosure that apply to us. They may not use or disclose your information for their own purposes.

No third-party use or disclosure without your consent. We do not use or disclose your information (including any de-identified, anonymized, aggregated, or pseudonymized form of it) to any third party, for any reason, without your consent. The only exceptions are the service providers described above (who act on our behalf under these same commitments) and disclosures we are required to make by law or that are necessary to protect rights and safety. We do not sell or “share” your personal information (as those terms are defined under California law), and we never share your health data for advertising.

How We Protect Your Data

  • Your data is encrypted in transit and at rest.
  • Owner-scoped access: your records are private to your account. No other user can read them.
  • The most sensitive inputs are handled within your session and not retained beyond what the Service needs.
  • Access controls, least-privilege, and regular security reviews.
  • Your data is stored in the United States (AWS U.S. regions).

How Long We Keep It, and Deleting Your Data

  • 30-day deletion grace period: when you request deletion, you have 30 days to undo it before it becomes permanent. Deleting your account removes all of your data, including billing records and uploaded files.
  • 7-year retention cap: we keep claim and health records no longer than 7 years, after which they are automatically purged. (This is our own retention limit. It is not a HIPAA requirement, since, as noted above, HIPAA does not apply to us.)
  • Dormant (inactive) accounts: if your account stays inactive for 24 consecutive months, we will email you a reminder and then, if it remains inactive, delete or de-identify the account and all data associated with it (including any non-VA information you shared with us) unless we are required by law to keep it. You can keep your account active simply by signing in.

Business Transfers, Sale, or Wind-Down

If VA Disability Pro is involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, your information may be transferred as part of that transaction only if the receiving party agrees, in writing, to protect it under terms at least as protective as this Privacy Policy, including the same consent requirements and the same limits on third-party use and disclosure. We will give you advance notice (by email and within the Service) before any transfer of your data becomes effective, and you may delete your account and data first if you do not want it transferred.

If VA Disability Pro ends the Service or winds down its business without a successor to assume these obligations, we will securely delete or de-identify your data and will not sell or otherwise transfer it in a way inconsistent with this policy.

If There's a Data Breach

If your health information is acquired or disclosed without authorization, we will notify you without unreasonable delay (and no later than 60 days), and notify the FTC, and prominent media where 500 or more residents of a state are affected, consistent with the FTC Health Breach Notification Rule.

Your Privacy Rights

You can access, correct, export, or delete your data at any time from your account or by emailing privacy@vadisabilitypro.com. We will not discriminate against you for exercising these rights, and we respond within the timeframes the law requires (e.g., 45 days under California law). We may need to verify your identity, and you may use an authorized agent.

California (CCPA/CPRA): you have the rights to know, access, correct, and delete your personal information; to opt out of the “sale” or “sharing” of personal information; and to limit the use of your sensitive personal information. We do not sell or share personal information and we use sensitive personal information only to provide the Service, so no further limitation is needed, but you may still contact us. We honor Global Privacy Control (GPC) browser signals as opt-out requests.

Consumer Health Data (Washington My Health My Data Act)

If you are a Washington consumer (or your data is collected there), the following applies to your “consumer health data” (the conditions, symptoms, and medical documents you provide):

  • What & why: we collect it from you to generate your claim materials and provide the Service, as described above.
  • Consent: we collect and use your consumer health data only with your consent, for these purposes.
  • Sharing: only with the subprocessors listed above, to provide the Service. We do not sell consumer health data (and would never do so without your separate written authorization).
  • Your rights: to access, delete, and withdraw consent. Email privacy@vadisabilitypro.com to exercise them.

Cookies & Analytics

We use necessary cookies to keep you signed in and limited analytics to understand and improve usage. We do not use third-party advertising cookies. You can control cookies through your browser, and we honor GPC signals as described above.

Children

The Service is for adults (18+) pursuing their own VA claim. It is not directed to children, and we do not knowingly collect personal information from anyone under 13 (or under 18). If we learn we have, we will delete it.

Changes & Contact

VA Disability Pro is operated by VA Disability Pro, LLC (Roswell, Georgia). We may update this policy; material changes update the version above and we will ask you to re-accept. Questions or privacy requests: privacy@vadisabilitypro.com.