Privacy Policy
Last updated: July 24, 2026
We will never sell your data. Ever. VetAid does not sell, rent, share, or monetize your personal information with any third party — no advertisers, no data brokers, no exceptions. We make money from subscriptions, not from your data.
No system is 100% secure. We handle sensitive veteran data including medical records, service records, and VA decisions with encryption and security best practices. But we believe in being honest: if major banks and financial institutions can't guarantee perfect security, we can't either. By using VetAid, you acknowledge this risk. Only upload documents you are comfortable sharing.
VetAid is not a HIPAA Covered Entity or Business Associate. HIPAA (the Health Insurance Portability and Accountability Act) regulates healthcare providers, health plans, and healthcare clearinghouses — and the vendors that process data on their behalf. VetAid is a direct-to-consumer tool you use to organize and analyze your own records. Because of that, your data here is not governed by HIPAA. It is governed by this Privacy Policy and applicable state and federal consumer-privacy laws (including the FTC Health Breach Notification Rule, 16 CFR Part 318). We voluntarily implement security practices that meet or exceed HIPAA's encryption standards, but you should not assume HIPAA protections apply.
1. Information We Collect
Information You Provide
- Military service details (branch, dates, locations, MOS)
- Disability conditions and ratings
- Uploaded documents (C&P exams, decision letters, medical records, DD-214s)
- Portal messages between you and your attorney/VSO
Information We Automatically Process
- Text extracted from uploaded documents via OCR and PDF parsing
- AI-structured analysis of document content
- Portal access logs (timestamps, access counts)
2. PII Redaction
Personal identifiers are automatically stripped. Before any document text is stored in our database or sent to the AI engine, we automatically detect and redact:
- Social Security Numbers (SSN) in all formats
- Individual Taxpayer Identification Numbers (ITIN)
- VA file numbers and claim numbers
- Medical Record Numbers (MRN) and chart numbers
- Date of birth (when explicitly labeled)
- Phone numbers
- Street addresses and ZIP codes
- Bank account and routing numbers
Redacted information is replaced with placeholders like [SSN REDACTED] and is never stored. Note: redaction is high-recall but not perfect — PII embedded in unusual contexts (handwritten margins, OCR errors) may slip through. Original PDFs that contain unredacted PII are stored encrypted at rest.
Optional Research Program — off by default.
You can optionally allow VetAid to use anonymized copies of the VA decision letters you upload to improve our analysis engine for other veterans. This is strictly opt-in (a checkbox at upload, off by default) and strictly limited:
- Only VA-written decision documents (rating decisions and denial letters) are ever included. Your medical records, service records, personal statements, and C&P exams are never included, even if you opt in.
- Included documents go through a second round of automated redaction, and your name and VA file number are additionally removed before any research use.
- You can turn this off at any time in the Documents tab of the app. Turning it off stops future use of your documents; documents are also re-checked against your current preference before any research processing.
- Research data is never sold or shared with third parties — it is used solely to improve VetAid's own analysis engine.
3. Data Encryption
Sensitive data stored in our database is encrypted at rest using AES-128-CBC with HMAC-SHA256 authentication (Fernet symmetric encryption). Encrypted columns include:
- Extracted document text and AI-structured analysis results
- Veteran name and VA file number
- Claimed, rated, and denied conditions
- Service locations and deployment history
Data in transit is protected by TLS over HTTPS. Portal access PINs are hashed using PBKDF2-SHA256 with 200,000 iterations and per-PIN random salts — we cannot recover your PIN, only verify it.
Encryption alone is not perfect security. We continue to invest in stronger key management (per-user keys, hardware-backed key storage) and welcome responsible-disclosure reports of security issues.
4. AI Processing
Document text is sent to our AI engine for analysis. Important facts about this processing:
- Our AI provider, Anthropic (Claude API), does not use API inputs or outputs to train models (per Anthropic's commercial data policy)
- Data is transmitted over encrypted HTTPS connections
- Only the minimum necessary text is sent for each analysis stage
- SSNs and other PII are stripped before text is sent to the AI
4a. Subprocessors
VetAid uses the following third-party services to operate. Each is contractually obligated to handle your data only as needed to provide their service to us, and not for their own purposes:
- Anthropic, PBC — AI analysis (Claude API). Data not used to train models.
- Render, Inc. — Web hosting and persistent storage. Disk-level encryption at rest provided by underlying cloud infrastructure.
- Supabase, Inc. — Authentication and account management.
- Resend (Drsnd, Inc.) — Transactional email delivery (welcome, re-engagement, and Sentinel update emails).
- Google LLC — Google Analytics for aggregate site metrics; Google Ads for marketing attribution. No identifiable case data is shared.
We also collect first-party anonymous interaction analytics on our own pages to improve usability: pointer movement, scroll depth, and click positions. This data contains coordinates and on-page element labels only — never keystrokes, form contents, or anything you type — is keyed to a random per-visit identifier rather than your account, honors your browser's Do Not Track setting, and is processed by us (stored with our infrastructure subprocessors above), not by a session-recording vendor.
If we add a new subprocessor or change one of these, we will update this list and notify you of material changes.
5. Data Storage
- Case data is stored in a SQLite database with sensitive PHI columns encrypted at rest (see Section 3)
- Uploaded files (PDFs, images, scans) are stored encrypted at rest with the same encryption scheme. Only the case owner can re-download them, and they are permanently deleted when you delete your case
- Extracted text from your uploads has SSN, ITIN, VA file number, MRN, DOB, phone numbers, addresses, and bank/routing numbers automatically redacted before being stored or sent to the AI engine
- Portal share links expire after 30 days by default
- Chat history is retained for the lifetime of the share link
6. Who Has Access
- You — full access to your case data
- Your authorized recipients — attorneys/VSOs you share with via portal links
- VetAid administrators — for system maintenance and security only
- No third parties, ever — we do not sell, rent, share, or monetize your data with advertisers, data brokers, or any other party
7. Your Rights
You have the right to:
- Access all data we hold about you (visible in your case dashboard)
- Delete all your data at any time using "Delete My Data"
- Revoke shared access links at any time
- Export your case data and documents
7a. State-Specific Privacy Rights
Depending on where you reside, you may have additional rights under state law, including under the California Consumer Privacy Act (CCPA/CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), Texas Data Privacy and Security Act (TDPSA), and similar laws in other states. These rights generally include:
- The right to know what personal information we have collected about you
- The right to delete your personal information
- The right to correct inaccurate personal information
- The right to portability (a copy of your data in a usable format)
- The right to opt out of "sale" or "sharing" of personal information (we do not sell or share for cross-context behavioral advertising)
- The right to limit use of sensitive personal information
- The right to non-discrimination for exercising these rights
To exercise any of these rights, use "Delete My Data" or contact us through the Service's support channels. We will respond within the timeframe required by applicable law (generally 30–45 days). We do not "sell" personal information as that term is defined under any state privacy law, and we do not engage in targeted advertising using your VetAid case data.
8. Data Deletion
When you delete your data:
- Your case record is permanently deleted
- All uploaded documents and extracted text are deleted
- All AI analysis results are deleted
- All portal share links are deactivated and deleted
- All chat messages are deleted
- This action is irreversible
9. Breach Notification
In the unlikely event of a data breach affecting your personal information, we will notify affected users within 72 hours via the email associated with their account, and will provide details about what data was affected and steps being taken.
10. Contact
For privacy-related inquiries, contact us through the Service's support channels.