Skip to main content

Privacy Policy

Effective date: August 8, 2026  ·  VeteranHQ

VeteranHQ (“VHQ,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, how we protect it, and what rights you have regarding your data. This policy applies to all users of the VeteranHQ platform, including individual veteran users and law firm or attorney users, as well as our website, iOS and other mobile applications, API, and Chrome browser extension.

1. Information We Collect

1.1 Account Information

When you create an account, we collect your name, email address, and a securely hashed version of your password (using bcrypt with a work factor of 12). If you register via Google OAuth, we receive your name, email, and Google account identifier. We never store your password in plaintext or recoverable form.

1.2 Veteran Profile Information

You may voluntarily provide profile information to personalize your benefits analysis, including: branch of service, Military Occupational Specialty (MOS), current VA disability rating and individual rated conditions, service dates, state of residence, ZIP code, deployment history, number of dependents, discharge type, combat veteran status, and service component. Sensitive fields (state, ZIP code, MOS, individual ratings, deployments) are encrypted at rest using AES-256-GCM.

1.3 Chrome Extension Data

If you install and authorize our Chrome browser extension, it collects data from your VA.gov account when you are logged in to VA.gov. This includes:

  • Claims and claim details (status, phase, contentions, tracked items, documents)
  • Rated disabilities (condition name, rating percentage, diagnostic code, effective date)
  • Appeals (issues, events, decisions, alerts)
  • Compensation payment history (date, amount, type)
  • Service history and periods of service
  • Intent to File (ITF) records
  • Benefit letter eligibility
  • VA debts
  • Declared dependents
  • eFolder document metadata (document titles and dates, not document contents)
  • VA decision letters and benefit letters, including text extracted from the letter document
  • Date of birth, VA file number (BIRLS), mailing address, and phone number from your VA.gov profile
  • VA appointments (date, time, location, clinic, and service type)
  • GI Bill entitlement, used and remaining benefit amounts, and enrollment verifications
  • VA payment account details (payment method, bank name, and the last four digits of the account)
  • In-progress VA forms saved to your VA.gov account

The extension accesses this data using your existing VA.gov session. It does not capture, transmit, or store your VA.gov username or password. The extension synchronizes data approximately every 5 minutes while VA.gov is open and on certain navigation events. The extension requires browser permissions for storage, alarms, and notifications, and access to VA.gov and VeteranHQ domains. During a full VA data pull, the extension may automatically download newly available VA letter PDFs, including decision letters and benefit letters, and send them to VeteranHQ without any upload by you. VeteranHQ then attempts to extract the decision-relevant text. When extraction succeeds, the retained text is encrypted at rest and used for analysis; for long letters we retain selected sections rather than the entire document. When extraction does not succeed, we retain encrypted claim metadata instead of letter text.

1.4 Uploaded Documents

When you or your authorized attorney upload documents — such as C&P exam results, medical records, VA decision letters, discharge paperwork, or C-Files — we store the original files in encrypted cloud object storage (AWS S3) and extract text content for AI analysis. C-File content is embedded using BAA-covered AI services (AWS Bedrock) to ensure PHI remains within HIPAA-compliant infrastructure.

1.5 Chat Conversations

We retain the messages you send and receive through the VeteranHQ chat interface, including AI responses, extended thinking content, tool call results, and citations. This data is stored to provide continuity of service and allow you to reference prior conversations. You may delete individual conversations or your entire chat history at any time.

1.6 Social Security Numbers

Important Notice Regarding Social Security Numbers

Certain VA form generation features require a Social Security Number (SSN) or VA file number to produce complete form drafts. When provided, SSNs are handled with heightened security controls:

  • SSNs are transmitted exclusively over encrypted connections (TLS 1.3).
  • SSNs are injected server-side during PDF generation only and are never included in AI tool call results, chat responses, or client-facing card UIs.
  • SSNs are never logged, cached, or stored in plaintext outside of the encrypted veteran profile.
  • If you do not wish to provide an SSN through the platform, you may leave the field blank and manually complete it on the generated PDF.

1.7 Payment Information

App Store subscription payments are processed by Apple. VeteranHQ receives signed transaction and subscription metadata needed to verify access, such as product and transaction identifiers, subscription status and period dates, and an account-binding token. We do not receive your Apple payment-card details. Direct web subscription payments are processed by Stripe, Inc.; for those subscriptions, we retain Stripe customer and subscription identifiers and status, along with limited card metadata returned by Stripe: the card brand, the last four digits, and the expiration month and year. VeteranHQ does not store, process, or have access to your full card number or CVV. Payment-provider handling is governed by Apple's Privacy Policy or Stripe's Privacy Policy, as applicable.

1.8 Usage Data & Analytics

We collect information about how you use VeteranHQ, including pages or API features used, searches performed, saved or dismissed items, session timing, last account activity, browser or app type, device type, IP address, user agent, and referring pages. Account-scoped interactions are linked to your VeteranHQ account so the service can preserve your preferences, secure your account, and personalize results. We use aggregated usage patterns for product analysis. We use Vercel Analytics and Vercel Speed Insights only for web performance monitoring.

1.9 Location Data

If you choose “Use My Location” in the iOS facility finder, the app sends your current latitude and longitude to VeteranHQ to find nearby VA facilities. The coordinates are included in operational request logs and a coordinate-based search cache is retained for up to twenty-four (24) hours. Location is linked to your signed-in account, used only to provide facility search, and is never used for advertising or cross-app tracking. Your state or ZIP-level location may also be stored with your veteran profile and used to personalize benefit and facility results. Location permission is optional.

1.10 Support Communications

If you contact support in the app or on the website, we retain the ticket subject, message, replies, status, and related account identifiers so we can respond, maintain continuity, and improve support operations.

1.11 Diagnostics & Performance

Our API retains operational telemetry such as request identifiers, route patterns, response status, response time, and sanitized error details. Production error monitoring samples performance traces at 10% and error events at 50%. Before error events are sent to Sentry, VeteranHQ removes request bodies, query values, cookies, authentication headers, IP headers, names, and email addresses. Sanitized events may retain an opaque user or request identifier so an incident can be investigated. We use this information only for security, reliability, debugging, and aggregate service analytics.

1.12 Cookies & Tracking Technologies

VeteranHQ uses the following tracking technologies: (a) Authentication cookies stored in your browser's localStorage (JWT access and refresh tokens) to maintain your login session; (b) Vercel Analytics for privacy-friendly, aggregated web analytics (no cross-site tracking, no personal data sold); (c) Vercel Speed Insights for page performance monitoring. We do not use third-party advertising cookies, retargeting pixels, or cross-site tracking technologies. We do not participate in ad networks or sell data to advertisers.

2. How We Use Your Information

We use the information we collect for the following purposes and no others:

  • Personalized Benefits Analysis: We use your veteran profile, uploaded documents, and VA.gov sync data to generate tailored benefits recommendations, identify potential secondary conditions, calculate estimated ratings, and surface programs you may qualify for.
  • AI-Powered Chat & Research: Your profile, documents, and conversation history are provided to AI models to generate contextual, personalized responses. Conversation history provides continuity across sessions.
  • Document Processing & Analysis: Uploaded documents are analyzed using AI tools to extract findings, identify opportunities, flag potential VA errors, and generate structured case briefings.
  • VA Form Generation: Your profile data and VA sync data are used to pre-populate VA form drafts for your review and completion.
  • Law Firm Client Services: When a veteran authorizes a law firm to access their data, we facilitate that access through scope-gated, audited, consent-tracked client relationships.
  • Service Improvement: We analyze aggregated, anonymized usage patterns and query analytics to improve the platform. Individual user data is never used in identifiable form for this purpose. We do not use your data to train third-party AI models.
  • Billing & Account Management: We use your account information to manage your subscription, process billing events, and send transactional communications about your account status.
  • First-Party Retention Communications: An authorized administrator may use your name, email address, and canceled-subscription status to send a VeteranHQ follow-up or win-back message. We do not provide this information to third-party advertisers or use it for cross-app tracking.
  • Security & Fraud Prevention: We use login attempt data, IP addresses, and usage patterns to detect and prevent unauthorized access, abuse, and fraudulent activity.
  • Legal Compliance: We may use or disclose information as necessary to comply with applicable law, legal process, or enforceable government request.

3. Health Information & HIPAA Compliance

3.1 Nature of Health Information

VeteranHQ processes information that may constitute Protected Health Information (“PHI”) as defined under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), including veteran medical conditions, disability ratings, C&P exam results, medical records, and service-connected health data.

3.2 HIPAA Compliance Posture

VeteranHQ maintains administrative, technical, and physical safeguards consistent with the HIPAA Security Rule (45 CFR Part 160 and Subparts A and C of Part 164) and the HIPAA Privacy Rule (45 CFR Part 160 and Subparts A and E of Part 164). Our infrastructure runs on BAA-covered Amazon Web Services (AWS), including AWS Lightsail (compute), AWS S3 (object storage), and AWS Bedrock (PHI-safe AI embeddings). A Business Associate Agreement with AWS is in effect, as is a Business Associate Agreement with Anthropic for AI model processing.

Scope of HIPAA applicability for individual veteran users (B2C): When an individual veteran uses VeteranHQ directly — without a law firm or healthcare provider intermediary — VeteranHQ is not acting as a Business Associate under HIPAA, because there is no upstream HIPAA covered entity in that data flow. In these direct-to-consumer interactions, VeteranHQ applies HIPAA Security Rule safeguards as a matter of policy, not as a legal obligation under HIPAA itself. Your information is still protected under this Privacy Policy, applicable state privacy laws (including the CCPA/CPRA for California residents), and Section 5 of the FTC Act. The safeguards we describe in this section — encryption, access controls, audit logging, breach notification — apply to all user data regardless of HIPAA applicability.

3.3 Business Associate Relationships

When VA-accredited law firms (as Covered Entities or Business Associates under HIPAA) use the VeteranHQ B2B platform to process veteran client PHI, VeteranHQ functions as a Business Associate. VeteranHQ maintains Business Associate Agreements with applicable vendors and is prepared to execute BAAs with law firm clients upon request. Law firms requiring a BAA should contact legal@veteranhq.app.

3.4 PHI Safeguards

  • Encryption at Rest: All PHI is encrypted using AES-256-GCM at the application layer (veteran profile fields, individual ratings, deployments, MOS, state, ZIP). C-File content and documents are encrypted in AWS S3 with server-side encryption.
  • Encryption in Transit: All data transmission uses TLS 1.3. Non-HTTPS connections are rejected.
  • Access Controls: Role-based access control (RBAC) with four user roles and organization-level roles. Scope-gated data filtering enforces the Minimum Necessary standard (HIPAA §164.502(b)).
  • Audit Trail: Every access to PHI is logged in an append-only audit log including actor identity, action type, resource accessed, IP address, user agent, and timestamp (HIPAA §164.312(b)).
  • Consent Tracking: Veteran consent for law firm data access is recorded with timestamp, IP address, user agent, and specific scopes granted (HIPAA §164.508).
  • Patient Rights: Veterans can view all entities with access to their data and revoke access at any time through the Settings > Privacy page (HIPAA §164.524).
  • PHI-Safe AI Processing: C-File content is embedded using AWS Bedrock Titan (BAA-covered). Non-PHI regulatory content uses separate embedding services.
  • Session Security: Authentication sessions expire after inactivity. Failed login attempts trigger exponential account lockout (5 failures: 15 minutes, 10 failures: 1 hour, 15+ failures: 24 hours).

3.5 B2B Business Associate Posture and Flow-Down Obligations

When VeteranHQ functions as a Business Associate to a VA-accredited law firm or other HIPAA covered entity or business associate (our “B2B customers”), we are subject to all obligations of a Business Associate under 45 CFR §164.504(e), including the obligation to flow down Business Associate Agreement requirements to our own subcontractors that create, receive, maintain, or transmit PHI on our behalf.

In accordance with §164.504(e)(5), VeteranHQ has executed downstream Business Associate Agreements with the subcontractors that process PHI on our behalf: Amazon Web Services, Inc. (compute, storage, and AI embedding services) and Anthropic, PBC (AI model inference via Anthropic's 1P API with Zero Data Retention). PHI is not transmitted to any subcontractor or service provider acting on our behalf that is not covered by a Business Associate Agreement. Any future subcontractor that would create, receive, maintain, or transmit PHI will not be engaged until a Business Associate Agreement is fully executed. This commitment governs providers we engage to process data on our behalf; it is distinct from a disclosure you yourself initiate to an outside service of your choosing, which is described in Section 3.6.

Law firm customers who require a Business Associate Agreement with VeteranHQ should contact legal@veteranhq.app. Our downstream BAA template is available for review on request.

3.6 AI Assistant Connections You Initiate

VeteranHQ offers an optional connector that lets you link an outside AI assistant of your choosing to your VeteranHQ account, so that assistant can answer questions using your own claim information. This is off by default. Nothing is shared with any AI assistant unless you connect one, and you choose which assistant to connect.

What this means for your information: when you connect an AI assistant, the information you choose to share leaves VeteranHQ's systems and is received by that AI provider under that provider's own terms and privacy policy, not this one. We may not have a Business Associate Agreement with the provider you select, and some providers do not offer one for their consumer products. This is a different arrangement from the subcontractors described in Section 3.5: those providers process data on our behalf under our contracts, while an AI assistant you connect receives your information at your direction, as a recipient you selected. We tell you which provider you are connecting, and what categories of information it will be able to read, before the connection is made.

Scope: the connector reads only your own VeteranHQ account information, and only in the direct-to-consumer posture described in Section 3.2, where there is no upstream HIPAA covered entity in the data flow. It is read-only: it cannot write to, change, submit, or file anything, whether with VeteranHQ or with VA. Access requires your affirmative consent, which we record with a consent version, timestamp, and the scopes granted, and every read through the connector is written to the audit log described in Section 3.4.

Disconnecting, and what it does not undo: you can disconnect an AI assistant at any time from Settings, which immediately stops any further sharing. Disconnecting does not retrieve information that was already sent. What the provider retains after that point is governed by that provider's own retention and deletion controls, and information already contained in a conversation you had with that assistant generally remains in that conversation until you delete it with the provider. Please review the privacy policy of any AI assistant before you connect it.

4. Law Firm Access to Veteran Data

When a law firm invites a veteran to connect through VeteranHQ and the veteran accepts:

  • A Client Relationship is created with specific data scopes (profile, claims, VA syncs, documents, chat) that the veteran explicitly authorized.
  • The law firm can access only the data categories within the granted scopes. Empty or ungranted scopes return no data (fail-closed).
  • All law firm access to veteran data is logged in the PHI audit trail with the accessor's identity, action, IP address, and timestamp.
  • Client Relationships expire by default after one (1) year and must be renewed (SOC 2 CC6.1 alignment).
  • The veteran retains full control and may revoke attorney access at any time through Settings > Privacy, effective immediately.
  • No veteran data is duplicated into the law firm's account. The firm reads data from the veteran's account through the authorized relationship. Revoking access severs the connection completely.

Law firms are independently responsible for their own HIPAA compliance, data handling practices, and professional obligations with respect to any data they access, download, or export from VeteranHQ.

5. Third-Party Service Providers (Sub-Processors)

We engage the following categories of third-party service providers to operate VeteranHQ. All providers are bound by contractual obligations restricting their use of your data to providing services to VeteranHQ only. For a concise compliance-posture summary including BAA dates and PHI-handling status, see the Security & Trust page.

Amazon Web Services (AWS) — Infrastructure

Compute (Lightsail), object storage (S3), and PHI-safe AI embeddings (Bedrock Titan). All services are BAA-covered. Data resides in the us-east-1 (N. Virginia) region. AWS BAA is in effect.

Anthropic — AI Chat & Analysis

Anthropic AI models power the AI chat advisor, document analysis, and case briefing features. A Business Associate Agreement with Anthropic is in effect. All PHI is processed via Anthropic's 1P API with Zero Data Retention (ZDR) enabled — no prompts or outputs are stored by Anthropic. Anthropic's API does not use customer inputs for model training.

OpenAI — RAG Embeddings (Non-PHI Only)

Text embeddings for non-PHI regulatory content (38 CFR, M21-1 policy, state benefit descriptions). PHI content (C-Files, veteran-specific data) is processed through AWS Bedrock, not OpenAI.

Apple: In-App Purchase Processing

App Store subscription billing and payment processing. VeteranHQ receives signed transaction and subscription metadata to verify membership access but never receives raw Apple payment-card data. Governed by Apple's Privacy Policy and applicable App Store terms.

Stripe, Inc. — Payment Processing

Direct web subscription billing and payment processing. PCI DSS Level 1 certified. VeteranHQ never handles or stores raw payment card data. Governed by Stripe's Privacy Policy and Terms of Service.

Vercel — Frontend Hosting

Static frontend hosting and CDN. Vercel serves JavaScript, CSS, and HTML files only. No PHI passes through Vercel — all PHI flows directly between the user's browser and the VeteranHQ API on AWS. Vercel Analytics collects anonymized, aggregated performance data.

Resend: Email Delivery

Email delivery for account verification, password reset, subscription notifications, and administrator-authorized first-party follow-up or win-back messages. Emails contain no PHI by design, only account information such as verification codes, reset links, name, email address, and billing status.

Sentry — Error Monitoring

Application error and performance telemetry for debugging and reliability. Sentry receives sanitized stack traces, error messages, route patterns, request IDs, and non-PHI metadata. Request bodies, query values, cookies, authentication headers, IP headers, names, and email addresses are scrubbed server-side before error events are transmitted. Sanitized events may retain an opaque user or request identifier. Sentry operates under its own privacy and security program; no Business Associate Agreement is in place because no PHI is transmitted by design. Performance traces are sampled at 10% and error events at 50%.

Slack — Internal Engineering Notifications

VeteranHQ engineering uses Slack to receive operational alerts (deploys, error summaries, billing events, support pings). Messages sent to Slack are sanitized server-side to strip PHI before transmission; outbound payloads contain only user IDs, error codes, and non-PHI operational metadata. No Business Associate Agreement is in place because no PHI is transmitted. Slack is used exclusively for internal engineering, not for customer data processing.

Clio & DocuSign (Law Firm Integrations)

Optional integrations activated by law firm users. Clio: read-only sync of contacts, matters, and calendar. DocuSign: fee agreement e-signature. Data exchange occurs only when the law firm explicitly connects and authorizes the integration.

We do not sell, rent, or trade your personal information to any third party for marketing, advertising, or any purpose unrelated to providing the VeteranHQ service. We do not share your data with data brokers. We do not participate in ad networks.

6. Data Retention

We retain your data in accordance with the following schedule:

  • Active Account Data: Documents, chat messages, profile information, and VA sync data are retained for the duration of your active account. You may request deletion of specific items at any time.
  • Account Deletion: Upon account deletion, all personal data — including uploaded documents, chat history, profile information, and VA sync data — is permanently removed from our active systems within thirty (30) days.
  • Audit Logs: PHI access audit logs are retained for a minimum of six (6) years as required by HIPAA regulations (45 CFR §164.530(j)), even after account deletion. Audit logs contain only access metadata (who accessed what, when, from where) — not the underlying PHI content.
  • Query Analytics: Anonymized, aggregated query analytics are retained for ninety (90) days and then automatically purged.
  • Facility Search Cache: Coordinate-based facility search cache entries are retained for up to twenty-four (24) hours. Operational request logs containing facility-search parameters follow the service logging and security-retention controls described in this policy.
  • Backups: Encrypted database backups are retained for thirty (30) days on a rolling basis and then deleted.
  • Anonymized Data: Anonymized, aggregate data that is not linked to your identity and cannot be re-identified may be retained indefinitely for service improvement and statistical analysis.

6.1 Dormant / Inactive Accounts

To minimize the personal data we hold, we apply a graduated retention schedule to inactive individual (B2C) veteran accounts. We measure activity by the most recent of any sign-in, any data sync from the VeteranHQ browser extension, or your account creation date — so an account whose extension is syncing is never treated as inactive, even without an interactive login.

  • Reminders (around 12 and 18 months of inactivity): We email you to let you know your account and saved analysis are still here. No data is changed.
  • Data reduction (around 24 months of inactivity): After a final-warning notice period, we remove the VA data synced from VA.gov to your account (claims, ratings, payments, appeals, and similar). Your account is not deleted at this stage, your uploaded documents are retained, and you can re-sync your VA data by signing back in and reconnecting the extension on a plan that includes VA sync.
  • Account deletion (around 48 months of inactivity): If the account remains inactive, it and its remaining personal data are permanently deleted on the same 30-day timeline described under “Account Deletion” above. Audit logs are retained for the period stated above.

Signing in at any time stops this process and restores your account to active status, cancelling any scheduled data reduction or deletion. This schedule does not apply to accounts with an active paid subscription, accounts connected to a law firm through an authorized relationship, or accounts subject to a legal hold. We will not delete account data while final-warning emails to your address are undeliverable.

To request deletion of your data, use the account deletion feature in Settings or contact us at support@veteranhq.app.

7. Data Security

We implement administrative, technical, and physical safeguards designed to protect your data:

7.1 Technical Controls

  • All data in transit encrypted via TLS 1.3 (HTTPS enforced, HSTS enabled with preload)
  • Sensitive data at rest encrypted with AES-256-GCM at the application layer
  • Object storage (S3) encrypted with server-side encryption (SSE-S3)
  • Passwords stored using bcrypt with a work factor of 12 (never plaintext, never recoverable)
  • JWT-based authentication with short-lived access tokens and refresh token family rotation (replay detection)
  • Exponential account lockout on failed login attempts
  • Input validation on all API endpoints (Zod schema enforcement)
  • CSP, HSTS, X-Frame-Options, and other security headers enforced via Helmet
  • Rate limiting across all endpoints with per-route profiles
  • SSH key-based server access only (no password authentication)

7.2 Operational Controls

  • Role-based access control with principle of least privilege
  • Append-only audit logging of all PHI access
  • Automated health monitoring with self-healing restart on failure
  • Daily encrypted database backups to separate AWS storage
  • Structured logging with automatic redaction of sensitive fields (passwords, tokens, API keys)
  • Error and performance monitoring with Sentry (10% performance traces, 50% error events, no PHI in telemetry)

No system is 100% secure. While we implement industry-standard and HIPAA-aligned safeguards, we cannot guarantee absolute security against all threats. In the event of a security incident, we will follow our breach notification procedures (see Section 11). If you believe your account has been compromised, contact us immediately at support@veteranhq.app.

8. Your Rights

You have the following rights with respect to your personal information. These rights apply regardless of your state of residence, and we honor them for all users:

Access

You may request a copy of all personal information we hold about you, including your profile data, uploaded documents, chat history, VA sync data, and audit logs pertaining to your data.

Deletion

You may request deletion of your account and all associated personal data at any time. Deletion will be completed within 30 days, subject to audit log retention requirements.

Correction

You may update, correct, or amend your personal information at any time through your account settings, profile editor, or by contacting support.

Export

You may request a machine-readable export of your personal data (JSON format), including your profile, documents, chat history, and VA sync data.

Restriction

You may restrict processing of your data by revoking attorney access, deleting specific documents or conversations, or downgrading your account.

Revocation

If you have authorized a law firm to access your data, you may revoke that authorization at any time through Settings > Privacy, effective immediately.

Opt-Out

You may opt out of non-essential communications at any time. Transactional communications (billing, security, account) cannot be opted out of while your account is active.

Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights. Exercising your rights will not result in a different price, quality, or level of service.

To exercise any of these rights, contact us at privacy@veteranhq.app. We will verify your identity and respond within thirty (30) days. If we need additional time, we will notify you of the reason and extension period (not to exceed an additional 60 days).

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA”), provides you with additional rights regarding your personal information.

9.1 Categories of Information Collected

In the preceding 12 months, we have collected the following categories of personal information: (A) Identifiers (name, email, account ID); (B) Personal information under Cal. Civ. Code §1798.80(e) (name, SSN if voluntarily provided for form generation); (C) Protected classification characteristics (veteran status, military branch); (D) Internet or network activity (usage data, browsing on VeteranHQ); (E) Professional information (MOS, service dates, service component); (F) Sensitive personal information (SSN, health-related information including disability ratings and medical conditions, precise geolocation via ZIP code).

9.2 We Do Not Sell or Share Your Personal Information

VeteranHQ does not sell your personal information as defined by the CCPA. VeteranHQ does not share your personal information for cross-context behavioral advertising. We have not sold or shared personal information in the preceding 12 months.

9.3 Your CCPA Rights

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of personal information we have collected, subject to certain exceptions (legal obligations, audit log retention).
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Limit Use of Sensitive Personal Information: You may request that we limit our use of sensitive personal information to that which is necessary to perform the services.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To submit a CCPA request, email privacy@veteranhq.app with the subject line “CCPA Request.” We will verify your identity using your account email and respond within 45 days.

10. Additional State Privacy Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with consumer privacy laws may have additional rights, including the right to access, correct, delete, and obtain a portable copy of their personal data, and the right to opt out of targeted advertising, profiling, and sale of personal data.

VeteranHQ does not engage in targeted advertising, profiling for decisions that produce legal or similarly significant effects, or sale of personal data. Accordingly, opt-out rights for these activities are not applicable.

To exercise any rights under your state's privacy law, contact privacy@veteranhq.app. If you are not satisfied with our response, you may contact your state's attorney general.

11. Data Breach Notification

In the event of a security breach that compromises the confidentiality, integrity, or availability of your personal information, VeteranHQ will:

  • Investigate promptly: We will conduct an immediate investigation to determine the scope and impact of the breach.
  • Notify affected users: We will notify affected users without unreasonable delay and in no case later than sixty (60) calendar days after discovery of a breach of unsecured PHI, in accordance with 45 CFR §164.404. Where operationally feasible, we aim to notify within seventy-two (72) hours of confirmed discovery. Nothing in this Policy shall be construed to reduce VeteranHQ's obligations under HIPAA, state breach notification laws, or other applicable law.
  • Notify regulators: Where required by law, we will notify applicable regulatory authorities, including the HHS Secretary for HIPAA-covered breaches affecting 500 or more individuals.
  • Provide details: Breach notifications will include: a description of the incident, the types of information involved, the steps we are taking to address the breach, and recommended actions you can take to protect yourself.
  • Remediate: We will take all reasonable steps to contain the breach, prevent recurrence, and mitigate harm to affected individuals.

If you believe your data has been compromised, contact us immediately at security@veteranhq.app.

12. International Users

VeteranHQ is operated from the United States and is intended primarily for users located in the United States. If you access VeteranHQ from outside the United States (including military personnel stationed overseas), your data will be transferred to and processed in the United States.

By using VeteranHQ, you consent to the transfer of your data to the United States. The United States may not provide the same level of data protection as your home jurisdiction. We apply the same security safeguards described in this policy to all user data regardless of the user's location.

VeteranHQ does not specifically target users in the European Economic Area (EEA), United Kingdom, or other jurisdictions that require a specific legal basis for processing under GDPR or equivalent legislation. If you believe you have rights under such legislation and wish to exercise them, contact privacy@veteranhq.app.

13. Children's Privacy

VeteranHQ is intended for adults aged 18 and older. We do not knowingly collect, solicit, or maintain personal information from anyone under the age of 18. If you believe we have inadvertently collected information from a minor, please contact us immediately at privacy@veteranhq.app and we will promptly delete it.

14. Do Not Track Signals

Some browsers transmit “Do Not Track” (DNT) signals. As there is no industry-standard protocol for DNT signals, VeteranHQ does not currently respond to DNT signals. However, as described in Section 1.9, we do not engage in cross-site tracking, third-party advertising tracking, or retargeting, and we do not sell personal information to third parties.

15. AI-Specific Data Practices

VeteranHQ uses third-party AI models to power chat responses, document analysis, and case briefings. The following practices govern AI data handling:

  • No Training on Your Data: Your data (chat messages, documents, profiles) is not used to train, fine-tune, or improve third-party AI models. Our AI provider's API usage terms prohibit the use of API inputs and outputs for model training.
  • Prompt Caching: VeteranHQ uses AI prompt caching to improve response speed and reduce cost. Cached prompts contain your veteran profile context (encrypted in transit) and are ephemeral — they exist only within your active session.
  • AI Outputs: AI-generated outputs (analyses, recommendations, form drafts, case briefings) are stored as part of your chat history and are subject to the same retention, encryption, and deletion policies as all other user data.
  • Human Review: VeteranHQ may review anonymized, aggregated conversation patterns (with no individually identifiable information) to improve the quality of AI responses. We never review individual conversations except at your request (e.g., for a support ticket) or as required by law.

15.1 Connecting Your Own AI Assistant (MCP Connector)

VeteranHQ offers an optional connector, built on the Model Context Protocol (MCP), that lets you attach an AI assistant of your choosing (such as Claude) to your VeteranHQ account so it can read your VA claim and rating data on your behalf. The connector is off by default. It activates only after you turn it on in Settings and acknowledge a specific, versioned consent disclosure that lists the categories of data your AI client will be able to read. If the wording of that disclosure ever changes, your earlier approval stops counting and we ask you to decide again before any further access. Only a verified, active VeteranHQ account can open a connector session.

When the connector is on, and each time your AI client asks, VeteranHQ sends data from the following categories:

  • Your name, email, and service history (branch, dates, MOS, deployments)
  • Your combined rating, and each condition's rating, diagnostic code, and effective date
  • Your claim status, claim details, milestones, and evidence lists
  • Denied and deferred conditions, and any appeals
  • Your VA payment history, including dates and amounts
  • Your dependents
  • Your document titles, types, and the AI-written summaries of what is in them

This data includes health-related information, such as your rated conditions and disability ratings. Your uploaded files and their full text, and your Medical Vault, never go through the connector. The connector is read-only end to end: it publishes no tool that can change, add, delete, or submit anything on your account or with the VA.

Every read of your record through the connector is recorded in the append-only PHI audit log described in Section 3.4. Connector access tokens expire after ninety (90) days. Your token is shown to you once and is never stored by VeteranHQ; only its identifier appears in our logs. You can turn the connector off at any time in Settings, which immediately invalidates every token you have created, with no waiting period.

The AI client you connect is your own choice and is not a VeteranHQ sub-processor. Once your data reaches your AI client, it is held in that conversation under your agreement with that AI provider, not under this Privacy Policy. We cannot delete it there, we cannot see how it is used, and our encryption and retention rules do not follow it. No Business Associate Agreement between VeteranHQ and its vendors covers the AI client you choose to connect. Connect only a client you trust, and only for as long as you need it. For a plain-language walkthrough of what the connector can and cannot do, see the Connector page.

16. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will: (a) update the effective date at the top of this page; (b) notify you via email at least thirty (30) days before the changes take effect; and (c) where required by law, obtain your consent before implementing changes that materially affect the processing of your data. Your continued use of VeteranHQ after the effective date of an updated Privacy Policy constitutes your acceptance of the changes. If you do not agree, you must stop using the service and may request deletion of your data.

17. Business Transfers, Change of Ownership, and Business Discontinuation

If VeteranHQ is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, your information may be transferred as part of that transaction. In any such event:

  • Any successor entity will be contractually bound to honor the commitments in this Privacy Policy, or to provide privacy protections at least as protective as those described here;
  • You will be notified by email and through an in-app notice at least thirty (30) days before your information becomes subject to a different privacy policy;
  • You will have the opportunity to export or request deletion of your data prior to the transfer.

If VeteranHQ ceases operations without a successor entity, we will securely delete all veteran data — including VA claims information and personally identifiable information — using industry-standard methods, and will provide at least thirty (30) days' advance notice and a window for you to export your data beforehand.

All veteran data remains encrypted (AES-256-GCM at rest) throughout any such transition.

18. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy or how we handle your data, please contact us:

VeteranHQ, a product of Silicon Vanguard LLC

2108 N St Ste N
Sacramento, California 95816
United States

General Support: support@veteranhq.app

Privacy Requests: privacy@veteranhq.app

Security Issues: security@veteranhq.app

Legal & BAA Requests: legal@veteranhq.app