Skip to main content

Privacy Policy

Last updated: September 6, 2026

The short version

  • Free tools: your records are processed in your browser and never stored on our servers.
  • Paid plans: your case is saved encrypted (HIPAA-grade AWS storage) so you don't lose progress — delete it anytime with Start Over.
  • We never sell your information or use it to train AI.
  • Nothing goes to VA unless you or your representative sends it. Where a document is submitted to VA through this platform, it is at the direction of the person filing, and we act only as the courier.
  • Questions or deletions: support@vaclaimcommander.com.

This summary is for quick reading. The full policy below is the authoritative version.

1. Who We Are

VA Claim Commander is a software tool that helps veterans prepare documentation for VA disability claims. We are not a healthcare provider, health plan, or healthcare clearinghouse. We are not a covered entity under the Health Insurance Portability and Accountability Act (HIPAA).

Even though HIPAA does not require it of us, we hold ourselves to HIPAA-aligned safeguards throughout — because the medical information you share deserves that level of care. In the free veteran flow your records are processed in your browser and are not stored on our servers at all; and where you ask us to store information on your behalf, it is encrypted and held under a HIPAA Business Associate Agreement (BAA) with our infrastructure provider (see Sections 5a and 5b).

1a. What's Free

Veterans can build a claim and generate a complete personal statement, nexus letter draft, and buddy statement drafts at no cost, with no card required. Downloading, printing, sending a document for signature, or generating a full claim package requires a paid plan.

2. What Information We Process

When you use VA Claim Commander, you may upload or enter:

  • Military service records (DD-214, OMPF, STRs)
  • Personal medical records, lab results, and clinical notes
  • Personal identifying information (name, date of birth, last 4 digits of SSN, address)
  • VA rating decisions and correspondence
  • Contact details for people you name as witnesses (name, email, and the relationship they have to you) so we can send them a statement request on your behalf, and — in Commander for Advocates — the contact details of the representative's clients
  • Your account email address, and payment records held by Stripe (we never see or store card numbers)

We do not collect precise geolocation, your device's contacts, biometric data, or genetic information. Our servers see your IP address in the course of serving requests, as every website does; it is kept in short-lived server logs and is not linked to your records. If a record you upload mentions a family member's medical or family history, it is handled exactly like the rest of your records — used only to prepare your claim, never shared, and deleted with the rest.

You are uploading your own records for the purpose of generating your own VA disability claim documents. This is your information, and you are choosing to share it with this tool.

3. How Your Information Is Used

Your uploaded documents and entered information are used exclusively to:

  • Generate nexus letters, personal statements, buddy statements, and cover letters for your VA claim
  • Map your documented symptoms to the rating criteria your statements address, and prepare you for the C&P exam
  • Analyze your records to identify conditions and suggest secondary claim opportunities

We do not sell your information, for money or for anything else. We do not share it with marketers, data brokers, or partners. We do not use your health or claim information to target advertising to you or anyone else. We do not share de-identified, anonymized, or pseudonymized versions of your records with any third party; the only statistics we keep are aggregate product counts (for example, how many documents were generated in a month) that contain no record content. Every third party that processes your information is a service provider working for us under a written agreement (Section 4), and none of them may use or disclose it for any purpose of their own — including attempting to re-identify anyone — without your consent.

4. Third-Party Services That Process Your Information

VA Claim Commander uses a small number of third-party services for AI processing, document reading and search, hosting and storage, authentication, payment, email, and error monitoring. Each one is under a written agreement (its API or service terms, and where the service handles health information, a HIPAA Business Associate Agreement) that limits it to providing the service to us. None of them is permitted to sell your information or use it to train AI models. Your information is transmitted to or stored by the following services:

  • Anthropic (AI provider) — When you generate documents, your claim content — including your conditions, service history, symptoms, and any information you entered — is transmitted to Anthropic's Claude API for AI processing. This is the most sensitive data flow in the application. Anthropic does not use API inputs or outputs to train their models (per their API Terms of Service). Under standard API terms, Anthropic may retain API inputs and outputs for up to 30 days for safety and abuse monitoring. We have not enabled zero-data-retention (ZDR) options at this time — if that changes, this policy will be updated. Anthropic's privacy policy governs their handling of this data.
  • Voyage AI (record search) — So a representative or a veteran can search a file and ask questions of it, the text of uploaded records is sent to Voyage AI's embeddings API, which turns each page into a numeric index used to find the relevant pages. Under Voyage AI's terms we have opted out of its use of customer content for model training (effective September 6, 2026): text sent since then is deleted by Voyage AI immediately after it is processed and is not used to train its models. Voyage AI does not disclose customer content to third parties other than its own sub-processors. Voyage AI's privacy policy governs their handling of this data.
  • Amazon Web Services (AWS) — The Commander for Advocates and Commander Health products run on AWS. Stored records and generated documents live in encrypted AWS storage and databases under a HIPAA Business Associate Agreement (see Sections 5a, 6, and 8b). Scanned pages that contain no readable text are read with Amazon Textract, AWS's optical character recognition service, so the file can be searched; the page image is sent to Textract for that purpose only.
  • Department of Veterans Affairs (VA) — When an accredited representative using Commander for Advocates chooses to submit a document package to VA through this platform, the selected documents and the veteran's identifying details required by VA (name, VA file number or Social Security number, and ZIP code) are transmitted to VA's Benefits Intake API, and VA's receipt and processing status are stored with the case. This happens only at the representative's explicit direction, document by document; nothing is sent to VA automatically. VA's own privacy rules govern the records once received.
  • Resend (email) — Account, intake, and notification emails (for example, the secure intake link a representative sends a veteran, or a deadline digest) are delivered through Resend, which receives the recipient's email address and the message. Medical records and document content are never sent by email.
  • Sentry (error monitoring) — When the application encounters an error, a report describing the error is sent to Sentry so we can fix it. Reports are scrubbed of record content and identifying fields before they leave our servers.
  • Vercel — Our public website and the free veteran flow are hosted on Vercel's infrastructure. Vercel processes API requests and retains server logs (which may include file names and request metadata) per their data retention policies. Vercel does not store your document content.
  • Clerk — We use Clerk for user authentication. Clerk stores your sign-in credentials (email address and authentication identity) on their servers. Your Clerk account persists until you delete it. Clerk's privacy policy governs their handling of this data.
  • Stripe — We use Stripe to process payments. When you make a purchase, Stripe stores transaction records (purchase amount, date, and payment method metadata — not full card numbers) on their servers. Stripe's privacy policy governs their handling of this data.

Your medical records and claim document content are transmitted securely over HTTPS and are not permanently stored on our servers. Document content processed through our API exists only for the duration of the request.

5. Data Storage

For veterans using the free direct-to-consumer flow, VA Claim Commander does not maintain a database of your medical records or claim documents on our servers. Your data is stored as follows:

Note: the Commander for Advocates (Pro) product and Commander Health store information server-side — see Section 5a and Section 8b. Commander Health stores structured clinical summaries with veteran consent.

  • Browser session storage (cleared when you close the tab or browser) — Your uploaded documents, generated claim materials, and active session state are stored in your browser's session storage. This clears automatically when your session ends.
  • Browser local storage (persists until you clear it) — Your form data — veteran information, conditions, and intake answers — is stored in your browser's local storage so you can return to an in-progress claim. Click "Start Over" to clear this data, or clear your browser data manually.
  • In transit — When you generate documents, your data is transmitted to our servers and to Anthropic for processing, then discarded from our servers when the request completes.
  • Clerk (sign-in account) — Your account credentials (email address and authentication identity) are retained on Clerk's servers until you delete your account.
  • Stripe (payment records) — If you make a purchase, Stripe retains transaction records on their servers per their data retention policies.

5a. Commander for Advocates (Pro) — Server-Side Client Records

The Commander for Advocates product, used by accredited representatives (VSO officers and claims agents) to manage their clients, works differently from the free veteran flow above. So a representative can manage a veteran's case over time, the following is stored on our servers, strictly isolated to the representative's organization:

  • Client records — the veteran's name and contact details, with sensitive identity fields (date of birth and the last four digits of the SSN) encrypted at rest using AES-256-GCM.
  • Documents the representative uploads — such as VA decision letters, claims files (C-files), medical and service records, and prior evidence — stored in encrypted object storage to support the veteran's claim. Document storage is an organization-level setting the representative controls and can turn off.
  • Work product for each client — generated documents, the veteran's and witnesses' signed statements, claimed conditions, tasks, and deadlines.
  • Submissions to VA, at the representative's direction — when the representative chooses to submit a document package to VA through the platform, a record of what was sent (which documents, when, and VA's receipt and status) is kept with the case, so the file shows exactly what VA received. The platform transmits only what the representative selected, and only when they choose to send it; the representative remains the filer of record.
  • Records packets for a reviewing clinician — when the representative chooses to send records to a clinician (Commander Health or a provider of their own), the platform assembles only the records the representative selected into one packet, keeps a copy with the case, and delivers it to the representative to pass on. Nothing is sent to any clinician without the representative choosing it.

This information is retained until the representative deletes the document or client, or closes the account, and is held on infrastructure operated under HIPAA Business Associate Agreements (BAAs) with our infrastructure providers. A veteran whose representative uses this product may contact us at support@vaclaimcommander.com with questions about data held on their behalf.

5b. Saved Veteran Account (Paid Plans)

On a paid veteran plan, we save the case information you enter — your service details, the conditions you're claiming, your statements, your witnesses' information, and the documents you generate — to your account so your work follows you across devices and over the months a VA claim can take. This saving is on by default on paid plans so you never lose your progress; we protect it quietly rather than asking you to manage a setting.

  • What we store — the case information you provide to build and track your claims, the documents we draft for you, and — so your records follow you to a new device without re-uploading — the text we read from the records you upload (the words on the page, never the PDF files themselves, which stay in your browser). We do not sell any of it, and we do not use it to train AI models.
  • Where it's stored — encrypted, access-controlled storage operated under a signed HIPAA Business Associate Agreement (BAA) with Amazon Web Services (AWS) (the same infrastructure that protects Commander Health records), encrypted at rest and in transit.
  • AI processing — when you ask us to draft a document, the relevant text is sent to our AI provider for processing and is not used to train AI models.
  • You stay in control — the way to turn saving off is to delete your data. Click "Start Over" in the app to permanently erase your saved case — including the records text — at any time, or email support@vaclaimcommander.com to delete your account and permanently purge all associated data (see Section 8, Your Rights). If you cancel your plan, we keep your case for 60 days so you can return, then permanently delete it.
  • De-identified information — with your permission, de-identified (non-identifying) information may be used to improve the tool. This is never your identifiable records.

Without cloud save, the flow is unchanged. Unless your case is saved to your account as described above, nothing you enter is stored on our servers — your records are processed in your browser and discarded after each request (see Section 5).

6. Security

We implement appropriate technical safeguards including:

  • HTTPS encryption for all data transmission
  • Access controls requiring a password to use the application
  • In the free veteran flow, no permanent server-side storage of medical records (records are processed in your browser and discarded after the request)
  • For Commander for Advocates and Commander Health, encryption at rest and strict organizational isolation for stored records (see Sections 5a and 8b)

No method of transmission over the internet is 100% secure. You use this service at your own risk and should exercise care about what documents you upload.

Commander for Advocates — encryption & Business Associate Agreements

VSO officers and accredited claims agents are not covered entities under HIPAA. We've built Commander for Advocates with the technical safeguards HIPAA requires: AES-256-GCM encryption on sensitive identity fields, encrypted object storage for the documents a representative uploads, strict organizational data isolation, and access controls. The records and documents a representative stores (see Section 5a) are encrypted at rest and can be deleted by the representative at any time.

7. Cookies, Analytics & Tracking

We use a small number of third-party analytics services to understand how visitors find and use the site — and whether our advertising leads to a sign-up — so we can improve them. These services may set cookies or use similar technologies. They are page-level analytics only — we never pass your medical records, claim content, document text, or the identifying information you enter into any analytics service.

  • Google Analytics 4 — measures aggregate traffic and page views (for example, which pages visitors land on and how they navigate the site). Governed by Google's privacy policy.
  • Microsoft Clarity — helps us see how pages are used (clicks and navigation patterns) so we can fix confusing layouts. Sensitive input fields, uploaded documents, and generated document previews are masked and are not captured. Governed by Microsoft's privacy policy.
  • Meta Pixel — measures the performance of our advertising so we can reach veterans who may need this tool. It records that a page was viewed; it is not passed your claim content or medical information. Governed by Meta's privacy policy.
  • Google Ads conversion tracking — Google's advertising tag (gtag.js). It records page views and a single "sign-up" event so we can measure whether an ad led a veteran to create a free account. Because a sign-up completes inside the app, this tag also loads on signed-in pages, not only marketing pages; even there it is passed only the page address and title — never your medical records, claim content, document text, or the information you enter. Governed by Google's privacy policy.

You can limit or block these technologies using your browser's cookie and privacy controls, browser extensions that block trackers, or your device's "Do Not Track" / opt-out settings. Blocking them does not affect your ability to use VA Claim Commander. Analytics services are used to improve the product and our outreach — never to sell your information (see Section 3).

7a. How Long We Keep Your Information

  • Free veteran flow — nothing is kept on our servers. Your records exist in your browser and in the request that generates a document, and are discarded when that request completes.
  • Paid veteran plan — your saved case is kept until you delete it or close your account. If your account is dormant for 24 months (no sign-in), we email you, and if we hear nothing within 30 days we delete the saved case and its documents.
  • Commander for Advocates — a client's records and work product are kept until the representative deletes the document or client, or the organization closes its account. An organization that has been dormant for 24 months is emailed, and absent a reply within 30 days its stored records are deleted.
  • Commander Health — your clinical summary is kept for the duration of your case plus 90 days (Section 8b).
  • Account and billing records — your sign-in identity is kept by Clerk until you delete your account; Stripe keeps transaction records for the period required by tax and payment rules.
  • Backups — encrypted database backups are kept for 7 days and then expire, so deleted information leaves backups within 7 days of deletion.

7b. Deleting Your Information

You can have 100% of your information deleted — VA-related and not — at any time. Deletion is permanent and complete; it is not merely hidden.

  • Your claim work (free flow) — click "Start Over" in the application, or clear your browser data.
  • Your whole account (veterans) — open Account in the application and choose "Delete my account". You will be asked to type DELETE to confirm. This immediately and permanently erases your saved case, generated documents, witness requests, and sign-in identity.
  • A client's records or an organization account (Commander for Advocates) — a representative deletes documents and clients from the case file; to close the organization and purge everything it holds, email support@vaclaimcommander.com from the organization's admin email with the subject "Delete our organization".
  • By email, for anything — email support@vaclaimcommander.com from the email address on your account with the subject "Delete my data". We confirm the request with you and complete it within 30 days, including removal from backups. A veteran whose representative holds records about them may also write to us; we will confirm the representative's obligations to them and act on any legally required request.

Deleted information cannot be recovered. Download anything you want to keep before you delete.

7c. If There Is a Data Breach

If we learn that your information was accessed or disclosed without authorization, we will notify you by email at the address on your account without unreasonable delay and within the time required by law, and we will tell you what happened, what information was involved, what we have done about it, and what you can do to protect yourself. Where a representative's client records are affected, we notify the representative and, where we can, the veteran.

7d. If VA Claim Commander Changes Hands

If VA Claim Commander is sold, merged, or transferred to a new owner, or if the company ceases operating, we will notify you by email and on this page before any of your information is transferred. You will have at least 30 days to choose one of the following, and we will honor whichever you choose:

  • Download your information (your saved case and documents) and have it securely destroyed on our side, or have it transmitted to a destination you name;
  • Allow your information to move to the new owner, whose policies must be at least as protective as this one; or
  • Close your account, which deletes your information as described in Section 7b.

We will also notify you of any change in ownership of the company, whether or not your information moves.

8. Your Rights

Your claim form data lives in your browser's local storage, which you control. Click "Start Over" in the application or clear your browser data to remove it at any time.

If you use a paid plan, the case you build is saved to your account (Section 5b). You can view, export, or permanently delete your saved case at any time from your account, or by emailing support@vaclaimcommander.com. Deletion permanently purges the stored case — it is not merely hidden.

Your Clerk sign-in account (including your email address and authentication identity) is stored on Clerk's servers. To request deletion of your Clerk account and associated identity data, email support@vaclaimcommander.com and we will assist with account deletion.

Seeing and correcting your information. If you use the veteran app, everything you entered and every document drafted for you is in the app to read, edit, export, or delete. If an accredited representative uses Commander for Advocates on your behalf, your information is held for that representative, who owes you access to your file; the representative can share any document with you through your claim portal, and you can ask them to correct anything that is inaccurate, incomplete, or out of date. You may also email support@vaclaimcommander.com with a correction request and we will correct the information or record your request with it.

Payment records associated with purchases are retained by Stripe. We cannot delete Stripe transaction records on your behalf, but we do not have access to your payment card numbers — only transaction metadata (date, amount, last 4 of card).

8a. Commander Connect (VA.gov Import)

Commander Connect (our Chrome extension) reads benefits data displayed on your VA.gov screen after you log in — your rated conditions, percentages, static status, combined rating, Intent to File status, active claims, and service dates. It never sees, reads, or stores your VA.gov password or credentials.

This data is never stored on our servers by the import itself — it travels directly to your VA Claim Commander session in your browser, and only after you explicitly confirm the import. The extension makes no network requests of its own and contains no analytics or tracking.

8b. Commander Health

Commander Health is a clinical review service that connects veterans with licensed nurse practitioners for independent medical opinions in support of VA disability claims.

What we store

When you use Commander Health, we create and store a structured clinical summary derived from the medical records you upload through VA Claim Commander. This summary contains:

  • Identified diagnoses and ICD codes
  • Key diagnostic test results (e.g., AHI scores, lab values, audiogram results)
  • Treatment history extracted from your records
  • Relevant clinical findings documented by your treating providers

What we do not store

We do not store your raw medical records. Your uploaded files are processed during your session and discarded. Only the structured clinical summary derived from those records is retained.

Who can access your summary

Your structured clinical summary is accessible only to you and the licensed clinician assigned to your Commander Health case. It is encrypted at rest using AES-256-GCM encryption and transmitted only over HTTPS. Your assigned clinician uses this summary to prepare and sign your independent medical opinion.

How long we retain it

Your clinical summary is retained for the duration of your Commander Health case plus 90 days following case completion or cancellation. You may request earlier deletion at any time by contacting support@vaclaimcommander.com.

Your consent

Before your Commander Health case is created, you will be asked to explicitly consent to the storage of your structured clinical summary. You may withdraw consent at any time by requesting case cancellation and deletion of your summary.

Database storage

Commander Health case data — including your clinical summary, assigned clinician, case status, and generated documents — is stored in a secured PostgreSQL database hosted on Amazon Web Services (AWS) under a signed HIPAA Business Associate Agreement (BAA). Data is encrypted at rest and access is restricted to authenticated application processes and your assigned clinician.

9. Your Rights Under State Privacy Laws

Depending on where you live, state privacy laws — such as the California Consumer Privacy Act (CCPA/CPRA), the Virginia Consumer Data Protection Act, and similar laws in other states — may give you the right to:

  • Know what personal information we hold about you and how it is used
  • Access or receive a copy of that information
  • Request correction of inaccurate information
  • Request deletion of your information
  • Opt out of the sale or sharing of your personal information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising in exchange for money. For veterans in the free flow, most of your data never leaves your browser, so there is nothing on our servers for us to access or delete (see Section 5). For paid saved accounts, Commander for Advocates, and Commander Health, you may exercise these rights as described in Sections 5a, 5b, and 8b, or by contacting us.

Some states — including Washington (My Health My Data Act), Nevada, and Connecticut — provide additional protections for consumer health data. Because we treat the medical information you share with HIPAA-aligned safeguards regardless of where you live (Section 1), those protections are reflected in how we handle your data throughout this policy. To exercise any state privacy right, email support@vaclaimcommander.com. We will verify your request and respond within the timeframe your state law requires. We will not discriminate against you for exercising these rights.

10. Children's Privacy

VA Claim Commander is intended for veterans and accredited representatives and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact support@vaclaimcommander.com and we will delete it.

11. Not a Medical Service

VA Claim Commander generates documentation to support your VA claim. We are not a healthcare provider. Medical opinion documents we draft (such as nexus letters) require review and signature by a licensed healthcare provider before submission to the VA. Personal and buddy statements are lay evidence that you or your witness review and sign yourselves. Nothing in our application constitutes medical advice or a medical opinion.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make a material change, we will email the address on your account and post a notice on this page before the change takes effect, with the updated date above. Continued use of VA Claim Commander after changes constitutes acceptance of the updated policy.

13. Contact

Questions about this Privacy Policy:

support@vaclaimcommander.com

If you're in crisis or thinking about suicide, you're not alone. The Veterans Crisis Line is free, confidential, and available 24/7 — you don't need to be enrolled in VA care. Dial 988, then press 1 · Text 838255 · Chat online