Compass · Claims
Your records, protected

How we protect your records

Plain answers to the question that matters most: what happens to the medical record you upload?

Effective [EFFECTIVE DATE]

On this page
The short versionWhat happens on your deviceWhen local processing is not possibleAI provider disclosure & subprocessorsEncryption & no training on your dataRetention & deletionSecurity architecture summaryBreach responseYour rights & choicesWho we are & how to reach us

The short version

You upload medical records to understand your VA claim. Those records can contain Social Security numbers, dates of birth, diagnoses, addresses, dependent information, and trauma history. We treat them accordingly.

  • We do not have a database. Nothing you upload is saved to our servers after your analysis finishes.
  • Whatever can run on your own device runs on your device: text extraction from images, semantic search, and a first pass that strips out personal identifiers.
  • When a step must run on our server, only redacted text is sent, and only over an encrypted connection.
  • Your records are never used to train AI models.
  • You stay in control: closing the tab or refreshing clears your session.

The sections below explain each of these in plain language. If anything here is unclear, email us at [CONTACT EMAIL].

What happens on your device

Compass Claims is built local-first. As much of the work as possible happens inside your own browser, where your data never leaves your computer:

  • Image OCR — text is read from scanned images directly in your browser.
  • Semantic search — the model that matches your conditions to diagnostic codes runs on-device, so nothing is sent to a third party for this step.
  • PII redaction (first pass) — before any text is sent anywhere, a built-in redactor removes HIPAA Safe Harbor identifiers (names, SSNs, dates, addresses, and similar).
  • Calculator and letter drafts — combined-rating math runs in your browser; letter content (which contains real names and incidents) is held only in memory and is intentionally lost when you navigate away.

When local processing is not possible

Some steps cannot run in a browser. Reading text out of PDFs and Word documents, and the AI extraction and coaching features, run on our server. Here is exactly what that means:

  • What is sent: only text that has already been redacted of personal identifiers. The raw file and your name do not travel with it.
  • A second redaction pass runs on the server before any text reaches an AI provider: defense in depth, in case the first pass missed something.
  • How it travels: encrypted in transit (HTTPS/TLS).
  • How long it lives: only for the moment it takes to process your request. It is processed in memory and not written to any database or log of record.
  • Who touches it: the AI providers listed in the next section, and no one else.

AI provider disclosure & subprocessors

When server-side AI is used, redacted text is sent to third-party AI providers through their APIs. We disclose every provider that may receive your text:

ProviderWhat they doWhat they receive
GoogleExtracts conditions and diagnostic codes from recordsRedacted record text
AnthropicPowers the AI coach and per-condition gap analysisRedacted record text + your questions
Vercel AI GatewayRoutes AI requests to Google and AnthropicRedacted text in transit
Hosting provider (Vercel)Runs the app servers that perform server-side processingRedacted text in transit (not stored)

We send data to these providers through their commercial APIs under terms that prohibit using your inputs to train their models. We do not sell your data, and we do not share it with advertisers or data brokers.

Encryption & no training on your data

  • In transit: all communication between your browser, our server, and AI providers is encrypted with HTTPS/TLS.
  • At rest: there is no “at rest.” We do not store your records, so there is no stored copy to encrypt or breach.
  • Training: your records and questions are never used to train Compass Claims or any AI provider’s models. They are used only to generate your result, then discarded.

Retention & deletion

  • Server: nothing is retained. Your uploaded text exists only during the request that processes it.
  • Your device: a few non-medical preferences (for example, calculator inputs and dismissed prompts) may be saved in your browser’s local storage so the tool remembers your place. You can clear these any time by clearing your browser data.
  • Session: medical data, extracted text, and analysis results live only in the current session and are gone on refresh or when you close the tab.
  • How to delete everything: close the tab. Because we keep no server-side copy, there is nothing for us to delete on your behalf, but you can always email [CONTACT EMAIL] with questions.

Security architecture summary

Our protection is layered, so no single failure exposes your data:

  • Layer 1 — Local redaction: identifiers are stripped in your browser before anything is sent.
  • Layer 2 — Server re-redaction: a second independent pass runs before any AI call.
  • Layer 3 — No persistence: a database-free design means there is no stored honeypot of veteran records.
  • Layer 4 — Encrypted transport: everything moves over HTTPS/TLS.
  • Layer 5 — Minimal disclosure: only the named AI providers receive redacted text, under no-training API terms.

Breach response

Because we do not store your medical records, a server compromise would not expose a database of veteran records: there isn’t one. Still, if we ever discover a security incident that could have affected your information, we commit to:

  • Investigating promptly and containing the issue.
  • Notifying affected users without undue delay, and as required by applicable law.
  • Explaining, in plain language, what happened, what was (and was not) affected, and what steps you can take.
  • Reviewing and hardening the systems involved.

To report a suspected vulnerability or incident, email [CONTACT EMAIL].

Your rights & choices

  • You choose what to upload. You can use the manual-entry path and never upload a document at all.
  • You can use the tool without creating an account. There is no login.
  • You can clear your local data at any time through your browser.
  • Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA. Contact us to exercise them.

Who we are & how to reach us

Compass Claims is operated by [LEGAL ENTITY]. It is an independent educational tool and is not affiliated with the U.S. Department of Veterans Affairs. This policy is governed by the laws of [JURISDICTION].

Questions about this policy or your data? Email [CONTACT EMAIL]. See also our Terms of Service.

Board of Veterans’ Appeals decisions are illustrative, not binding precedent. They show how the VA has weighed similar evidence before: a favorable decision for another veteran does not guarantee the same outcome in your claim. See how we weigh our sources.

Read the companion document: