VACA Privacy Notice

Effective July 26, 2026

Our commitment

VACA does not sell, rent, trade, purchase, lend, or give personal information to advertisers or data brokers. VACA does not use personal claim information for advertising.

Minimal information VACA must retain

To provide a secure private workspace, VACA necessarily retains the approved email address, internal user and workspace identifiers, authentication/session records, account status, and the structured claim information the user chooses to save. Minimal security and administrative audit records may also be retained.

VACA is designed not to retain original uploaded documents, full unredacted C-files, Social Security numbers, VA file numbers, dates of birth, full residential addresses, payment-card data, or other identifiers that are not needed to operate the service. Users must redact source material before submitting text.

Workspace separation

Each approved user receives a separate workspace. Server-side access checks restrict workspace records to the authenticated user and authorized owner administration.

Cloudflare email verification

Cloudflare Access sends and validates the one-time login code. VACA receives the verified email identity required to locate the approved account and private workspace. VACA does not generate or store the Cloudflare one-time code.

Self-learning and reusable knowledge

Private workspace facts are not automatically published as shared knowledge. Reusable learning must be de-identified before it enters the shared source library. Direct identifiers, private documents, and secret values must not be copied into the shared library. Reusable learning should describe claim patterns, evidence methods, authorities, development strategies, and outcomes without identifying the veteran.

Disclosure

VACA does not voluntarily share personal workspace information with outside marketers, data brokers, or claims companies. Information may be processed by infrastructure providers strictly to operate and secure the service, or disclosed when legally required.

Deletion and revocation

The owner may revoke access immediately. A verified administrative deletion permanently removes the user and linked workspace data after a current backup and explicit confirmation. De-identified reusable knowledge that no longer identifies or links to the user may remain.

User responsibility

Do not enter information that is unnecessary for claim development. Redact names, claim numbers, Social Security numbers, dates of birth, addresses, phone numbers, and unrelated medical details.

Changes

This notice will be updated when VACA's actual data handling changes. The policy must match the deployed system and may not promise that no personal data is stored when an approved email and private workspace are required.