Privacy Policy
Last updated: August 5, 2026
1. Who We Are
VA Rating Assistant ("we", "us", "our") is operated by FastWebCreations LLC and provides a platform to help users estimate VA disability ratings and manage related documents. We focus on U.S. users and do not target EU/UK residents. For privacy matters, contact support@varatingassistant.com or write to 522 W Riverside Ave STE N, Spokane, WA 99201-0580. Washington State law governs this policy where applicable.
2. Information We Collect
- Identification and contact information (e.g., name, email, phone, address)
- Account and profile information (credentials, preferences, profile fields, user/admin role)
- Identity verification information from ID.me — because you sign in to VA Rating Assistant through ID.me, we receive your name and email address from ID.me, along with confirmation that ID.me verified your identity. We do not receive your Social Security number, government-issued ID images, or biometric data from ID.me.
- Financial information (via Stripe: payment tokens, last4, billing address; no full card numbers)
- Health/medical information you provide or generate in the Service (may include PHI)
- Files/documents you upload (e.g., VA forms, medical records) and related metadata
- Device and usage/telemetry data (IP address, browser/OS, device identifiers, event logs). In our mobile apps this includes a random app installation identifier and, if you turn on the optional Send diagnostics setting, crash and error reports. See Section 6b.
- Photographs of documents you choose to capture with your device camera in our mobile apps, used only to create the document you are uploading (see Section 6b)
- Communications (support tickets, feedback messages)
- Geolocation: coarse, IP-based for security and fraud prevention (no precise tracking)
We do not import your contacts/address book and we do not accept dependent/family member information.
3. How We Use Information
- Provide, operate, maintain, and improve the Service
- Process payments and manage subscriptions
- Communicate with you (e.g., notifications, support)
- Ensure security, prevent fraud/abuse, and perform incident response
- Comply with legal obligations and enforce our agreements
- Analytics and service improvement, including use of de-identified, anonymized, or pseudonymized data; we do not re-identify such data
4. Special Category and Sensitive Data
Some uploaded documents may contain health/medical information. This data is encrypted, accessed only as needed to provide the Service, and is never sold. Do not upload dependent or family member information; the Service is intended only for your own records relevant to VA disability rating analysis.
5. How We Store and Protect Your Data
- Data is stored securely in AWS (Aurora Serverless v2/RDS for database; encrypted S3 for file storage and retention). Your uploaded documents and files are retained in encrypted S3 buckets with customer-managed KMS encryption keys for the duration specified in our retention policy (see Section 8).
- Health records and sensitive documents are encrypted at rest and in transit.
- Access is restricted to authorized users and administrators following minimum-necessary principles.
- We implement administrative, technical, and physical safeguards aligned to HIPAA technical safeguards and SOC 2 aligned controls within the AWS shared responsibility model.
6. Third-Party Service Providers
We use trusted service providers that process data on our behalf under contracts that require confidentiality, security, processing only under our instructions, and no re-identification of de-identified data. Current providers include:
- AWS (Lambda, S3, Textract, RDS/Aurora Serverless v2, Cognito, Bedrock; Amplify, CloudFront, Route53), hosting, storage, authentication, AI processing, CDN; Region: us-east-2 (Ohio); HIPAA BAA in place
- Stripe, payments; billing tokens and related metadata; DPA in place
- AWS SES, email notifications; email address and message metadata; HIPAA-aligned rule: no PHI in email bodies
- AWS CloudWatch, security and application logging; minimized personal data
- Crash and error reporting is self-hosted. We run our own GlitchTip instance on our AWS account. Crash reports are not sent to a third-party crash-reporting vendor, and no advertising or analytics SDK is embedded in our mobile apps. Reports pass through an automated scrubber that removes personal and health information before they leave your device, and your IP address is anonymized.
We do not share data with partners beyond processors without your consent. We will update this list as vendors change and notify users of material changes.
Identity verification through ID.me is handled separately — ID.me is an independent provider, not a processor acting on our behalf. See Section 6a.
6a. Signing In with ID.me
VA Rating Assistant uses ID.me to verify your identity and sign you in. ID.me is now the only way to sign in. As of August 5, 2026 we disabled email-and-password and Google sign-in for the Service, and creating or accessing an account requires identity verification through ID.me. Parts of the Service that do not involve your records, such as the disability rating calculator and the reference guides, can be used without an account at all.
ID.me is an independent identity verification provider. It is not one of our service providers or processors — ID.me determines its own purposes for handling your information and acts as a separate, independent controller of the data it collects from you.
When you sign in, ID.me verifies your identity and, with your consent, shares a limited set of attributes with us: your name and email address, along with confirmation that your identity was verified. We never receive or store your ID.me password, Social Security number, government-issued ID documents, or biometric data.
If you created your VA Rating Assistant account with a password or through Google, that sign-in method no longer works. Your account and everything in it still exists. Contact us at support@varatingassistant.com from the email address on the account and we will connect your ID.me identity to it, so nothing is lost. Please do not create a new account with ID.me first, because a new account starts empty and your existing records will not follow it.
ID.me's collection, use, and retention of your information — including any information you provide directly to ID.me to verify your identity — is governed by ID.me's own Privacy Policy and Terms of Service, not by this Privacy Policy. We encourage you to review them. You can see which applications are connected to your ID.me account, and manage that access, from your ID.me account settings.
6b. Our Mobile Apps (iOS and Android)
This Privacy Policy covers the VA Rating Assistant mobile apps for iOS and Android in addition to our website. The apps talk only to our own servers; they do not embed advertising, attribution, or third-party analytics software development kits.
What the apps access on your device
- Camera, only when you choose to scan a document. Pages you capture are assembled into a PDF on your device and uploaded over an encrypted connection to the same protected storage described in Section 5. Captured images are not kept in your photo library by us and are not used for any other purpose.
- Files you select, only the documents you pick to upload.
- An app installation identifier, a random value created on first launch that is not tied to your device's advertising identifier and cannot be used to identify you personally. We use it to count app usage and to distinguish one installation from another.
- The apps do not request location access, contacts, microphone, or photo-library browsing.
Crash and diagnostic reports are optional
The apps include a Send diagnostics setting in your Profile that controls whether crash and error reports are sent to us. It defaults to off in the European Union and on elsewhere, and you can change it at any time. When it is off, no report leaves your device. When it is on, reports are sent to our own self-hosted system described in Section 6, after an automated scrubber removes personal and health information and anonymizes your IP address. Diagnostic reports never contain your medical records, your conditions, or the contents of your documents.
Signing in on mobile
Parts of the apps work without an account, including the disability rating calculator, the reference guides, the VA forms and facilities directories, and general chat. Uploading and analyzing your records requires an account. Signing in uses ID.me, the identity service the U.S. Department of Veterans Affairs itself uses, because the account holds medical records and we want to be confident that the person opening a file is the veteran it belongs to. Sign-in always opens your device's own browser; the apps never see or store your ID.me password. Section 6a describes what ID.me shares with us.
Biometric app lock is optional and stays on your device
The apps include an optional Biometric app lock in your Profile. It is off unless you turn it on. When it is on, the app locks itself every time it leaves the foreground, and reopening it requires Face ID, Touch ID, or your Android device's biometric unlock, with your device passcode as a fallback.
We never receive, collect, transmit, or store any biometric information. Your fingerprint, face scan, and any other biometric identifier are held by Apple or Google in your device's own secure hardware, and they are never sent to us. When you unlock the app, your device's operating system tells the app only whether the check succeeded or failed. VA Rating Assistant has no access to the underlying biometric data, cannot retrieve it, and does not keep any record derived from it. Turning the lock on or off changes nothing that is stored on our servers.
The app lock protects the app on your device. It is not a substitute for your device passcode, and it does not encrypt or protect the records held on our servers, which are covered by Section 5.
Deleting your account from the app
You can permanently delete your account from inside the apps, under Profile. Deletion is immediate and covers your account, your uploaded documents, and the data derived from them, on the terms described in Section 8.
App stores
Apple and Google operate the app stores that distribute our apps and handle your download and, where applicable, your payment. Their handling of that information is governed by their own privacy policies, not this one.
7. No Sale and No Targeted Advertising
We do not sell personal data to third parties. We do not use personal information for targeted or cross-context behavioral advertising. We follow strict data protection guidelines per the CARIN Code of Conduct and NCVHS Beyond HIPAA requirements. All data sharing with service providers (as listed in Section 6) is governed by contractual agreements that prohibit data sale and require compliance with applicable privacy laws.
8. Data Retention and Deletion
- Uploaded documents (PDFs) retention: Uploaded documents (including medical records and VA forms) are retained for 90 days on Free and one-time plans, then deleted, unless you purchase an active storage subscription before the scheduled deletion date.
- Storage subscriptions: If you purchase a storage subscription, your uploaded documents retention window is extended beyond the base 90 days while your subscription is active and paid. If your storage subscription ends and is not renewed, documents are scheduled for deletion at the end of the last paid retention window.
- Reminder emails: We send deletion reminder emails at 30, 15, 5, and 1 day(s) before the scheduled deletion date, and we send a confirmation email after deletion.
- Deletion scope: Deletion applies to uploaded documents and related stored artifacts generated from those uploads (for example, stored PDFs/exports/artifacts that depend on the uploaded document). If an object is already missing from storage, we treat database deletion as authoritative.
- Derived/extracted data: Structured data derived from your documents (for example, extracted condition metadata) may remain available in your dashboard for the life of your account unless you delete your profile/account. If you delete your profile/account, we delete derived data that we control, subject to legal obligations.
- Backups: Backups are retained on a rolling overwrite cycle (typically about 30 days).
- Logs: We retain audit/security logs for a limited period for security and compliance purposes, and we minimize sensitive content in logs.
- Deletion requests: You may request account deletion in-app or by emailing support@varatingassistant.com.
- Legal holds: Where required by law or necessary for fraud prevention/disputes/tax compliance, we may retain limited records and restrict access to the minimum required, and delete when the obligation ends.
9. Your Rights and Choices
You can access a copy of your information, request deletion, or ask questions about this policy by contacting us.
- Export: You may export your data in PDF, DOCX, or CSV.
- Delete: Use in-app deletion or email us. We will confirm when deletion is complete.
For privacy questions or requests, email support@varatingassistant.com or write to 522 W Riverside Ave STE N, Spokane, WA 99201-0580.
10. Data Location and Transfers
Primary data residency is AWS us-east-2 (Ohio). We focus on U.S. users and do not currently transfer data from the EU/UK to the U.S. or target EU/UK residents.
11. Data Breach Notification
If a data breach affecting your information occurs, we will notify you without undue delay (and within 72 hours where required), describe the incident and affected information, steps we are taking, suggested actions you may take, and how to obtain additional guidance.
12. Changes in Ownership
If there is a merger, acquisition, reorganization, or sale of assets, we will notify you. You will be able to download your information, close your account, and we will ensure any new owner adopts privacy/security protections at least as strong as ours before any transfer of personal information.
13. Changes to This Policy
For material changes, we will provide 30 days prior notice via email, in-app notice, and/or website banner. Legal or security updates may be effective immediately with appropriate notice. Continued use after the effective date constitutes acceptance of the updated policy.
14. Contact
For privacy questions or requests, email support@varatingassistant.com or write to 522 W Riverside Ave STE N, Spokane, WA 99201-0580.