Privacy Policy
Last updated: September 9, 2026
1. Introduction
AIVA Claims Assistant ("AIVA," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered VA claims assistance platform.
2. Information We Collect
Personal Information
- Name and email address (for account creation)
- Mobile or landline phone number, if you choose to give us one so our team can follow up with you by call or text. Providing a phone number is optional and you can use AIVA without it. See SMS / Text Messaging for how we use it.
- Authentication data (email, password hash, passkeys, two-factor enrollment) β handled by AIVA directly and stored in our own database. We do not use a third-party authentication service to hold your credentials. If you choose "Continue with Google" or "Continue with Apple", that provider confirms your identity to us and shares your email and name; your Google or Apple password is never sent to AIVA. Email/password and email-code sign-in never contact Google or Apple.
- Documents you upload (medical records, service records)
- Information you provide in forms and claim documents
Automatically Collected Information
- Device and browser information
- IP address and approximate location
- Usage data and analytics (via AIVA's first-party Traks service)
3. How We Use Your Information
- To provide and maintain our AI-powered claim preparation services
- To analyze your medical records and generate draft claim documents
- To communicate with you about your account and services
- To send email updates (you can unsubscribe at any time)
- To send text messages you have asked to receive (you can reply STOP at any time)
- To improve our platform and develop new features
- To comply with legal obligations
4. SMS / Text Messaging
If you give us your mobile phone number and agree to receive text messages, AIVA may text you about your account and your claim. Giving us a mobile number and agreeing to texts is always optional β every part of AIVA works without it, and we will never require it in order to help you with a claim.
- What we send β account notifications, claim-status updates, appointment and consultation reminders, and replies from our support team. We do not send advertising or promotional texts on behalf of anyone else.
- Message frequency varies.
- Message and data rates may apply.
- To opt out β reply STOP to any message. You will get one confirmation and then no further texts.
- For help β reply HELP, or email help@aivaclaims.com.
- Carriers are not liable for delayed or undelivered messages.
- Opting out of text messages does not close your account or stop the email we send about your claim.
Text messaging originator opt-in data and consent will not be shared with any third parties. We do not share mobile information with third parties or affiliates for marketing or promotional purposes. No mobile information is sold, rented, or released to data brokers or lead aggregators.
Telnyx is our messaging provider. It processes your phone number and the content of the messages only to deliver the texts you asked for, acting on AIVA's instructions as a service provider β not as a third party receiving your consent data for its own use.
5. Subprocessors & Third-Party Services
To provide our service we rely on the following subprocessors. Each processes only the data required for its function, under a data-processing agreement where applicable.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Cloudflare | Hosting, CDN, edge security, DDoS protection, application database (D1) and file storage (R2) | IP address, request metadata, account email and name, password hash, session tokens, passkey and two-factor credentials, uploaded documents | Global |
| Cloudflare Email Sending | Transactional email delivery | Email, message content | US |
| Telnyx | SMS and voice messaging delivery for the text messages you opt in to receive | Phone number, message content | US |
| Google Voice | Current delivery path for support and document-request text messages, being migrated to Telnyx | Phone number, message content | US |
| Google (Sign in with Google) | Optional social sign-in. Used only if you choose the Google button; email/password and email-code sign-in never contact Google. | Your Google account email, name and profile picture, returned to AIVA after you approve the sign-in. AIVA does not receive your Google password. | US / global |
| Apple (Sign in with Apple) | Optional social sign-in. Used only if you choose the Apple button; email/password and email-code sign-in never contact Apple. | Your Apple ID email (or Apple's private relay address if you choose to hide it) and name, returned to AIVA after you approve the sign-in. AIVA does not receive your Apple password. | US / global |
| DocuSeal | Electronic signature for HIPAA authorization & VA forms | Name, signature, document content | US |
| Cloudflare Workers AI | First-party AI inference for the claim-assistant chat and support chat. Runs on Cloudflare's network (already AIVA's hosting provider). Per Cloudflare's published Workers AI data policy, inference content is not used to train models and is not retained. | Typed chat questions and lightweight claim-status context (claim type, current step, intent-to-file flag). No documents. | US / global |
| Traks | First-party, cookie-free usage analytics | Anonymized page views, device/browser type, approximate region | AIVA Cloudflare account |
| Telegram | Human handoff of AI support-chat conversations | Name, email, chat transcript | US / EU |
We do not use Meta / Facebook tracking pixels, ad networks, or session-replay tools. If we add a new subprocessor we will update this list before that processor goes live.
6. How AI Processes Your Claim
AIVA uses artificial intelligence to answer questions about the VA claim process. These AI features run on Cloudflare Workers AI, a first-party service on Cloudflare's network (Cloudflare is already AIVA's hosting provider). Per Cloudflare's published Workers AI data policy, inference content is not used to train models and is not retained by Cloudflare.
What this means for you:
- The website sends the AI only your typed questions, a lightweight summary of your claim status (claim type, current step, and intent-to-file flag).
- The Benefits Finder does not send form inputs to an AI model. It filters a fixed catalog of official government sources by VA disability rating.
- It does not upload your documents, and it does not draft nexus letters through this website. Nexus-letter drafting and medical-record analysis are performed in AIVA's local processing pipeline and are not transmitted to any third-party AI gateway by this website.
- We do not sell, rent, or share your claim content with advertisers, data brokers, or other third parties.
- We do not opt your data into model training.
- AI output is a draft for your review β you always decide what gets submitted to the VA.
- You can request that we delete your AI-processing history at any time by emailing help@aivaclaims.com.
7. Connecting Your Hospital Records
"Private Doctors Records" lets you pull your own medical records from a hospital or clinic that offers a patient-access API (for example, an Epic MyChart portal) and use them to prepare your claim. This is optional. AIVA works without it.
What we request
When you connect, AIVA asks your organization for read-only access to these record types, and only for you (the signed-in patient): Patient (name, date of birth, sex), Condition (diagnoses), Procedure, MedicationRequest, Observation (lab results, vital signs, social history), DiagnosticReport, DocumentReference and Binary (clinical notes and attached documents), Encounter (visits), AllergyIntolerance, and Immunization. We never request write access, and we cannot see or store your patient-portal password: you sign in on your organization's own website.
Where the data goes
- Retrieval happens in your browser for a one-time connection. Your browser talks directly to your organization's patient API. Your records and the access token do not pass through AIVA's servers during retrieval.
- Nothing is stored unless you choose to import. When the retrieval finishes, AIVA shows you what it found and asks whether to import it. If you import, AIVA saves the structured record set (diagnoses, procedures, visits, medications, lab results) to your account, writes a plain-text summary into your secure documents folder, and shows you the clinical documents it found so you can pick which, if any, to upload. If you discard, or close the page, nothing leaves your browser.
- How it is used. Only to prepare your VA claim: the summary and any documents you upload are analyzed the same way as records you upload yourself (see How AI Processes Your Claim).
- Not sold, no secondary use. We do not sell your records, do not use them for advertising or research, do not use them to train AI models, and do not transfer them to any third party other than the subprocessors listed above that store and process data on AIVA's behalf.
- Retention. Imported records follow the "Uploaded documents" window in section 9: kept while your account is active; deleted within 30 days of account closure or on request.
- Record of use. Each connection and import is logged (organization name, record counts, date, your account id) so you can ask us who accessed what and when. The log never contains the records themselves.
Keeping a connection (optional)
For organizations on athenahealth, the connect page offers one checkbox: "Keep AIVA connected to refresh my records automatically." It is unchecked unless you check it. If you do, and you then choose to import, AIVA stores one thing on its servers: an encrypted refresh token issued by your organization (never your password, and never a standing access token). Once a day, for connections you chose to keep and only those, AIVA's servers use that token to fetch the same structured record set (diagnoses, procedures, visits, medications, lab results) and save it to your account exactly as an import does. Clinical documents are not fetched this way; those are still retrieved only in your browser, where you pick what to upload. You can disconnect at any time from the connect page (aivaclaims.com/ehr/connect, "Connected practices", Disconnect) or by emailing help@aivaclaims.com; disconnecting stops the refreshes and discards the token. Your organization can also revoke the token on its side, which ends the connection the next time AIVA tries to use it.
Revoking access
Unless you kept a connection as described above, AIVA does not keep a standing connection to your organization: each import uses a one-time authorization that expires on its own. To remove AIVA from your organization's list of connected apps, use your patient portal's settings (in MyChart: Menu, Security Settings, Linked Apps and Devices; in an athenahealth patient portal, the connected-apps settings). To delete imported records from AIVA, delete them from your documents folder or email help@aivaclaims.com.
8. Data Security
We implement industry-standard security measures including:
- TLS/SSL encryption for all data in transit
- Encrypted storage for sensitive documents
- First-party authentication (passwords stored only as salted hashes; optional passkeys and two-factor authentication)
- Regular security audits and monitoring
- Access controls and audit logging
9. Data Retention
We keep your data only as long as we need it. The table below shows our default retention windows; shorter periods apply on request.
- Account & profile data β kept while your account is active; deleted within 30 days of account closure.
- Uploaded documents (medical records, service records) β kept while your account is active; deleted within 30 days of account closure or on request.
- AI chat history & drafts β kept for active claim reference; deleted with the account or on request.
- Server logs & error events β automatically purged after 90 days.
- Analytics events β kept for up to 14 months, then aggregated or deleted.
- Billing / tax records β retained for 7 years where required by IRS / state tax law.
You can request deletion at any time by emailing help@aivaclaims.com. We will complete the deletion within 45 days and confirm in writing.
10. Breach Notification
If we discover a security incident that compromises your personal information we will notify affected users and the required regulators. Our internal commitment:
- Initial investigation and containment within 24 hours of discovery.
- Notification to affected users without undue delay, and in any case within 72 hours of confirming an EU/UK resident is affected (GDPR Art. 33).
- Notification to affected users within the timeframes set by each applicable US state breach-notification law (generally 30-60 days).
- A post-incident summary explaining what happened, what we changed, and what you can do to protect yourself.
To report a suspected security issue, email help@aivaclaims.com or see our security.txt.
11. Your Rights
Depending on where you live, you may have additional rights under California (CCPA/CPRA), EU/UK (GDPR), or other state privacy laws. Exercising these rights is free and will never result in worse service or higher prices.
Rights available to all users
- Right to know β what personal information we have about you and how it is used
- Right to access β a copy of your personal information in a portable format
- Right to correct β fix inaccurate data
- Right to delete β request deletion of your account and personal data (some records may be retained where required by law)
- Right to opt out of marketing β unsubscribe from any marketing email with one click
- Right to non-discrimination β we will not penalize you for exercising any of these rights
California residents: Do Not Sell or Share My Personal Information
AIVA does not sell your personal information, and we do not share it for cross-context behavioral advertising. We also do not use third-party advertising cookies, Meta / Facebook pixels, or session-replay tools.
If your browser sends a Global Privacy Control (GPC) signal we will treat it as a valid Do-Not-Sell / Do-Not-Share request. You can also exercise any privacy right (access, deletion, correction, opt-out) by emailing help@aivaclaims.com. We will respond within 45 days as required by CPRA Β§1798.130.
EU / UK residents (GDPR)
In addition to the rights above, you have the right to restrict or object to processing, to withdraw consent at any time, and to lodge a complaint with your local supervisory authority. Our lawful basis for processing is consent (optional cookies, marketing) and contract performance (account, claim preparation).
12. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
15. Contact Us
If you have questions about this Privacy Policy, please contact us at: help@aivaclaims.com