Privacy Policy

Last updated: May 22, 2026

Canary Doctor LLC (“DisabilityProAI,” “we,” “our”) provides an AI-enabled document-summarization platform used by United States licensed attorneys and their staff. We act as a service provider to law-firm customers and are not a “business” under the California Consumer Privacy Act (CCPA) nor a “covered entity” under HIPAA.

This Policy explains how we collect, use, protect, and disclose personal information about account holders (attorneys and staff). If you are a claimant whose medical records are processed, please contact your attorney for any privacy requests.

1. Scope & Eligibility

  • This Policy covers the website https://disabilityproai.com and related sub-domains (the “Service”).
  • Age 18+ only: The Service is intended exclusively for adults. We do not permit individuals under 18 to create accounts or submit information directly.
  • United States only: The Service is intended only for customers and authorized users located in the United States and for United States disability-law workflows.

2. What We Collect

CategoryExamplesPurposeRetention
Account detailsName, work e-mail, firm name, bar IDCreate & secure accountLife of account plus operational/legal retention
Auth & usage dataOAuth tokens, IP, logs, device infoSecurity, debugging, service reliability2 yrs
BillingSent directly to StripePayment processingStripe policy
User ContentMedical records you upload; AI summariesProvide the ServiceCurrent standard policy: auto-deleted after 30 days

PHI notice: We are not a HIPAA “covered entity,” but we treat all medical records as highly sensitive and apply the safeguards described in §7.

3. How & Why We Use Information

  • Operate, deliver, maintain, secure, and support the Service
  • Authenticate users, prevent fraud, ensure security
  • Communicate essential account or product updates (opt-out of marketing at any time)
  • Comply with applicable laws and defend legal claims

4. Sharing & Disclosure

TypeRecipient(s)Safeguard
Cloud hosting & AIVercel (hosting), Supabase (database), Google Cloud / Vertex AI (OCR & LLM)SOC 2, encryption, DPAs
PaymentsStripePCI-DSS compliance
Application operationsVercel and Supabase logsUsed for security, debugging, and reliability
Legal / safetyCourts, regulators, or law enforcement when legally requiredOnly as mandated

We do not sell personal information or Customer Content. We do not share Customer Content for cross-context behavioral advertising, marketing, or unrelated third-party use. We do not train foundation models or customer-specific AI models on uploaded files, OCR text, prompts, embeddings, reports, chat content, or other User Content. Our configured cloud AI providers process User Content to provide the Service and are not authorized by us to use it to train or fine-tune managed models without our permission or instruction.

5. United States Use Only

The Service is designed for use only by customers and authorized users located in the United States and for United States disability-law workflows. You may not use the Service for non-U.S. customers, non-U.S. authorized users, or processing that would require us to comply with non-U.S. privacy, data-protection, or international-transfer regimes unless we expressly agree in writing before such use.

6. Your Rights & Choices

RightHow to exercise
Access / Deletion / CorrectionUse the Data Management tab in your dashboard or e-mail privacy@disabilityproai.com
Opt-out of marketingClick “unsubscribe” in any non-transactional e-mail
Global Privacy ControlWe do not sell personal information or share Customer Content for cross-context behavioral advertising. Where a legally applicable opt-out preference signal is received, we treat it as an opt-out signal for that browser or device.

Claimant whose records are processed: Please contact your attorney, who can delete the entire matter via the portal; we cannot identify your data without their help.

7. Security Measures

TLS 1.3 encryption in transit, AES-256 encryption at rest
Role-based access, MFA where available, and security regression testing
Customer notice within five business days after confirming a security incident affecting Customer Content, where legally or contractually required
Vendor security assurance materials reviewed or maintained where available

8. Data Retention Schedule

Data SetRetentionDisposal
Raw uploads (PDF/images)Current standard policy: auto-deleted 30 days after uploadGCS lifecycle + scheduled cleanup
AI summaries & reportsCurrent standard policy: auto-deleted 30 days after case creationScheduled cleanup + hard delete
Account & billingAccount life + 30 daysAnonymization
Auth & usage logs2 yearsPurged quarterly
Incident & audit logs2 yearsCold storage erase

We may retain information longer if required by law, court order, or to defend legal claims. We may update retention periods prospectively through the Terms, Privacy Policy, or a written customer agreement.

9. Cookies & Analytics

We use first-party cookies and similar technologies that are necessary for authentication, security, billing, and application functionality. We do not currently load Google Analytics, advertising pixels, retargeting tags, or session replay tools on the public marketing site. Stripe payment scripts are loaded only when a user enters a billing or checkout flow.

10. AI Transparency

Uploaded documents are processed with Google’s Gemini via Vertex AI for OCR and language-model analysis. DisabilityProAI does not train models on User Content, and we configure our AI processing for service delivery rather than model training. Google Cloud states that managed Vertex AI model inputs are not used to train or fine-tune AI/ML models without the customer’s prior permission or instruction. Reports are currently scheduled for deletion 30 days after case creation. AI summaries are drafts; attorneys retain responsibility for human review.

11. Accessibility

We aim for WCAG 2.1 AA conformance. Contact accessibility@disabilityproai.com with feedback; we respond within two business days.

12. Children (Under 18)

The Service is not directed to, and must not be used by, anyone under 18 years old. We do not knowingly collect personal information from minors. If you believe a minor has provided us information, contact privacy@disabilityproai.com so we can delete it.

13. Changes to This Policy

We will post any material changes here and e-mail account holders at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.

14. Contact Us

Privacy & Security Officer

Alex Mohseni
Canary Doctor LLC
350c Fortune Terrace #227, Potomac, MD 20854
privacy@disabilityproai.com