Privacy Policy

Last updated: April 2, 2026

Canary Doctor LLC (“DisabilityProAI,” “we,” “our”) provides an AI-enabled document-summarization platform used by licensed attorneys and their staff. We act as a service provider to law-firm customers and are not a “business” under the California Consumer Privacy Act (CCPA) nor a “covered entity” under HIPAA.

This Policy explains how we collect, use, protect, and disclose personal information about account holders (attorneys and staff). If you are a claimant whose medical records are processed, please contact your attorney for any privacy requests.

1. Scope & Eligibility

  • This Policy covers the website https://disabilityproai.com and related sub-domains (the “Service”).
  • Age 18+ only: The Service is intended exclusively for adults. We do not permit individuals under 18 to create accounts or submit information directly.

2. What We Collect

CategoryExamplesPurposeRetention
Account detailsName, work e-mail, firm name, bar IDCreate & secure accountLife of account + 30 d
Auth & usage dataOAuth tokens, IP, logs, device infoSecurity, debugging, analytics2 yrs
BillingSent directly to StripePayment processingStripe policy
User ContentMedical records you upload; AI summariesProvide the ServiceAuto-deleted after 30 days

PHI notice: We are not a HIPAA “covered entity,” but we treat all medical records as highly sensitive and apply the safeguards described in §7.

3. How & Why We Use Information

  • Operate, deliver, and improve the Service
  • Authenticate users, prevent fraud, ensure security
  • Communicate essential account or product updates (opt-out of marketing at any time)
  • Comply with applicable laws and defend legal claims

Legal bases for EEA/UK visitors: contract performance, legitimate interests, and your consent for marketing e-mails.

4. Sharing & Disclosure

TypeRecipient(s)Safeguard
Cloud hosting & AIVercel (hosting), Supabase (database), Google Cloud / Vertex AI (OCR & LLM)SOC 2, encryption, DPAs
PaymentsStripePCI-DSS compliance
AnalyticsGoogle Analytics (IP truncated)Privacy-focused config
Legal / safetyCourts, regulators, or law enforcement when legally requiredOnly as mandated

We do not sell personal information or use your data to train independent AI models.

5. International Transfers

Data is stored on U.S. servers. By using the Service from another jurisdiction you consent to the transfer, storage, and processing of your data in the United States.

6. Your Rights & Choices

RightHow to exercise
Access / Deletion / CorrectionUse the Data Management tab in your dashboard or e-mail privacy@disabilityproai.com
Opt-out of marketingClick “unsubscribe” in any non-transactional e-mail
Global Privacy ControlWe honour the Sec-GPC: 1 header and will mark your account as “do-not-share”
ERASURE / GDPR rightsContact us to object, restrict, or request portability

Claimant whose records are processed: Please contact your attorney, who can delete the entire matter via the portal; we cannot identify your data without their help.

7. Security Measures

TLS 1.3 encryption in transit, AES-256 encryption at rest
Role-based access, MFA, and annual penetration tests
24-hour incident-response SLA with breach notifications
Vendor SOC 2 Type 2 reports on file

8. Data Retention Schedule

Data SetRetentionDisposal
Raw uploads (PDF/images)Auto-deleted 30 days after uploadGCS lifecycle + scheduled cleanup
AI summaries & reportsAuto-deleted 30 days after case creationScheduled cleanup + hard delete
Account & billingAccount life + 30 daysAnonymization
Auth & usage logs2 yearsPurged quarterly
Incident & audit logs2 yearsCold storage erase

We may retain information longer if required by law, court order, or to defend legal claims.

9. Cookies & Analytics

We use first-party cookies and Google Analytics to understand site usage. Disabling cookies may reduce analytics accuracy but will not break core functionality.

10. AI Transparency

Uploaded documents are processed with Google’s Gemini (via Vertex AI) for OCR and language-model analysis. Files are not used by Google to train its models; they are sent to Google’s Vertex AI endpoint for on-demand processing only. Reports are automatically deleted 30 days after case creation. AI summaries are drafts; attorneys retain responsibility for human review.

11. Accessibility

We aim for WCAG 2.1 AA conformance. Contact accessibility@disabilityproai.com with feedback; we respond within two business days.

12. Children (Under 18)

The Service is not directed to, and must not be used by, anyone under 18 years old. We do not knowingly collect personal information from minors. If you believe a minor has provided us information, contact privacy@disabilityproai.com so we can delete it.

13. Changes to This Policy

We will post any material changes here and e-mail account holders at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.

14. Contact Us

Privacy & Security Officer

Alex Mohseni
Canary Doctor LLC
350c Fortune Terrace #227, Potomac, MD 20854
privacy@disabilityproai.com