Canary Doctor LLC (“DisabilityProAI,” “we,” “our”) provides an AI-enabled document-summarization platform used by United States licensed attorneys and their staff. We act as a service provider to law-firm customers and are not a “business” under the California Consumer Privacy Act (CCPA) nor a “covered entity” under HIPAA.
This Policy explains how we collect, use, protect, and disclose personal information about account holders (attorneys and staff). If you are a claimant whose medical records are processed, please contact your attorney for any privacy requests.
1. Scope & Eligibility
- This Policy covers the website https://disabilityproai.com and related sub-domains (the “Service”).
- Age 18+ only: The Service is intended exclusively for adults. We do not permit individuals under 18 to create accounts or submit information directly.
- United States only: The Service is intended only for customers and authorized users located in the United States and for United States disability-law workflows.
2. What We Collect
| Category | Examples | Purpose | Retention |
|---|---|---|---|
| Account details | Name, work e-mail, firm name, bar ID | Create & secure account | Life of account plus operational/legal retention |
| Auth & usage data | OAuth tokens, IP, logs, device info | Security, debugging, service reliability | 2 yrs |
| Billing | Sent directly to Stripe | Payment processing | Stripe policy |
| User Content | Medical records you upload; AI summaries | Provide the Service | Current standard policy: auto-deleted after 30 days |
PHI notice: We are not a HIPAA “covered entity,” but we treat all medical records as highly sensitive and apply the safeguards described in §7.
3. How & Why We Use Information
- Operate, deliver, maintain, secure, and support the Service
- Authenticate users, prevent fraud, ensure security
- Communicate essential account or product updates (opt-out of marketing at any time)
- Comply with applicable laws and defend legal claims
4. Sharing & Disclosure
| Type | Recipient(s) | Safeguard |
|---|---|---|
| Cloud hosting & AI | Vercel (hosting), Supabase (database), Google Cloud / Vertex AI (OCR & LLM) | SOC 2, encryption, DPAs |
| Payments | Stripe | PCI-DSS compliance |
| Application operations | Vercel and Supabase logs | Used for security, debugging, and reliability |
| Legal / safety | Courts, regulators, or law enforcement when legally required | Only as mandated |
We do not sell personal information or Customer Content. We do not share Customer Content for cross-context behavioral advertising, marketing, or unrelated third-party use. We do not train foundation models or customer-specific AI models on uploaded files, OCR text, prompts, embeddings, reports, chat content, or other User Content. Our configured cloud AI providers process User Content to provide the Service and are not authorized by us to use it to train or fine-tune managed models without our permission or instruction.
5. United States Use Only
The Service is designed for use only by customers and authorized users located in the United States and for United States disability-law workflows. You may not use the Service for non-U.S. customers, non-U.S. authorized users, or processing that would require us to comply with non-U.S. privacy, data-protection, or international-transfer regimes unless we expressly agree in writing before such use.
6. Your Rights & Choices
| Right | How to exercise |
|---|---|
| Access / Deletion / Correction | Use the Data Management tab in your dashboard or e-mail privacy@disabilityproai.com |
| Opt-out of marketing | Click “unsubscribe” in any non-transactional e-mail |
| Global Privacy Control | We do not sell personal information or share Customer Content for cross-context behavioral advertising. Where a legally applicable opt-out preference signal is received, we treat it as an opt-out signal for that browser or device. |
Claimant whose records are processed: Please contact your attorney, who can delete the entire matter via the portal; we cannot identify your data without their help.
7. Security Measures
8. Data Retention Schedule
| Data Set | Retention | Disposal |
|---|---|---|
| Raw uploads (PDF/images) | Current standard policy: auto-deleted 30 days after upload | GCS lifecycle + scheduled cleanup |
| AI summaries & reports | Current standard policy: auto-deleted 30 days after case creation | Scheduled cleanup + hard delete |
| Account & billing | Account life + 30 days | Anonymization |
| Auth & usage logs | 2 years | Purged quarterly |
| Incident & audit logs | 2 years | Cold storage erase |
We may retain information longer if required by law, court order, or to defend legal claims. We may update retention periods prospectively through the Terms, Privacy Policy, or a written customer agreement.
9. Cookies & Analytics
We use first-party cookies and similar technologies that are necessary for authentication, security, billing, and application functionality. We do not currently load Google Analytics, advertising pixels, retargeting tags, or session replay tools on the public marketing site. Stripe payment scripts are loaded only when a user enters a billing or checkout flow.
10. AI Transparency
Uploaded documents are processed with Google’s Gemini via Vertex AI for OCR and language-model analysis. DisabilityProAI does not train models on User Content, and we configure our AI processing for service delivery rather than model training. Google Cloud states that managed Vertex AI model inputs are not used to train or fine-tune AI/ML models without the customer’s prior permission or instruction. Reports are currently scheduled for deletion 30 days after case creation. AI summaries are drafts; attorneys retain responsibility for human review.
11. Accessibility
We aim for WCAG 2.1 AA conformance. Contact accessibility@disabilityproai.com with feedback; we respond within two business days.
12. Children (Under 18)
The Service is not directed to, and must not be used by, anyone under 18 years old. We do not knowingly collect personal information from minors. If you believe a minor has provided us information, contact privacy@disabilityproai.com so we can delete it.
13. Changes to This Policy
We will post any material changes here and e-mail account holders at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.
14. Contact Us
Privacy & Security Officer
Alex Mohseni
Canary Doctor LLC
350c Fortune Terrace #227, Potomac, MD 20854
privacy@disabilityproai.com