Privacy & security

How Claim Raven protects your VA data, OAuth and ID.me handling, what we never see or sell, HIPAA posture, AI vendor controls, and how to delete your account.

Is my information secure?

Claim Raven uses layered safeguards for data in transit, VA connection tokens, browser sessions, and defined sensitive saved results, but no online service can promise zero risk. What is retained, encrypted, or sent to an AI provider depends on the feature you choose.

What can Claim Raven access?

Claim Raven can receive only the VA information covered by the permissions you approve and the connection available to your account. Current read-only connections may provide claim status and submission history, disability ratings, service history, and veteran status. Claim Raven does not currently request enrolled-benefits access, cannot change VA records, and does not file a claim through this connection.

How do I revoke access to my VA data?

For the most complete disconnect, clear the active VA connection inside Claim Raven and confirm the connected app is disconnected in VA.gov. This stops new VA sharing but does not delete the Claim Raven account or previously saved imports and analyses.

Where is my data stored?

Claim Raven stores account and saved feature data in a managed PostgreSQL database and uses private object storage for certain uploaded files. The exact location, what is retained, and how you remove it depend on the feature: Raven Eye does not retain its original source file after processing, while Ask Raven attachments and Raven Scan records can remain until you use the applicable deletion control or request account deletion.

Do you sell my data?

Claim Raven’s current Privacy Policy says it does not sell consumer health data and does not sell your data for profit or any monetary transaction. It does not use VA data, claim information, uploaded records, or AI content for advertising, marketing profiles, or sale. To provide the feature you request, Claim Raven may send limited information to contracted AI, hosting, storage, payment, email, SMS, support, security, or diagnostic providers. The Policy separately says it does not share data with marketers, advertisers, or partners; its Consumer Health Data Notice explains current provider categories, purposes, and location-dependent privacy rights.

How do I delete my account and data?

Account deletion is currently a verified support process, not a self-service Settings action. Email Claim Raven from the address on your account, complete identity verification, and wait for confirmation that required active-system deletion steps succeeded.

Is Claim Raven HIPAA-compliant?

Claim Raven does not represent the Service as HIPAA-compliant or as a HIPAA-certified service. HIPAA generally applies to covered entities, such as health plans, health care clearinghouses, and certain health care providers, and to business associates that handle protected health information on their behalf. Claim Raven is a veteran-facing technology service, not a health plan or health care provider; for information you submit directly to Claim Raven, its Privacy Policy and other applicable privacy and consumer-health laws govern. A particular organizational arrangement may require separate legal and contractual review, so do not submit protected health information on behalf of a covered entity unless Claim Raven has confirmed the arrangement in writing.

Do AI vendors keep my data?

Claim Raven may send the text, files, images, and account context needed for an AI feature to contracted commercial AI providers. The current Privacy Policy identifies the providers and current routing boundaries; commercial API terms do not use inputs and outputs for foundation-model training by default unless a customer opts in. Standard abuse-monitoring retention is commonly up to 30 days, but limited content may be retained longer for safety-policy enforcement or legal obligations, and settings can differ by provider, account, and feature. Claim Raven applies best-effort masking only on supported text paths, so raw PDFs, images, and OCR can require sending an unredacted visual input. It does not share account data with advertising vendors or data brokers.

How VA OAuth authorization works

Your Claim Raven account sign-in and an optional VA.gov connection are separate. When a live VA connection is available and you choose it, VA directs you to authenticate with a verified ID.me or Login.gov account and review the permissions shown before approving access. Claim Raven does not receive or store your VA.gov, ID.me, or Login.gov password; it stores the resulting authorization tokens in encrypted form. The current checked implementation is configured for VA sandbox and demo use, so never enter real credentials into a screen identified as sandbox or demo.

Keep personal records and support requests safe

Keep credentials and complete claim records private, use the route intended for each task, and prepare a redacted support-safe example when you need technical help.