Effective Date: June 9, 2026. Last Updated: September 5, 2026.
The Short Version
We collect very little. Calculator inputs are processed to show your result on screen, and results you save on this device stay in your browser. The only time an estimate reaches us is when you ask us to email it to you, and then we keep the figures for a limited time described below. We do not sell or share personal information for cross-context behavioral advertising. We honor Global Privacy Control signals. This policy explains what we collect, why, and the rights you have. Health-related figures you ask us to email are also covered by our standalone Consumer Health Data Privacy Notice.
1. Scope and Operator
This Privacy Policy describes how Aurelis LLC, a California limited liability company, doing business as "The Veteran Benefit Desk" ("Aurelis LLC," "The Veteran Benefit Desk," "we," "us," or "our") collects, uses, and discloses personal information about you and the rights you have. "Personal information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, consistent with California law. This policy applies to the public website and the related services that link to it (the "Services"). Paid enterprise and developer API products are governed by their own written agreements, including a Data Processing Addendum. This policy does not apply to third-party websites or services that may be linked from the Services, which have their own policies. (CalOPPA, Cal. Bus. & Prof. Code section 22575(b)).
2. Categories of Information We Collect
- Local-only data. Calculator inputs are processed within your request to compute the result on screen and are not written to our database. Calculations you save (for example combined rating, monthly compensation, back pay, DIC, TDIU, and pre-discharge estimates) are stored in your browser's localStorage on your device. We never receive or store these unless you use an email feature below.
- Emailed estimates, roadmaps, and reminders (only if you ask). If you ask us to email a calculator estimate, a rating goal roadmap, or a proposed-reduction deadline reminder, we store your email address, the calculator you used, the summary figures needed to render the message (which can include the disability ratings and monthly amounts you entered), the notice and deadline dates you provided for a reminder, the time of the request, and a link that reopens the estimate. Retention for these records is defined in Section 12.
- Rate change alerts (only if you choose). If you submit your email to be notified when VA rates change, we store the email address, the page where you submitted it, and the timestamp, so we can send occasional rate-update notices. You can opt out at any time using the instructions in any such message or by contacting us. This is not a marketing list.
- Directory and advertiser applications and accounts. If a VA-accredited representative or a business applies for a listing or holds an account, we collect the information submitted (for example name, business name, email, phone, website, category, states served, accreditation source, logo, and description) and account records such as login timestamps and the hashed password. We do not store plain-text passwords.
- Communications. If you contact us, we collect the content of your message and your contact details so we can respond. The text of your message (not your name or email address) may be processed by an AI model provider to draft a reply that a member of our team reviews before anything is sent; see Section 7.
- Security and hosting logs. Our own application keeps short-lived security records: sign-in attempts and rate-limit counters for one hour, security events for 90 days, and the IP address and browser string attached to a form submission for 30 days, after which they are removed. Our hosting and infrastructure providers also keep standard server logs (IP address, user-agent string, request path, and timestamp) for security and abuse prevention for the period stated in their own retention schedules.
- No cross-site tracking pixels. We do not embed advertising or retargeting trackers such as Meta Pixel, Google Ads remarketing tags, or TikTok Pixel.
California Notice at Collection: Categories, Retention, and Disclosure
The table below maps our collection to the categories in Cal. Civ. Code section 1798.140. In the preceding 12 months we have not sold or shared personal information as California law defines those terms, and we have disclosed personal information for a business purpose only to the service provider categories listed on our Sub-processors page.
| Category | Collected? | Examples on this Service | Retention |
|---|---|---|---|
| Identifiers | Yes | Email address you submit for alerts, the newsletter, or emailed estimates, roadmaps, and reminders; name and contact details in applications and messages; IP address in security records and hosting logs | Opt-in records until you unsubscribe or ask us to delete; form-submission IP addresses 30 days; application and account records for the life of the account plus a reasonable period; hosting logs per the provider's schedule |
| Customer records (Cal. Civ. Code 1798.80(e)) | Yes | Business contact details and hashed account credentials for representative and advertiser accounts | Life of the account plus a reasonable period for legal, tax, and dispute needs |
| Commercial information | Yes | Billing and transaction records for paid placements (card numbers stay with the payment processor) | As long as legally required for tax and accounting |
| Internet or other network activity | Limited | Request path and user-agent in hosting logs; first-party measurement using a daily-rotating pseudonym rather than a persistent profile | Application security records one hour to 90 days; hosting logs per the provider's schedule |
| Geolocation data | Coarse only | Country and region code supplied by the network; no precise geolocation | Same as the measurement records it appears in |
| Sensitive personal information | Limited | Account login in combination with a hashed password; the disability ratings, monthly amounts, and reduction notice dates contained in an estimate, roadmap, or reminder you asked us to email | Login for the life of the account; emailed figures deleted 90 days after the last email you requested, and reminder dates 30 days after the last deadline they track |
| Professional or employment information | Yes | Accreditation and business details a representative or business submits for a listing | Life of the listing |
| Protected classifications, biometric information, audio or visual data (beyond a logo you upload), education information, inferences | Not collected | We do not collect these categories | Not applicable |
3. Sources and Purposes
We collect personal information directly from you when you use the Services, apply, or contact us; automatically from your device through strictly necessary cookies and security records; and from our service providers who help operate the Services. We use information to: provide, secure, maintain, and improve the Services; deliver the estimates, roadmaps, reminders, and alerts you requested; respond to inquiries and process applications and accounts; detect and prevent fraud, abuse, and unauthorized access; comply with legal obligations; and enforce our terms and agreements. We provide notice of the categories and purposes at or before collection. (Cal. Civ. Code section 1798.100; GDPR Art. 13).
4. Cookies and Similar Technologies
We use a small number of strictly necessary cookies for session integrity and security. We do not currently use analytics, advertising, or cross-context behavioral advertising cookies. For details, see our Cookie Policy. Strictly necessary cookies are exempt from consent requirements where they are essential to a service you requested. (ePrivacy Directive 2002/58/EC Art. 5(3)).
5. Do Not Track and Opt-Out Preference Signals
We honor browser-based opt-out preference signals, including Global Privacy Control (GPC), as a request to opt out of any sale or sharing of personal information, consistent with Cal. Civ. Code section 1798.135(b)(1). Because browsers do not use a uniform standard for legacy "Do Not Track" signals, we respond through the GPC mechanism described here.
6. Legal Bases for Processing (EU and EEA)
For users in the EU or EEA, we process personal data only where a lawful basis under GDPR Article 6(1) applies: your consent; performance of a contract with you; compliance with a legal obligation; protection of vital interests; or our legitimate interests (such as securing and improving the Services), except where overridden by your rights. Where we rely on consent you may withdraw it at any time; where we rely on legitimate interests you may object.
7. How We Share Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. (Cal. Civ. Code section 1798.140(ad), (ah)). We disclose information only to: service providers under written confidentiality and data-protection terms and only to perform services for us, namely cloud hosting and database infrastructure, transactional email delivery, payment processing, error monitoring, and an AI model provider that processes the text of a contact-form message to draft a reply for human review (we send the message text only, never your name or email address, and we use the provider through a commercial API rather than a consumer product); government or law enforcement when required by valid legal process; and a successor entity in connection with a merger, acquisition, or sale of all or substantially all of our assets. Representatives and advertisers do not receive analytics tied to individual visitors and do not control our editorial content. The categories of providers are published on our Sub-processors page.
8. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to: know and access the personal information we collect, use, and disclose; delete personal information we collected from you, subject to legal exceptions; correct inaccurate personal information; opt out of the sale or sharing of personal information (we do not sell or share); limit the use of sensitive personal information (we do not use sensitive personal information beyond what is described here); and not be discriminated against for exercising your rights. (Cal. Civ. Code sections 1798.100, 1798.105, 1798.106, 1798.110, 1798.120, 1798.121, 1798.125).
We do not knowingly sell or share the personal information of consumers under 16 years of age. To exercise your rights, use the privacy request form, email legal@veteranbenefitdesk.com, or use the Contact page. For access, deletion, and correction requests we verify your identity using reasonable methods matched to the sensitivity of the information, and where we cannot verify a request we will tell you. Opt-out requests and requests to withdraw consent are not subject to identity verification beyond what is needed to act on them. We respond within the time allowed by the applicable law, which for California requests is 45 days from receipt, extendable once by a further 45 days where reasonably necessary with notice to you. You may designate an authorized agent to submit a request with written authorization. If we deny a request, we will explain why and how to appeal, and you may contact the California Privacy Protection Agency or your state's attorney general. (Cal. Civ. Code section 1798.135(b)).
Sensitive Personal Information
The sensitive personal information we may hold is limited to two things. First, an account login in combination with a password for approved representative and business accounts, stored as a salted hash and used solely for authentication and account security. Second, when you ask us to email a calculator estimate, rating goal roadmap, or proposed-reduction deadline reminder, the figures needed to render that message, which can include the disability ratings and monthly amounts you entered and the notice dates you provided; these are used solely to send what you asked for and are deleted on the schedule in Section 12. We do not collect government identifiers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, or the contents of communications not directed to us. Because we use sensitive personal information only for the purposes permitted by Cal. Civ. Code section 1798.121(d) and the implementing regulations, we are not required to offer a separate "Limit the Use of My Sensitive Personal Information" link.
De-identified Data and Financial Incentives
Our first-party visit measurement uses a daily-rotating pseudonym derived from a salted hash rather than a persistent identifier. Where we maintain de-identified or aggregated data, we maintain and use it only in de-identified form, we do not attempt to re-identify it except as permitted by law to test our safeguards, and we require any recipient to commit to the same. (Cal. Civ. Code section 1798.140(m)). We do not offer financial incentives, loyalty programs, or price or service differences in exchange for personal information.
9. Your Rights in Other States
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights similar to those above (for example to access, correct, delete, and opt out of targeted advertising and sale) under their state's law. Use the privacy request form or the Contact page to exercise them, and you may appeal a decision as your state's law allows; we will tell you how to appeal when we respond.
10. Your Rights in the EU and EEA (GDPR)
If you are in the EU or EEA, you have the rights of access, rectification, erasure, restriction, data portability, and objection, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. (GDPR Articles 15 to 22). You may exercise these rights through the Contact page and may lodge a complaint with your local supervisory authority. (GDPR Art. 77).
Consumer Health Data (Washington, Nevada, and Similar Laws)
This site is educational and is designed not to collect health information. Calculator inputs are processed within your request to compute the result on screen and are not written to our database, and calculations you save stay in your browser. The narrow exception is information you explicitly ask us to keep so we can deliver something you requested: an emailed calculator estimate or rating goal roadmap stores your email address together with the figures needed to render it, which can include the disability ratings you entered, and a reduction deadline reminder stores your email address and the notice dates you provided.
To the extent any of this is consumer health data under the Washington My Health My Data Act (Wash. Rev. Code chapter 19.373), Nevada SB 370 (NRS 603A.400 and following), or a similar law, our standalone Consumer Health Data Privacy Notice describes the categories collected, the purposes, the sources, what is shared and with which categories of providers, how long it is kept, and how to exercise your rights and appeal. In short: we collect it only with your consent, expressed by your request; we use it solely to provide what you asked for; we do not sell it; we do not use it for advertising or profiling; we share it only with the service provider categories that host our database and deliver our email; and we do not use geofencing of any kind.
11. Data Security
We use administrative, technical, and physical safeguards appropriate to the risk, including encryption in transit (TLS), encryption at rest in our managed database, role-based access control, least-privilege access, a second-factor one-time code emailed to administrators at sign-in, and rate limiting and brute-force protection on authentication endpoints. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
12. Data Retention
We retain personal information only as long as necessary for the purposes described here or to meet a legal obligation, whichever is longer. (GDPR Art. 5(1)(e)). Specific rules:
- Emailed estimates and roadmaps. The summary figures (including any disability ratings and monthly amounts) are deleted 90 days after the last email you requested. Your email address is kept only while you remain opted in to follow-up messages; when you unsubscribe or ask us to delete, the record is removed within 90 days and sooner on request.
- Proposed-reduction deadline reminders. The notice and deadline dates are deleted 30 days after the last deadline they track; the record is removed at the same time.
- Sent email copies. Our email queue keeps a copy of each message we sent for up to 90 days so we can diagnose delivery problems, then deletes it.
- Security records. Sign-in attempts and rate-limit counters are kept for one hour, security events for 90 days, and the IP address and browser string attached to a contact, privacy, or report form for 30 days.
- Hosting logs. Kept by our hosting and infrastructure providers for the period stated in their own retention schedules.
- Accounts and applications. Retained for the life of the account and for a reasonable period afterward to meet legal, tax, and dispute-resolution needs, then deleted or de-identified.
13. Breach Notification
If a security incident compromises personal information, we will notify affected individuals and any required regulators consistent with applicable law, including Cal. Civ. Code section 1798.82, which requires notice to affected California residents within 30 calendar days of discovery, and GDPR Articles 33 and 34 for EU and EEA residents.
14. International Users and Transfers
The Services are operated from the United States, and our providers process data in the United States. If you access the Services from outside the United States, your information will be processed in the United States, which may have different data-protection laws than your country. We do not currently rely on any specific cross-border transfer mechanism such as Standard Contractual Clauses for information you submit directly to us; if that changes, we will update this policy. Contact us with any questions about where your information is processed.
15. Business Transfers
In a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of the transaction, and the successor will handle it consistent with this policy unless you are notified otherwise.
16. Children
The Services are intended for adults 18 years of age or older. The Services are not directed to children under 13, and we do not knowingly collect their personal information. Persons under 18 may read the public educational content but should not submit personal information, request emailed estimates or reminders, or create accounts. If you believe a child under 13 has provided us personal information, please contact us and we will delete it. (16 C.F.R. part 312 (COPPA Rule)).
17. Shine the Light
California residents may request information about disclosures of personal information to third parties for their direct marketing purposes under California's "Shine the Light" law. (Cal. Civ. Code section 1798.83). We do not disclose personal information to third parties for their own direct marketing.
18. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by a new "Last Updated" date at the top of this page and, where required, by additional notice. Prior versions are kept on file and are available on request.
Contact
- Operator: Aurelis LLC, doing business as The Veteran Benefit Desk
- Mailing address: Aurelis LLC, c/o Northwest Registered Agent, 2108 N Street, Suite N, Sacramento, CA 95816, United States
- Requests and questions: email legal@veteranbenefitdesk.com or use the Contact page. Notices may be sent to the mailing address above.