Privacy Policy

Last updated: August 13, 2026

This Privacy Policy explains how Pete Technology Inc. ("Pete," "we," "us," or "our") collects, uses, discloses, and protects information in connection with Pete's software for VA disability attorneys and their firms.

1. Scope

This Privacy Policy applies to our websites, marketing pages, account flows, attorney application, case-record workflows, communications capture features, AI features, support communications, VA API-connected workflows where enabled, and related services (collectively, the "Services").

Pete serves attorneys and firms. Veterans may provide information through case-bound document or communication flows that a participating firm shares with them. In those contexts, the firm may also control how information is collected and used for representation, conflict checks, and case work.

For customer-controlled case materials, Pete generally acts as a service provider or processor to the firm. For our websites, marketing, account administration, security operations, and direct business communications, Pete may act as the business or controller responsible for the processing described here. Any signed Order Form, data processing addendum, or business associate agreement controls where it conflicts with this Privacy Policy.

2. Information we collect

We may collect the following categories of information:

  • account and contact information, such as name, email address, phone number, firm, role, title, and login details;
  • professional information, such as VA accreditation, bar information, firm affiliation, permissions, and team membership;
  • veteran and case information, such as service history, conditions, claim history, rating information, deadlines, forms, documents, C-files, medical records, STRs, C&P exams, correspondence, and notes;
  • VA API-derived information where a firm enables an approved VA integration, such as claim, appeal, power-of-attorney, form, submission, status, and related case-source metadata;
  • communications information, such as emails, SMS messages, phone call metadata, call recordings, video meeting metadata, transcripts, and case communications;
  • connected email information, such as connected account address, provider account identifiers, granted scopes, connection health, message and thread identifiers, sender and recipient addresses, cc and bcc addresses, subjects, snippets, body text, labels or folders, timestamps, attachment indicators, and case-matching metadata;
  • connected calendar information, such as connected account address, provider account identifiers, granted scopes, connection health, busy intervals, meeting titles, descriptions, locations, attendees, time ranges, external event identifiers, and provider meeting or join links;
  • consent, authorization, audit, and security records, such as communication opt-ins, access events, administrative actions, upload events, signing events, processing status, and support history;
  • files and document content uploaded to or generated by the Services;
  • billing and commercial information, such as subscription details, invoices, payment status, and firm billing contacts;
  • integration information from connected email, calendar, phone, storage, or authentication providers, including encrypted OAuth credentials and provider permission metadata; and
  • technical and usage information, such as IP address, device information, browser, pages viewed, referring pages, logs, cookie identifiers, and product usage events.

3. Sources of information

We collect information directly from users, firms, veterans who use firm-shared flows, connected integrations, service providers, public sources, and automated technologies such as cookies, logs, and analytics events.

If you connect third-party systems to Pete, such as email, calendar, phone, SMS, video, storage, or authentication providers, we process information from those systems as needed to provide the connected functionality.

Firms and authorized firm users are responsible for providing any required notices and obtaining any required rights, permissions, client consents, communication consents, and authorizations before they submit, connect, or direct Pete to process information on their behalf.

4. Connected email and calendar integrations

If an authorized user connects a Google, Microsoft, or other supported email or calendar account, Pete processes information from that provider only as needed to provide the connected, case-bound functionality enabled by the user or firm. Email, calendar, and account-sign-in OAuth connections are separate; granting one type of access does not by itself grant another type of access.

Email integrations may let Pete read and sync recent or incremental messages from the connected mailbox, store message and thread content in case records, classify inbound messages, match messages to cases, maintain case communication history, create attorney or staff review cards, and send case-specific email from the connected mailbox where the user has granted provider send authority and approves the send through the applicable workflow.

Calendar integrations may let Pete read availability or busy intervals from the connected calendar, evaluate available meeting times, create case-related meetings, add attendees, include meeting descriptions or locations, store provider event identifiers, and record provider meeting or join links after the provider creates the event.

When a user explicitly opts in while connecting email, Pete may read a bounded sample of recent sent emails from that connected mailbox to build a compact drafting style profile for that user and firm. Pete stores the resulting style profile, not a second copy of the sent-email sample, and uses it as non-authoritative guidance for future email drafts. The profile does not replace case facts, attorney review, recipient review, or final approval before sending.

OAuth access and refresh tokens for connected accounts are kept only in server-managed encrypted storage and used to refresh the connection and run the connected workflow. When a connection is disconnected, future access through that connection stops, and stored OAuth credentials are deleted under our retention procedures. Existing case records, sent-message records, created meeting records, audit records, security records, and provider data outside Pete may remain unless deleted through an applicable firm-approved deletion workflow, provider control, Order Form, or legal requirement.

The Services are not a standalone inbox, bulk-email system, calendar replacement, booking-page builder, or docketing system of record. Provider account data is not sold, shared for cross-context behavioral advertising, or used to train third-party large language models.

Use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace data is used only to provide or improve the visible case-bound email and calendar features, for security, to comply with law, or with the user's consent where required. Google Workspace data is not transferred to advertising platforms, data brokers, or information resellers; is not used for serving ads, retargeting, personalized advertising, credit-worthiness, lending, or unrelated profiling; and is subject to human-access limits for specific user or customer authorization, security, legal compliance, or aggregated and anonymized internal operations.

5. How we use information

We use information to:

  • provide, operate, secure, and maintain the Services;
  • create and maintain case records, case workups, deadlines, communications logs, and case answers;
  • authenticate users, manage firm membership, and enforce permissions;
  • support phone, SMS, email, meeting, and case-record workflows;
  • sync, classify, match, draft, review, and send case-bound email where authorized;
  • check calendar availability and create case-related meetings where authorized;
  • request, retrieve, submit, sync, or monitor VA-connected case information where an authorized firm user enables an approved integration;
  • generate AI-assisted outputs requested by authorized users;
  • provide support, respond to inquiries, and communicate about the Services;
  • process payments, manage subscriptions, and administer trials or demos;
  • monitor reliability, prevent abuse, detect security events, and debug issues;
  • create audit trails, enforce access controls, support exports and deletion workflows, and preserve security evidence;
  • improve the Services using aggregated or de-identified information; and
  • comply with legal, regulatory, and contractual duties.

6. AI processing

AI-assisted features help organize case materials, support attorney review, summarize approved communications, and answer questions from available case materials.

Email and calendar AI features stay case-bound or user-bound. Pete may use connected email content to classify messages, summarize case communications, draft attorney-reviewable replies, or build an opt-in drafting style profile as described above. Pete does not use connected email or calendar content to build generalized AI models, and attorney or authorized firm-user approval remains required for final case-specific client email sends.

Customer case data, veteran records, and uploaded files are not used to train third-party large language models. Sensitive AI workflows run only through provider paths approved for the data being processed, and provider settings, contractual controls, and product configuration are used to prevent model training or retention beyond what is needed to provide, secure, support, and maintain the Services.

AI inputs and outputs may include sensitive case information when an authorized user asks Pete to process that case. Do not paste unrelated case materials, privileged notes, medical facts, or veteran identifiers into unsupported tools or support channels.

AI output may be incomplete or inaccurate. Attorneys and authorized firm users should verify output and citations before relying on them in a legal matter.

7. How we disclose information

We may disclose information:

  • to the firm, attorneys, representatives, and other authorized users connected to the relevant case or firm;
  • to veterans or prospective clients through firm-shared flows when needed to provide document, communication, or case-bound features;
  • to service providers that support hosting, storage, authentication, security, analytics, communications, email, calendar, billing, support, AI processing, OCR, monitoring, and operations under appropriate confidentiality, security, and data-protection obligations;
  • to third-party integrations you or your firm connect to the Services;
  • back to connected email and calendar providers when needed to send approved emails, create calendar events, refresh account access, or operate the connected workflow you or your firm enabled;
  • to professional advisors, auditors, insurers, legal counsel, payment processors, and other business partners that support ordinary business, compliance, risk-management, or financing activities;
  • to comply with law, court orders, subpoenas, professional obligations, government requests, or regulatory requirements;
  • to protect the rights, privacy, safety, security, or property of Pete, customers, users, veterans, or others; and
  • in connection with a merger, financing, acquisition, reorganization, sale of assets, bankruptcy, or similar corporate transaction, subject to appropriate protections.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising as those terms are used in California privacy law.

Veteran data, VA API-derived data, case records, and Customer Data are not sold, licensed, brokered, or monetized. We use that information only to provide, secure, support, maintain, and improve the Services for authorized customers and their cases, or as required by law.

Connected provider data, including Google Workspace data and Microsoft account data, is not disclosed to advertising platforms, data brokers, or information resellers. If a merger, financing, acquisition, reorganization, sale of assets, bankruptcy, or similar transaction involves provider data that is subject to additional provider consent or transfer rules, we handle that data only as permitted by the applicable provider policy, law, Order Form, and user or customer consent requirement.

8. Sensitive information and veteran records

Sensitive legal and veteran records may include protected health information, VA records, military service information, and information subject to heightened confidentiality obligations. VA API-derived records and VA-connected submission or status data are restricted case data.

The Services do not operate as a public veteran directory, marketplace, or open intake front door. Veteran-facing collection or communication surfaces are firm-originated and case-bound. Access to restricted case data is limited to authorized firm users, approved workflows, and service providers needed to operate, secure, support, and maintain the Services.

Firms remain responsible for determining their own legal, ethical, federal and state record-confidentiality, bar-rule, client-consent, vendor-review, and record-retention obligations. Where required, we may enter into a data protection addendum or other customer agreement covering the applicable data.

9. Cookies and analytics

We use cookies and similar technologies to operate the site, remember preferences, understand usage, improve performance, and protect the Services. You can manage non-essential cookies through the cookie preferences control on our site.

Analytics and operational events are designed to avoid raw case contents, medical facts, legal strategy, document text, government identifiers, and other sensitive case details. Authentication, security, and strictly necessary cookies may be required for the Services to function.

Some browsers offer "Do Not Track" or similar signals. Because there is not a uniform standard for these signals, we do not currently respond to them. If a required standard applies, we will update this Privacy Policy.

10. Retention

We retain information for as long as needed to provide the Services, comply with legal and contractual obligations, resolve disputes, maintain security, enforce agreements, and support legitimate business purposes. VA API-derived case data follows the same case-record retention posture as other restricted case material unless a customer agreement, legal hold, applicable law, or approved deletion workflow requires a different period.

Retention periods may vary depending on the type of data, firm settings, an Order Form, a data processing addendum, legal requirements, case status, backup cycles, and whether deletion would interfere with security, auditability, or legal obligations.

Deleted information may persist for a limited time in backups, logs, audit records, or archives until those systems are overwritten or no longer required. We may retain aggregated or de-identified information that does not identify a customer, firm, user, veteran, client, claimant, case, or document.

Email and calendar connection secrets are retained only while the account remains connected or needs reconnection, and are deleted when the user disconnects the integration in Pete. Email messages, sent-message records, calendar event records, case activity, and audit records that have already become part of a case record follow the applicable case-record, audit, legal-hold, backup, and customer-agreement retention posture. Users may also need to revoke Pete's access directly in the relevant Google, Microsoft, or other provider account settings.

11. Security

We use administrative, technical, and organizational safeguards designed to protect information from unauthorized access, loss, misuse, alteration, or disclosure. These safeguards may include encryption, access controls, tenant isolation, audit logging, vendor review, least-privilege operations, private document storage, short-lived authorized access, and server-only handling of integration credentials. OAuth access and refresh tokens for connected email and calendar accounts are encrypted before storage.

Public descriptions of the Services are not security certifications, legal opinions, or promises that a specific regulatory framework applies to a customer's use case. Customers remain responsible for their own legal and compliance determinations.

No method of transmission or storage is completely secure. If you believe your account or information has been compromised, contact us promptly at security@pete.vet.

12. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict certain personal information, or to opt out of certain processing. These rights are not absolute and may be limited by law, firm obligations, case records, security needs, or contractual duties.

Where Pete processes Customer Data on behalf of a firm, we may refer or coordinate your request with that firm. We will not discriminate against you for exercising privacy rights, but some requests may limit our ability to provide the Services.

To exercise privacy rights, email privacy@pete.vet. We may need to verify your identity and, for requests about firm-controlled case information, coordinate with the relevant firm.

13. United States state privacy notices

Certain U.S. state privacy laws provide residents with specific rights. In the past twelve months, we may have collected identifiers, professional information, commercial information, internet or network activity, communications, sensitive information, and inferences derived from use of the Services.

We collect this information from the sources described above and use or disclose it for the purposes described in this Privacy Policy. We do not sell personal information and do not share personal information for cross-context behavioral advertising.

We use and disclose sensitive personal information only as needed to provide, secure, support, maintain, improve, or comply with legal obligations for the Services, or as otherwise permitted by applicable law. We do not use sensitive personal information to infer characteristics for unrelated marketing.

California residents may also request information about certain disclosures of personal information for direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes.

14. Children

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Pete, contact us so we can take appropriate steps.

15. International users

The Services are operated from the United States. If you access the Services from outside the United States, you understand that information may be processed in the United States and other locations where our service providers operate.

16. Changes and contact

We may update this Privacy Policy from time to time. The updated version will be indicated by the updated date above. Material changes may be communicated by posting notice, sending email, or another reasonable method.

Questions about privacy can be sent to privacy@pete.vet.