Skip to main content

Last updated July 18, 2026

Privacy

The guide is designed to avoid accounts and long-term server-side conversation records. Your saved session lives mostly in your browser, but chat, PDF generation, security checks, and abuse controls still require ordinary server and provider processing.

Health and care information is covered separately by our Consumer Health Data Privacy Policy.

What stays in your browser

Your active planning session is saved in your browser using localStorage. This lets you close the page and come back later on the same browser without creating an account.

The saved browser data can include your chat messages and structured planning profile details you share during the session, such as family structure, care setting, financial ranges, legal document status, and planning goals.

Anyone with access to that browser profile or device may be able to see the saved session. Use a private device and clear the session if that matters.

What is processed while you use the guide

Before a page or API request is served, the hosting provider derives a country code from the requester's public IP address so the service can be limited to visitors in the United States. The country code is used for that request and is not intentionally added to the browser-saved planning session or a long-term analytics database.

When you send a chat message, the relevant conversation context and planning profile are sent to the server and to our AI provider so the assistant can generate a response.

When you generate a PDF, the profile details needed for that document are sent to the server-side document generator for that request. PDF generation does not require another AI call.

State-rule lookup requests may process the state you select so the guide can return Medicaid planning context for that state.

AI processing and model training

The AI provider processes chat context and profile details only so the guide can respond to your request while you are using the service.

We do not use your planning inputs, chat messages, or generated reports to train our own models.

We do not authorize the AI provider to use your identifiable planning content to train foundation models. Provider-side abuse, security, and operational logging may still occur under that provider's terms and policies.

Cookies, rate limits, and verification

The site may set an HttpOnly cookie named elp_sid for up to 24 hours to recognize an anonymous browser session for rate limiting, abuse prevention, report-download limits, and bot-check flow. It is necessary to protect the service and is not used for advertising.

The short-lived counter store uses HMAC-protected session and IP identifiers, request counts, token-use totals, verification status, and timestamps. Burst counters expire after about 10 minutes; daily, document, and verification counters expire within about 24 hours.

Routine application logs may include request size, message count, response status, latency, model, token totals, and error details. They do not intentionally include stable session/IP identifiers, full chat transcripts, or planning profiles.

If bot verification is triggered, the verification provider may process browser, device, and network signals to determine whether a request is automated abuse.

What we do not do

We do not sell your planning information.

We do not share your planning information for cross-context behavioral advertising.

We do not use your planning information for targeted advertising.

We do not maintain a server-side conversation database for completed sessions.

We do not require an account, login, or email address to use the planning session.

Analytics and error monitoring

The current site is designed without advertising pixels or cross-site tracking for marketing.

If analytics or error-monitoring tools are added, they should be limited to operations, security, performance, and product-quality purposes, and this Privacy page should be updated to identify the categories of data processed.

Do not assume that browser extensions, network providers, hosting providers, or linked third-party sites follow this Privacy page.

Service providers and infrastructure logs

Like most hosted web apps, our hosting, AI processing, bot-verification, and counter-storage providers process the limited information needed to provide their functions.

Those logs are separate from the browser-saved planning session and are not designed as a user-facing planning record.

Do not enter information you would not want processed by an AI service, ordinary web infrastructure, or the providers needed to operate the site.

Retention and clearing your data

Browser-saved session data remains on your device until you use New Conversation, clear site data, clear browser storage, or the browser removes it.

Use New Conversation in the chat to remove the locally saved messages and planning profile for this site from your browser.

You can also clear this site data directly through your browser settings.

The anonymous security cookie, daily counters, and verification state expire within about 24 hours; burst counters expire after about 10 minutes.

Under the current AI provider's standard API controls, chat inputs and outputs are automatically deleted from its systems within 30 days, subject to security, legal, or account-specific exceptions.

Routine application and infrastructure logs remain only for the provider or account retention window used to operate and secure the service. We do not copy them into a long-term user analytics database.

We do not provide the planning session as a permanent records system.

Sensitive information

Elder law planning can involve sensitive financial, medical, and family information. Share only what is useful for educational planning and attorney preparation.

Do not enter Social Security numbers, Medicare or Medicaid IDs, account numbers, passwords, full medical records, court filings, or other details that are not needed for the educational planning summary.

Do not use this site for emergencies, active litigation strategy, privileged attorney-client communications, or information you are not authorized to share.

This site is not designed as a HIPAA-compliant medical-record system or a confidential attorney-client portal.

US state privacy rights

Depending on where you live, you may have rights to request access, deletion, correction, portability, restriction, or opt-out choices for certain personal information.

California residents may have CCPA/CPRA rights, including the right to know, delete, correct, opt out of sale or sharing, limit certain sensitive-information uses, and avoid discrimination for exercising privacy rights.

Residents of Colorado, Connecticut, Virginia, and similar US privacy-law states may have comparable rights, including rights related to access, deletion, correction, portability, targeted advertising, sale, profiling, and appeal.

To make a privacy request, email privacy@elderlawprep.com. We may need enough information to verify the request and connect it to browser-side or server-side records that still exist.

Because the guide does not require accounts and stores the active planning session in your browser, some requests may be satisfied by using New Conversation or clearing this site data in your browser.

Children

The guide is intended for adults handling elder law and care-planning questions. It is not intended for children under 18.

Changes

We may update this Privacy page as the site, providers, or abuse controls change. The Last updated date shows when this page was most recently revised.

Not confidential legal advice

Using this site does not create an attorney-client relationship. The tool provides educational planning help only and should not be treated as confidential legal counsel, a medical-record system, or a secure repository for sensitive documents.