Last updated July 21, 2026
The short version. RightsBook is built to keep your information private. The rights chat has no account and stores nothing on our servers. The optional Vault, where you keep your own documentation, is end-to-end encrypted so only you can read it. We do not use analytics, we do not track you across apps or websites, we show no ads, and we never sell your data.
RightsBook is an independent educational resource that helps Medicaid Home and Community-Based Services (HCBS) participants and their families understand their rights. RightsBook is not affiliated with Medicaid, any state Department of Health Care Services, any regional center, or any federal or state agency, and it does not provide legal advice.
When you ask a question, the text of your conversation and the state you selected are sent to an AI language-model provider so it can write an answer grounded in public HCBS regulations. We do not require an account for this, we do not log or store the content of your questions or answers on our servers, and nothing about a question is kept server-side after the answer is returned.
Because your question text is processed by a third-party AI provider to generate the answer, please do not type sensitive personal details (such as full names, addresses, or medical record numbers) into the chat. You do not need to identify yourself to get an answer.
Your past questions and answers, and the state you last selected, are saved locally on your device (in your browser or app storage) so you can return to them. This stays on your device and is not sent to us. Clearing the app's data, or clearing your browser storage, removes it.
If you choose to use the Vault to keep incidents, appeal deadlines, request letters, documents, and photos, you create an account with your email address and set a PIN.
Encrypted Vault data is synced and stored through our infrastructure provider (Supabase) so it is available across your devices.
The Vault is offered with a free trial and an optional paid subscription or one-time unlock. Purchases made in the iOS app are handled by Apple, and subscription status is managed for us by RevenueCat; web purchases are handled by Stripe. We receive confirmation that a purchase or subscription is active, but we do not receive or store your full card number. Please see Apple's, RevenueCat's, and Stripe's privacy policies for how they handle payment information.
To run RightsBook we rely on a small set of providers that process data on our behalf:
RightsBook is intended for adults, including participants, family members, and advocates. It is not directed to children under 13, and we do not knowingly collect personal information from children.
You can delete your on-device history by clearing the app's data. You can ask us to delete your account and its encrypted Vault data by emailing the address below. Because the Vault is end-to-end encrypted, we can delete the encrypted data but cannot read it.
If we make a material change to how we handle your information, we will update this page and revise the date above.