Security
Your conversation, held briefly and carefully.
Years of private messages are the most sensitive thing anyone hands us. Here is exactly what happens to them, how long we keep them, and who can reach them.
The four things that matter
Short retention, strong encryption, logged access, and no second use.
Most security pages are adjectives. These are the controls, and each one is something you can hold us to.
Three days, by default
Your conversation is deleted three days after processing finishes. Not archived, not anonymised — deleted. You can make that window shorter, longer, or end it yourself at any moment.
Encrypted the whole way
Encrypted in transit and encrypted at rest. Keys are managed in AWS Key Management Service and scoped per case, so one case's key opens one case.
Every access recorded
A small number of named engineers can reach stored conversations, and every read is written to an append-only log. Support staff cannot read case content at all.
Never sold, never trained on
We do not sell personal information, we do not share it for advertising, and we do not train models on your messages. Our providers are contractually held to the same.
Where your data goes
Four steps, and the last one is deletion.
Nothing here is left implied. This is the whole path a message takes.
Sign in
Accounts and sign-in run through Clerk. Multi-factor is available on every plan and required on firm accounts.
Upload
The file is encrypted before it leaves your browser and stays encrypted at rest. Large uploads resume rather than restart.
Processing
Your record, call log and transcript are built in an isolated environment that reaches nothing else. Identifiers we detect are removed or tokenised before storage.
Translation
If you use it, selected messages go to a model provider under a zero-retention agreement — not stored by them, not used for training.
Analytics
Product analytics count events, not content. We measure that a record was built, never what was in it.
Deletion
At the end of your window, live copies go immediately and encrypted backups roll off within thirty days.
Retention
You choose how long we keep it.
Three days is the default because most filings are finished inside it. Everything else is your call, and you can end it early whenever you like.
3 days Default
Long enough to finish a filing. Applies to every plan unless you change it.
7 days Optional
For a filing you are still working through.
21 days Optional
For a matter that runs over several weeks.
365 days Firm and archive plans
Moved to cold storage on a lifecycle policy, retrieved when you ask.
Deletion is not instantaneous and we would rather say so. Live copies go immediately; encrypted backups roll off within thirty days, and nothing is restored from them except to recover from a failure.
Translation
What we remove before a model sees anything.
Translation is the one part of the product that involves an outside provider, so it gets the most explanation.
Only what you select
Translation runs on the messages you choose, not on your whole archive. If you never use it, nothing is ever sent to a model provider.
Identifiers removed first
Phone numbers, email addresses and case numbers we detect are stripped or replaced with a one-way token before anything is sent, and every removal is recorded so the change can be audited.
Zero retention at the provider
Messages are not stored by the provider and are not used to train anything. That is contractual, not a preference.
A human still signs it
We produce a draft translation with its confidence marked. A person reviews and certifies it, because that is what a filing requires and what we will not automate.
The platform
Built on AWS, isolated, watched.
We are not going to publish a network diagram. These are the properties that decide whether your data is safe, without handing anyone a map.
Isolated by design
Processing runs in its own environment with no path to anything else. The database is not reachable from the public internet.
Tamper-evident output
Every package we produce carries a cryptographic hash of what it was built from, so an opponent can confirm it has not been altered since.
Backups you can rely on and still escape
Encrypted, tested, and short-lived. Backups exist so a failure does not lose your work, and they expire so deletion still means something.
Monitored continuously
Access patterns, failed sign-ins and unusual activity are watched. Alerts go to people, not just to a dashboard.
Who else is involved
Our sub-processors, named.
Every company that touches your data on our behalf, and what each one does. If this list changes, we update it here.
Clerk
Accounts and sign-in. Holds your email address, never your conversation.
Supabase
Database and file storage for your records, in the United States.
Amazon Web Services
Compute, encryption keys and backups, in the United States.
Stripe
Payment. Holds your billing details; we never see your card number.
What we commit to
Three promises, in plain words.
These are the ones that are easy to make and hard to keep, which is why they are written down.
We will tell you if something goes wrong
If your data is involved in a breach we will contact you directly, with what we know and what we are doing, within the timeframe the law requires and sooner if we can.
We will not quietly change this
If our handling of your data changes materially, we will ask you again rather than update a policy page and hope. We have changed this page before and said so.
We will say no where we can
If we receive a legal demand we will require it to be valid, narrow it where possible, and tell you unless we are prohibited from doing so.
Questions
Reviewing us for a firm?
We will sign a data processing agreement and answer a security questionnaire. Ask and you will get a person, not a form. The written security policy sets out the same commitments in the form a reviewer expects.