Skip to content

GOOD FAITH, ON THE RECORD.

Security

Your conversation, held briefly and carefully.

Years of private messages are the most sensitive thing anyone hands us. Here is exactly what happens to them, how long we keep them, and who can reach them.

The four things that matter

Short retention, strong encryption, logged access, and no second use.

Most security pages are adjectives. These are the controls, and each one is something you can hold us to.

Three days, by default

Your conversation is deleted three days after processing finishes. Not archived, not anonymised — deleted. You can make that window shorter, longer, or end it yourself at any moment.

Encrypted the whole way

Encrypted in transit and encrypted at rest. Keys are managed in AWS Key Management Service and scoped per case, so one case's key opens one case.

Every access recorded

A small number of named engineers can reach stored conversations, and every read is written to an append-only log. Support staff cannot read case content at all.

Never sold, never trained on

We do not sell personal information, we do not share it for advertising, and we do not train models on your messages. Our providers are contractually held to the same.

Where your data goes

Four steps, and the last one is deletion.

Nothing here is left implied. This is the whole path a message takes.

Your computerread locallyEncryptedTLS, then at restProcessedisolated, loggedDeletedday threeWHAT WE HOLDeverything you sentnothingThree days by default. You choose the window.

Sign in

Accounts and sign-in run through Clerk. Multi-factor is available on every plan and required on firm accounts.

Upload

The file is encrypted before it leaves your browser and stays encrypted at rest. Large uploads resume rather than restart.

Processing

Your record, call log and transcript are built in an isolated environment that reaches nothing else. Identifiers we detect are removed or tokenised before storage.

Translation

If you use it, selected messages go to a model provider under a zero-retention agreement — not stored by them, not used for training.

Analytics

Product analytics count events, not content. We measure that a record was built, never what was in it.

Deletion

At the end of your window, live copies go immediately and encrypted backups roll off within thirty days.

Retention

You choose how long we keep it.

Three days is the default because most filings are finished inside it. Everything else is your call, and you can end it early whenever you like.

3 daysDEFAULT7 days21 days365 daysARCHIVEshorter is saferlonger if the matter needs itYou can shorten it, extend it, or delete everything at any time.

3 days Default

Long enough to finish a filing. Applies to every plan unless you change it.

7 days Optional

For a filing you are still working through.

21 days Optional

For a matter that runs over several weeks.

365 days Firm and archive plans

Moved to cold storage on a lifecycle policy, retrieved when you ask.

Deletion is not instantaneous and we would rather say so. Live copies go immediately; encrypted backups roll off within thirty days, and nothing is restored from them except to recover from a failure.

Translation

What we remove before a model sees anything.

Translation is the one part of the product that involves an outside provider, so it gets the most explanation.

Only what you select

Translation runs on the messages you choose, not on your whole archive. If you never use it, nothing is ever sent to a model provider.

Identifiers removed first

Phone numbers, email addresses and case numbers we detect are stripped or replaced with a one-way token before anything is sent, and every removal is recorded so the change can be audited.

Zero retention at the provider

Messages are not stored by the provider and are not used to train anything. That is contractual, not a preference.

A human still signs it

We produce a draft translation with its confidence marked. A person reviews and certifies it, because that is what a filing requires and what we will not automate.

REMOVED WHERE DETECTEDPhone numbersEmail addressesCase numbersPostal addressesGOES THROUGHThe message itselfTranslating it is the job.Translation modelZero retention. No training.Every removal is recorded, so the change can be audited.

The platform

Built on AWS, isolated, watched.

We are not going to publish a network diagram. These are the properties that decide whether your data is safe, without handing anyone a map.

Isolated by design

Processing runs in its own environment with no path to anything else. The database is not reachable from the public internet.

Tamper-evident output

Every package we produce carries a cryptographic hash of what it was built from, so an opponent can confirm it has not been altered since.

Backups you can rely on and still escape

Encrypted, tested, and short-lived. Backups exist so a failure does not lose your work, and they expire so deletion still means something.

Monitored continuously

Access patterns, failed sign-ins and unusual activity are watched. Alerts go to people, not just to a dashboard.

Who else is involved

Our sub-processors, named.

Every company that touches your data on our behalf, and what each one does. If this list changes, we update it here.

Clerk

Accounts and sign-in. Holds your email address, never your conversation.

Supabase

Database and file storage for your records, in the United States.

Amazon Web Services

Compute, encryption keys and backups, in the United States.

Stripe

Payment. Holds your billing details; we never see your card number.

What we commit to

Three promises, in plain words.

These are the ones that are easy to make and hard to keep, which is why they are written down.

We will tell you if something goes wrong

If your data is involved in a breach we will contact you directly, with what we know and what we are doing, within the timeframe the law requires and sooner if we can.

We will not quietly change this

If our handling of your data changes materially, we will ask you again rather than update a policy page and hope. We have changed this page before and said so.

We will say no where we can

If we receive a legal demand we will require it to be valid, narrow it where possible, and tell you unless we are prohibited from doing so.

Questions

Reviewing us for a firm?

We will sign a data processing agreement and answer a security questionnaire. Ask and you will get a person, not a form. The written security policy sets out the same commitments in the form a reviewer expects.