Privacy Policy
Last updated: August 31, 2026
1. Overview
2. Information We Collect
We collect the following categories of information:
Account Information
Email address, firm name, display name, and hashed password when you register.
Document Content
Legal documents you upload for processing. These are stored securely in encrypted cloud storage, associated exclusively with your tenant (firm).
Usage Data
Page views, API calls, document processing counts, and feature usage for billing and product improvement.
Technical Data
IP address, browser type, device identifiers, and log data for security monitoring.
3. How We Use Your Information
- To provide and operate the Service (secure document storage, knowledge graph indexing, search/chat, manual deadline capture).
- To authenticate users and enforce multi-tenant data isolation.
- To calculate and bill for per-user subscription charges.
- To send transactional emails (account confirmation, password reset).
- To monitor for security incidents and prevent abuse.
- To improve AI-assisted workflows using anonymized, aggregated metrics only — never your document content.
4. Multi-Tenant Data Isolation
5. Data Sharing and Third Parties
- Cloud Infrastructure: AWS (S3 for document storage, CloudFront/Lambda/API hosting, monitoring). AWS is bound by a Data Processing Addendum.
- AI Processing (OCR & Legacy Extraction): Mistral AI for document OCR and the read-only legacy extraction pipeline. Only the minimum text required for those workflows is sent, and Mistral is contractually barred from training on it.
- Knowledge Search & Chat: Anthropic Claude for tenant-scoped search/chat responses. Prompts contain only the relevant snippets plus metadata, and Anthropic is contractually prohibited from training on your data.
- Vector Database: Qdrant Cloud for semantic search indexing. We store embeddings (numerical vectors) and metadata, never raw document text.
- Payment Processing: Xendit for billing. We do not store full card numbers. Accepts Maya and credit/debit cards.
- Legal Requirements: We may disclose data if required by law, court order, or to protect rights and safety.
6. Google API Services — Limited Use Disclosure
DueCounsel's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Specifically:
- No AI/ML training: We do not use, transfer, or sell raw, aggregated, anonymized, or derived data obtained from Google Workspace APIs to develop, train, improve, or fine-tune any foundational, generalized, or third-party artificial intelligence or machine learning model. Google Calendar data is never included in any model training or improvement pipeline.
- Limited purpose: Google Calendar data is used solely to provide and improve the user-facing calendar synchronization feature you explicitly enabled — displaying your events inside DueCounsel and writing DueCounsel deadlines and hearings back to your chosen calendar.
- No transfer: We do not transfer Google user data to third parties except as necessary to provide the calendar sync feature, to comply with applicable law, or as part of a merger or acquisition following notice to you.
- No advertising: We do not use Google user data for serving advertisements of any kind, including retargeting, personalized, or interest-based advertising.
- No human access: No DueCounsel employee reads your Google Calendar data, except with your explicit consent for a specific support request, where required for security purposes, to comply with applicable law, or where the data is aggregated and anonymized for internal operations.
We request only the narrowest scopes required for the feature:
calendar.events— read and write calendar events, enabling two-way sync of deadlines and hearings.calendar.calendarlist.readonly— list your calendars so you can choose which one to sync.
You may disconnect Google Calendar at any time from your DueCounsel integration settings or by revoking access at myaccount.google.com/permissions. Disconnecting deletes the stored OAuth tokens and stops all synchronization.
7. Data Retention
- Account data is retained while your account is active and for 30 days after termination.
- Documents and extracted deadlines are retained while your subscription is active.
- You may request deletion of your data at any time by contacting us. Processing may take up to 30 days.
- Audit logs are retained for 12 months for security purposes.
8. Security
- Passwords stored as PBKDF2-SHA256 hashes with unique salts.
- All data transmitted over TLS 1.2+.
- Documents stored in encrypted S3 buckets (AES-256).
- JWT-based authentication with short-lived tokens.
- Access logs and anomaly detection.
9. Attorney-Client Privilege
10. Cookies
11. Your Rights
- Access a copy of data we hold about you.
- Correct inaccurate account information.
- Request deletion of your data.
- Data portability (export your extractions as CSV or ICS).
- Opt out of non-essential communications.
12. Children
13. Changes to This Policy
14. Contact
DueCounsel Privacy Team