Privacy Policy

Last updated: August 31, 2026

1. Overview

DueCounsel (“we”, “us”, “our”) is committed to protecting the privacy of law firms and their clients. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service. By using DueCounsel, you consent to this policy.

2. Information We Collect

We collect the following categories of information:

Account Information

Email address, firm name, display name, and hashed password when you register.

Document Content

Legal documents you upload for processing. These are stored securely in encrypted cloud storage, associated exclusively with your tenant (firm).

Usage Data

Page views, API calls, document processing counts, and feature usage for billing and product improvement.

Technical Data

IP address, browser type, device identifiers, and log data for security monitoring.

3. How We Use Your Information

  • To provide and operate the Service (secure document storage, knowledge graph indexing, search/chat, manual deadline capture).
  • To authenticate users and enforce multi-tenant data isolation.
  • To calculate and bill for per-user subscription charges.
  • To send transactional emails (account confirmation, password reset).
  • To monitor for security incidents and prevent abuse.
  • To improve AI-assisted workflows using anonymized, aggregated metrics only — never your document content.

4. Multi-Tenant Data Isolation

Each law firm is assigned a unique tenant identifier. All documents, extractions, and AI search results are strictly scoped to your firm's tenant. No user can access another firm's data through the Service. Data isolation is enforced at every layer: API, database queries, and vector search indexes.

5. Data Sharing and Third Parties

We do not sell your data. We share data with third parties only as follows:
  • Cloud Infrastructure: AWS (S3 for document storage, CloudFront/Lambda/API hosting, monitoring). AWS is bound by a Data Processing Addendum.
  • AI Processing (OCR & Legacy Extraction): Mistral AI for document OCR and the read-only legacy extraction pipeline. Only the minimum text required for those workflows is sent, and Mistral is contractually barred from training on it.
  • Knowledge Search & Chat: Anthropic Claude for tenant-scoped search/chat responses. Prompts contain only the relevant snippets plus metadata, and Anthropic is contractually prohibited from training on your data.
  • Vector Database: Qdrant Cloud for semantic search indexing. We store embeddings (numerical vectors) and metadata, never raw document text.
  • Payment Processing: Xendit for billing. We do not store full card numbers. Accepts Maya and credit/debit cards.
  • Legal Requirements: We may disclose data if required by law, court order, or to protect rights and safety.

6. Google API Services — Limited Use Disclosure

DueCounsel's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Specifically:

  • No AI/ML training: We do not use, transfer, or sell raw, aggregated, anonymized, or derived data obtained from Google Workspace APIs to develop, train, improve, or fine-tune any foundational, generalized, or third-party artificial intelligence or machine learning model. Google Calendar data is never included in any model training or improvement pipeline.
  • Limited purpose: Google Calendar data is used solely to provide and improve the user-facing calendar synchronization feature you explicitly enabled — displaying your events inside DueCounsel and writing DueCounsel deadlines and hearings back to your chosen calendar.
  • No transfer: We do not transfer Google user data to third parties except as necessary to provide the calendar sync feature, to comply with applicable law, or as part of a merger or acquisition following notice to you.
  • No advertising: We do not use Google user data for serving advertisements of any kind, including retargeting, personalized, or interest-based advertising.
  • No human access: No DueCounsel employee reads your Google Calendar data, except with your explicit consent for a specific support request, where required for security purposes, to comply with applicable law, or where the data is aggregated and anonymized for internal operations.

We request only the narrowest scopes required for the feature:

  • calendar.events — read and write calendar events, enabling two-way sync of deadlines and hearings.
  • calendar.calendarlist.readonly — list your calendars so you can choose which one to sync.

You may disconnect Google Calendar at any time from your DueCounsel integration settings or by revoking access at myaccount.google.com/permissions. Disconnecting deletes the stored OAuth tokens and stops all synchronization.

7. Data Retention

  • Account data is retained while your account is active and for 30 days after termination.
  • Documents and extracted deadlines are retained while your subscription is active.
  • You may request deletion of your data at any time by contacting us. Processing may take up to 30 days.
  • Audit logs are retained for 12 months for security purposes.

8. Security

We implement industry-standard security measures including:
  • Passwords stored as PBKDF2-SHA256 hashes with unique salts.
  • All data transmitted over TLS 1.2+.
  • Documents stored in encrypted S3 buckets (AES-256).
  • JWT-based authentication with short-lived tokens.
  • Access logs and anomaly detection.

9. Attorney-Client Privilege

We understand that documents uploaded may contain privileged communications. DueCounsel operates as a technology service provider to your firm. We do not access document content except as necessary to provide the Service. We recommend consulting your jurisdiction's ethics rules regarding cloud storage of client documents before use.

10. Cookies

We use essential session cookies and localStorage tokens (JWT) for authentication. We do not use advertising or cross-site tracking cookies. You may disable cookies in your browser settings, but this will prevent you from logging in.

11. Your Rights

Depending on your jurisdiction, you may have rights to:
  • Access a copy of data we hold about you.
  • Correct inaccurate account information.
  • Request deletion of your data.
  • Data portability (export your extractions as CSV or ICS).
  • Opt out of non-essential communications.
To exercise these rights, email privacy@duecounsel.ph.

12. Children

The Service is not directed to individuals under 18. We do not knowingly collect personal information from minors.

13. Changes to This Policy

We will notify you of material changes via email or in-app notice at least 14 days before they take effect. Continued use of the Service after that date constitutes acceptance.

14. Contact

DueCounsel Privacy Team

privacy@duecounsel.ph