CaseCounsel

Legal

Privacy Policy

Last updated: April 2026 · Prototype version

Prototype notice. This policy applies to the legaltech prototype. A production privacy policy and Data Processing Addendum will replace this document at launch. For enterprise diligence, we'll share our controls matrix and threat model under NDA.

What we collect

  • Account data: Auth0 identity (sub, email, name), tenant (Auth0 Organization) membership, assigned roles.
  • Firm + client data: clients, matters, time entries, expenses, invoices, legal requests, knowledge-base articles you create.
  • Operational metadata: audit events (actor, action, HTTP path, request ID, hashed IP / email for correlation). Never plaintext PII in logs.
  • AI interactions: prompts + responses routed through Gemini in real mode; never used to train third-party models (per provider terms).

How we protect it

  • PII columns are encrypted at rest with AES-256-GCM envelope encryption — a per-tenant DEK wrapped by a master KEK.
  • Tenant identity comes only from the verified Auth0 JWT claim — never a request body, header, or query string.
  • TLS 1.2+ in transit. HSTS + secure cookies + strict CSP.
  • Role-scoped access: every route gates on a permission code. Cross-tenant reads return 404 (no existence leak).
  • Immutable audit trail: every mutation lands in audit_events with actor + request ID + non-PII metadata.

How we use it

To operate the Service, provide support, improve reliability, and comply with legal obligations. We don't sell personal data or share it with third parties for marketing.

Sub-processors

  • Auth0 (Okta) — authentication, identity management.
  • Azure (planned at production launch) — infrastructure hosting, Key Vault, Blob Storage.
  • Gemini (Google) — AI generation when AI_MODE=real.
  • Anthropic — alternative AI provider (planned Phase 15).

Your rights (GDPR / CCPA)

  • Access — you can request a copy of your personal data.
  • Correction — you can request corrections.
  • Deletion — you can request deletion (subject to legal retention).
  • Portability — you can request export in a machine-readable format.
  • Objection — you can object to certain processing (e.g. marketing, though we don't do any).

Retention

We retain operational data for the duration of the engagement plus a reasonable period for legal compliance and audit continuity. Soft-deleted records (clients, matters, requests, articles) keep their audit trail intact.

International transfers

At production launch, tenants will select a data-residency region. Prototype data currently sits on local dev infrastructure.

Children

The Service is not directed to children under 16. We don't knowingly collect their data.

Changes

We'll notify you of material changes via email or in-product notice. Continued use after a change means acceptance.

Contact

Privacy questions or data requests? Use the contact page.