Privacy Policy

Last Updated: January 12, 2025

1. Introduction

At AttorneyAI ("we", "our", or "us"), we take your privacy seriously. This Privacy Policy describes how we collect, use, protect, and share information when you use our legal research platform, website, and services (collectively, the "Services"). By using our Services, you agree to the terms of this Privacy Policy.

2. Information We Collect

2.1 Account Information

  • Full name, email address, phone number
  • Law firm or organization name
  • Bar association number and license information
  • Jurisdiction and practice areas
  • Password (encrypted with bcrypt, never stored in plain text)

2.2 Usage Data

  • Search queries and research history
  • AI conversation history and case analyses
  • Documents uploaded and generated
  • Feature usage patterns and preferences
  • Time spent on platform and session information

2.3 Technical Data

  • IP address (anonymized for GDPR compliance)
  • Browser type, version, and device information
  • Operating system and screen resolution
  • Cookies and similar tracking technologies
  • Referral source and clickstream data

2.4 Legal Content

  • Case files, legal memoranda, and research notes
  • Client communications (subject to attorney-client privilege)
  • Uploaded documents and contracts
  • Annotations and bookmarks

3. How We Use Your Information

  • Service Delivery: Provide legal research, AI analysis, document automation, and case management features
  • Personalization: Customize search results, recommendations, and user interface based on your jurisdiction and practice areas
  • Security: Detect and prevent fraud, abuse, and unauthorized access
  • Customer Support: Respond to inquiries, troubleshoot issues, and provide technical assistance
  • Legal Compliance: Comply with applicable laws, regulations, and legal requests
  • Analytics: Analyze usage patterns to improve Services and develop new features (using anonymized, aggregated data only)
  • Communications: Send transactional emails (account updates, security alerts), product updates, and marketing (with your consent)

4. Data Security Measures

We implement industry-standard security measures to protect your data:

  • Encryption: AES-256 bit encryption at rest, TLS 1.3 for data in transit
  • Access Controls: Role-based access control (RBAC) with multi-factor authentication (MFA)
  • Certifications: ISO 27001, SOC 2 Type II compliance
  • Security Audits: Regular penetration testing and vulnerability assessments by third-party security firms
  • Data Backup: Daily automated backups with point-in-time recovery
  • Employee Training: Mandatory security awareness training for all staff
  • Incident Response: 24/7 security monitoring with documented incident response procedures

5. Third-Party Services

We use the following third-party services:

  • Payment Processors: Stripe (PCI-DSS compliant) - we do not store credit card information
  • Cloud Infrastructure: Vercel (hosting), AWS S3 (document storage), PostgreSQL (Neon/Railway)
  • AI Providers: Enterprise-grade AI models (all data encrypted, no training on your data)
  • Email Service: Transactional emails via Resend/SendGrid
  • Analytics: Privacy-focused analytics (no personal data shared)

All third-party providers are vetted for GDPR and data protection compliance. We have Data Processing Agreements (DPAs) with all vendors.

6. Your Privacy Rights

Under GDPR (Europe) and CCPA (California), you have the right to:

  • Access: Request a copy of all personal data we hold about you
  • Rectification: Correct inaccurate or incomplete information
  • Erasure ("Right to be Forgotten"): Request deletion of your account and data
  • Data Portability: Receive your data in machine-readable format (JSON/CSV)
  • Object to Processing: Opt-out of certain data processing activities
  • Restrict Processing: Limit how we use your data
  • Withdraw Consent: Unsubscribe from marketing emails at any time
  • Lodge a Complaint: File a complaint with your local data protection authority

To exercise these rights, contact us at: privacy@ailydian.com

We will respond to your request within 30 days (GDPR) or 45 days (CCPA).

7. Cookies and Tracking

We use cookies for:

  • Essential: Authentication, session management (cannot be disabled)
  • Functional: Language preferences, UI customization
  • Analytics: Usage statistics (anonymized, opt-out available)

You can manage cookie preferences in your browser settings. Note that disabling cookies may limit some functionality.

8. International Data Transfers

Our Services are hosted in the United States. If you access our Services from the European Economic Area (EEA) or other regions with data protection laws, your data may be transferred to and processed in the U.S. We use Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection.

9. Data Retention

  • Active Accounts: Data retained for the duration of your subscription
  • Inactive Accounts: Anonymized after 90 days of inactivity
  • Deleted Accounts: Permanently deleted within 30 days (except where required by law)
  • Legal Requirements: Some data may be retained longer to comply with tax, accounting, or legal obligations (e.g., 7 years for financial records)

10. Children's Privacy

Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at privacy@ailydian.com.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email at least 30 days in advance. Your continued use of the Services after changes take effect constitutes acceptance of the revised policy.

Contact Us

For privacy-related questions or to exercise your rights, contact us at:

Email: privacy@ailydian.com

Data Protection Officer: dpo@ailydian.com

Support: support@ailydian.com