Privacy Policy

Last updated: July 1, 2026

LawCipher, Inc. ("LawCipher," "we," "us," or "our") is committed to protecting the privacy of individuals who use our deposition intelligence platform (the "Platform"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

By accessing or using the Platform, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Platform.

1. Information We Collect

We collect several types of information to provide, maintain, and improve our Platform:

Personal Information

When you register for an account, subscribe to a plan, or contact our support team, we may collect:

  • Full name, email address, and professional credentials
  • Billing address and payment information (processed securely by our third-party payment processor)
  • Organization name, job title, and jurisdiction of practice
  • Account credentials including password hashes (never stored in plaintext)

Case Data and Documents

To deliver our core services, we process and store the legal case materials you upload:

  • Deposition videos, audio recordings, and transcripts
  • Legal documents, evidence files, and exhibits
  • Email communications and chat exports (Slack, Teams, WhatsApp, iMessage)
  • Annotations, tags, coding decisions, and case notes you create within the Platform

Usage and Technical Data

We automatically collect certain information when you access or use the Platform:

  • Log data: IP address, browser type, operating system, referring URLs, and pages visited
  • Usage data: feature interactions, page consumption, query history, and session duration
  • Device data: hardware model, unique device identifiers, and mobile network information
  • MCP behavioral data: anonymized logs of how Model Context Protocol tools are used to tune our AI models (see Section 4 for anonymization details)

2. How We Use Information

We use the collected information for the following purposes:

  • Provision of Services: To operate, maintain, and personalize the Platform, including AI-powered processing, transcription, analysis, and search.
  • Usage Metering and Billing: To track page consumption, generate invoices, process payments, and manage subscription plans.
  • Customer Support: To respond to your inquiries, troubleshoot issues, and provide technical assistance.
  • Product Improvement: To analyze usage patterns and anonymized MCP behavioral data to improve AI model accuracy and platform performance.
  • Security and Compliance: To detect and prevent fraudulent, unauthorized, or illegal activity; to comply with legal obligations and audit requirements.
  • Communications: To send service-related notices, security alerts, billing reminders, and promotional materials (with opt-out options).

3. Data Sharing and Disclosure

We may share your information in the following circumstances:

Service Providers

We engage trusted third-party service providers to perform functions on our behalf, including cloud infrastructure (Cloudflare), payment processing (Polar.sh), AI model inference (OpenRouter, which may route prompts to upstream providers including Google and Anthropic), and email delivery (Brevo). These providers are contractually bound to protect your data and use it solely for the purposes we specify.

AI Inference Disclosure: When you use AI features (summarization, Q&A, chat, extraction, coding suggestions, translations, Deep Dive), your prompts and the relevant source content are transmitted to third-party AI providers via OpenRouter for the sole purpose of generating responses. We contractually prohibit these providers from using your data for model training or improvement. Source content is limited to the minimum necessary to fulfill your request and is not retained by the AI provider beyond the duration of the inference request.

Legal Compliance

We may disclose information if required to do so by law or in response to valid legal requests by public authorities, including to meet national security or law enforcement requirements.

Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction. We will notify you via email and a prominent notice on the Platform of any change in ownership.

Aggregated and Anonymized Data

We may share aggregated, anonymized data that cannot reasonably identify you or any individual. This includes anonymized MCP behavioral data used to fine-tune our AI models. All personally identifiable information is removed before aggregation, and we employ differential privacy techniques to ensure individual usage patterns cannot be reverse-engineered.

Sub-Processors

We use a limited set of sub-processors to deliver the Platform. The current list is available at lawcipher.com/subprocessors. We will notify customers via email at least 14 days before adding or replacing any sub-processor that processes personal data. If you object to a new sub-processor, you may terminate your subscription without penalty within 30 days of notification.

4. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with the Platform. Case data and documents are retained in accordance with your subscription tier and any legal hold obligations you have configured:

  • Active Accounts: All data is retained and accessible for the duration of your subscription.
  • Closed Cases: Data is preserved for 90 days after case closure, after which it may be archived or deleted in accordance with your retention policy.
  • Account Termination: Upon account deletion, we will delete or anonymize your personal information within 60 days, subject to legal hold requirements or regulatory obligations.
  • Legal Holds: Data subject to an active legal hold is preserved indefinitely until the hold is released, regardless of account status.

MCP behavioral data used for model training is retained in anonymized form for the duration of our model lifecycle (typically 24 months) to enable longitudinal improvement of AI accuracy.

5. Your Rights — GDPR, CCPA, and Other Privacy Laws

European Economic Area (EEA) Users — GDPR

If you are located in the European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of Access: You may request a copy of the personal information we hold about us.
  • Right to Rectification: You may request correction of inaccurate or incomplete information.
  • Right to Erasure (Right to be Forgotten): You may request deletion of your personal information, subject to certain exceptions.
  • Right to Restrict Processing: You may request that we limit the processing of your personal information in certain circumstances.
  • Right to Data Portability: You may request a copy of your data in a structured, machine-readable format.
  • Right to Object: You may object to the processing of your personal information for direct marketing purposes or on grounds relating to your particular situation.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority if you believe our processing of your personal information infringes applicable law.

We will respond to GDPR requests within 30 days, extendable by up to 60 days for complex or high-volume requests, as permitted under GDPR Article 12(3).

Automated Decision-Making (GDPR Article 22)

The Platform uses automated decision-making and profiling in several features that may produce legal effects concerning you or similarly significantly affect you:

  • Predictive Coding & Active Learning: Automated classification of documents as relevant or not relevant based on training sets. You may request manual review of any automated classification.
  • Witness Credibility Scoring: The Deposition Analyzer generates credibility scores based on paralinguistic signals and testimonial consistency. These scores are assistive tools and do not constitute a definitive assessment of credibility.
  • MCP Re-Scoring: When you use Model Context Protocol tools to re-weight predictive models, the resulting rankings are automated but initiated and controlled by you.

You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you. All AI-generated outputs are presented as suggestions requiring human review and independent professional judgment. To contest an automated decision, contact us at privacy@lawcipher.com.

California Users — CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: You may request deletion of personal information we have collected from you, subject to certain exceptions.
  • Right to Opt-Out: You have the right to opt out of the sale of your personal information. LawCipher does not sell personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
  • California Shine the Light (Civil Code § 1798.83): California residents may request information about our disclosure of personal information to third parties for their direct marketing purposes. LawCipher does not share personal information for third-party direct marketing.

Other U.S. State Privacy Laws

If you are a resident of Virginia (CDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), or Iowa (ICDPA), we extend the following additional rights to you to the extent required by applicable law: the right to confirm whether we process your personal data, the right to obtain a copy of your personal data, the right to request correction of inaccuracies, the right to request deletion, the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects, and the right to appeal a refusal to take action on a request.

Exercising Your Rights

To exercise any of the rights described above, please submit a request to privacy@lawcipher.com. We will respond to your request within 30 days. We may need to verify your identity before processing your request. You may also designate an authorized agent to make a request on your behalf.

6. Security

We implement industry-standard technical and organizational measures to protect your data:

  • Encryption at Rest: All data stored in R2 object storage is encrypted using AES-256.
  • Encryption in Transit: All traffic between your browser and our Platform is encrypted via TLS 1.3.
  • Database Isolation: Each tenant's data resides in a dedicated D1 database instance, ensuring complete logical isolation.
  • Access Controls: Role-based access control (RBAC) governs data visibility within your organization. Multi-factor authentication is supported.
  • Audit Logging: All access to case data, AI operations, and administrative actions is logged and available for review.
  • Penetration Testing: We plan to engage independent security firms to conduct regular penetration tests and vulnerability assessments. We also maintain a responsible disclosure program for security researchers.
  • SOC 2: LawCipher plans to pursue SOC 2 Type II certification. Until certified, we adhere to the control objectives and criteria described in the SOC 2 framework as a design target.

Despite these measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security, but we are committed to promptly notifying affected users and relevant authorities in the event of a data breach involving personal information as required by applicable law (including within 72 hours for GDPR-notified breaches). We maintain a written incident response plan and conduct regular security reviews.

7. International Data Transfers

LawCipher primarily operates on Cloudflare's global edge network, which spans data centers worldwide. Your data may be transferred to and processed in any country where Cloudflare maintains facilities. When we transfer data from the European Economic Area, the United Kingdom, or Switzerland to other countries, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Cloudflare's participation in the EU-US Data Privacy Framework
  • Data Processing Agreements (DPAs) with all sub-processors

8. Cookies and Tracking Technologies

We use Cloudflare Web Analytics to understand site usage and performance. Cloudflare Web Analytics is privacy-first and does not use cookies for cross-site tracking. You can control cookie preferences through our cookie consent banner on first visit. We do not use cookies for targeted advertising.

Cookie Table

Cookie NamePurposeDurationType
better-auth.session_tokenAuthentication sessionSession / 30 daysEssential
_gaGoogle Analytics — user differentiation2 yearsAnalytics
_ga_<ID>Google Analytics — session management2 yearsAnalytics
cf_clearanceCloudflare Turnstile — bot verification30 minutesEssential
__cf_bmCloudflare — bot management30 minutesEssential
cookie-consentRecords cookie consent preferences1 yearEssential

You may set your browser to refuse all or some cookies, or to alert you when cookies are being sent. However, disabling cookies may affect the availability and functionality of certain Platform features.

9. Third-Party Links

The Platform may contain links to third-party websites or services that are not owned or controlled by LawCipher. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.

10. Children's Privacy

The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us at privacy@lawcipher.com.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date at the top. For significant changes, we will also send an email notification to registered users. Your continued use of the Platform after the effective date of the revised policy constitutes your acceptance of the changes.

12. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

LawCipher, Inc.
30 N Gould St, STE R
Sheridan, WY 82801
Email: privacy@lawcipher.com
Data Protection Officer: dpo@lawcipher.com