Privacy Policy
Policy version: 2026-08-31
1. Information We Collect
We collect the information you type into a questionnaire — names, addresses, dates, and the other answers a document needs — the name and email address on your account, and transaction records. Your password is held by our sign-in provider (Supabase) only in hashed form.
2. How We Use Your Information
Your answers are placed, as typed, into the template you chose to prepare your document, and used for transaction records and service communications. No model reads your answers or your documents on LegalDraft: nothing you enter is sent to an AI model provider, and we do not use your personal data to train AI models.
3. Data Storage & Security
Your data is stored using United States Vercel and Supabase infrastructure with encryption in transit and at rest. Account-bound legal work requires an authenticated user, active tenant membership, and the exact purchased grant. Explicit share links are recipient-bound, limited, expiring, revocable, and never replace account ownership.
4. Information Sharing
We do not sell your personal information. We may share information with: (a) a licensed attorney you engage through attorney finalization, (b) service providers who help us operate the platform — hosting, the database and account sign-in (Vercel, Supabase), payment processing (Stripe), email delivery (Resend), and the bot check on the account forms (Cloudflare) — each only to the extent needed to provide the service, and (c) as required by law.
5. Data Retention
We use the following schedule. A legal hold, active dispute, fraud investigation, or legal requirement may pause deletion only for the affected records. When content is deleted, minimized financial and integrity records may remain for the periods below without retaining the legal document itself.
| Data class | Retention | Treatment |
|---|---|---|
| Account identity | Account lifetime; removal within 30 days after a verified deletion request | Profile/contact fields are deleted or de-identified unless a legal hold applies. |
| Matter content and work product | Matter lifetime, then up to 7 years after closure; earlier verified deletion requests are completed within 30 days | Source text, drafts, reviews, workspace content, and generated versions are deleted; immutable ledgers retain hashes and minimized facts. |
| Share and intake links | Link expiry or revocation, then up to 90 days of minimized security metadata | Tokens remain hashed; expired/revoked grants stop authorizing immediately. |
| Support and privacy requests | 2 years after resolution | Needed to document the request, response, complaint, refund, or correction. |
| Operational and AI telemetry | 90 days | Counts, model/provider status, latency, cost, and opaque trace IDs only—not prompts, document text, names, emails, or model output. |
| Authentication sessions | 30-day maximum session; revoked/expired session records age out after 30 additional days | Single-session enforcement, 7-day inactivity timeout, and immediate sign-out revocation apply. |
| Purchase, export, and security audit records | 7 years | Retained in minimized form for accounting, chargebacks, fraud prevention, and integrity evidence; legal content is not retained in an export receipt. |
6. Your Rights
Signed-in LegalDraft users can download their account data and schedule or cancel account deletion from the account privacy center. You may also request access, correction, or deletion through support@legaldraft.io. We verify the requester before disclosing or deleting account data and complete eligible deletion requests within 30 days.
7. Deletion, Holds & Backups
Account deletion is scheduled with a seven-day cancellation window. Legal holds, active payment disputes, and required firm-data transfers pause deletion without removing data. On completion, access is revoked, the authentication identity is irreversibly soft-deleted, and eligible legal content and identity fields are removed or de-identified. Backup copies are not used for ordinary product access and age out through the managed backup cycle; if a backup is restored, the deletion ledger is reapplied before customer access resumes.
8. Cookies
We use host-only essential cookies for authentication, session security, language, and accessibility preferences. We do not use advertising cookies. Authenticated sessions are time-boxed to 30 days, limited to one active session, and require sign-in again after 7 days of inactivity.
9. Contact
For privacy inquiries: support@legaldraft.io
LegalDraft Technologies LLC
United States