Privacy Policy
Last updated: March 31, 2026
1. Overview
This Privacy Policy explains how LegalCase ("we," "us," or "our") collects, uses, and safeguards your information when you use our Service. LegalCase is a cloud-based platform built by a licensed attorney, designed to help clients and legal professionals organize case timelines, documents, and exhibits in a shared, structured environment.
We take privacy seriously — not just as a legal obligation, but because we understand the sensitivity of legal matters and the trust you place in us when you use this platform.
2. Information We Collect
We collect the following categories of information:
- Account information: name, email address, and account credentials
- Case information: documents, photos, timelines, exhibits, and other materials you upload or create
- Communications: messages or notes exchanged within the platform between clients and attorneys
- Usage data: log data, device information, IP addresses, and interaction data used to operate and improve the Service
- Payment information: billing details processed securely by our third-party payment processor; we do not store full payment card data
3. How We Use Your Information
We use your information solely to:
- Provide, maintain, and improve the Service
- Enable collaboration between clients and their legal representatives
- Communicate with you about your account, security, or Service updates
- Comply with legal obligations
We do not use your case documents, uploads, or case-specific information for any commercial purpose, advertising, or product training.
4. Legal Documents and Privileged Information
LegalCase is specifically designed to store and organize materials that may be subject to attorney-client privilege, work product protection, or other legal confidentiality protections. We treat all case-related documents, communications, and exhibits uploaded to the Service as sensitive and confidential.
We do not review, analyze, access, or use your uploaded documents for any purpose other than technical support explicitly requested by you, or as otherwise required by law.
You retain full ownership of all data, documents, and information you upload to LegalCase at all times. We claim no ownership interest in your case materials or client information.
5. Administrative Access
As operator of LegalCase, we maintain administrative access to our database infrastructure as required to operate, maintain, and secure the Service. This access is governed by the following limitations:
- We do not access, review, or use your case documents or case-specific data except to provide technical support at your explicit request
- Any administrative access to user data is logged and time-stamped
- We will not voluntarily disclose your documents or case information to any third party except as required by applicable law, valid court order, or to prevent imminent harm
- In the event we are compelled by legal process to disclose your data, we will notify you promptly to the extent permitted by law so that you may seek a protective order or other appropriate relief
6. Data Security
We implement the following technical and administrative safeguards to protect your information:
- Row-Level Security (RLS): Database-level access controls that restrict each user to their own data
- Encrypted data transmission: All data is transmitted using TLS/SSL encryption
- Access controls: User authentication and role-based permissions limit who can access case information
- Hosted infrastructure: We use Supabase, a trusted cloud infrastructure provider, with data stored in secure facilities
No security system is impenetrable. While we take reasonable and appropriate precautions consistent with industry standards, we cannot guarantee absolute security. We encourage you to use strong passwords and to notify us immediately of any suspected unauthorized access to your account.
7. Data Breach Notification
In the event of a security incident involving unauthorized access to your case data, we will notify affected users promptly and without unreasonable delay, consistent with applicable law and ABA Formal Opinion 483. Notification will be provided via the email address associated with your account.
You retain ownership of all data you upload to LegalCase at all times. We do not claim any ownership interest in your case documents or client information.
8. Sharing and Third Parties
We do not sell your personal information. We may share information with:
- Service providers: Third-party vendors who assist us in operating the Service (e.g., cloud hosting, payment processing), subject to confidentiality obligations
- Legal requirements: When required by law, regulation, court order, or governmental authority
- Protection of rights: When necessary to protect the rights, safety, or property of LegalCase, our users, or the public
We require all third-party service providers to implement appropriate data protection measures consistent with this Policy.
9. AI-Assisted Features
Certain optional features in LegalCase use third-party artificial intelligence services to help you organize case materials more efficiently. These features are always opt-in — they are never activated automatically, and you can always complete the same tasks manually without using AI.
How exhibit packet splitting works
When you upload a combined exhibit packet (PDF) to split into individual exhibits, the process works in three stages:
- Local analysis (on our servers, no third parties): Your PDF is uploaded to LegalCase servers where our software reads the text on each page to detect exhibit boundaries — the labels and stickers that mark where one exhibit ends and the next begins. It also attempts to read the exhibit list (table of contents) at the front of the packet to extract exhibit descriptions. This step processes the entire PDF but no data leaves our infrastructure.
- AI-assisted reading (opt-in, third-party): If the local analysis cannot extract exhibit descriptions — typically because the exhibit list pages are scanned images rather than digital text — you may choose to use AI-assisted reading. If you click this option, only the exhibit list pages (the table of contents, typically 1–3 pages) are rendered as images and sent to a third-party AI provider. The actual exhibit documents (medical records, financial statements, contracts, etc.) are never sent to any AI service.
- Targeted local search (on our servers, no third parties): If the AI identifies exhibits that the initial local scan missed, our software performs a second local search of the PDF to locate the exact pages for those exhibits. This step processes the PDF entirely on our servers.
What the AI provider receives
When you opt in to AI-assisted reading, the AI provider receives rendered images of exhibit list pages. These pages are standard court filings and may contain:
- Case numbers and court information
- Party names and attorney names
- Exhibit labels and brief descriptions (e.g., "Exhibit A — Medical Records")
The AI provider does not receive the underlying exhibit documents themselves, your case notes, communications, or any other materials stored in LegalCase.
Data retention by AI providers
Our current AI provider (Anthropic) does not use API inputs or outputs to train its models. Data sent to the API is not stored beyond the duration of processing the request. For more information, see Anthropic's Privacy Policy.
Your control
You are always shown a clear prompt before any data is sent to an AI service. You can choose to type exhibit descriptions manually instead. If you prefer not to use AI-assisted features, simply do not click the AI option — no data will be transmitted to any third party.
10. Attorney Ethics Compliance
LegalCase is built by a licensed attorney and designed with professional responsibility rules in mind. We understand that attorneys using this Service have independent ethical obligations regarding client confidentiality under applicable Rules of Professional Conduct.
Cloud-based storage of client documents is ethically permissible under ABA guidance and the ethics opinions of over 20 state bar associations, provided attorneys exercise reasonable care to maintain confidentiality. LegalCase is designed to support attorneys in meeting that standard.
We encourage attorneys to:
- Review their jurisdiction's ethics rules regarding cloud-based document storage prior to use
- Inform clients that documents may be stored using LegalCase as part of their engagement letter or retainer agreement
- Contact us at help@getlegalcase.com with any compliance questions
Nothing in these Terms or this Privacy Policy creates an attorney-client relationship between LegalCase and any user. LegalCase is a software platform, not a law firm.
11. Mobile Application
When you use the LegalCase mobile application, we may collect additional technical information specific to mobile devices, including device identifiers and push notification tokens (if you opt in to notifications). The app requests access to your device's camera, microphone, photo library, and file storage only when you choose to upload materials. You can manage these permissions through your device settings at any time.
12. Data Retention
We retain your account and case data for as long as your account is active or as necessary to provide the Service. You may request deletion of your account and associated data at any time by contacting us at help@getlegalcase.com.
Upon account deletion, we will remove your personal information and case data from our active systems within 30 days, except where retention is required by law or legitimate business necessity (such as resolving disputes or enforcing our agreements).
13. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information, subject to legal limitations
- Portability: Request a copy of your data in a structured, machine-readable format
- Objection: Object to certain processing of your personal information
To exercise any of these rights, please contact us at help@getlegalcase.com. We will respond to your request within 30 days.
14. California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your CCPA rights, contact us at help@getlegalcase.com.
15. European Economic Area, United Kingdom, and Switzerland (GDPR)
If you are located in the EEA, UK, or Switzerland, our legal bases for processing your information are:
- Contract: Processing necessary to provide the Service you requested
- Legitimate Interests: Processing necessary for our legitimate business interests, such as improving security and preventing fraud
- Consent: Where you have given us specific consent
You have the additional right to lodge a complaint with your local data protection authority.
16. Children's Privacy
LegalCase is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that a minor has provided us with personal information, we will take steps to delete such information promptly.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes by email or by posting a notice on the Service prior to the change becoming effective. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
18. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
LegalCase
Email: help@getlegalcase.com
Website: www.getlegalcase.com
We take privacy inquiries seriously and will respond within 5 business days.