Privacy Policy

Last Updated: March 25, 2026

1. Information We Collect

We collect information you provide directly to us when you create an account or use our services:

  • Account Information: Name, email address, firm name, bar number, and billing information.
  • Case Data: Files, documents, chronologies, and notes you upload or create within CaseProof. This may include sensitive legal materials.
  • Usage Data: Log data, browser type, IP address, pages visited, and feature interactions to improve our service.
  • Communications: Messages you send to our support team or via in-app feedback.

2. How We Use Your Information

  • To provide, maintain, and improve the CaseProof platform.
  • To process transactions and send related information, including purchase confirmations and invoices.
  • To send technical notices, updates, security alerts, and support messages.
  • To respond to your comments, questions, and customer service requests.
  • To analyze usage patterns and improve product features.
  • To comply with legal obligations.

We do not use your case data to train AI models or for any purpose other than providing the service to you.

3. Data Storage and Security

Your data is stored using Supabase, a SOC 2 Type II compliant infrastructure provider. All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.2 or higher.

We implement access controls, audit logging, and regular security reviews. Only authorized personnel have access to production systems, and such access is logged and monitored.

4. Data Sharing

We do not sell your personal data or case data to third parties. We may share information only in these limited circumstances:

  • Service Providers: Trusted vendors who process data on our behalf (e.g., payment processing via Stripe, infrastructure via Supabase, AI processing via OpenAI). Each is bound by data processing agreements.
  • Legal Requirements: If required by law, court order, or governmental authority.
  • Business Transfers: In connection with a merger or acquisition, with prior notice to you.

5. Your Rights

You have the following rights regarding your data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your account and associated data. Case data is permanently deleted within 30 days.
  • Export: Export your case data at any time in standard formats (PDF, DOCX, JSON).
  • Opt-Out: Opt out of non-essential communications at any time.

To exercise any of these rights, contact us at privacy@caseproof.com.

6. Attorney-Client Privilege Notice

CaseProof is designed for use by licensed attorneys and legal professionals. Case data, documents, and communications you store in CaseProof may be subject to attorney-client privilege and work product protections. We treat all case data as confidential and privileged. Our employees are prohibited from accessing your case data except for limited technical support purposes with your explicit permission. We are not a party to any attorney-client relationship and do not provide legal advice.

7. Cookies and Tracking

We use essential cookies to maintain your authenticated session. We may use analytics cookies to understand how users interact with our platform. You can disable non-essential cookies in your browser settings, though this may affect some functionality.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting a notice on our website at least 30 days before the changes take effect.

9. Contact Information

For privacy-related questions or to exercise your rights, contact our Privacy Team:

Email: privacy@caseproof.com

CaseProof, Inc.