Legal
Privacy Policy
Effective Date: May 26, 2026 · Last Updated: May 26, 2026
Lawdiem, Inc. (“Lawdiem,” “we,” “us,” or “our”) provides software tools used by licensed attorneys in the practice of law. This Privacy Policy explains what information we collect, how we use it, how we safeguard it, and the rights and choices you have. It applies to your use of our websites, applications, and Services (as defined in our Terms of Service).
This Policy is written for an audience of practicing lawyers. It assumes familiarity with the ABA Model Rules of Professional Conduct — in particular Rule 1.6 (confidentiality of information) — and with the duty of technological competence under Rule 1.1, Comment 8 and ABA Formal Opinion 512 (July 29, 2024). Nothing in this Policy is legal advice, and nothing in it relieves you of any duty owed to your client, the tribunal, or your bar.
1. Two Categories of Information
We distinguish two categories of information, and we treat them very differently.
(a) Account Information — information about you as a Customer and an Authorized User: name, work email address, firm name, bar number(s), billing contact, billing address, payment method tokens (handled by our payment processor — we do not store full card numbers), authentication credentials, IP addresses used to access the Services, device and browser metadata, and logs of administrative actions.
(b) Customer Data — everything you and your Authorized Users upload to, generate within, or transmit through the Services in the course of practicing law: pleadings, transcripts, exhibits, discovery materials, client communications, time entries, intake notes, audio captured by Rebuttal, briefs submitted to SpotlightAuthority, search queries to AppositeCase, drafts created in CaseFile, and so on. Customer Data routinely includes attorney work product and information protected by the attorney-client privilege and by Rule 1.6.
We treat Customer Data as if a protective order applies to it. We do not use Customer Data for our own business purposes, do not analyze it for product analytics, do not look at it except when you specifically ask us to (e.g., a support request you authorize), and do not retain it longer than necessary to provide the Services.
2. How We Collect Information
We collect:
3. How We Use Information
We use Account Information to: provision and operate your account; authenticate Authorized Users; bill and collect fees; communicate about the Services (including service announcements, security notices, and required legal notifications); detect, prevent, and investigate fraud, abuse, and security incidents; and meet our own legal, accounting, audit, and tax obligations.
We use Customer Data solely to: provide the Services to you; enable the specific features you invoke (e.g., transcribe audio, highlight cited passages, return apposite cases); enforce your access controls and audit logs; preserve and restore data on your behalf; respond to a support request you have authorized; and comply with applicable law or valid legal process. We use Customer Data for no other purpose.
We do not use Customer Data to train, fine-tune, or improve AI models. This is a categorical commitment. Lawdiem will not use Customer Data — and will not permit any sub-processor, model provider, or other vendor to use Customer Data — to train, fine-tune, evaluate, or otherwise improve any generative-AI or machine-learning model, whether ours or any third party’s, outside the confines of your dedicated tenant. Inference runs on prompts and context you supply; the model does not learn from them. See the Security page for the architectural controls that enforce this.
We do not sell Customer Data. We do not share Customer Data with advertisers, data brokers, or analytics platforms. We do not use Customer Data to generate aggregated insights for marketing.
4. Sub-Processors
We rely on a small set of vetted sub-processors to provide the Services. Each is bound by written terms that require confidentiality, data-protection commitments compatible with ABA Model Rule 5.3 and Rule 5.3 cmt. 3 (internet-based document storage and outside vendors), and limits on use of data to providing services to Lawdiem.
Our current core sub-processors include:
A current list of sub-processors is available on request at notice@lawdiem.com. We will provide reasonable advance notice of material changes to the sub-processor list and an opportunity to object before the change takes effect for your tenant.
We do not use any external generative-AI service that retains, logs for training, or makes available to other customers any content you send to it. AI inference for the Services runs inside an AWS environment configured so that prompts and outputs are not retained outside your tenant and are not used to train any shared model.
5. Disclosures to Third Parties
We disclose information only in the following narrow circumstances:
We do not disclose Customer Data to advertisers, marketers, analytics vendors, data brokers, AI training partners, or model developers.
6. International Data Transfers and Hosting Location
Lawdiem hosts Customer Data in AWS regions located within the United States by default. If you require a specific region (for example, for cross-border or sectoral reasons), contact us at notice@lawdiem.com; regional options may be available for enterprise tenants.
If you or your Authorized Users access the Services from outside the United States, you understand that Account Information and Customer Data are processed in the United States and may be subject to United States law.
7. Data Retention and Deletion
We retain Account Information for the life of your account and for a reasonable period thereafter for legitimate business, audit, tax, and legal-hold purposes.
We retain Customer Data for the life of your subscription. Upon termination, we will make Customer Data available for export for thirty (30) days, after which we will delete or anonymize it within a reasonable period in accordance with our standard backup and retention practices, subject to (a) any legal hold; (b) any litigation, regulatory, or arbitration preservation obligation we are on notice of; or (c) routine backup retention schedules (after which the data is overwritten in the ordinary course).
Audit logs and security telemetry may be retained for a longer period to support investigations of suspected misuse, breach response, and forensic review.
You may delete specific matter files, documents, or audio recordings from your tenant at any time; deletion from the active tenant is immediate, and deletion from backups follows the normal backup rotation.
8. Your Choices and Rights
Administrative controls. Customer administrators can add and remove Authorized Users, assign roles, configure matter-level access controls, enable SSO and multi-factor authentication, and review audit logs of who accessed what and when.
Access, correction, export. You can access and update most Account Information from within the Services. You can export Customer Data at any time using the export tools in the relevant Service. If you need help, contact notice@lawdiem.com.
Communications preferences. You may opt out of non-essential marketing communications (we currently send very few). You cannot opt out of service-related communications (security notices, billing notices, required legal notifications) while you remain a Customer.
Where applicable law gives you statutory privacy rights (e.g., CCPA/CPRA, state comprehensive privacy laws, GDPR for EEA/UK individuals), you may exercise those rights by writing to notice@lawdiem.com. For Customer Data that is law-firm or client material, those rights are typically exercised by the Customer (the firm), not by the individual — please direct requests through your firm’s administrator. We will respond consistent with applicable law.
9. Children
The Services are not directed to, and we do not knowingly collect information from, anyone under 18. The Services are intended for licensed attorneys and the firms through which they practice.
10. Risk Disclosures You Should Read
We are committed to safeguarding Customer Data and have implemented the controls described on the Security page. Practicing lawyers — under the duty of technological competence — should nonetheless understand the following residual risks:
11. Security Incident Notification
If we become aware of a security incident that has resulted in, or that we reasonably believe has resulted in, unauthorized access to your Customer Data, we will notify you without undue delay and, in any case, consistent with applicable law and any breach-notification commitments in your subscription agreement. The notification will describe what we know about the incident, the categories of data affected, the steps we are taking, and the steps you may wish to take. As the data controller for purposes of your professional and ethical obligations, you remain responsible for any client, court, regulatory, or bar notifications.
12. Changes to This Policy
We may update this Policy from time to time. We will post an updated version with a new “Last Updated” date. For material changes, we will give reasonable notice via email or in-product notification before the change takes effect. Continued use of the Services after the effective date of an update constitutes acceptance.
13. Contact Us
For privacy questions, sub-processor lists, data-subject requests, or to report a concern:
- Legal notices: notice@lawdiem.com
- General inquiries: info@lawdiem.com
- Postal: Lawdiem, Inc., Attn: Privacy, 7812 Linnie Ln., Austin, Texas 78724
© 2026 Lawdiem, Inc. All rights reserved.