Legal

Privacy Policy

Effective Date: May 26, 2026 · Last Updated: May 26, 2026

Lawdiem, Inc. (“Lawdiem,” “we,” “us,” or “our”) provides software tools used by licensed attorneys in the practice of law. This Privacy Policy explains what information we collect, how we use it, how we safeguard it, and the rights and choices you have. It applies to your use of our websites, applications, and Services (as defined in our Terms of Service).

This Policy is written for an audience of practicing lawyers. It assumes familiarity with the ABA Model Rules of Professional Conduct — in particular Rule 1.6 (confidentiality of information) — and with the duty of technological competence under Rule 1.1, Comment 8 and ABA Formal Opinion 512 (July 29, 2024). Nothing in this Policy is legal advice, and nothing in it relieves you of any duty owed to your client, the tribunal, or your bar.

1. Two Categories of Information

We distinguish two categories of information, and we treat them very differently.

(a) Account Information — information about you as a Customer and an Authorized User: name, work email address, firm name, bar number(s), billing contact, billing address, payment method tokens (handled by our payment processor — we do not store full card numbers), authentication credentials, IP addresses used to access the Services, device and browser metadata, and logs of administrative actions.

(b) Customer Data — everything you and your Authorized Users upload to, generate within, or transmit through the Services in the course of practicing law: pleadings, transcripts, exhibits, discovery materials, client communications, time entries, intake notes, audio captured by Rebuttal, briefs submitted to SpotlightAuthority, search queries to AppositeCase, drafts created in CaseFile, and so on. Customer Data routinely includes attorney work product and information protected by the attorney-client privilege and by Rule 1.6.

We treat Customer Data as if a protective order applies to it. We do not use Customer Data for our own business purposes, do not analyze it for product analytics, do not look at it except when you specifically ask us to (e.g., a support request you authorize), and do not retain it longer than necessary to provide the Services.

2. How We Collect Information

We collect:

  • Information you provide when you create an account, configure your tenant, contact support, or upload material to the Services.
  • Information generated automatically when you use the Services — for example, sign-in events, feature-usage events, error logs, and performance telemetry. We design telemetry to capture that an event occurred and basic technical metadata, not the substantive content of the document, query, or output.
  • Information from third parties you authorize — for example, e-filing systems, identity providers (SSO), or accounting/calendar integrations that you choose to connect.

3. How We Use Information

We use Account Information to: provision and operate your account; authenticate Authorized Users; bill and collect fees; communicate about the Services (including service announcements, security notices, and required legal notifications); detect, prevent, and investigate fraud, abuse, and security incidents; and meet our own legal, accounting, audit, and tax obligations.

We use Customer Data solely to: provide the Services to you; enable the specific features you invoke (e.g., transcribe audio, highlight cited passages, return apposite cases); enforce your access controls and audit logs; preserve and restore data on your behalf; respond to a support request you have authorized; and comply with applicable law or valid legal process. We use Customer Data for no other purpose.

We do not use Customer Data to train, fine-tune, or improve AI models. This is a categorical commitment. Lawdiem will not use Customer Data — and will not permit any sub-processor, model provider, or other vendor to use Customer Data — to train, fine-tune, evaluate, or otherwise improve any generative-AI or machine-learning model, whether ours or any third party’s, outside the confines of your dedicated tenant. Inference runs on prompts and context you supply; the model does not learn from them. See the Security page for the architectural controls that enforce this.

We do not sell Customer Data. We do not share Customer Data with advertisers, data brokers, or analytics platforms. We do not use Customer Data to generate aggregated insights for marketing.

4. Sub-Processors

We rely on a small set of vetted sub-processors to provide the Services. Each is bound by written terms that require confidentiality, data-protection commitments compatible with ABA Model Rule 5.3 and Rule 5.3 cmt. 3 (internet-based document storage and outside vendors), and limits on use of data to providing services to Lawdiem.

Our current core sub-processors include:

  • Amazon Web Services, Inc. — hosting, storage, key management, and compute, all within an AWS Virtual Private Cloud (VPC) configured for Lawdiem.
  • Payment processor — payment processing (handles card data; we do not store full card numbers).
  • Identity/SSO provider — single-sign-on and federated authentication for Customers that elect it.
  • Transactional email provider — service emails (security notices, password resets, billing).
  • Error-monitoring provider — application error and performance monitoring (configured to scrub Customer Data from payloads).

A current list of sub-processors is available on request at notice@lawdiem.com. We will provide reasonable advance notice of material changes to the sub-processor list and an opportunity to object before the change takes effect for your tenant.

We do not use any external generative-AI service that retains, logs for training, or makes available to other customers any content you send to it. AI inference for the Services runs inside an AWS environment configured so that prompts and outputs are not retained outside your tenant and are not used to train any shared model.

5. Disclosures to Third Parties

We disclose information only in the following narrow circumstances:

  • At your direction — for example, when you choose to share a matter file with co-counsel, send a deliverable to a third-party platform, or invoke an integration. You control what is shared.
  • To sub-processors, as described in Section 4, strictly to provide the Services to you.
  • For legal process and safety — when we believe in good faith that disclosure is required by applicable law, regulation, court order, subpoena, or valid governmental request; necessary to protect the rights, property, or safety of Lawdiem, our Customers, or the public; or necessary to investigate, prevent, or address fraud, security, or technical issues. Where legally permitted, we will use reasonable efforts to give you advance notice (and to give you a meaningful opportunity to challenge or quash the request) before disclosing Customer Data in response to legal process, so that you may assert applicable privileges and confidentiality obligations on behalf of your clients.
  • In a corporate transaction — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to the acquiring party agreeing to be bound by privacy and security commitments at least as protective as those in this Policy.

We do not disclose Customer Data to advertisers, marketers, analytics vendors, data brokers, AI training partners, or model developers.

6. International Data Transfers and Hosting Location

Lawdiem hosts Customer Data in AWS regions located within the United States by default. If you require a specific region (for example, for cross-border or sectoral reasons), contact us at notice@lawdiem.com; regional options may be available for enterprise tenants.

If you or your Authorized Users access the Services from outside the United States, you understand that Account Information and Customer Data are processed in the United States and may be subject to United States law.

7. Data Retention and Deletion

We retain Account Information for the life of your account and for a reasonable period thereafter for legitimate business, audit, tax, and legal-hold purposes.

We retain Customer Data for the life of your subscription. Upon termination, we will make Customer Data available for export for thirty (30) days, after which we will delete or anonymize it within a reasonable period in accordance with our standard backup and retention practices, subject to (a) any legal hold; (b) any litigation, regulatory, or arbitration preservation obligation we are on notice of; or (c) routine backup retention schedules (after which the data is overwritten in the ordinary course).

Audit logs and security telemetry may be retained for a longer period to support investigations of suspected misuse, breach response, and forensic review.

You may delete specific matter files, documents, or audio recordings from your tenant at any time; deletion from the active tenant is immediate, and deletion from backups follows the normal backup rotation.

8. Your Choices and Rights

Administrative controls. Customer administrators can add and remove Authorized Users, assign roles, configure matter-level access controls, enable SSO and multi-factor authentication, and review audit logs of who accessed what and when.

Access, correction, export. You can access and update most Account Information from within the Services. You can export Customer Data at any time using the export tools in the relevant Service. If you need help, contact notice@lawdiem.com.

Communications preferences. You may opt out of non-essential marketing communications (we currently send very few). You cannot opt out of service-related communications (security notices, billing notices, required legal notifications) while you remain a Customer.

Where applicable law gives you statutory privacy rights (e.g., CCPA/CPRA, state comprehensive privacy laws, GDPR for EEA/UK individuals), you may exercise those rights by writing to notice@lawdiem.com. For Customer Data that is law-firm or client material, those rights are typically exercised by the Customer (the firm), not by the individual — please direct requests through your firm’s administrator. We will respond consistent with applicable law.

9. Children

The Services are not directed to, and we do not knowingly collect information from, anyone under 18. The Services are intended for licensed attorneys and the firms through which they practice.

10. Risk Disclosures You Should Read

We are committed to safeguarding Customer Data and have implemented the controls described on the Security page. Practicing lawyers — under the duty of technological competence — should nonetheless understand the following residual risks:

  • Every data transfer carries risk. Transmission of information over the internet, between client devices and cloud services, and between cloud services and counterparties (including opposing counsel and clients) carries an irreducible risk of interception, misdirection, corruption, loss, or unauthorized disclosure. No vendor — including Lawdiem — can eliminate this risk.
  • Cyberattacks are a permanent feature of the threat landscape. All modern software systems are subject to evolving cyber-threats, including zero-day exploits, supply-chain compromises, social-engineering attacks, insider threats, and nation-state actors. The widespread adoption of AI-assisted programming has materially accelerated the rate at which adversaries can discover vulnerabilities, generate exploits, and probe for undocumented or backdoor access paths in production software. No vendor can warrant invulnerability to attack.
  • AI outputs are probabilistic and may be inaccurate. Generative-AI features may produce incorrect, incomplete, biased, or fabricated content, including invented citations. You must independently verify every AI-generated output before relying on it for any professional purpose. See ABA Formal Op. 512.
  • Inadvertent disclosure remains possible. Notwithstanding the safeguards described on the Security page, inadvertent disclosure of confidential, sensitive, or privileged information remains possible — by misconfiguration, user error, opposing-counsel error, third-party compromise, court order, or otherwise. Under our Terms of Service, you agree to hold Lawdiem harmless for any such inadvertent disclosure except to the extent caused by Lawdiem’s gross negligence or willful misconduct.
  • You are the lawyer; you bear ultimate responsibility. Under ABA Model Rule 1.6, the duty of confidentiality runs from you to your client. Under Rule 5.3, you have a supervisory duty over nonlawyer assistance, including third-party services. Under Rule 1.1, Comment 8 and Formal Op. 512, you have a duty to understand the technology you use. We provide a secure tool. You provide the professional judgment.

11. Security Incident Notification

If we become aware of a security incident that has resulted in, or that we reasonably believe has resulted in, unauthorized access to your Customer Data, we will notify you without undue delay and, in any case, consistent with applicable law and any breach-notification commitments in your subscription agreement. The notification will describe what we know about the incident, the categories of data affected, the steps we are taking, and the steps you may wish to take. As the data controller for purposes of your professional and ethical obligations, you remain responsible for any client, court, regulatory, or bar notifications.

12. Changes to This Policy

We may update this Policy from time to time. We will post an updated version with a new “Last Updated” date. For material changes, we will give reasonable notice via email or in-product notification before the change takes effect. Continued use of the Services after the effective date of an update constitutes acceptance.

13. Contact Us

For privacy questions, sub-processor lists, data-subject requests, or to report a concern:


© 2026 Lawdiem, Inc. All rights reserved.