Where your documents are, who sees them, and what the AI sees.

Location

Documents, case files, chats and audit records are stored on servers in the DigitalOcean Mumbai region, India. Object storage is encrypted at rest with keys we control; all transport is encrypted.

Isolation

Every organisation and every matter is isolated at the database level. A query from one matter cannot read another matter's rows. This is enforced by the database, not by application code.

What the AI sees

Before any AI processing, identifiers — names found by pattern, phone numbers, account numbers, PAN, addresses, email — are replaced with tokens such as PERSON_1 or ACCT_A. The mapping is stored separately, encrypted, and never sent to the AI provider. Name detection is currently pattern-based; a free-text name may reach the AI. For scanned pages the AI sees the page image to read it.

Pseudonymised text is processed by Anthropic's API (US) directly, with no intermediary. Anthropic may retain API inputs and outputs for a limited period under its commercial data-retention policy; we have not enabled a zero-data-retention arrangement at this stage. [LEGAL REVIEW]

Who can see your content

You and the members you invite. Our staff cannot read matter content in the ordinary course; exceptional access is logged with a reason. [LEGAL REVIEW]

Audit

Every review action, every correction, every page opened, every deletion is logged with who and when — identifiers only, never content.

Deletion

Delete a matter and its documents, case file, chat, drafts and encryption keys are removed; a receipt lists what was removed. Backups expire on rotation within 7 days.

What we do not do

No training of AI models on your content. No advertising. No third-party analytics scripts. No case-law citations from model memory. No outcome predictions.

Full details: Privacy Policy.