This policy describes how LegalBrief handles information when you visit legalbrief.co or use the LegalBrief deposition-summary service. If you do not agree with this policy, do not upload a transcript or use the service.
Information we collect
Account information
When you sign in, we receive the account information needed to identify your workspace, such as your email address and, when available, your display name. Supabase Auth processes your password and session credentials; LegalBrief application records do not include your plaintext password.
Billing information
Payments are handled by Stripe. LegalBrief receives billing status, plan, customer and subscription identifiers, trial and billing-period dates, webhook event identifiers, and limited customer details. We do not store complete payment-card numbers.
Transcripts and generated material
We process the PDF, original filename, file size, processing status, and generated summary needed to provide the service. Files may contain information about people who are not LegalBrief users. You are responsible for having authority to upload and process that material.
Technical and usage information
We collect basic service logs needed to operate, protect, and diagnose the site, along with records used to enforce trial, plan, retry, and deletion limits. If you allow optional advertising measurement, Google may receive browser measurement data and a one-way identifier derived from a completed checkout. LegalBrief also keeps the first consented campaign parameters and Google click identifier, when present, and associates that record with an account created in the same browser. LegalBrief does not send the underlying Stripe checkout-session identifier, transcript content, or your account email address in its tag calls.
Account email
Supabase Auth and the configured email-delivery provider process your email address and account messages such as confirmation and password reset emails.
Support communications
If you contact support, the support-email providers and LegalBrief receive your email address, message, and any information or attachments you choose to include.
How we use information
- Provide and maintain your workspace and summaries.
- Process payments, trials, cancellations, and customer support.
- Protect the service, prevent abuse, and troubleshoot failures.
- Understand site performance and advertising when you consent.
- Meet legal obligations and enforce our terms.
Service providers
We use service providers to run LegalBrief. These include Supabase for account management, database services, and private file storage; Vercel for application hosting and AI routing when configured; OpenAI or another configured AI model provider for transcript processing; Stripe for billing; the configured email-delivery provider for authentication email; email forwarding and mailbox providers for support requests; and Google for optional advertising measurement. Providers process information under their own terms and privacy commitments.
AI processing
The uploaded PDF, its filename, and LegalBrief's processing instructions are sent either directly to OpenAI or through Vercel AI Gateway to the configured model provider, depending on the deployment configuration. The response is used to create and validate the requested summary. Background processing requires provider-side response state while the job is running.
After processing completes or fails, and when you delete a record, LegalBrief requests deletion of the associated remote AI response and retries deferred deletion through scheduled maintenance. This is not a zero-data-retention guarantee; provider-side handling is also governed by the selected provider's configuration and terms.
Storage, security, and retention
LegalBrief uses encrypted network connections and access-controlled storage. No online service can promise absolute security. Limit uploads to material you are authorized to process and use your organization’s own confidentiality and information-security rules.
See Security & Data Handling for a plain-language description of the current service architecture and important limitations.
The source PDF is queued for deletion after successful processing. Deferred deletions are retried. Once deposition records are 30 days old, a protected daily cleanup also targets remaining source PDFs for queued deletion in batches. Failed summaries can retain the source until that cleanup runs, and deletion can take longer while a failed operation is retried.
Generated summaries do not currently have a fixed automatic deletion period. When you delete a deposition record, its stored summary is cleared immediately, its original filename and file size are replaced, and its status and selected processing fields are reset. The record identifier, account association, source-file path, and remote-response identifier may remain until queued cleanup finishes and the scrubbed record is removed. Operational deletion records, usage records, and billing records may remain after a deposition is deleted.
Cookies and advertising measurement
Essential cookies are used for sign-in and security. Your measurement choice is written to browser local storage and a first-party cookie that lasts for up to one year. A completed-checkout conversion uses a local-storage marker until it is cleared, or a one-year cookie fallback, to avoid sending the same event twice.
Google Ads measurement is optional and loads only after you choose “Allow measurement.” Page-view events are limited to designated public marketing pages and omit query strings; workspace, deposition, and billing-success page views are excluded. The current tag configuration keeps ad personalization denied. If a landing URL contains campaign parameters or a Google click identifier, the first consented attribution record is stored in the browser for up to 90 days and may be associated with your account when you sign up. Use the “Cookie settings” button at the bottom of the site to change your choice.
Your choices
You may request access, correction, or deletion of your LegalBrief account information, subject to legal and operational requirements. You can delete deposition records from your workspace and manage a subscription, including cancellation when available, through the billing portal. The current release does not include self-service account deletion; send an account request to the contact address below.
International processing
Service providers may process information in countries other than your own. Those countries may have different privacy laws.
Changes to this policy
We may update this policy as the service changes. The effective date at the top identifies the current version. Material changes will be communicated when required.
Contact
Privacy questions or requests can be sent to support@legalbrief.co.