Security & data handling

Know where the transcript goes.

Deposition transcripts can contain confidential and personal information. This page describes LegalBrief's current controls and limitations so you can decide whether the service fits your matter.

Practical controls, stated precisely.

  • HTTPS encrypts information while it travels between the browser and the service.
  • Authentication and row-level access controls restrict database records by account.
  • Transcript storage is private rather than publicly addressable.
  • Uploads use path-specific signed tokens, and confirmation is rejected after the two-hour reservation window.
  • PDF size, signature, page count, password protection, searchable text, and usable page-line structure are checked before AI processing.
  • Chronology citations are checked against transcript pages and lines; findings, admissions, and potential inconsistencies also require excerpts that match their cited ranges.
  • API and download responses are marked private and not cacheable.
  • Payment-card details are handled by Stripe.
  • Optional Google Ads measurement loads only after consent.

What each service does.

01

Account

Supabase provides authentication and associates records with the signed-in account.

02

Transcript

The uploaded PDF is held in private storage, validated by the application, and sent to the configured AI processing path to create the requested summary.

03

Summary

The validated summary is stored in your private workspace. Deleting it immediately removes its content from the application record.

04

Billing

Stripe handles payment details. LegalBrief receives subscription and customer status, not complete payment-card numbers.

Current providers include Vercel for application hosting, Supabase for authentication, database, and storage, Stripe for billing, a configured provider for authentication email, support-email providers, configured AI model providers for summary generation, and Google for optional advertising measurement. AI requests are sent directly to OpenAI when that path is configured or through Vercel's AI Gateway to the selected model provider. Provider details can change as the service evolves.

No certification shorthand.

LegalBrief does not currently claim SOC 2 certification, HIPAA compliance, guaranteed zero data retention, managed backup coverage, a formal uptime or recovery-time commitment, or customer-managed encryption keys. No online service can promise absolute security.

Before uploading a transcript, confirm that you have authority to process it and that use of the service is consistent with client instructions, protective orders, professional duties, and your organization's security requirements.

Keep only what the workflow needs.

A source transcript is queued for deletion after successful processing. A protected daily job retries deferred deletion and also targets remaining source files for queued deletion in batches once their deposition records are 30 days old. Failed summaries can retain their source until that cleanup runs, and deletion can take longer while a failed operation is retried.

The application also requests deletion of remote AI responses on completion, failure, or user deletion. Those external operations can require retries, so LegalBrief does not promise immediate provider deletion or zero data retention. Generated summaries have no fixed automatic deletion period; deleting one immediately scrubs its summary content from the application record while cleanup continues.

Read the Privacy Policy or email support@legalbrief.co with a security or data-handling question.