Legal

Privacy Policy

The short version: your documents are private until you decide otherwise, and every access is recorded.

This is prototype content written to illustrate the intended privacy model described in the CourtDocs technical blueprint. It is not legal advice and is not a binding policy.

01What we collect

CourtDocs collects only what the platform needs to function: account details, the documents you choose to upload, metadata about those documents, the matters you create, calendar events, message metadata, billing status and permission settings.

Documents themselves are stored in encrypted object storage, never inside the application database. The database holds metadata such as owner, matter, folder, type, size, upload date and access classification.

02Who can see your documents

By default, nobody but you. Every document begins at the Private access level. Uploading a file to CourtDocs does not share it with any attorney, firm or CourtDocs employee.

An attorney or firm must request access. You choose whether to grant specific documents, an entire folder, or to decline. Access can be revoked where legally and operationally appropriate.

CourtDocs administrators do not receive automatic access to private documents. Opening a restricted document requires elevated authorisation and creates a permanent audit record.

03Tenant separation

Each participating law firm operates as a separate tenant. Every firm resource is bound to a tenant identifier and queries enforce that separation, so one firm cannot reach another firm client list, documents or matters.

04Audit trail

Significant actions create permanent audit records: uploads, opens, downloads, shares, deletions, signatures, permission changes, attorney case access, payments, status changes, new-device logins and administrator access to restricted information.

Each entry captures the actor, the action, the resource, a timestamp, the IP address where appropriate, the device or session and the result.

05Retention and deletion

Deleting a sensitive record moves it to Deleted Items rather than destroying it immediately. After a retention period it is permanently deleted. Legal holds and mandatory retention obligations override deletion where they apply.

06Encryption

Data is encrypted in transit using TLS and at rest in both the database and object storage. Backups are encrypted. Particularly sensitive fields, including identification and medical identifiers, receive additional field-level encryption.

07Prototype notice

This page is part of a design prototype. It describes the intended privacy model of the CourtDocs platform and is not a binding legal document. A production privacy policy would be prepared with qualified privacy counsel.