Privacy Policy

Last updated: July 2026

This Privacy Policy describes how Attest Law (“Attest,” “we,” “us”) collects, uses, and protects information when you use our services. It is written for the attorneys and firms who are our customers, and it also describes how we handle the client case data those firms entrust to us.

1. Information we collect

  • Account information — name, email address, firm name, and billing details when you create an account or subscribe.
  • Case data — documents, questionnaire responses, and case details that you or your clients upload to the services.
  • Usage data — log and device information such as IP address, browser type, and actions taken in the product, used to operate and secure the services.

2. Client case data

Case data belongs to your firm. We process it only to provide the services — storing documents, running the analyses you request, and generating drafts for attorney review. Every record is scoped to your firm, and we do not read, mine, aggregate, or sell case content. Case data is encrypted in transit and at rest.

3. Subprocessors

We use a small number of service providers to run Attest — infrastructure and storage, AI model providers, email delivery, and error monitoring. Each one is named on our subprocessor list, along with what it does for us and what data it can reach. When a document is analyzed, the relevant content is sent to the applicable provider’s API to produce the analysis; these providers do not train models on API customer data. We share only what is necessary for each provider to perform its function, and we will update the list if it changes.

4. No AI training on customer data

Your case files and client data are never used to train AI models — not by us, and not by our AI providers. AI features operate on your data solely to produce outputs for your firm.

5. Retention and deletion

We retain case data for as long as your account is active so your casework remains available to you. You can delete individual documents or cases in the product at any time. When you close your account, or on request at any time, we delete your firm’s data from primary systems promptly and from backups on a fixed schedule. Limited billing records may be retained where required by law.

6. Security

We protect data with encryption in transit and at rest, per-firm data isolation enforced at the database level, expiring and revocable client portal links with tokens hashed at rest, and an append-only audit log of uploads, AI runs, and approvals. Details are on our security page.

7. Your choices

You can access, correct, export, or delete your firm’s data through the product or by contacting us. Clients of a firm should direct requests about their information to that firm, which controls the case file; we support firms in fulfilling those requests.

8. Changes

We may update this policy from time to time. If a change is material, we will provide notice through the services or by email before it takes effect.

9. Contact

Privacy questions and deletion requests can be sent to [email protected].