Legal Documentv2.3

Privacy Policy

This Privacy Policy explains how Prosei AI collects, uses, and protects your personal information when you use our platform.

Effective: September 15, 2026

PRIVACY NOTICE

This Privacy Policy ("Policy") constitutes a legally binding agreement between you (the "User," "you," or "your") and Prosei AI LLC governing the collection, use, disclosure, and protection of personal information and data obtained through your use of the Prosei AI platform.

BY ACCESSING OR USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY THIS PRIVACY POLICY.

1. SCOPE AND APPLICATION OF THIS POLICY#

This Privacy Policy applies to all personal information and data collected by the Company through the Service, including information collected through our website, web application, mobile applications (if applicable), and any other digital properties owned or controlled by the Company.

This Policy does not apply to:

  • Information collected offline or through channels other than the Service;
  • Third-party websites, applications, or services that may be linked to or from the Service;
  • Information practices of third-party service providers, except as expressly described herein.

2. CATEGORIES OF PERSONAL INFORMATION COLLECTED#

2.1 Information Provided Directly by Users

The Company collects personal information that you voluntarily provide when registering for, accessing, or using the Service, including without limitation:

  • Account Registration Information: Email address, full legal name, username, password (encrypted using industry-standard cryptographic algorithms), and security authentication credentials;
  • Profile Information: Jurisdiction, state of residence, user preferences, account settings, and notification preferences;
  • Legal Case Information: Case titles, case descriptions, case numbers, court jurisdictions, case types, case status information, litigation parties, party roles, party contact information, and any other case-related data or metadata;
  • Document Content and Metadata: Legal documents, court filings, pleadings, motions, correspondence, evidence, images, photographs, and any other files or content uploaded to or transmitted through the Service, together with associated metadata including file names, file types, file sizes, upload timestamps, and modification histories;
  • Extracted Text and Document Analysis Data: Textual content extracted from uploaded documents through optical character recognition (OCR) or parsing technologies;
  • User-Generated Content: Notes, annotations, comments, descriptions, deadlines, calendar entries, task lists, and any other textual or multimedia content created or uploaded by users;
  • Communications with the Company: Content of emails, support tickets, feedback submissions, or other communications sent to the Company;
  • Consent Records: Records of consent provided or withdrawn for specific data processing activities, including artificial intelligence analysis;
  • Payment Information: If and when payment features are implemented, billing addresses, payment card information (processed through third-party payment processors), and transaction history.

2.2 Information Collected Automatically

The Company automatically collects certain information when you access or use the Service through the use of cookies, web beacons, log files, and similar tracking technologies:

  • Device Information: Device type, device identifiers, hardware model, operating system type and version, browser type and version, screen resolution, and device settings;
  • Network and Connection Information: Internet Protocol (IP) address, Internet Service Provider (ISP), geolocation data (city and state level, derived from IP address), and network connection type;
  • Usage and Activity Data: Pages viewed, features accessed, actions performed, buttons clicked, time spent on pages, navigation paths, session duration, frequency of use, and patterns of interaction with the Service;
  • Log Data: Access times, error logs, crash reports, performance metrics, server logs, and diagnostic information;
  • Referral Information: Referring websites, search terms used to locate the Service, and marketing campaign identifiers;
  • Authentication and Security Data: Login timestamps, authentication attempts, session identifiers, and security event logs.

2.3 Information from Third-Party Sources

The Company may receive information about you from third-party sources, including:

  • Authentication Providers: If you authenticate through third-party services (e.g., Google OAuth), we may receive basic profile information such as name, email address, and profile picture;
  • Analytics Providers: Aggregated usage statistics and analytics data from third-party analytics services;
  • Legal Compliance Sources: Information necessary to comply with legal obligations, such as information from courts, law enforcement, or regulatory agencies.

2.4 Sensitive Personal Information

ATTORNEY-CLIENT PRIVILEGE WARNING

The Service may process sensitive information including legal case information, court documents, and information about legal disputes. We strongly recommend consulting with licensed legal counsel before uploading documents subject to attorney-client privilege or other confidentiality protections to understand the potential implications for privilege waiver.

Health information. Legal matters frequently contain health information: medical records in a personal injury claim, psychological evaluations in a custody matter, treatment history in a disability or employment case. Where the documents you upload contain health information, it is governed by our Consumer Health Data Privacy Policy, a separate document that describes what we collect, who processes it, and the specific rights you have over it under Washington's My Health My Data Act and Nevada's SB 370.

3. HOW WE USE INFORMATION#

3.1 Primary Purposes

We use collected information to:

Provide and Maintain the Service:

  • Create and manage user accounts;
  • Authenticate users and ensure security;
  • Provide case management functionality;
  • Store and organize documents;
  • Process AI feature requests (when enabled);
  • Generate AI-assisted content;
  • Track deadlines and send reminders.

Improve and Develop the Service:

  • Analyze usage patterns and trends;
  • Develop new features and functionality;
  • Optimize performance and user experience;
  • Conduct research and development;
  • Perform testing and quality assurance.

Communicate with Users:

  • Send service-related notifications;
  • Provide customer support;
  • Respond to inquiries and requests;
  • Send administrative messages;
  • Provide updates about the Service.

Ensure Safety and Security:

  • Detect and prevent fraud;
  • Monitor for security threats;
  • Investigate suspicious activity;
  • Enforce our Terms of Service;
  • Protect against malicious activity.

Legal and Compliance:

  • Comply with legal obligations;
  • Respond to legal process;
  • Establish, exercise, or defend legal claims;
  • Enforce our agreements;
  • Protect rights and safety.

3.2 Marketing and Promotional Uses

With your consent, we may use your information to:

  • Send promotional emails about new features;
  • Inform you about service updates;
  • Provide educational content about legal processes;
  • Offer special promotions or discounts.

You may opt out of promotional communications at any time.

3.3 AI Training and Improvement

WE DO NOT USE YOUR CONTENT TO TRAIN AI MODELS.

Your case information, documents, and AI interactions are not used to train or improve general AI capabilities. We may use aggregated, anonymized usage patterns to improve our Service implementation and user experience.

5. INFORMATION SHARING AND DISCLOSURE#

WE DO NOT SELL, RENT, OR TRADE YOUR PERSONAL INFORMATION TO THIRD PARTIES FOR THEIR COMMERCIAL PURPOSES.

5.1 Service Providers

We share information with third-party service providers that help us operate the Service:

Infrastructure Providers:

  • Google (Firebase, Cloud Storage, Cloud Run): Authentication, database, file storage, and converting exhibit files to PDF;
  • Vercel: Application hosting and content delivery, so your requests transit their network;
  • Supabase: Stores the numeric embeddings used for semantic search across your documents;
  • Voyage AI: Converts document text into those embeddings.

AI Services:

Anthropic, Inc.

  • Purpose: AI processing for document analysis and content generation;
  • Data Shared: Document text, prompts, case context (only when AI features are enabled);
  • Important: Anthropic does not use customer data for model training;
  • Privacy Policy: anthropic.com/legal/privacy

Speech Recognition:

Deepgram, Inc.

  • Purpose: Converting speech to text for the transcription features (only when you upload or record audio or video for transcription, or use the microphone input in chat);
  • Data Shared: The audio or video you submit for transcription, and short voice clips from the chat microphone;
  • Important: Deepgram's retention and use of audio are governed by its own privacy policy, linked below; the transcript itself is stored by us in your case and is covered by this Policy;
  • Privacy Policy: deepgram.com/privacy

Court Filing and Service of Process:

InfoTrack US, Inc.

  • Purpose: Court e-filing and service-of-process fulfillment (only when you use the File or Serve features);
  • Data Shared: Documents you select for filing or service, and the case, party, and filing details you confirm in the filing flow;
  • Important: Documents submitted for filing are retained by InfoTrack for fulfillment and court-record purposes;
  • Privacy Policy: infotrack.com/privacy

Payments and Communications:

  • Stripe: Payment processing. Card details are handled by Stripe on Stripe's own checkout pages and never reach our servers;
  • Resend: Sends transactional email such as notifications and account messages.

Analytics and Monitoring:

  • PostHog: Product analytics and session replay. Replays are configured to hide all on-screen text and all form inputs, and we do not record console output or network request bodies, so document contents are never captured;
  • Sentry: Application error and crash reporting;
  • Vercel Web Analytics: Aggregate page traffic, without cookies and without a persistent per-visitor identifier.

These four receive account and diagnostic information only, never the contents of your documents.

All service providers are contractually required to protect the confidentiality and security of Personal Information, use it only as necessary to provide services, and comply with applicable privacy laws. The complete, current list is maintained at prosei.ai/security and in Annex II of our Data Processing Agreement.

5.3 Business Transfers

In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, information may be transferred as part of the transaction. We will notify you of any change in ownership or control of Personal Information.

6. GOOGLE USER DATA#

This Section describes how we access, use, store, and share data obtained through Google APIs when you choose to connect a Google account. Connecting a Google account is optional and the Service is fully functional without it. Where this Section differs from a more general statement elsewhere in this Policy, this Section governs Google user data.

6.1 Permissions We Request

We request only the permissions required by the feature you choose to connect, and we request them at the moment you connect it:

  • Gmail, read (gmail.readonly): permits us to read messages in your mailbox so that case-related correspondence can be displayed inside the Service and filed under the correct case;
  • Gmail, send (gmail.send): permits us to send only those messages you compose and expressly submit for sending from within the Service. We do not send, forward, delete, or modify any message on your behalf;
  • Google Calendar (calendar.events.owned): permits us to create, update, and delete calendar entries that the Service creates on a calendar you own, for the deadlines and hearings you track. We do not read your existing calendar entries;
  • Google Drive (drive.file): permits us to access only the specific files you select through Google's file picker, and files the Service itself creates. We cannot see any other file in your Drive;
  • Account identity (userinfo.email, userinfo.profile): your email address and basic profile information, used to identify the connected account and to support signing in with Google.

We do not request permission to read your existing calendar entries, to browse your Drive, or to modify or delete your email.

6.2 How We Use It

Gmail. When you connect a Gmail account, we periodically retrieve recent messages and store, for each one, the subject, sender, recipients, message body, timestamps, and the Gmail message identifier. We use this to display your correspondence inside the Service and to associate each message with the correct case by comparing its participants against the party email addresses recorded in that case. We do not retrieve attachments.

Google Calendar. We create, update, and remove calendar entries corresponding to deadlines and hearings you record in the Service. We do not read entries created by you or by any other application.

Google Drive. We retrieve the content of files you explicitly select in order to store and analyze them within your case, and we write documents you export from the Service.

We do not use Google user data for advertising, we do not sell it, and we do not use it to train any artificial intelligence or machine learning model.

6.3 Storage, Sharing, and Deletion

Google user data is stored in our Firebase infrastructure under access controls that restrict each record to the account that created it. OAuth access and refresh tokens are encrypted at rest using AES-256-GCM and are never transmitted to your browser.

Email content is not sent to our artificial intelligence provider. The AI features described in Section 5.1 operate on documents, prompts, and case details that you provide; messages synchronized from a connected Gmail account are not included in that processing.

Documents you import from Google Drive are treated as ordinary case documents once imported, which means that if you then use an AI feature on such a document, its text is processed as described in Section 5.1.

You may disconnect a Google account at any time from Settings, which removes our stored tokens and ends further access. You may separately revoke our access from your Google Account permissions page. Deleting your Prosei AI account deletes synchronized email, calendar records, and imported documents as described in Section 18.

6.4 Limited Use Commitment

Prosei AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Specifically, we affirm that we:

  • limit our use of Google user data to providing and improving the user-facing features described in this Section;
  • do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or in connection with a merger or acquisition as described in Section 5.3;
  • do not use Google user data for serving advertisements of any kind;
  • do not allow any person to read Google user data, except where you give explicit permission, where it is necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized;
  • do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.

7. DATA RETENTION#

We retain Personal Information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, enforce our agreements, and fulfill the purposes described in this Privacy Policy.

Specific Retention Periods:

  • Active Accounts: Retained while account is active;
  • Closed Accounts: Deleted within 90 days of account closure;
  • Backup Copies: May persist for up to 180 days in secure backups;
  • Active Cases: Retained while case is active;
  • Archived Cases: Retained for 7 years after archival;
  • Deleted Cases: Permanently deleted within 30 days;
  • Documents: Retained with associated cases, deleted within 30 days of deletion;
  • Support Communications: Retained for 3 years;
  • Access Logs: Retained for 1 year;
  • Security Logs: Retained for 2 years.

Inactive Account Policy: Accounts inactive for more than 24 months may be notified of pending deletion, given 30 days to reactivate, and deleted if no action is taken.

8. DATA SECURITY#

We implement comprehensive security measures including:

  • Technical Safeguards: Encryption in Transit (TLS 1.2+), Encryption at Rest (AES-256), Access Controls (RBAC), Multi-factor authentication, Firewalls, Regular security scanning.
  • Organizational Safeguards: Access limited to necessary employees, Security training, Background checks, Confidentiality agreements, Vendor security assessments.
  • User Responsibilities: Maintaining strong passwords, protecting credentials, using secure networks.

Limitations: No security system is impenetrable. We cannot guarantee absolute security. In the event of a breach, we will notify affected users as required by law.

9. INTERNATIONAL DATA TRANSFERS#

Your information may be transferred to and processed in countries other than your country of residence, including the United States. We ensure appropriate safeguards (such as Standard Contractual Clauses) where required.

Primary data processing occurs in the United States. By using the Service, you consent to this transfer.

10. YOUR PRIVACY RIGHTS#

Regardless of location, you have the right to Access, Correct, Delete, Port, Restrict, and Object to processing of your data.

To exercise your privacy rights, contact us at prosei.ai.official@gmail.com, via in-app settings, or through customer support. We aim to acknowledge requests within 3 business days and respond substantively within 30 days.

11. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)#

California residents have additional rights: Right to Know, Right to Delete, Right to Correct, Right to Opt-Out (we do not sell info), and Right to Non-Discrimination.

Categories Collected (Past 12 Months): Identifiers, Personal Information, Commercial Information, Internet Activity, Geolocation, Professional Information, Sensitive Personal Information.

We do not sell or share Personal Information for cross-context behavioral advertising.

12. EUROPEAN PRIVACY RIGHTS (GDPR)#

If you are in the EEA, UK, or Switzerland, you have rights under GDPR including Access, Rectification, Erasure, Restriction, Data Portability, Objection, and Rights regarding automated decision-making.

Contact DPO: prosei.ai.official@gmail.com

You have the right to lodge a complaint with your local supervisory authority.

13. COOKIES AND TRACKING TECHNOLOGIES#

We use Essential (security, auth), Functional (preferences), and Analytics (usage) cookies. You can manage cookies via browser settings or in-app preferences.

14. CHILDREN'S PRIVACY#

The Service is not intended for individuals under 18. We do not knowingly collect info from minors. If discovered, we will delete it promptly.

15. DATA BREACH NOTIFICATION#

In the event of a breach, we will investigate, assess risk, and notify affected individuals without undue delay (or within 72 hours for GDPR) via email, in-app notification, or website notice.

16. CHANGES TO THIS PRIVACY POLICY#

We reserve the right to modify this Policy. Material changes will be notified via email or in-app notice. Continued use constitutes acceptance.

17. CONTACT INFORMATION#

For privacy inquiries:

18. DATA DELETION#

You have the right to request deletion of your personal data and all associated content at any time. When your account is deleted, we permanently remove:

  • Account & Profile: Your name, email, and authentication credentials;
  • Case Data: All cases, parties, deadlines, and notes;
  • Documents: All uploaded files and AI analysis results;
  • Email Connections: OAuth tokens and synced email data;
  • AI Conversation History: All chat messages and AI-generated content.

Retained after deletion (legal requirement): Billing records and transaction history are retained for 7 years as required by applicable financial regulations. Anonymized, non-identifiable usage data may be retained for up to 90 days for fraud prevention.

Processing time: When you request deletion we schedule it and show you the scheduled date. Your account and case data are permanently deleted after a 30-day grace period, during which you may cancel the request. Residual copies in backups are purged after that.

If you are unable to access your account, email us at prosei.ai.official@gmail.com with the subject line "Data Deletion Request" and we will process your request within 30 days.

19. ADDITIONAL US STATE PRIVACY RIGHTS#

Sections 11 and 12 describe rights under California and European law. Several other US states have comprehensive privacy laws of their own. If you live in one of them, this Section describes the rights those laws give you. Where a right below overlaps one in Section 10 or Section 11, you may exercise it under whichever applies to you.

Across these states you generally have the right to confirm whether we process your personal information and to access it, to correct inaccuracies, to request deletion, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal information, and profiling that produces legal or similarly significant effects. We do not sell your personal information, we do not use it for targeted advertising, and we do not use it for that kind of profiling.

  • Virginia (Consumer Data Protection Act);
  • Colorado (Colorado Privacy Act);
  • Connecticut (Connecticut Data Privacy Act);
  • Utah (Utah Consumer Privacy Act);
  • Nevada (SB 220), under which you may opt out of the sale of covered information. We do not sell covered information as Nevada law defines it. Nevada's SB 370, which covers consumer health data, is addressed separately in our Consumer Health Data Privacy Policy.

This list is not exhaustive, and more states pass such laws each year. If you live in a state that gives you a privacy right this policy does not name, that right still applies to you and we will honor it. Exercise any of these rights the same way as in Section 10, by contacting us at the address in Section 17. We will not discriminate against you for making a request.

Several of these laws let you appeal a refused request. If we decline a request you have made, we will tell you why, and you may reply to that decision at the same address to have it reviewed. Where your state provides one, you may also contact your state Attorney General.

Acknowledgment of Agreement

BY USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THIS PRIVACY POLICY.

Copyright © 2026 Prosei AI LLC. All rights reserved.