Privacy Policy

Last updated: September 9, 2026

Rule #1 – We do not sell your personal data

At Caselaw.ai, your privacy is our priority. We want to be absolutely clear on this point:

We do not sell your personal data. We will never sell, rent, or trade your personal information to third parties for marketing or any other commercial purpose.

We may share limited information only in the following circumstances:

  • Payment Providers: We use Stripe as a trusted third-party service provider to help us charge for services. Stripe only receives the minimum data necessary to perform their transactional function and are bound by confidentiality and data protection obligations.
  • Legal Compliance: We may disclose information if required by court order.
  • Business Transfers: If Caselaw.ai is involved in a merger, acquisition, or sale of assets, user information may be transferred as part of that process, but always under strict privacy safeguards.

Rule #2 – We do not share data

  • Your data is never used to train AI models.
  • We do not share your information with any AI providers — whether the data is public or private, it remains off-limits.
  • We prevent third parties from accessing, scraping, or learning from your research on Caselaw.ai: the questions you ask, the documents you upload, and the cases you read. Measuring how our pages are used is the one place an outside service is involved, and Rule #4 sets out exactly what it sees.

Rule #3 – We do not store data for ourselves

When you use Caselaw.ai, your information stays yours.

  • We do not store session data outside your account.
  • We do not keep uploaded documents beyond your use of them.
  • We do not keep the questions you type, or the cases you open, for analytics or profiling.
  • We do not link prompts to your identity.
  • We do keep a record of the search terms our system sends to our case index, so we can see which areas of law people are researching and where our coverage is thin. That record is not tied to you or to your account. Rule #4 sets out exactly what it holds.
  • We do not build advertising or marketing profiles, and we never sell anything we measure. We do count page views and clicks so we can keep the site working well, partly on our own servers and partly through Google Tag Manager. Rule #4 sets out both in full.

The only exception is your personal account data (such as chat history, saved documents, and the time entries you record in the time tracker), which is stored solely so you can access it whenever you log in. This information exists for your benefit, not ours; cannot be accessed by Caselaw.ai staff; and is never used for AI training, advertising, or third-party sharing. Your account data is yours: private, secure, and under your control.

A word on the time tracker, because it is the one part of the product that records when you were working. It holds only what you put in it: the clock you started and stopped, the project you filed it under, anything you typed as a description, and the rate you set. Nothing starts it but you. We do not watch how long you spend on a page, we do not time you from your searches, and none of it counts toward anything we measure under Rule #4.

We know what a time sheet can contain. A project name and a line of description may identify a client or the matter you are working on, so those entries are treated as your account data under this rule and nothing else: they are not read by our staff, not used for AI training, not shared, and never part of any total we look at. Yours is the only account that can see them. They stay until you remove them, you can export the lot as a spreadsheet whenever you want, and you can delete any entry, or all of them, at any time.

One thing we do use your account for is email. If you hold a Caselaw.ai account, we may write to you about the product: new features, service changes, and occasional announcements. Every one of those carries a one-click unsubscribe link. Opting out sticks. We refresh our mailing list from our account list, and that refresh can never put you back on it. If you change your mind, the same link puts you back.

Your research never decides who gets those emails. We do not group people by what they have searched for, read, or uploaded, and we do not sell, rent, or share your address. Service email is separate: a reply to a support ticket, a receipt, or a notice about your account is part of holding one, and the unsubscribe link does not cover it.

Rule #4 – We measure the site, not you

We count how our pages are used so we know what to fix and what to build next. Two systems do that. The first is ours, running on our own servers, and it is the one described in most of this section. The second is Google Tag Manager, which we load on our pages to measure how well they do their job. This section covers both, including what Google sees that we do not.

What we count:

  • Which pages are opened, and how long a page is actually on screen
  • Which buttons and links are clicked
  • The site that sent you here, and the campaign link you followed, if there was one
  • Your browser, operating system, device type and language
  • The search terms our system sends to our case index, and how many cases came back

What we never record:

  • Your IP address, on our side. It is checked against our own office networks and then discarded, never written down. Google's tag is the exception, and the part about it below explains what happens there.
  • The words you type. Your questions, uploaded documents and the messages you send us stay out of this entirely. Search terms are the one exception, and those are written by our system rather than by you. The paragraph below explains them in full.
  • Anything sold to anyone. We do not sell what we measure and we do not hand it to an advertising network. What our own servers record stays with us. What Google's tag collects goes to Google, and nowhere else.

On our side, visitors are counted using a random number your browser stores for itself. It is not tied to your name or your email. While you are signed in, page views and clicks are recorded against your account, so our support team can see how the product is behaving for you when you ask us for help, and so we know which features are worth improving. Nothing you type is part of that record.

Google Tag Manager. We load Google's tag manager on every page of this site apart from our own staff admin panel. It reports which pages are opened, and it tells us when someone clicks the two buttons that matter most to our business: Buy now on the Discovery Brief page, and Request a demonstration. That is the whole of what we send it. Your questions, your uploads and the cases you read are not part of it and never reach Google.

Three things follow from using Google at all, and they are worth stating plainly:

  • Google sets its own cookies in your browser so it can tell a repeat visit from a new one. They can last up to two years. You can clear or block them whenever you like, and this site works normally without them.
  • Google's servers see your IP address, the same way they would on any site that uses their tools. Google uses it to work out a rough location. It is not passed on to us, and we neither see it nor store it.
  • What Google collects is held by Google, under its own privacy policy and its own retention settings rather than ours.

We do not put a cookie banner in front of you for this. A banner everyone clicks through without reading is worth less than a page that tells you what is actually happening, which is what this one is for. If you would rather Google saw none of it, browser tracking protection blocks it, so does any ad blocker, and Google publishes its own opt-out add-on. Blocking it costs you nothing here.

A word on searches. When you ask a research question, our system turns it into a short list of legal keywords and sends those to our case index. We keep that keyword list, any court or jurisdiction filter applied to it, and how many cases came back. We do not keep your question. The record holds no name, no email, no account number, no visitor number and no session number, so there is no way to trace it back to you. All it tells us is that someone searched for, say, "constructive dismissal reasonable notice" and got ten results.

We file each of those keyword lists under an area of law, so the record above would be filed under employment. That is done on our own server by matching the keywords against a fixed list of legal terms. No outside service sees it, and no artificial intelligence reads it. What we look at day to day is the summary those labels add up to: which areas of law people research, and which areas keep coming back with no cases, because that is where we need to widen our coverage. We read it for that, and for nothing else.

Because that record is written by our own server as the search runs, rather than by the script in your browser, a Do Not Track signal and the opt-out button below do not stop it. Neither one needs to: there is nothing in it that points to you.

We still hold the line on the rest. A tag manager can load almost anything, so here is what we will not load into it: no heatmaps, no session replay, no advertising or remarketing pixels, no profiles built to sell you something, and no experiments run on you without your knowledge. If that ever changes, this page changes first.

If your browser sends a Do Not Track or Global Privacy Control signal, our own tracker skips you completely, apart from the anonymous search record described above. You can also switch it off here, for this browser, at any time. Both of those cover our tracker rather than Google's tag; to stop that one, use the browser settings or the add-on described above.

We delete our own records automatically once they pass our retention window, which is never longer than twelve months. What Google holds runs on Google's retention settings, which we do not control.

Rule #5 – Our data comes from court rulings, not users

Every answer on Caselaw.ai is grounded in court decisions, legal statutes, and official public records.

We do not use law firm databases or memos, or user-uploaded content as training data.

Rule #6 – End-to-end Encryption

We protect the Caselaw.ai platform with industry-leading security. Our servers are hosted on secure U.S.-based infrastructure and include:

  • End-to-end TLS encryption
  • Authentication and permission controls
  • Rate limiting and bot protection
  • Encrypted storage for saved data in user accounts

If/when you save data in your user account, it is safeguarded with the same level of protection and care you would expect from a trusted legal technology provider.

Questions, Comments, Concerns

Privacy is something we take personally. If anything in this policy is unclear, if you'd like more technical details, or if you want to verify our practices before relying on Caselaw.ai for serious work, just reach out. We'll respond promptly and with full transparency.

Contact us here.