LegalDocs-Assist, operated by CaseFlow Automation Ltd
How It Works: A Plain English Guide
For fee-earners, not engineers. Written to be read on a Sunday afternoon.
Last reviewed: 26 June 2026
This guide explains what LegalDocs-Assist does, how it handles your firm's data, and where the limits of the AI are. No jargon, no marketing, no inflated claims. If something here doesn't match what you see when you use the product, that's a bug in this document and we'd like to know.
What Does LegalDocs-Assist Do?
đź“„
LegalDocs-Assist is a drafting and analysis platform for UK fee-earners working in three areas: RTA credit hire, housing disrepair, and clinical negligence. You feed it the letters and documents that come across your desk; it reads them, analyses the legal arguments inside, and helps you draft the reply.
Think of it as a very well-read assistant that has read 133 UK credit hire and motor claims authorities, knows what CPR Part 32 requires of a witness statement, and never gets tired at 5pm. It will not, however, sign your letters for you. Every output is a draft for a fee-earner to review.
The Tools, in Plain English
Claimant Witness Statement. Drafts a court-ready witness statement from your wizard inputs, in line with CPR Part 32 and the practice direction's statement-of-truth wording.
Impecuniosity Assessment. Walks through the ten-step financial test for a credit hire impecuniosity claim and tells you which steps your evidence already supports and which still need work. Reached as Stage 1 of the Claimant Witness Statement workflow, and also available as a standalone assessment.
Insurer Letter Analyser. Reads an insurer's letter and tells you which legal authorities they are citing, which ones they have misquoted, and where they have no leg to stand on.
AI Reply Generator. Drafts a reply to the insurer's letter, leaning on our verified case law and on the strategy logic baked into the system. Reached from inside the Insurer Letter Analyser once an incoming letter has been analysed.
Liability Assessment. Takes the parties' accident statements and gives you a structured view of where liability is likely to fall, with the cases that support it.
Case Law Bible. A searchable library of 210 UK authorities covering credit hire, liability, housing disrepair, and clinical negligence, each with a plain-English summary and the practical point a fee-earner needs.
Medical Pagination (clinical negligence). Takes a stack of medical records and turns them into a single properly-paginated bundle for court. See the note further down about how this one tool handles PDFs differently.
Disrepair Chronology (housing disrepair). Reads tenant correspondence and repair records and produces a chronology you can drop straight into a particulars of claim.
Industry Resources. A curated hub of the ABI GTA, Law Society and Ministry of Justice notes, and the major hire-provider terms and conditions. Read-only, kept current.
What AI Model Does It Use?
🤖
Every AI feature in LegalDocs-Assist runs on the same model: Google's Gemini 3 Flash (preview), accessed through an enterprise gateway. We deliberately chose a single model rather than a mix, so that the safety controls described below apply uniformly to every AI call the system makes, there is no second-tier model running on a quieter code path with weaker controls.
The enterprise gateway terms prohibit Google from using your inputs or our outputs to train their models. That covenant sits above our own commitment not to train on your data.
Does the AI Make Things Up?
đź”’
This is the single biggest risk of using AI in a legal setting. The model is perfectly capable of inventing a plausible-looking case name and citation that does not exist. We treat that as the central engineering problem of the platform, and have built three independent layers of protection that every AI output passes through. The same three layers run on every AI feature in the product, not just selected ones.
Layer 1, Prompt rules: The AI is given strict instructions that it is "strictly prohibited from citing, referencing, or mentioning any case law that does not appear in the knowledge base." If it can't find authority, it must say so, not guess.
Layer 2, Citation validator: After the AI generates its response, every case name it cites is automatically cross-referenced against our database of 210 UK authorities across five practice areas. Any citation not found in that database is stripped from the output before you see it.
Layer 3, Text-body scrubber: A separate scanner then reads through all the prose (summaries, reasoning, strategic advice) looking for any remaining "X v Y" case-name patterns the validator did not catch. If it finds one that isn't in our verified database, it replaces it with a warning placeholder so you can see at a glance that something was removed.
Think of it as a three-checkpoint gate. First, the AI is told in advance which authorities it is allowed to cite. Then, the structured list of citations in its answer is checked against our records, one by one. Finally, the entire body of the answer is read again by a separate scanner looking for case names hiding in the prose. All three checks happen automatically, every time, before anything reaches your screen.
That said, no AI is perfect. The three layers stop the failure mode that procurement teams worry about most, fabricated citations reaching a final letter, but we still recommend checking any citation independently before relying on it in court correspondence. The system is a starting point, not a final answer.
What Happens to My Documents?
đź’»
For the text‑based tools, your source documents stay on your computer. When you upload a text‑based PDF or Word document into the Insurer Letter Analyser, the Witness Statement Generator, the Liability Assessment, or any of the other text‑based tools, the file is read and converted to text inside your browser. The original file itself does not leave your device; only the extracted text is sent for analysis. Even then, the text goes through our privacy filter first (the next section explains how).
There are two documented exceptions. Scanned or image‑only PDFs are briefly uploaded so we can OCR them on the server, then deleted within the hour. Medical pagination uploads the PDF itself; it is dealt with separately further down so you can see exactly what happens to it.
The AI drafting itself happens on our server, under Zero Data Retention terms with the AI provider, and the generated output is deleted shortly after it is returned to you (see "How long is my data kept" below).
When you load a letter into a photocopier, the machine reads it and produces a copy, but the original letter never leaves the room. Our PDF handling works the same way: the file stays with you, and only the text on it travels, with personal details blanked out before it does.
How Can You Be Sure?
"Trust us" isn't always enough, particularly if your IT team or a client is asking. The short answer: any IT professional can watch your browser's network traffic while a PDF is being loaded into one of the text-based tools. They will see zero outbound requests at that stage. The only call to our servers happens after you click Analyse, and it carries extracted text, not the original file. The document genuinely does not move.
This is not just our policy. It's how the underlying technology works. The PDF reader runs entirely inside the browser tab, using the same open-source library that Firefox uses to display PDFs natively. It is physically incapable of uploading the file.
The Medical Pagination Exception
Medical pagination is the one tool where the PDF itself is uploaded to our servers, because the work the tool does (renumbering, OCR-ing, and assembling the records into a single court-ready bundle) genuinely needs the file, not just the text.
Three things to know about how we handle that file:
It is uploaded to encrypted storage that only your Client organisation can read. No other firm on the platform can see it.
As soon as the paginated bundle is produced, the source medical PDF is deleted from our storage. The output bundle is then held for one hour so you can download it, after which it is deleted automatically. Nothing is kept beyond that window.
Nothing in the medical PDF is used to train any AI model, by us or by our AI provider. The same training prohibition that applies everywhere else in the product applies here too.
If your firm's policy is that medical records may not be uploaded to any third-party platform at all, do not use the medical pagination tool. Every other AI tool in LegalDocs-Assist will still work without it, on extracted text alone.
How Is Personal Information Protected?
🛡️
Before any text reaches the AI, it passes through our PII masking gateway. "PII" stands for Personally Identifiable Information, the kind of detail that identifies a real person and that you would expect to be handled carefully.
The gateway looks for personal details and replaces them with neutral placeholders before the text reaches Google's model. So instead of "Mrs Lisa Chen", the AI sees "[NAME_REDACTED]". Instead of "john.smith@example.com", the AI sees "[EMAIL_REDACTED]". The AI does its analysis on the cleaned text, and the placeholders are reinserted in your output so the final draft reads naturally.
The gateway covers 14 verified categories: titled personal names, email addresses, UK phone numbers, National Insurance numbers, NHS numbers (Mod 11 validated), UK driving licence numbers, vehicle registration marks (VRMs), IBANs, credit and debit card numbers, sort codes, bank account numbers, dates of birth (in context), policy and claim references, and street addresses. The full per-category technical detail lives in our PII Masking Architecture document for anyone who wants it.
UK postcodes are deliberately not masked. They are material to BHR locality arguments in credit hire and to venue analysis in housing disrepair — masking them would degrade the legal output. We rely on two safeguards instead: the AI provider's enterprise no-training terms, and an output-side scrubber (postcodeScrubber.ts) that strips any postcode the AI introduces that was not in the original input.
One carve-out worth knowing about. In the Witness Statement Generator, the party names you enter on the form (claimant, defendant, witnesses) are passed to the model so the statement can attribute evidence to the correct person. Everywhere else in the product, titled and labelled names are masked like any other identifier.
An honest note: masking detects and replaces the personal identifiers it can find. It is mandatory and a strong first layer, but it is pattern‑based and not a perfect filter, and we do not claim it is fully redacted or guaranteed. Users are asked to send only what the task needs. If a document contains material that genuinely should not leave your firm, do not paste it in and rely on the filter; remove it first.
Is My Data Used to Train the AI?
đźš«
No. We do not use your data to train AI models, and the enterprise contract we hold with Google prohibits Google from using it either. The AI provider operates under the Lovable AI Gateway's Zero Data Retention terms, in force since March 2026: your prompts and the model's responses are not retained by the provider and are not used to train any model. Your correspondence and case details are used for one purpose only: to generate the specific output you asked for.
How Long Is My Data Kept?
📦
LegalDocs Assist is designed not to retain personal case data. Uploaded source documents and the outputs the tool generates — witness statements, paginated bundles, chronologies, timelines, advice, correspondence — are deleted shortly after they are produced or on session close. A scheduled purge runs continuously as a backstop, so nothing is ever retained beyond 24 hours. Firms are expected to download or save their own copy of any output they need, and to re‑run the tool if they need it again. Medical‑bundle pagination files are deleted within about an hour of completion. Inactive login sessions expire on their own. The only data retained is the minimal account record needed to run the subscription. Activity and audit logs are retained as described in the Privacy Policy.
Uploaded files are never included in any backup. The database has standard disaster‑recovery backups, but because case content is deleted within 24 hours those backups hold essentially no personal case data, and once a record is deleted there is nothing to restore it from.
Special category (health) data. Medical records are core to clinical‑negligence and personal‑injury work, so the Service routinely processes special‑category health data. The safeguards are browser‑side processing of source documents, server‑side PII masking, encryption in transit and at rest, and immediate deletion within 24 hours. As data controller, your firm is responsible for the Article 9 lawful basis.
What Happens When We Delete Something?
🗑️
Deletion is immediate and permanent. When you delete a record or document, it leaves the live database and, if it has files attached, those leave storage too. Because storage is not backed up, there is no copy to restore from.
If your firm leaves the platform, we permanently delete your firm's entire tenant — all case content, all documents and bundles, and the user accounts that go with it. The admin path that does this is hardened and is executed only by CaseFlow Automation Ltd platform administrators: a firm has to be archived first (a reversible step that gives you a thirty (30) day grace period during which the firm can be reinstated), then permanently deleted from the archived list as a second gate. Firms cannot self-delete. Where the trigger is contract termination, the permanent delete happens within thirty (30) days of termination. We record the fact of the deletion in an audit log — who, when, and the counts — but never the content itself. The only thing we keep is the minimal account and billing record the law requires us to keep, with personal data stripped out where we can. This is a contractual commitment we honour operationally, not an automated platform feature.
What Are My Rights?
⚖️
UK GDPR gives you the usual rights — access, rectification, erasure, restriction, portability and objection.
For data about your firm's clients and claimants, your firm is the data controller and we are the processor. So requests from those individuals go to your firm; we help you fulfil them, including by deleting or exporting the records on your instruction.
For data we hold about you as a user of the platform — your login, your usage logs — you can contact us directly at info@caseflowautomation.co.uk. You can also complain to the Information Commissioner's Office at any time.
Can Other Companies See My Data?
🏢
No. Each Client organisation on LegalDocs-Assist operates in its own walled-off space. Your firm's correspondence, drafts, witness statements, history, and templates are invisible to every other firm on the platform. This is enforced at the database level by row-level security rules that sit underneath the application, it is not a setting in a configuration screen that could be accidentally turned off.
Think of separate filing cabinets in separate locked rooms inside the same building. Each firm has their own room and their own key. There is no master key that opens every room, and there is no shared cabinet that two firms can both reach into.
What About GDPR?
⚖️
UK GDPR requires organisations to collect the minimum personal data necessary, to protect it properly, and to be transparent about what they do with it. We are registered with the Information Commissioner's Office under registration number ZC013423 and operate under UK GDPR. Here's how the design of the product lines up against those duties:
âś… Data minimisation: for nearly every tool, PDFs stay on your device and only extracted text travels. Text is then masked before reaching the AI.
âś… Privacy by design: the masking gateway is mandatory. There is no path in the code that reaches the AI without going through it.
âś… Transparency: We tell you exactly what we do (you're reading it now).
âś… Encryption: data is encrypted in transit between your browser and our servers, and at rest in the database.
âś… Your rights: you can request access to, correction of, or deletion of your data at any time.
âś… ICO registered: registration number ZC013423.
Is It Legal Advice?
⚠️
No. LegalDocs-Assist is decision support. It helps a fee-earner draft and analyse faster, working from a structured knowledge base; it does not replace the judgement of the qualified solicitor who signs the letter. Every AI output in the product is labelled as a draft requiring review, and outputs are never auto-sent.
We make that point clear throughout the platform: you will see it on first login, on every page that invokes the AI, and alongside every generated response.
The Quick Summary
đź“„ For nearly every tool, your PDFs stay on your device; medical pagination is the documented exception, with retention controls.
🛡️ Personal details are masked server-side before any AI call.
🤖 One enterprise-grade model (Google's Gemini 3 Flash preview) across every AI feature, so the safety controls apply uniformly.
đźš« Your data is not used to train AI models, by us or by Google.
🏢 Each Client organisation's data is isolated at the database level through row-level security.
đź”’ Three layers of protection against fabricated case law (prompt rules, citation validator, text-body scrubber) applied at every AI invocation site.
⚖️ Registered with the ICO (ZC013423) and operating under UK GDPR.
⚠️ AI outputs are drafts requiring fee-earner review, never auto-sent.
Got questions? If anything in this guide isn't clear, or doesn't match what you see in the product, write to us at info@caseflowautomation.co.uk.