Data & AI handling

How We Protect Your Data

Here is exactly what happens to your information when you use the platform, step by step.

Featured webinar

Watch: the risk we are built to remove

A 30-minute webinar on how putting client documents straight into public AI tools can become a data breach, and why LegalDocs Assist is built the opposite way.

Your data's journey

Seven steps, in plain English. No long-term storage on our servers, no training on your content.

1. You upload

You upload or paste the information you are working from: documents, correspondence, records.

2. We mask the personal details

On our server, the personal identifiers we can detect are automatically masked before anything goes to the AI. It is a strong first layer, not a perfect filter, so we also ask you to send only what the task needs.

3. The AI returns the work

The masked text is sent to the AI, which returns the statement, chronology or pagination. The AI runs under Zero Data Retention terms, so it does not keep your data or train on it.

4. Your firm takes the output

You download the output into your own case management system. That is your record to keep.

5. The data is deleted

On session close the data is removed. Nothing is kept long-term on the platform.

6. A scheduled purge backs it up

A scheduled purge runs as a safety net, clearing anything left so case content is not retained beyond 24 hours.

7. A recovery draft stays on your device

So a crashed tab does not cost you your work, your typed and confirmed details are kept as a recovery draft in your own browser for up to 48 hours, then deleted. Documents are never stored in the browser, so a restored draft asks you to drop the files again. Signing out clears it at once.

What this means for you

We can't lose what we don't keep

Because case content is not retained, a breach would find almost nothing.

No backups of your files

Uploaded files are not held in any backup, so once deleted they are gone.

The AI never keeps or learns from your data

Your data is locked to your firm by row-level security and verified logins.

The short version: mask it, use it once, delete it.
We can't lose what we don't keep.

Why this helps you too

The less data anyone holds, the less there is to lose. Keeping retention to almost nothing minimises your clients' exposure and supports your firm's own data-minimisation obligations as the data controller.