Legal

Privacy Policy

Version 1.0 · Effective & last updated: November 29, 2025TrustFoundry is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information.

Key Principles

What We Collect: We collect account information, search queries, and usage data to provide our legal research services. We strongly encourage you to remove personally identifiable client information before submitting queries.

Data Security: We implement industry-standard encryption, secure authentication, and continuous monitoring to protect your information. Search queries are retained for only 30 days for debugging, then deleted or de-identified.

Your Rights: You have the right to access, correct, delete, or export your data at any time. California residents have additional CCPA rights. We will never sell your search queries or data to third parties.

1. Information We Collect

1.1 Information You Provide to Us

Account Information

  • Name, email address, phone number
  • Organization/law firm name and business address
  • Job title and professional information
  • Password (encrypted and never stored in plain text)
  • Billing and payment information (processed by our payment provider, Stripe)

API Credentials

  • API keys and authentication tokens
  • Developer account information
  • Integration configurations

Search and Usage Data

  • Legal search queries and citation requests
  • Search filters, parameters, and preferences
  • Case citations and legal materials accessed
  • Validation and Authority requests
  • Documents uploaded for citation extraction

Note: We strongly encourage you to remove personally identifiable client information before submitting search queries.

Customer Support Data

  • Communications when you contact support
  • Feedback, bug reports, and feature requests
  • Screen recordings or screenshots you provide (with your consent)

Survey and Marketing Data

  • Responses to surveys or questionnaires
  • Conference registration information
  • Newsletter subscription preferences

1.2 Information We Collect Automatically

Device and Browser Information

  • IP address (anonymized for analytics)
  • Browser type and version
  • Operating system
  • Device type (desktop, mobile, tablet)
  • Screen resolution and device identifiers

Usage Analytics

  • Pages visited and features used
  • Time spent on pages
  • Click paths and navigation patterns
  • API endpoint usage and request frequency
  • Response times and error rates
  • Geographic location (country/state level, not precise location)

Cookies and Similar Technologies

  • Session cookies for authentication
  • Preference cookies for user settings
  • Analytics cookies (see Section 4 for details)

1.3 Information from Third Parties

Payment Processors: Transaction completion confirmations from Stripe, payment method information (last 4 digits of card)

Authentication Providers: If you sign in with Google, Microsoft, or other single sign-on providers, we receive your name, email address, and profile picture

Business Intelligence Services: Company and organization information from B2B visitor identification services, firmographic data to understand which law firms visit our website

1.4 What We DON'T Collect

We do not collect:

  • Social Security numbers or tax identification numbers
  • Credit card numbers (handled entirely by Stripe)
  • Precise geolocation data
  • Biometric data
  • Health information or medical records
  • Information about your clients (unless you include it in your searches, which we discourage)
  • Contents of communications between you and your clients
  • Privileged or confidential legal communications

2. How We Use Your Information

2.1 To Provide and Improve Our Services

  • Service Delivery: Process your legal research queries, return search results, validate citations, and provide API responses
  • Platform Operation: Maintain, monitor, and optimize the performance of our Services
  • Personalization: Remember your preferences, recent searches, and frequently accessed jurisdictions
  • Product Development: Develop new features and improve existing functionality
  • Quality Assurance: Test and debug our platform to ensure accuracy and reliability

2.2 To Communicate With You

  • Service Communications: Send account notifications, service updates, security alerts, and technical notices
  • Customer Support: Respond to your inquiries, troubleshoot issues, and provide assistance
  • Marketing Communications: Send newsletters, product updates, conference invitations, and promotional offers (you can opt out anytime)
  • Legal Notices: Communicate changes to our Terms of Service, Privacy Policy, or other legal agreements

2.3 For Analytics and Research

  • Usage Analytics: Understand how users interact with our Services to improve user experience
  • Market Research: Analyze trends in legal research to identify popular practice areas and jurisdictions
  • Benchmarking: Create aggregated, anonymized usage statistics for internal business purposes
  • De-identified Data: Generate de-identified and aggregated data sets that cannot identify you or your clients

2.4 For Legal and Safety Purposes

  • Legal Compliance: Comply with applicable laws, regulations, and legal process
  • Terms Enforcement: Enforce our Terms of Service and other agreements
  • Fraud Prevention: Detect and prevent unauthorized access, abuse, or misuse of our Services
  • Security: Protect the rights, property, and safety of TrustFoundry, our users, and the public

2.5 With Your Consent

For any other purposes disclosed to you at the time of collection or with your explicit consent.

2.6 What We DON'T Do With Your Information

We do not:

  • Sell your search queries to third parties
  • Train AI models on your search queries or legal research data without explicit consent
  • Share your search history with competing legal research companies
  • Disclose client-identifiable information contained in your searches
  • Use your data for advertising beyond our own Services
  • Provide your research patterns to opposing counsel, adversaries, or other law firms

3. How We Share Your Information

3.1 We DO Share Information With:

Service Providers and Subprocessors

We share information with third-party vendors who perform services on our behalf, including:

  • Cloud Infrastructure Providers
  • Payment Processing Providers
  • Marketing Analytics Providers
  • Customer Support Services
  • Email Services
  • Infrastructure Monitoring
  • Authentication Service Providers

All service providers are contractually bound to: process data only for the purposes we specify, implement appropriate security measures, comply with applicable data protection laws, and not use your data for their own purposes.

Law Firm or Organization Administrators

If you access TrustFoundry through an organization account (e.g., your law firm purchased a team subscription): administrators can view usage data, billing information, and may have access to your search history. Your organization is responsible for its own data practices and privacy policies. We are not responsible for your organization's privacy or security practices.

Legal and Regulatory Authorities

We may disclose information when required by law or legal process, including:

  • Court orders, subpoenas, or search warrants
  • Government investigations
  • Requests from law enforcement or regulatory agencies

Where legally permitted, we will: notify you in advance of disclosure, challenge overbroad or inappropriate requests, and provide only the minimum information required.

Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the acquiring entity. We will notify you via email and website notice. The successor entity will be bound by this Privacy Policy.

3.2 We DO NOT Share Information With:

  • Competing legal research platforms (Westlaw, LexisNexis, Fastcase, Casetext, etc.)
  • AI training companies for model improvement purposes
  • Data brokers or marketing companies
  • Social media platforms (except for login authentication if you choose to use it)
  • Opposing counsel or adversaries in your legal matters
  • Anyone else without your explicit consent or legal requirement

3.3 Aggregated and De-Identified Data

We may publicly share or provide to third parties aggregated, de-identified data that cannot reasonably be used to identify you or your clients, such as:

  • "Federal case law searches increased 25% in Q3"
  • "Top 5 most-searched jurisdictions"
  • "Average API response time across all users"

This data does not include any search queries, case names, or client-identifiable information.

4. Cookies and Tracking Technologies

4.1 What Are Cookies?

Cookies are small text files stored on your device that help websites function and collect information about your usage. We use cookies and similar technologies (web beacons, pixels, local storage) to provide and improve our Services.

4.2 Types of Cookies We Use

Strictly Necessary Cookies (Always Active)

These cookies are essential for the Services to function and cannot be disabled:

  • Session authentication (keeps you logged in)
  • Security tokens (prevents CSRF attacks)
  • API request authentication
  • Load balancing and routing

Functional Cookies (Can Be Disabled)

These cookies remember your preferences and settings:

  • Language preferences
  • Jurisdiction filters
  • Recent searches
  • Display settings (light/dark mode)
  • Dashboard customizations

Analytics Cookies (Can Be Disabled)

These cookies help us understand how users interact with our Services:

  • Google Analytics (with IP anonymization enabled): Page views, session duration, bounce rate
  • Mixpanel: Feature usage, conversion tracking, user journey analysis
  • Hotjar: Heatmaps and session recordings (only with your explicit consent)

Marketing Cookies (Can Be Disabled)

These cookies track your interactions with our marketing materials:

  • Email open and click tracking
  • Conference registration sources
  • Referral tracking
  • LinkedIn conversion tracking (for business visitors only)

4.3 Third-Party Cookies

Third-party cookies enable payment processing, user authentication, and customer support features.

4.4 How to Manage Cookies

Cookie Banner: When you first visit our website, we display a cookie consent banner allowing you to accept all cookies, reject optional cookies, or customize your cookie preferences.

Browser Settings: Most browsers allow you to block all cookies, accept only first-party cookies, delete cookies after each session, or receive alerts when cookies are being set.

Note: Blocking necessary cookies will prevent you from using our Services.

Opt-Out Links:

4.5 Do Not Track (DNT)

Some browsers support "Do Not Track" signals. Our Services do not currently respond to DNT signals, but we provide granular cookie controls through our cookie banner and settings page.

5. Data Retention

5.1 How Long We Keep Your Information

We retain your personal information only as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law.

Active Accounts

  • Account information: Retained while your account is active
  • Search queries: Retained for 90 days, then aggregated and de-identified
  • API logs: Retained for 30 days for debugging, then deleted
  • Billing records: Retained for 7 years per tax and accounting requirements

Inactive Accounts

  • If you don't log in for 24 months, we may delete your account after email notice
  • You can request immediate deletion at any time (see Section 7)

After Account Deletion

  • Personal information is deleted within 30 days
  • Aggregated, de-identified data may be retained indefinitely
  • Legal documents (invoices, contracts) retained per legal requirements (typically 7 years)
  • Backup copies deleted within 90 days of deletion request

5.2 Why We Retain Data

  • Service Provision: Maintain account access and preferences
  • Customer Support: Troubleshoot issues and provide assistance
  • Legal Compliance: Fulfill tax, accounting, and regulatory obligations
  • Security: Detect fraud, abuse, and security incidents
  • Analytics: Improve our Services through usage analysis

5.3 Search Query Retention

We follow a strict data minimization approach:

  • Real-time: Search queries processed in memory for immediate results
  • Short-term (30 days): Retained for debugging, error analysis, and customer support
  • After 30 days: Queries are either deleted entirely OR de-identified (all user identifiers removed) and used for product improvement

We NEVER retain client-identifiable information beyond the short-term debugging period.

You can request immediate deletion of specific searches or all search history at any time.

6. Data Security

6.1 Security Measures

We implement industry-standard technical and organizational measures to protect your information, including:

  • Encryption of data in transit and at rest
  • Secure authentication and access controls
  • Regular security monitoring and updates
  • Administrative safeguards and employee training

While we strive to protect your information, no security system is impenetrable. We continuously review and update our security practices to address emerging threats.

6.2 Security Incident Notification

In the event of a data breach affecting your personal information:

  • We will notify you within 72 hours of discovery
  • Notification will include: nature of breach, affected data, steps we're taking, and recommended actions for you
  • We will report to relevant authorities as required by law

6.3 Your Security Responsibilities

You are responsible for:

  • Keeping your password secure and confidential
  • Not sharing API keys with unauthorized individuals
  • Using strong, unique passwords
  • Enabling two-factor authentication (when available)
  • Logging out of shared computers
  • Reporting suspicious activity immediately

6.4 Limitations

No system is 100% secure. While we use reasonable measures to protect your information, we cannot guarantee absolute security. Transmission over the internet and electronic storage always carry some risk.

If you have reason to believe your account security has been compromised, immediately contact us at [email protected].

7. Your Privacy Rights

7.1 Rights for All Users

Regardless of location, you have the right to:

  • Access: Request a copy of the personal information we hold about you and receive information about how we use your data
  • Correction: Update inaccurate or incomplete information and modify account details through your dashboard
  • Deletion: Request deletion of your personal information, close your account and have data removed
  • Portability: Receive your data in a machine-readable format (JSON or CSV) and transfer your data to another service provider
  • Objection: Object to processing based on legitimate interests and opt out of marketing communications

7.2 Additional Rights for California Residents (CCPA)

If you are a California resident, you have additional rights:

Right to Know

  • Categories of personal information collected
  • Categories of sources from which information is collected
  • Business purposes for collecting information
  • Categories of third parties with whom information is shared

Right to Delete

Request deletion of personal information, subject to certain exceptions

Right to Opt-Out

We do not sell personal information as defined by CCPA. If our practices change, we will provide a "Do Not Sell My Personal Information" link.

Right to Non-Discrimination

We will not discriminate against you for exercising your CCPA rights. You will not receive different pricing or service quality.

Shine the Light Law

Request information about disclosure of personal information to third parties for direct marketing (we don't do this)

Authorized Agents

You may designate an authorized agent to make requests on your behalf

For California-specific inquiries: [email protected] with subject line "CCPA Request"

7.3 How to Exercise Your Rights

Self-Service Options

  • Update account information in your dashboard settings
  • Download your data from the "Privacy" section
  • Delete your account from account settings

Contact Us

  • Email: [email protected]
  • Subject line: "Privacy Rights Request"
  • Include: Your name, email, account email (if different), and specific request

What to Expect

  • We will respond within 30 days (45 days for complex requests)
  • We may request additional information to verify your identity
  • There is no fee for exercising your rights (unless requests are excessive or unfounded)

7.4 Verification Process

To protect your privacy, we verify your identity before fulfilling requests:

  • For account holders: Log in to your account
  • For non-account holders: Provide information matching our records
  • For deletion requests: Two-factor authentication may be required

7.5 Limitations on Rights

We may deny requests that:

  • Risk the privacy or rights of others
  • Are prohibited by law
  • Would compromise security or fraud detection
  • Involve information we must retain for legal or contractual obligations

If we deny a request, we will explain why and inform you of your right to appeal.

8. Children's Privacy

8.1 Age Restriction

Our Services are not intended for individuals under 18 years of age (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children.

8.2 Parental Notice

If we become aware that we have collected personal information from a child without parental consent, we will:

  • Delete the information immediately
  • Terminate the associated account
  • Notify the parent/guardian if contact information is available

8.3 Reporting

If you believe we have collected information from a child, please contact us immediately at [email protected].

9. Third-Party Links and Services

9.1 External Links

Our Services may contain links to third-party websites, including:

  • Court websites (PACER, state court systems, etc.)
  • Government databases (USA.gov, regulations.gov, etc.)
  • Legal news sources
  • Public websites
  • Integration partners

We are not responsible for:

  • Privacy practices of third-party websites
  • Content or security of external sites
  • Data collection by third parties

We recommend: Review the privacy policies of any third-party sites you visit.

9.2 Third-Party Integrations

If you integrate TrustFoundry with third-party services (e.g., case management systems, Word plugins):

  • The third party's privacy policy governs their data practices
  • We may share data necessary for the integration to function
  • You are responsible for reviewing and accepting third-party terms

9.3 Social Media Plugins

Our website may include social media buttons (LinkedIn, Twitter/X). These buttons:

  • May allow social networks to track your visits
  • Are governed by the social network's privacy policy
  • Can be blocked using browser privacy settings

10. Changes to This Privacy Policy

10.1 Notification of Changes

We may update this Privacy Policy from time to time. When we make changes:

For Minor Changes

  • Updated policy posted at trustfoundry.ai/privacy
  • "Last Updated" date changed at the top
  • Continued use constitutes acceptance

For Material Changes

  • Email notification to registered users at least 30 days in advance
  • Prominent notice on our website
  • In-product notification upon login
  • Option to opt out or delete account before changes take effect

10.2 Material Changes Include:

  • Changes to data usage purposes
  • New categories of data collected
  • Expansion of data sharing practices
  • Reduction of user rights
  • Changes to data retention periods

10.3 Version History

Previous versions of this Privacy Policy are available at trustfoundry.ai/privacy/archive.

10.4 Your Options

If you disagree with changes:

  • You may terminate your account before the effective date
  • We will delete your data per your request
  • Continued use after the effective date constitutes acceptance

11. Contact Us

11.1 Privacy Questions and Requests

Email: [email protected]

Subject Line Options:

  • "General Privacy Question"
  • "Data Access Request"
  • "Data Deletion Request"
  • "CCPA Request"
  • "Security Concern"

Response Time: We respond to all inquiries within 5 business days, with full resolution within 30 days (or 45 days for complex requests).

11.2 Security Issues

Email: [email protected]

For: Reporting security vulnerabilities, data breaches, or suspicious activity

Expected Response: Within 24 hours for critical issues

For questions, concerns, or to exercise your privacy rights, contact us at: [email protected]