Data Protection Policy

Privacy Policy & Zero-Trust Ephemeral Protocol

Compliance Standard: GDPR (EU 2016/679) · CCPA/CPRA · NIST SP 800-88 R1 · Version 3.4.0

1. Zero-Trust Ephemeral Data Lifecycle

AI Law Lab adheres to a strict zero-trust data minimization standard. We believe that legal data is fundamentally confidential. Unlike consumer AI applications, we never monetize, sell, or retain user research prompts or case facts beyond the active analytical window.

Encrypted in Flight & Rest

TLS 1.3 in transit with AES-256 GCM storage encryption.

24h Retention Reaper

Automated cryptographic overwrite after 24 hours.

Zero Model Training

Your case documents are never used to train foundation models.

2. Information We Process

We process two strictly distinct categories of information:

  • Confidential Workspace Data: Case narratives, uploaded evidentiary documents, jurisdiction filters, and legal hypotheses provided by authenticated users. This data is kept strictly private, isolated via SHA-256 tenant keys, and purged by the Retention Reaper after 24 hours.
  • Public Research & Docket Data: Non-confidential research matters expressly submitted under public mode, public court citations, statutory references, and public docket filings displayed on the homepage feed with explicit user consent under Terms of Service Section 4.

3. Automated Overwrite & Purge Protocol (Retention Reaper)

Every database record associated with an analysis session is marked with a created_at timestamp. An autonomous background cron daemon executes an hourly audit, executing hard deletions and pg_trgm / pgvector index vacuums on records exceeding twenty-four (24) hours.

4. Third-Party Infrastructure & Subprocessors

Depending on user administrative configuration, queries may be dispatched to authorized infrastructure subprocessors:

  • Inference Gateways: DeepSeek, Anthropic, OpenAI (Zero Data Retention API contracts).
  • Embedding Service: Local on-device vectorization (default), or OpenAI / Ollama.
  • Dispatch & Postal Gateways: USPS Electronic Verification, FedEx Developer API, UPS, DHL.
  • Communications: Twilio (SMS/Voice), Resend / SMTP (Transactional notices).
  • Billing Gateway: pay.agime.ai (PCI-DSS compliant merchant processing).

5. Your Legal Rights (GDPR & CCPA)

Under applicable data protection laws, you retain the right to request access to your active session records, immediate manual purge of your data prior to the 24-hour cycle, and export of audit logs. Requests may be directed to our Data Protection Officer at privacy@agime.ai.

AI Law Lab 3.4.0 · AGIME Data GovernanceView Terms of Service →