Introduction and scope
This Privacy Policy describes how Of Counsel AI (“Of Counsel AI,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information when you use a website, application, or other service that links to this Policy (collectively, the “Service”). It applies to information collected through the Service and related support, billing, sales, and product communications.
By using the Service, you acknowledge the practices described in this Policy. Your use of the Service is also governed by our Terms of Service. If you use the Service through an organization, that organization may control the workspace, Customer Content, account access, and privacy requests associated with it. A specific enterprise agreement, data-processing agreement, or other signed agreement controls where it conflicts with this Policy.
Information we collect
Information you provide
- Identity, account, and workspace information: name, email address, organization, role, workspace membership, authentication identifiers, account preferences, and similar information used to create, recover, and administer an account.
- Customer Content and uploaded files: contracts, PDFs, word-processing files, images, and other documents; file names and file metadata; extracted text and structured fields; coverage choices; matter or audience context; instructions; writing samples or profiles; templates; drafts; review actions; feedback; and other material submitted to or produced through the Service.
- Information contained in documents: names, email addresses, telephone numbers, postal addresses, signatures, party and representative details, dates, contract terms, commercial and financial information, employment information, legal-matter information, and any other personal, confidential, or sensitive information included in an upload. Documents may contain information about people other than the person uploading them.
- AI inputs, outputs, and derived information: prompts, system instructions, retrieved context, document excerpts, classifications, clause and term extraction, summaries, issue spotting, risk assessments, citations, model responses, generated reports, and edits or decisions made during review.
- Billing and commercial information: customer and purchaser identifiers, subscription or purchase details, plan, invoice, payment status, transaction history, and procurement information. Payment-card details are handled by our payment processor rather than stored by the application.
- Communications: product questions, support requests, pilot or example requests, survey responses, security inquiries, privacy requests, and other messages you send us.
Information collected automatically
When you access or use the Service, we and our service providers may collect IP address, browser and device information, operating system, referring page, pages and features used, timestamps, cookie or session identifiers, approximate location derived from IP address, diagnostic records, and security events.
We also collect Service and AI usage metadata, which may include the feature used, request status, provider and model identifiers, prompt and completion token counts, cost and billing measurements, latency, timing, retries, errors, safety signals, and related performance information. We may associate this information with an account, workspace, browser session, contract review, or transaction.
Information from other sources
We may receive information from an organization that provides your workspace; identity, billing, communications, and security providers; service providers acting on our behalf; and public or official sources used to provide legal-intelligence features. For example, a payment processor may provide the purchaser’s name, email address, transaction identifier, and payment status. If we combine information from another source with information collected through the Service, we handle the combined information under this Policy.
How we use information
- Provide, authenticate, configure, bill for, and support the Service.
- Create and recover accounts, maintain anonymous-session continuity, connect purchases to contract reviews, and deliver reports.
- Receive and store documents, extract text and terms, apply selected legal coverage, retrieve relevant source material, and prepare requested analysis or proposed updates.
- Generate, route, and evaluate AI requests and responses, including selecting models or providers and using fallbacks when appropriate.
- Maintain document, source, instruction, model, review, payment, access, and output history needed for a reviewable workflow.
- Permit specifically authorized product personnel to inspect Market Sense contracts, extracted data, model prompts and responses, and reports for quality assurance, troubleshooting, safety review, research, and product improvement. Those reads are subject to access restrictions and application audit logging.
- Develop and improve extraction methods, prompts, evaluations, quality controls, product features, and de-identified or aggregated datasets.
- Respond to questions, support requests, privacy requests, and security or procurement inquiries.
- Send operational notices, security alerts, billing messages, and other Service-related communications.
- Measure usage and cost, monitor performance, troubleshoot failures, prevent abuse, and protect users, customers, third parties, and the Service.
- Comply with law, establish or defend legal claims, and enforce our agreements and policies.
AI processing and model routing
Unless a specific enterprise agreement states otherwise, AI requests from the Service route through OpenRouter. OpenRouter transmits each request to the Model Provider selected by us or through automated routing. The provider that receives a particular request may vary based on model availability, capability, quality, cost, reliability, safety, data-policy settings, and other operational factors. A request may be retried with a different eligible provider or endpoint, so more than one provider may process it. Not every provider receives every request.
Information sent for a request may include all or part of an uploaded document, extracted text and fields, contract language, selected legal authority, approved analysis, matter or audience context, instructions, writing-profile material, prompts, and draft content.
We may retain the exact AI input and output, provider and model identifiers, token counts, cost, timing, errors, and related diagnostic metadata in our own systems. Our retention of those records is separate from any retention by OpenRouter or a Model Provider.
Model Providers and endpoints have different terms and practices concerning retention, review, safety monitoring, model training, and processing location. A provider’s general policy may also differ from the policy for a particular endpoint. We may use available routing or data-policy controls, but we do not represent that every request is subject to zero data retention or that every provider follows identical practices unless a specific enterprise agreement expressly says otherwise.
Processors, subprocessors, and Model Providers
We use service providers to operate the Service. Depending on the service and applicable law, these parties may act as our processors or subprocessors, as a customer’s processors or subprocessors, or as independent controllers for limited activities they determine themselves.
Provider categories include identity and access management; cloud hosting, storage, databases, and content delivery; payment and fraud prevention; email and communications; customer support; security, monitoring, error reporting, and abuse prevention; analytics; document parsing and extraction; and AI routing, inference, evaluation, and model services.
Unless a specific enterprise agreement limits the eligible providers, our AI processing providers include OpenRouter and may include any model developer, Model Provider, inference host, or endpoint made available through OpenRouter. Because that ecosystem changes frequently, the current roster is maintained in OpenRouter’s provider directory. Provider-specific data handling and model terms are described in OpenRouter’s provider data-policy directory and linked provider terms. Those live directories identify the set of AI providers that may be eligible to process a request, including providers added, removed, renamed, or substituted over time.
We may add, remove, or replace other service providers as the Service evolves. We require service providers to process information for authorized purposes and under protections appropriate to their role. A specific enterprise agreement or data-processing agreement may provide additional subprocessor terms, restrictions, or notice rights.
Storage and retention
Our application may store the original uploaded file, file metadata, extracted text and structured terms, prompts and other AI inputs, model outputs, generated reports, review and access history, account and session records, usage and token metadata, billing status, communications, and security or audit records.
Self-service Market Sense uploads and reports do not automatically expire under the default product configuration, including when an anonymous user does not complete checkout. We retain them on an ongoing basis for account and report recovery, review history, quality assurance, safety, research, and product improvement. We may quarantine or delete malicious, unlawful, or harmful content, and we may delete, restrict, de-identify, or preserve information when required by law, a verified privacy request, a provider obligation, or an applicable agreement.
Other information is retained for as long as reasonably needed for the purposes described in this Policy, including to provide and secure the Service, maintain business and audit records, resolve disputes, enforce agreements, and meet legal or contractual obligations. Retention may vary by data type, account status, workspace configuration, source restriction, and customer agreement. Cached, backup, and audit copies may remain for a limited period after active records are deleted.
OpenRouter and Model Providers may separately process or retain request data and metadata under their own terms and endpoint-specific practices. Deleting information from Of Counsel AI does not necessarily delete a copy already processed by another provider where that provider is legally or contractually permitted to retain it.
Security
We use organizational, technical, and access controls intended to protect information against loss, misuse, and unauthorized access, disclosure, alteration, or destruction. Access to Customer Content is limited by role and operational need. We also maintain records intended to support security review, troubleshooting, and accountability.
No transmission or storage system is completely secure. Customers should control workspace membership, use strong authentication, and submit only information appropriate for the configured Service and provider terms. See our Security page for additional context.
Third-party services and links
The Service may link to public authorities, publications, Model Providers, or other services operated by third parties. Those services control their own collection and processing practices. This Policy does not govern information you provide directly to a third party, and a link or citation does not mean that Of Counsel AI controls or endorses that third party.
Legal bases for processing
Where applicable law requires a legal basis, we process personal information as needed to perform a contract or take requested pre-contract steps; for our legitimate interests in operating, securing, supporting, and improving the Service; to comply with legal obligations; and with consent where consent is the appropriate basis. Our legitimate interests do not override rights and interests protected by applicable law.
If a customer submits personal information about another person, the customer is responsible for providing required notices, obtaining required consents, and establishing an appropriate legal basis for the processing it directs.
Your choices and privacy rights
Depending on where you live, you may have rights to know or access personal information; correct inaccurate information; request deletion; obtain a portable copy; restrict or object to processing; withdraw consent; opt out of certain sales, sharing, targeted advertising, or profiling; and appeal a denied request. We do not discriminate against a person for exercising an applicable privacy right.
You may update certain account and workspace information through the Service. We may verify your identity, ask for information needed to process a request, use an authorized-agent process where required, refer an organization-managed request to the customer that controls the workspace, or retain information where law permits or requires.
To submit a request or appeal, email hello@ofcounsel.ai with “Privacy Request” in the subject line. Please do not include privileged, confidential, or client-identifying matter information in the initial message.
Children and international processing
The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided information through the Service, contact us so we can review and address the request.
Of Counsel AI operates in the United States. If you access the Service from another country, information may be transferred to and processed in the United States and other locations where we, OpenRouter, a Model Provider, or another service provider operates. Privacy laws in those locations may differ from those where you live. Where required, we use contractual or other recognized transfer safeguards appropriate to the relationship.
Changes and contact
We may update this Policy as the Service, provider ecosystem, or legal requirements change. We will revise the “Last updated” date and provide additional notice when required by law. The version posted when you use the Service describes the practices then in effect.
Questions, concerns, and privacy requests may be sent to hello@ofcounsel.ai.