Legal

Privacy Policy

How Of Counsel AI collects, uses, discloses, retains, and protects personal information and customer content.

Last updated September 3, 2026

Introduction and scope

This Privacy Policy describes how Of Counsel AI (“Of Counsel AI,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information when you use a website, application, or other service that links to this Policy (collectively, the “Service”). It applies to information collected through the Service and related support, billing, sales, and product communications.

By using the Service, you acknowledge the practices described in this Policy. Your use of the Service is also governed by our Terms of Service. If you use the Service through an organization, that organization may control the workspace, Customer Content, account access, and privacy requests associated with it. A specific enterprise agreement, data-processing agreement, or other signed agreement controls where it conflicts with this Policy.

Information we collect

Information you provide

  • Identity, account, and workspace information: name, email address, organization, role, workspace membership, authentication identifiers, account preferences, and similar information used to create, recover, and administer an account.
  • Customer Content and uploaded files: contracts, PDFs, word-processing files, images, and other documents; file names and file metadata; extracted text and structured fields; coverage choices; matter or audience context; instructions; writing samples or profiles; templates; drafts; review actions; feedback; and other material submitted to or produced through the Service.
  • Information contained in documents: names, email addresses, telephone numbers, postal addresses, signatures, party and representative details, dates, contract terms, commercial and financial information, employment information, legal-matter information, and any other personal, confidential, or sensitive information included in an upload. Documents may contain information about people other than the person uploading them.
  • AI inputs, outputs, and derived information: prompts, system instructions, retrieved context, document excerpts, classifications, clause and term extraction, summaries, issue spotting, risk assessments, citations, model responses, generated reports, and edits or decisions made during review.
  • Billing and commercial information: customer and purchaser identifiers, subscription or purchase details, plan, invoice, payment status, transaction history, and procurement information. Payment-card details are handled by our payment processor rather than stored by the application.
  • Communications: product questions, support requests, pilot or example requests, survey responses, security inquiries, privacy requests, and other messages you send us.

Information collected automatically

When you access or use the Service, we and our service providers may collect IP address, browser and device information, operating system, referring page, pages and features used, timestamps, cookie or session identifiers, approximate location derived from IP address, diagnostic records, and security events.

We also collect Service and AI usage metadata, which may include the feature used, request status, provider and model identifiers, prompt and completion token counts, cost and billing measurements, latency, timing, retries, errors, safety signals, and related performance information. We may associate this information with an account, workspace, browser session, contract review, or transaction.

Cookies and anonymous sessions

We use cookies and related browser storage for authentication, session continuity, security, preferences, and core Service operation. We may also record limited product and marketing events, such as page views, navigation choices, and feature interactions, to understand Service performance and improve the experience.

For Market Sense, we create a pseudonymous browser session when a contract reaches the secure upload service. This lets the same browser return to an unpaid or incomplete review. We may retain the uploaded contract and associated review records even if checkout is not completed. If checkout is completed, we associate the review with the purchaser email address supplied through our payment processor, create or connect an account, and provide access through a one-time sign-in link.

You can use browser controls to block or remove cookies. Some controls may prevent sign-in, account recovery, saved preferences, or other features from working correctly. Of Counsel AI does not use Customer Content to deliver interest-based advertising.

Information from other sources

We may receive information from an organization that provides your workspace; identity, billing, communications, and security providers; service providers acting on our behalf; and public or official sources used to provide legal-intelligence features. For example, a payment processor may provide the purchaser’s name, email address, transaction identifier, and payment status. If we combine information from another source with information collected through the Service, we handle the combined information under this Policy.

How we use information

  • Provide, authenticate, configure, bill for, and support the Service.
  • Create and recover accounts, maintain anonymous-session continuity, connect purchases to contract reviews, and deliver reports.
  • Receive and store documents, extract text and terms, apply selected legal coverage, retrieve relevant source material, and prepare requested analysis or proposed updates.
  • Generate, route, and evaluate AI requests and responses, including selecting models or providers and using fallbacks when appropriate.
  • Maintain document, source, instruction, model, review, payment, access, and output history needed for a reviewable workflow.
  • Permit specifically authorized product personnel to inspect Market Sense contracts, extracted data, model prompts and responses, and reports for quality assurance, troubleshooting, safety review, research, and product improvement. Those reads are subject to access restrictions and application audit logging.
  • Develop and improve extraction methods, prompts, evaluations, quality controls, product features, and de-identified or aggregated datasets.
  • Respond to questions, support requests, privacy requests, and security or procurement inquiries.
  • Send operational notices, security alerts, billing messages, and other Service-related communications.
  • Measure usage and cost, monitor performance, troubleshoot failures, prevent abuse, and protect users, customers, third parties, and the Service.
  • Comply with law, establish or defend legal claims, and enforce our agreements and policies.

AI processing and model routing

Unless a specific enterprise agreement states otherwise, AI requests from the Service route through OpenRouter. OpenRouter transmits each request to the Model Provider selected by us or through automated routing. The provider that receives a particular request may vary based on model availability, capability, quality, cost, reliability, safety, data-policy settings, and other operational factors. A request may be retried with a different eligible provider or endpoint, so more than one provider may process it. Not every provider receives every request.

Information sent for a request may include all or part of an uploaded document, extracted text and fields, contract language, selected legal authority, approved analysis, matter or audience context, instructions, writing-profile material, prompts, and draft content.

We may retain the exact AI input and output, provider and model identifiers, token counts, cost, timing, errors, and related diagnostic metadata in our own systems. Our retention of those records is separate from any retention by OpenRouter or a Model Provider.

Model Providers and endpoints have different terms and practices concerning retention, review, safety monitoring, model training, and processing location. A provider’s general policy may also differ from the policy for a particular endpoint. We may use available routing or data-policy controls, but we do not represent that every request is subject to zero data retention or that every provider follows identical practices unless a specific enterprise agreement expressly says otherwise.

Processors, subprocessors, and Model Providers

We use service providers to operate the Service. Depending on the service and applicable law, these parties may act as our processors or subprocessors, as a customer’s processors or subprocessors, or as independent controllers for limited activities they determine themselves.

Provider categories include identity and access management; cloud hosting, storage, databases, and content delivery; payment and fraud prevention; email and communications; customer support; security, monitoring, error reporting, and abuse prevention; analytics; document parsing and extraction; and AI routing, inference, evaluation, and model services.

Unless a specific enterprise agreement limits the eligible providers, our AI processing providers include OpenRouter and may include any model developer, Model Provider, inference host, or endpoint made available through OpenRouter. Because that ecosystem changes frequently, the current roster is maintained in OpenRouter’s provider directory. Provider-specific data handling and model terms are described in OpenRouter’s provider data-policy directory and linked provider terms. Those live directories identify the set of AI providers that may be eligible to process a request, including providers added, removed, renamed, or substituted over time.

We may add, remove, or replace other service providers as the Service evolves. We require service providers to process information for authorized purposes and under protections appropriate to their role. A specific enterprise agreement or data-processing agreement may provide additional subprocessor terms, restrictions, or notice rights.

How we disclose information

We may disclose information to the service providers and Model Providers described above to perform their functions. For AI processing, a disclosure can include Customer Content, document text and extracted information, prompts, and other request context needed to generate an output. For other providers, we disclose information reasonably needed for authentication, storage, billing, communications, support, security, analytics, or similar operations.

We may also disclose information at your direction; to workspace administrators acting for their organization; with professional advisers under appropriate duties; to comply with law or legal process; to investigate fraud, misuse, prohibited content, or security incidents; to establish or defend legal claims; to protect rights, safety, and Service integrity; or in connection with a proposed or completed financing, merger, acquisition, reorganization, or sale of assets.

We do not sell Customer Content or personal information for money, and we do not use Customer Content for targeted advertising. We may use or disclose aggregated or de-identified information where it cannot reasonably identify an individual, subject to applicable law and contractual restrictions.

Storage and retention

Our application may store the original uploaded file, file metadata, extracted text and structured terms, prompts and other AI inputs, model outputs, generated reports, review and access history, account and session records, usage and token metadata, billing status, communications, and security or audit records.

Self-service Market Sense uploads and reports do not automatically expire under the default product configuration, including when an anonymous user does not complete checkout. We retain them on an ongoing basis for account and report recovery, review history, quality assurance, safety, research, and product improvement. We may quarantine or delete malicious, unlawful, or harmful content, and we may delete, restrict, de-identify, or preserve information when required by law, a verified privacy request, a provider obligation, or an applicable agreement.

Other information is retained for as long as reasonably needed for the purposes described in this Policy, including to provide and secure the Service, maintain business and audit records, resolve disputes, enforce agreements, and meet legal or contractual obligations. Retention may vary by data type, account status, workspace configuration, source restriction, and customer agreement. Cached, backup, and audit copies may remain for a limited period after active records are deleted.

OpenRouter and Model Providers may separately process or retain request data and metadata under their own terms and endpoint-specific practices. Deleting information from Of Counsel AI does not necessarily delete a copy already processed by another provider where that provider is legally or contractually permitted to retain it.

Security

We use organizational, technical, and access controls intended to protect information against loss, misuse, and unauthorized access, disclosure, alteration, or destruction. Access to Customer Content is limited by role and operational need. We also maintain records intended to support security review, troubleshooting, and accountability.

No transmission or storage system is completely secure. Customers should control workspace membership, use strong authentication, and submit only information appropriate for the configured Service and provider terms. See our Security page for additional context.

Third-party services and links

The Service may link to public authorities, publications, Model Providers, or other services operated by third parties. Those services control their own collection and processing practices. This Policy does not govern information you provide directly to a third party, and a link or citation does not mean that Of Counsel AI controls or endorses that third party.

Your choices and privacy rights

Depending on where you live, you may have rights to know or access personal information; correct inaccurate information; request deletion; obtain a portable copy; restrict or object to processing; withdraw consent; opt out of certain sales, sharing, targeted advertising, or profiling; and appeal a denied request. We do not discriminate against a person for exercising an applicable privacy right.

You may update certain account and workspace information through the Service. We may verify your identity, ask for information needed to process a request, use an authorized-agent process where required, refer an organization-managed request to the customer that controls the workspace, or retain information where law permits or requires.

To submit a request or appeal, email hello@ofcounsel.ai with “Privacy Request” in the subject line. Please do not include privileged, confidential, or client-identifying matter information in the initial message.

Children and international processing

The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided information through the Service, contact us so we can review and address the request.

Of Counsel AI operates in the United States. If you access the Service from another country, information may be transferred to and processed in the United States and other locations where we, OpenRouter, a Model Provider, or another service provider operates. Privacy laws in those locations may differ from those where you live. Where required, we use contractual or other recognized transfer safeguards appropriate to the relationship.

Changes and contact

We may update this Policy as the Service, provider ecosystem, or legal requirements change. We will revise the “Last updated” date and provide additional notice when required by law. The version posted when you use the Service describes the practices then in effect.

Questions, concerns, and privacy requests may be sent to hello@ofcounsel.ai.