Client Data Privacy Framework

Privacy Policy

How Disclosure Assistant collects, handles, and protects confidential legal financial records, bank statements, and account information.

Last updated: September 17, 2026

1. Information We Collect

We collect only the information strictly necessary to authenticate your account and execute automated bank statement extraction and financial disclosure analysis:

Account Credentials

Name, business email address, and encrypted password hash managed through Supabase Auth. We do not store plaintext passwords.

Financial Case Discovery Documents

Digital bank statement PDFs uploaded by your firm, extracted transaction line items (dates, payees, amounts, balances), attorney notes, and rule threshold parameters.

Billing & Payment Information

Billing contact name, email, billing address, and subscription status. Payment card details are processed directly by our Merchant of Record (Paddle / Creem) under PCI-DSS Level 1 compliance; raw card numbers never touch our servers.

Device & Usage Telemetry

IP address, browser type, operating system, and anonymous interaction metrics tracked via PostHog to detect UI errors and optimize performance. Document text contents are never transmitted in analytics telemetry.

Practice Management Integration Data (Optional)

If you choose to link Clio Manage, we store OAuth access tokens and retrieve matter identifiers to enable direct document and report export into your client folders.

2. How We Use Information

We process collected data exclusively for defined, legitimate business purposes:

  • Document Ingestion & Text Reconstruction: Parsing text coordinates from statement PDFs and reconstructing tabular structures (with automated OCR fallback via OkraPDF strictly for scanned paper files lacking a digital text layer).
  • Deterministic Rule Matching: Analyzing transactions against attorney-defined rules (e.g., cash withdrawals over $500, recurring round-dollar transfers, rapid in/out sequences, and keyword flags).
  • Report & Ledger Generation: Formatting case transactions into disclosure-ready PDF summaries and structured CSV/Clio spreadsheets for discovery exchanges.
  • Account Security & Session Management: Authenticating account access and enforcing our 15-minute inactivity security lock to prevent unauthorized viewing of sensitive discovery data on unattended workstations.
  • Transactional Communications: Sending password reset links, billing confirmations, and critical security notices via Resend.
  • Abuse Prevention: Ensuring service integrity, preventing unauthorized payment activity, and mitigating denial-of-service risks.

3. Who We Share Data With

We do not sell, rent, lease, or monetize customer data or confidential client financial records under any circumstances.

Data is shared solely with technical subprocessors required to operate our cloud infrastructure (including hosting on Vercel, database storage on Supabase/AWS, AI-assisted table parsing via OpenAI, scanned statement OCR fallback via OkraPDF, payment processing via Paddle/Creem, and email delivery via Resend).

For a complete, transparent list of every vendor, their physical hosting region, and the data they access, review our live Subprocessors Table on our Security & Compliance page.

Legal Compulsion: We will only disclose customer records if compelled by a valid subpoena, court order, or binding legal warrant. We will notify the account holder prior to disclosure unless legally prohibited by statute or court order.

4. Data Retention Policy

  • Customer-Governed Retention: Your uploaded statement PDFs, parsed transaction rows, and case settings remain accessible in your account for as long as you maintain the case active.
  • Immediate Self-Serve Deletion: You can delete any individual statement, specific case matter, or your entire account with one click in the application. Case deletions trigger an immediate cascading database purge.
  • Ephemeral AI Processing: Text lines sent to the OpenAI API for table reconstruction are processed in volatile memory and discarded immediately; OpenAI does not retain commercial API payloads for model training.
  • Backup Purge Cycles: Point-in-time disaster recovery snapshots are rotated and permanently expunged within 30 days of creation.

5. Your Privacy Rights (GDPR & CCPA/CPRA)

Regardless of your geographic location, Disclosure Assistant provides comprehensive privacy controls conforming to GDPR and California Consumer Privacy Act standards:

Right to Access & PortabilityExport your full transaction ledgers, review notes, and cases anytime in standardized CSV or JSON formats directly from the dashboard.
Right to Erasure ("Right to be Forgotten")Permanently delete any case or completely purge your account and all associated records from our production databases.
Right to RectificationDirectly edit transaction descriptions, amounts, and categories within the ledger if statement lines require attorney adjustment.
Right to Opt-Out of SaleWe do not sell personal or financial data. Opt-out of sale is active by default for all accounts.

6. Cookies & Tracking Technologies

Disclosure Assistant uses minimal cookies strictly to operate and secure the platform:

  • Essential Authentication Cookies: Secure, HTTP-only JWT session cookies managed by Supabase to maintain encrypted login sessions.
  • Session Inactivity Storage: A local storage key (da_last_activity_timestamp) used strictly by our client-side timer to trigger the 15-minute auto-logout window for confidential data protection.
  • Product Analytics: First-party PostHog analytics cookies to record anonymous navigation flow and platform health. We do not use third-party advertising cookies, retargeting pixels, or data brokers.

7. International Data Transfers

Disclosure Assistant operates primary serverless compute and encrypted databases in the United States (AWS us-east-1).

For law firms operating in the European Economic Area (EEA), United Kingdom, Canada, or Australia, cross-border transfers of account and case data to our US infrastructure are governed by Standard Contractual Clauses (SCCs) and GDPR Article 46 transfer safeguards integrated into our vendor agreements.

8. How to Exercise Your Rights

You can execute all privacy rights using direct self-service tools:

  1. To Export Data: Go to your Account Settings in the dashboard and click "Export All Data" (generates instant CSV or JSON packages).
  2. To Delete Your Account: Go to Account Settings, enter your password, and confirm "Delete Account". All cases, transactions, and credentials will be permanently erased immediately.
  3. To Disconnect Integrations: Visit Clio settings to revoke OAuth tokens with one click.
  4. For Formal Compliance Inquiries: Email our security and compliance team at security@disclosureassistant.com. All requests are acknowledged within 48 hours and fulfilled within 30 days free of charge.

9. Privacy & Compliance Contact

For inquiries regarding this Privacy Policy, compliance, or our data protection practices, contact:

Security & Compliance Inquiries: security@disclosureassistant.com

General Support: support@disclosureassistant.com