Privacy Policy

Last updated: May 14, 2026

1. Introduction

GridlyPaper ("we," "our," or "us") is committed to protecting the privacy and confidentiality of legal professionals who use our AI-powered legal research platform. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you access and use our Services.

Important Notice for Legal Professionals: Unlike consumer applications, GridlyPaper is designed specifically for attorneys and legal professionals. We understand that you may input sensitive client information, case strategies, and privileged legal research. We have implemented enhanced security measures specifically designed to protect attorney-client communications and legal work product.

2. Information We Collect

2.1 Personal Information

  • Full name and email address (account credentials)
  • Firm or organization name
  • Billing information (processed through secure payment processors)
  • Professional license information (if required for verification)

2.2 User Content

  • Research queries and search parameters
  • Research session history
  • Saved cases and legal citations
  • Generated memos and documents
  • Case notes and annotations

Attorney-Client Privilege Notice: We do not access, review, or store the substantive content of your legal research unless necessary to provide the Service. Your research queries and generated documents remain your intellectual property.

2.3 Automatically Collected Information

  • Device and browser information
  • IP address and usage analytics
  • Session duration and feature usage patterns
  • Cookies necessary for authentication

3. How We Use Your Information

We use your information for the following purposes:

  • Service Delivery: To provide AI-powered legal research, citation validation, and document generation services
  • Account Management: To create and maintain your account, process subscriptions, and track usage limits
  • Improvement: To analyze usage patterns and improve our AI models and user experience
  • Security: To detect and prevent unauthorized access, fraud, or misuse of our Services
  • Communications: To respond to your inquiries and provide customer support
  • Legal Compliance: To comply with applicable laws, regulations, and legal obligations

We NEVER: Sell your personal information to third parties, use your legal research for AI model training, or share your client information with advertisers.

4. AI Processing & Data Handling

4.1 AI Service Providers

We utilize Google Gemini AI and other authorized AI service providers to process your research queries. These providers operate under strict data processing agreements that prohibit them from using your input data for model training or retaining your queries beyond the processing duration.

4.2 Zero-Retention Commitment

Our AI service providers have confirmed zero-retention policies for API-processed data. Your legal queries are processed in real-time and are not stored, logged, or used to improve their general models. This ensures your legal research remains confidential.

4.3 Work Product Ownership

All research results, generated memos, and documents created through our Services remain your intellectual property. We claim no rights to your legal work product. You may use, share, and distribute your research outputs without restriction.

5. Data Security & Protection

We implement industry-leading security measures including:

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.3
  • Encryption at Rest: Sensitive data stored in our databases is encrypted using AES-256
  • Authentication: Multi-factor authentication available; bcrypt password hashing
  • Access Controls: Role-based access restrictions with audit logging
  • Network Security: DDoS protection, Web Application Firewall (WAF), and intrusion detection
  • Regular Audits: Quarterly security assessments and penetration testing

Attorney-Client Privilege Protections

Recognizing the sensitivity of legal work product, we have implemented additional protections: research queries are processed in isolated environments, we maintain detailed access logs, and our employees are bound by confidentiality agreements with termination provisions.

6. Data Retention & Deletion

6.1 Retention Periods

  • Account Data: Retained while your account is active and for 30 days after deletion
  • Research History: Retained until you delete it or your account is closed
  • Payment Data: Processed through payment processors; we retain only transaction records
  • Log Data: Retained for 12 months for security and debugging purposes

6.2 Your Data Rights

  • Access: Request a copy of all personal data we hold about you
  • Rectification: Correct inaccurate or incomplete data
  • Deletion: Request deletion of your account and all associated data
  • Portability: Export your data in machine-readable format
  • Objection: Object to processing for legitimate interests

To exercise these rights, submit a request through our support page. We will respond within 30 days as required by applicable law.

7. Third-Party Disclosure

We share data only with:

  • Supabase: Database and authentication services (data stored in US data centers)
  • Google Gemini: AI processing (under zero-retention terms)
  • GridlyPaper: Public legal case data retrieval
  • Payment Processors: Secure billing (we do not store payment details)
  • Legal Obligations: When required by law, court order, or government regulation

We do NOT share your data with: Advertising networks, data brokers, social media platforms, or any party for marketing purposes.

8. Cookies & Tracking

8.1 Essential Cookies

We use essential cookies for: authentication, session management, security, and remembering your preferences. These cookies are necessary for the Service to function and cannot be disabled.

8.2 No Tracking Cookies

We do NOT use: advertising cookies, tracking cookies, cross-site tracking, or any form of behavioral advertising. We do not employ third-party analytics that share data with advertisers.

9. International Data Transfers

Your data is primarily stored and processed in the United States. If you access our Services from outside the US, your data may be transferred to and processed in the US. We ensure adequate protection through:

  • Standard Contractual Clauses approved by the European Commission
  • Data Processing Agreements with all service providers
  • Compliance with GDPR, CCPA, and other applicable privacy laws

10. Children's Privacy

Our Services are designed for and targeted to legal professionals and law firms. We do not knowingly collect information from individuals under 18 years of age. If you become aware that a minor has provided us with personal information, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after such changes constitutes acceptance of the new Privacy Policy.

12. Contact Information

For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through our support page.

For data protection inquiries: Data Protection Officer