BP Portal

Interim Privacy Notice (pending counsel review)

Privacy Notice

Version 2026-08-25-interim-1

Interim notice. This text has not been reviewed by counsel. It describes how the system actually handles information today, so that firms evaluating it have an accurate answer rather than no answer.

1. Who this notice is about

Two groups. The people who use this software — attorneys and staff at the firms that have accounts — and the people who appear in the case files those users upload, who are not users and have no account here.

There is no public sign-up. Accounts are created for firms directly.

2. What is collected about users

Email address, the firm the account belongs to, and the answers given in the onboarding questionnaire. Every sign-in, terms acceptance, document generation, and document download is recorded with a timestamp and the originating IP address.

3. What is collected about people in case files

Whatever the uploaded documents contain. In practice this includes names, dates of birth, addresses, injuries, medical treatment and findings, and in some source documents Social Security numbers.

None of it is collected from those people directly. It arrives because a firm uploaded a case file, and it is used only to produce that firm's draft document.

4. Who it is shared with

The service providers listed below, each only for the function named. Case content is not sold, is not used to train any model, and is not shared with any other firm — every query the application makes is scoped to the firm that owns the case.

5. How long it is kept

Uploaded case files, generated documents, and the activity log are retained and are not automatically deleted. There is no scheduled deletion today. A firm that wants its files removed can ask, and they will be deleted.

The activity log is append-only by design: it cannot be edited, and it is not deleted along with the documents it describes, because a record of how a document was handled is only worth keeping if it outlives the document.

6. Security

Access is by emailed sign-in link; there are no passwords to leak. Every firm's data is separated at the database level, so one firm's account cannot read another's cases even in the event of an application bug.

7. Contact

Questions about this notice, or a request to delete a firm's files, go to the operator of this software through your firm's usual contact.

Service providers

  • Supabase

    Database, authentication, and file storage. Uploaded case files and generated documents are stored here.

  • Vercel

    Hosting for the web application. Handles requests; does not store case files.

  • Modal

    The compute environment that reads uploaded documents and assembles the generated draft.

  • Anthropic

    The language model that produces the draft text. Extracted case content is sent to it for that purpose.

  • Resend

    Email delivery for sign-in links and system alerts. Receives email addresses, not case content.

Terms of Use · Privacy Notice