PRIVACY POLICY

Last Updated: February 5, 2025

This Privacy Policy describes how Ourfirm.ai, Inc. ("OurFirm.ai," "we," "our," or "us") collects, uses, and protects your information when you use our artificial intelligence-powered legal practice management platform and related services (collectively, the "Services"). Please read this Privacy Policy carefully to understand our practices regarding your information.


1. SCOPE AND APPLICATION

This Privacy Policy applies to all users of the Services. By using the Services, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein. The Services are available only to attorneys licensed to practice law in New York State and Federal courts.


2. INFORMATION WE COLLECT

2.1 Account Information

When you register for the Services, we collect information necessary to verify your identity and establish your account, including your name, contact information, bar registration number, and professional credentials.

2.2 Payment Information

When you subscribe to the Services, our payment processor, Stripe, collects and processes your payment information. We do not store complete payment information on our servers.

2.3 Service Usage Information

We collect information about how you use and interact with the Services, including access times, features used, and other analytics data that help us improve the Services.

2.4 Legal Documents and Content

We process legal documents and information that you upload or create through the Services, including but not limited to drafts, discovery requests, and other legal materials ("User Content").

2.5 SMS Verification and Messaging Data

When you opt in to receive SMS messages for multi-factor authentication or account alerts, we collect your mobile phone number and record your consent. This information is used solely to send you one-time passcodes and important security notifications. We do not share your phone number or SMS consent data with any third parties.


3. USE OF INFORMATION

3.1 Service Provision. We use your information to:

  • Provide, maintain, and improve the Services;
  • Process your documents and generate legal content;
  • Manage your account and subscription;
  • Respond to your inquiries and provide customer support;
  • Ensure the security and integrity of the Services.

3.2 Data Processing and Retention. All data processing occurs in real-time through our secure systems. We employ end-to-end encryption for all data transmission and storage. Following processing, uploaded documents are permanently deleted from our systems. We do not retain, use, or access your data for artificial intelligence training or any purposes beyond providing the Services.


4. INFORMATION SHARING AND DISCLOSURE

4.1 Third-Party Service Providers. We engage the following third-party service providers to assist in providing the Services:

  • Amazon Web Services for secure cloud storage;
  • OpenAI, Anthropic, and Cerebras for artificial intelligence processing;
  • Stripe for payment processing.

These service providers receive only the information necessary to perform their specific functions and are contractually bound to protect the confidentiality and security of your information.

4.2 Legal Requirements. We may disclose your information if required to do so by law or in response to valid requests from public authorities (e.g., a court or government agency).

4.3 Business Transfers. If we are involved in a merger, acquisition, or sale of all or part of our assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your information.


5. DATA SECURITY

5.1 Security Measures

We implement and maintain appropriate technical, physical, and organizational security measures designed to protect your information against unauthorized access, disclosure, alteration, or destruction. These measures include:

  • End-to-end encryption for all data transmission and storage;
  • Secure cloud storage through AWS;
  • Regular security audits and monitoring;
  • Strict access controls and authentication requirements.

5.2 Security Standards

We are actively pursuing SOC 2 certification to demonstrate our commitment to maintaining the highest standards of security and privacy.

5.3 Data Incidents

In the event of a security breach that affects your information, we will notify you in accordance with applicable law and provide information about steps you can take to protect yourself.


6. USER RIGHTS AND CHOICES

6.1 Account Information

You may review and update your account information at any time through your account settings or by contacting us.

6.2 Data Access and Control

You maintain control over your User Content and may access, modify, or delete it through the Services.

6.3 Account Termination

You may terminate your account at any time. Upon termination, we will securely delete all associated data in accordance with our data retention policies.


7. DATA RETENTION

7.1 Processing Data

We delete uploaded documents immediately after processing. Processed documents remain securely stored only for as long as necessary to provide the Services or as required by law.

7.2 Account Data

We retain basic account information for as long as your account remains active or as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.


8. CHANGES TO THIS PRIVACY POLICY

We reserve the right to update this Privacy Policy from time to time. We will notify you of material changes through the Services or by email. Your continued use of the Services after such notification constitutes acceptance of the updated Privacy Policy.


9. CONTACT INFORMATION

If you have questions or concerns about this Privacy Policy or our privacy practices, please contact us at:

Ourfirm.ai, Inc.
Email: access@ourfirm.ai


10. JURISDICTION AND APPLICABLE LAW

This Privacy Policy is governed by the laws of the State of New York. Any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of the state and federal courts located in New York, New York.


11. SEVERABILITY

If any provision of this Privacy Policy is found to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary so that this Privacy Policy shall otherwise remain in full force and effect and enforceable.


By using the Services, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.