Privacy Policy

Last Updated: November 8, 2025

1. Introduction

LegalOS ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the Service.

We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy.

2. Information We Collect

2.1 Information You Provide to Us

We collect information that you voluntarily provide when using our Service, including:

  • Account registration information (name, email address, firm name, password)
  • Profile information (professional credentials, contact details)
  • Client and matter information entered into the system
  • Documents uploaded or created using our Service
  • Payment and billing information
  • Communications with us (support requests, feedback)
  • Information provided through intake forms and client portals

2.2 Automatically Collected Information

When you access the Service, we automatically collect certain information, including:

  • Log data (IP address, browser type, operating system, pages viewed)
  • Device information (device type, unique device identifiers)
  • Usage data (features used, time spent, interaction patterns)
  • Cookies and similar tracking technologies
  • Location data (general geographic location based on IP address)

2.3 Information from Third Parties

We may receive information about you from third-party services you connect to our Service, such as payment processors, e-signature providers, or authentication services.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain our Service
  • Process your transactions and manage your subscription
  • Create and manage your account
  • Send you administrative information, updates, and security alerts
  • Respond to your inquiries and provide customer support
  • Improve and personalize your experience with the Service
  • Develop new features and functionality
  • Monitor and analyze usage patterns and trends
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations and enforce our Terms of Service
  • Send you marketing communications (with your consent)
  • Train and improve our AI models (using anonymized data only)

4. How We Share Your Information

We do not sell, rent, or lease your personal information to third parties. We may share your information in the following circumstances:

4.1 Service Providers

We share information with third-party service providers who perform services on our behalf, such as payment processing, data hosting, email delivery, customer support, and analytics. These service providers are contractually obligated to protect your information and use it only for the purposes we specify.

4.2 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (such as a court order or subpoena).

4.3 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

4.4 With Your Consent

We may share your information with third parties when you give us explicit consent to do so.

5. Data Security

We implement appropriate technical and organizational security measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit using SSL/TLS protocols
  • Encryption of sensitive data at rest
  • Regular security assessments and penetration testing
  • Access controls and authentication mechanisms
  • Employee training on data security and privacy
  • Regular backups and disaster recovery procedures

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Data Retention

We retain your information for as long as your account is active or as needed to provide you with the Service. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

When you terminate your account, we will delete or anonymize your personal information within a reasonable timeframe, unless we are required to retain it for legal or regulatory purposes. You may request deletion of your data at any time by contacting us.

7. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

7.1 Access and Portability

You have the right to request access to the personal information we hold about you and to receive a copy of that information in a portable format.

7.2 Correction

You have the right to request correction of inaccurate or incomplete personal information. You can update most information directly through your account settings.

7.3 Deletion

You have the right to request deletion of your personal information, subject to certain exceptions (such as when we need to retain information for legal compliance).

7.4 Objection and Restriction

You have the right to object to or restrict certain processing of your personal information, such as for marketing purposes.

7.5 Withdraw Consent

Where we rely on consent to process your personal information, you have the right to withdraw that consent at any time.

To exercise any of these rights, please contact us at privacy@legalos.com. We will respond to your request within 30 days.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect information about your browsing activities and to enhance your experience with our Service.

8.1 Types of Cookies We Use

  • Essential Cookies: Required for the Service to function properly (authentication, security)
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Help us understand how you use the Service
  • Marketing Cookies: Track your visits across websites for advertising purposes (only with consent)

8.2 Managing Cookies

Most web browsers allow you to control cookies through their settings. However, if you disable cookies, some features of the Service may not function properly.

9. Third-Party Services

Our Service may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through our Service.

Third-party services we may integrate with include:

  • Payment processors (LegalOSPay)
  • E-signature providers (SignatureAPI)
  • Cloud storage providers
  • Analytics services
  • Email service providers

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country.

When we transfer your information internationally, we implement appropriate safeguards to protect your information in accordance with this Privacy Policy and applicable law.

11. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us, and we will delete that information.

12. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information we collect, use, and disclose
  • Right to request deletion of your personal information
  • Right to opt-out of the sale of your personal information (we do not sell personal information)
  • Right to non-discrimination for exercising your privacy rights

13. GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR), including:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to lodge a complaint with a supervisory authority

We process your personal data on the following legal bases: consent, contract performance, legal obligation, and legitimate interests.

14. AI and Data Processing

Our Service includes AI-powered features for document generation and legal research. When you use these features:

  • Your inputs may be processed by AI models to generate outputs
  • We may use anonymized and aggregated data to improve our AI models
  • We do not share your specific client data with third-party AI providers
  • AI-generated content should always be reviewed by a qualified professional

You maintain ownership of all content you create using our AI features.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We may also notify you via email or through the Service. Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.

16. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

Email: privacy@legalos.com
Support Email: support@legalos.com
Address: [Your Company Address]

For GDPR-related inquiries, you may contact our Data Protection Officer at dpo@legalos.com.

By using LegalOS, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein.