ArsLex Associate — Privacy Policy
This page is the canonical published copy of the Privacy Policy for ArsLex Associate. This Privacy Policy supplements, and should be read together with, our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.
Zero-retention AI. Your work kept until you delete it.
This is a plain-language summary of how ArsLex handles your data; the numbered sections below govern. Two things are true at once, and it is worth stating them separately. No AI provider retains or trains on your content — that has never changed. And we keep your documents and work product until you delete them: auto-deletion is a feature you can switch on, not something that happens on its own.
- Zero-retention AI. Your content is never used to train any model and is not retained by any model provider. Generation runs on Amazon Bedrock under AWS's zero-data-retention and zero-operator-access terms (Section 10).
- Embeddings never leave our infrastructure. Some ArsLex features work by turning text into numeric vectors: search by concept, grouping a production by subject, and selecting which passages of a long document the AI review pass should read. Every one of those vectors is computed on infrastructure ArsLex controls, and no third-party embedding service ever receives your text (Sections 4 and 10).
- Encrypted everywhere. Documents you upload and any AI-generated output are encrypted in transit and at rest (Section 9).
- An encryption key of your firm's own, on request. Beyond the encryption above, a firm can ask to have its documents in our durable object store sealed under a key held in AWS Key Management Service for that firm alone. Destroying that key renders those documents unreadable. A key destruction is never silent and never immediate: every administrator on the account is warned in the app and by email, an explicit confirmation is required, a waiting period runs before anything is destroyed, and the destruction itself requires deliberate action by ArsLex personnel rather than a scheduled job. If no administrator can be reached, the request cannot proceed. This is separate from, and does not change, ordinary deletion (Section 5.2).
- Kept until you delete it. We do not put your work on a clock. If you want one, you can turn on auto-deletion and choose a window from 1 to 365 days (Section 5.1).
- Delete means delete. Delete a document, a project, or your account and its records, search index, and files are removed from live systems immediately — there is no archive to restore from. Deleted data ages out of our encrypted backups within 30 days (Sections 5.2 and 5.4).
- Litigation holds. Your firm can place a hold on a matter. While it is in force, nothing under that matter can be deleted — by a schedule, by a user, or by us — until the firm releases it (Section 5.7).
- Backed up, and the restores are tested. Encrypted nightly backups, with restore drills that are actually run and recorded (Section 5.4).
- We do not read your work. We do not monitor or review client content. Personnel access to production data is restricted to the people who need it and is audited (Section 9).
- Chat is session-only. Conversations with the assistant are never saved: they sync between your signed-in devices through server memory only and are wiped when your session ends, when you log out, or when you clear them (Section 5.6).
- Tenant isolation. Each account's documents and searches are never visible to anyone else (Section 7).
- On-premises on request. The application, your database and your search index can run inside your own environment, so your documents and their extracted text stay on infrastructure you control. AI generation still calls an external model provider under our zero-retention terms (Section 10), so that portion of processing leaves your network. A deployment in which no processing leaves your environment is on our roadmap and is not available today.
Introduction
This Privacy Policy describes how ARSLEX LC ("ArsLex," "we," "us," "our"), a Wyoming limited liability company, collects, uses, retains, and protects personal data and other information in connection with ArsLex Associate (the "Service"). This Privacy Policy supplements, and should be read together with, our Terms of Service (the "Terms"), available at arslex.ai/terms. Capitalized terms not defined here have the meanings given in the Terms.
Geographic scope and hosting. The Service is offered primarily to customers in the United States and is hosted in the United States (Amazon Web Services, us-east-1). Where a Customer, or personal data a Customer processes through the Service, is subject to the EU General Data Protection Regulation ("EU GDPR") or the UK GDPR, our Data Processing Addendum (Schedule C to the Master Services Agreement) governs that processing and provides a lawful transfer mechanism for the resulting transfer to the United States — the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. We do not currently tailor the Service to the Swiss FADP or to data-protection laws outside the United States, the EU/EEA, and the United Kingdom. See Section 8 (Your rights, including EU/UK data subjects and international transfers) and Section 13 (Compliance posture).
1. What is ArsLex Associate
ArsLex Associate is a Microsoft Word add-in providing AI-assisted litigation support for legal professionals and legal trainees, including document upload and search, citation extraction and formatting, deposition digestion, complaint analysis, and brief drafting. The add-in runs within Microsoft Word and communicates with our backend (operated on Amazon Web Services) to process documents and generate AI-derived outputs.
The Service is not a lawyer, does not provide legal advice, and does not form an attorney-client relationship with anyone. See the Terms, Sections 7 and 16, for the full responsibility and disclaimer framing.
2. Categories of data we collect
2.1 Account data
When you create an account or are invited to a Customer account, we collect: your name; email address; organization name; role within the organization; preference flags (display settings, citation format defaults); and the timestamp and provenance of your acceptance of the Terms (IP address, user agent, version of the Terms accepted, and your responses to the acceptance attestations).
If you enable multi-factor authentication ("MFA"), we store an encrypted TOTP secret. Passwords are stored only as bcrypt hashes — we never store plaintext passwords.
2.2 Documents and Customer Content
When you upload documents through the add-in (PDFs, depositions, complaints, etc.), we extract text from each document, generate vector embeddings ("chunks") for search and retrieval, and store both the structured records (filename, document type, project association, page count, etc.) and the chunked text in our backend. Embeddings are generated on infrastructure ArsLex operates and controls; the text used to generate them is not sent to any third-party embedding service. Original PDF files are retained so that you can view, search, and re-index them, and are kept until you delete them or until an auto-deletion window you have configured expires (Section 5).
"Customer Content" as used here means the same as in the Terms: anything you upload, paste, generate, store, or transmit through the Service.
2.3 Project and matter structure
We store the client, matter, project, outline, allegation-response, and statement-of-facts records you create within the Service, along with metadata indicating when each record was created or modified and by whom.
2.4 Generated work product
We store the AI-derived outputs you generate within the Service — completed brief sections, deposition digests, complaint parses, search results, citation lists, statements of fact, and so forth — together with the inputs (chunks of Customer Content) that the Service used to produce them. We retain this record so that you can re-open prior work and so that we can comply with the Terms' integrity and audit obligations.
2.5 Billing data
If you have a paid subscription, our payment processor (Stripe) collects and stores cardholder data directly within Stripe's PCI-DSS Level 1 environment. We receive only a Stripe customer ID, a subscription ID, the last four digits of the card on file, and invoice records — we do not see or store raw card numbers, CVCs, or full billing addresses.
2.6 Operational telemetry
We collect basic operational logs from API requests (request path, response code, timestamp, request size, error events) for the purposes of debugging, security monitoring, and abuse prevention. We do not log the body of requests that contain Customer Content in production. We do not track browsing behavior, keystrokes within Word, or the content of your Word documents beyond what you explicitly upload or generate through the Service.
2.7 Local storage on your device
The add-in uses your browser's sessionStorage and in-memory state to cache authentication tokens, user preferences, and UI state. This data remains on your device and is not transmitted to our servers except as needed to authenticate API requests. We do not store long-lived tokens in browser localStorage (per the Office add-in iframe-based session architecture).
3. How we use your data
We use your data solely to operate and improve the Service for you and other Customers:
- Process documents you upload for text extraction, citation extraction, deposition digestion, and AI-assisted drafting
- Generate vector embeddings to support search across your documents
- Authenticate your identity and enforce access controls (including project and tenant-level scoping)
- Send transactional emails (account verification, password reset, MFA codes, invitations, billing receipts, security notices)
- Monitor service health, debug errors, and detect abuse
- Bill subscriptions and reconcile payments through Stripe
- Maintain records required for compliance with the Terms, including the acceptance attestations and any retention or deletion audit trail
We do not use Customer Content to train AI models. We do not use Customer Content for any purpose other than to deliver the Service to you and to fulfill the obligations described in this Privacy Policy and the Terms. We do not sell, rent, or share your data with third parties for their own commercial purposes.
4. Third-party subprocessors
The Service is delivered using a small number of third-party providers ("Subprocessors") that process Customer Content or personal data on our behalf. The current list — including the role, data categories, and processing region for each — is maintained at arslex.ai/subprocessors and is also available on written request to legal@arslex.ai.
Summary as of this Privacy Policy's effective date:
- Amazon Web Services, Inc. — Backend hosting, managed database, storage, operational logging
- Amazon Web Services, Inc. (Amazon Bedrock) — Large-language-model inference (AI text generation only; embeddings are computed on ArsLex-controlled infrastructure and are not sent to Bedrock or any third party)
- Resend, Inc. — Transactional email delivery
- Stripe, Inc. — Payment processing and subscription billing
- Microsoft Corporation — Inbound and outbound email for our
legal@,admin@, and similar role aliases
Where commercially available under the applicable provider plan, we configure each Subprocessor to use available training-opt-out, enterprise-tier, modified-abuse-monitoring, or zero-retention settings. Our LLM inference runs on Amazon Bedrock, which applies AWS's zero-data-retention and zero-operator-access models: it does not use inputs or outputs to train any models and, by default, does not store them.
Embeddings are not sent to a Subprocessor. The ArsLex Discovery Suite does not generate text embeddings at all. Where other ArsLex products generate embeddings to support search, they are produced by an embedding model that runs on infrastructure ArsLex operates and controls, inside our own cloud account; the text is not transmitted to any third-party embedding API. No Subprocessor on the list above receives Customer Content for the purpose of generating embeddings.
Material additions or substitutions of Subprocessors will be communicated under Section 14 of the Terms. The Subprocessor list at arslex.ai/subprocessors is the authoritative current version.
5. Data custody, retention, and deletion
We keep your Customer Content until you delete it. We do not apply an automatic deletion schedule to your work unless you ask us to. This section describes how long data lives, what you control, and what happens when you delete something.
5.1 How long we keep your data (auto-deletion is optional)
By default, nothing expires. Documents, depositions, brief outlines, generation history, citation usage, and the records of your matters and projects are retained for as long as your account exists, until you delete them.
Auto-deletion is a feature you can turn on. A tenant administrator can set an auto-deletion window in the ArsLex admin console, choosing from 1, 7, 30, 60, 90, 120, 180, or 365 days. When a window is in force, content that has not been worked on within that window is permanently deleted by an automated purge that runs daily and writes an audit row for each deletion; those deletions propagate across the relational database, the vector index, and underlying file storage in the same way as a deletion you perform yourself. A window can be changed or removed at any time, and changing it re-applies to work already in the account.
Windows can be set per matter. An administrator may set an auto-deletion window on an individual matter, which governs everything under that matter and overrides the account-wide setting. A tenant may also configure a separate, shorter window for depositions — which frequently contain unredacted witness testimony subject to protective orders — in which case generation outputs that consumed deposition material inherit that shorter window so derivative content does not outlive its source. Neither refinement is applied by default; both must be configured.
Accounts configured before August 7, 2026. Earlier versions of the Service applied a default retention window to new accounts. Accounts that had a window in force before that date keep it, and content in those accounts continues to auto-delete on that schedule, until an administrator changes the setting. The setting and its current value are shown in the admin console.
5.2 Customer-initiated deletion
You may delete a document, a project, a matter, or your entire account at any time. Deletion is immediate and it is a hard delete: in the same operation, the record is removed from the relational database, the corresponding chunks are removed from the vector index, and the underlying file is deleted from storage. There is no soft-delete state, no archive tier, and no restore-from-trash — once deleted, we cannot return the data to you. A daily sweep serves only as a backstop in the rare event of a transient failure.
Backups. Encrypted backups created before a deletion still contain the deleted data until those backups age out. Deleted data leaves our backups within thirty (30) days. We do not restore individual documents or accounts from backup; backups exist for whole-system disaster recovery only (Section 5.4).
Because deletion is permanent, and because ArsLex is one system among the several a firm relies on, we recommend keeping your own copy of anything you cannot afford to lose. That is a matter of prudent practice, not a limit on our obligation to hold what you have entrusted to us.
5.3 Audit log retention
The audit log of deletion events, litigation-hold events, and other security-relevant actions is retained for as long as needed to support the Service's integrity obligations and is itself subject to a tenant-configurable retention window. Audit retention is independent of the content settings in Section 5.1: shortening a content window does not shorten the audit trail.
5.4 Backups and durability
We take encrypted backups nightly, covering the document store, the vector index, and the managed database. Backups are encrypted at rest using AWS-managed encryption keys, are stored with public access blocked, and are hard-deleted on a thirty (30) day lifecycle. Backup success is monitored and a failed backup raises an operational alert.
Restores are tested. We run restore drills on a recurring schedule and after any change to the storage layer, and we record the outcome of each drill. A backup that has never been restored is not a backup.
Backups support whole-system disaster recovery. We do not offer per-document or per-account restoration, including for content deleted by mistake.
5.5 Subscription-cancellation behavior
If a Customer cancels its subscription, account data and Customer Content remain accessible for the remainder of the paid period. Following cessation of access, Customer Content is handled in accordance with Section 20 of the Terms and any auto-deletion window configured under Section 5.1. Customers seeking export or deletion of their data on cancellation should contact legal@arslex.ai per Section 8.
5.6 Chat conversations (session-only)
Chat conversations with the in-app assistant are never saved. They are held only in volatile server memory so that your signed-in devices can share one live conversation, and they are wiped when your session ends (after a period of inactivity), when you log out, or when you clear the conversation: always within hours. Chat content is never written to a database or to disk, never included in backups, and message text is never recorded in server logs. The material the assistant reads to answer you (your documents, outlines, and drafts) is governed by Sections 5.1 and 5.2, not by this paragraph.
5.7 Litigation holds
A Customer may place a litigation hold on a matter from the admin console, with a reason recorded. While a hold is in force, everything under that matter is preserved: the daily auto-deletion purge skips it, auto-deletion windows cannot be re-applied to it, and deletion of a project, document, or production set within it is refused. The hold is released by the Customer, and releasing it is what allows any configured window to resume. Setting and releasing a hold are both written to the audit log, so preservation can be demonstrated after the fact.
Deciding whether a hold is required is yours, not ours. We provide the mechanism; the duty to preserve — its trigger, its scope, and its release — remains that of the attorney and the Customer. See Section 8 of the Terms.
6. Confidentiality of deposition content in logs
Our production backend logs do not include deposition transcript text, deposition filenames, witness names, or AI-derived excerpts of deposition content. Deposition operations are logged by internal UUID only. This is enforced at the logger / formatter level and tested in our continuous-integration pipeline.
7. Tenant isolation
All Customer Content and account data is isolated per tenant. Users in one Customer's tenant cannot access, search, or view data belonging to another tenant. Within a tenant, data is further scoped by project — documents uploaded to one project are not visible from another project unless the user has been explicitly added to that project. Tenant isolation is enforced at the database, file-storage, and vector-index level and is exercised by automated tests on every deployment.
8. Your rights
You may:
- Access your account data and request a copy of the personal data we hold about you
- Correct inaccuracies in your account data
- Delete your account and all associated Customer Content (self-service via the add-in settings panel; tenant-wide deletion is available through the tenant-admin panel or by contacting legal@arslex.ai)
- Object to specific processing of your data, by contacting legal@arslex.ai
For rights other than self-service deletion, please contact legal@arslex.ai. We will respond to verifiable requests within a reasonable time and in any event no later than thirty (30) days from receipt.
Structured data export ("portability") is on our roadmap. In the interim, we will fulfill verifiable export requests by hand on contact.
EU and UK data subjects. Where the EU GDPR or UK GDPR applies to personal data processed through the Service, data subjects have the rights afforded by those laws — including rights of access, rectification, erasure, restriction of processing, data portability, and objection, and the right to lodge a complaint with a competent supervisory authority. For Customer Content we act as a processor on behalf of the Customer, who is the controller; we will therefore route data-subject requests we receive about Customer Content to the relevant Customer and assist that Customer in responding, as described in our Data Processing Addendum (Schedule C to the Master Services Agreement). Requests may be directed to legal@arslex.ai.
International data transfers. The Service is hosted in the United States. Where personal data subject to the EU GDPR or UK GDPR is processed through the Service, the resulting transfer to the United States is made under a lawful transfer mechanism — the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum — as incorporated by our Data Processing Addendum (Schedule C). A copy of the Data Processing Addendum, including the transfer clauses, is available to Customers on request to legal@arslex.ai.
9. Security
We protect Customer Content and personal data using industry-standard administrative, technical, and physical safeguards, including:
- Encryption in transit — all communication with the Service is over TLS (HTTPS)
- Encryption at rest — application storage, the managed PostgreSQL database, and all snapshots and backups are encrypted using AWS-managed encryption keys (AES-256)
- Password storage — bcrypt hashes only, never plaintext
- MFA secret encryption — TOTP secrets are encrypted at rest using a key derived from our application secret
- Session authentication — short-lived signed bearer tokens with refresh-token rotation; long-lived tokens are not stored in browser
localStoragefor our Office add-in surface - Role-based access control — tenant-admin and member roles, enforced at the API layer
- Rate limiting — API endpoints subject to per-user and per-tenant rate limits to deter abuse and brute-force attacks
- Production monitoring — independent health checks via AWS CloudWatch and Route 53 alarming to a verified SES delivery channel, with mobile push notifications on alert events
No system is perfectly secure. If a security incident affects your personal data, we will notify you in accordance with applicable law, as described in Section 13 of the Terms.
10. AI-specific considerations
Because the Service uses a third-party large-language-model provider (Amazon Bedrock, operated by AWS) to produce AI-derived outputs, please be aware of the following:
- Transit of Customer Content to providers. Portions of every document you upload may be transmitted, in chunks, to our LLM provider's API at the time you query, search, or generate content using the Service. This is the standard pattern for retrieval-augmented generation.
- No training on Customer Content. Our LLM provider does not use API submissions to train its models, and we do not opt in to any setting that would enable such training. See Section 4 of this Privacy Policy and Section 5 of the Terms.
- Provider-side retention. Our LLM provider, Amazon Bedrock, applies AWS's zero-data-retention (ZDR) and zero-operator-access (ZOA) models: by default it does not store the inputs or outputs of inference requests, no AWS operator can access them, and it does not use them to train or improve any models. AWS applies automated abuse detection per its published Bedrock abuse-detection policy.
- AI-output fallibility. AI outputs may be incomplete, inaccurate, outdated, or fabricated. You are responsible for independently reviewing and verifying every AI-derived output before relying on it. See Section 7 of the Terms.
11. Children's privacy
The Service is intended for use by legal professionals and legal trainees and is not directed to children under thirteen (13). The Service may not be used by anyone under the age of eighteen (18) unless expressly authorized by ArsLex in connection with an approved educational or organizational account. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly.
12. ABA Model Rules alignment
The Service is architected with the American Bar Association's Model Rules of Professional Conduct in mind, particularly:
- Rule 1.1 (Competence) and Comment 8 (technology competence) — we provide accurate documentation, recoverable processing pipelines, and visibility into how the Service uses Customer Content
- Rule 1.6 (Confidentiality) — tenant isolation, encryption, retention windows, and an absence of model training are intended to support attorneys' confidentiality obligations
- Rule 5.3 (Responsibilities regarding nonlawyer assistance) — we operate as a software vendor, do not exercise professional judgment, and rely on you to supervise the Service's outputs the same way you would supervise nonlawyer staff
Use of the Service does not, by itself, satisfy any specific ethics obligation. You remain responsible for confirming that your use of the Service complies with the ethics rules and practice-of-law restrictions of your jurisdiction.
13. Compliance posture
- SOC 2 Type I — planned. We are tracking controls aligned to the AICPA Trust Services Criteria as we prepare for an external audit. We will update this Privacy Policy when audit reports become available.
- SOC 2 Type II — planned, following Type I.
- HIPAA — not applicable. The Service is not designed, marketed, or warranted for protected health information ("PHI") under HIPAA. PHI must not be uploaded to the Service.
- GDPR / UK GDPR — where the EU GDPR or UK GDPR applies to personal data processed through the Service, we support it through our Data Processing Addendum (Schedule C to the Master Services Agreement), which acts on the basis that the Customer is the controller and ArsLex is the processor and which incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum as the lawful mechanism for the resulting transfer to the United States. See "Geographic scope and hosting" at the top of this Privacy Policy and Section 8 (EU and UK data subjects; International data transfers).
- Swiss FADP — the Service is not specifically configured for the Swiss Federal Act on Data Protection; please see the "Geographic scope and hosting" statement above. We will nevertheless honor verifiable data-subject access and deletion requests by hand on contact to legal@arslex.ai.
14. Cookies and similar technologies
The Service uses only cookies and similar technologies strictly necessary to deliver the Service: session authentication, MFA state, CSRF protection, and similar mechanics. We do not use third-party analytics, advertising, or social-media tracking cookies on the add-in surface. The marketing site at arslex.ai may use basic, first-party server log statistics; it does not use cross-site advertising trackers.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to the address on file for your account, or via a notice within the Service, at least the notice period required by Section 25 of the Terms (Changes to These Terms) before the change takes effect. The "Version" date at the top of this document is the authoritative version reference. Continued use of the Service after a material change takes effect constitutes acceptance of the updated Privacy Policy.
16. Contact
Questions, requests under Section 8, or other matters related to this Privacy Policy:
Email: legal@arslex.ai
Mailing address:
ARSLEX LC
30 N Gould St Ste R
Sheridan, WY 82801
United States
We are a small organization. We will respond to verifiable requests within a reasonable time and in any event no later than thirty (30) days from receipt.