Privacy Policy

ArsLex Associate — Privacy Policy

Last updated August 8, 2026

This page is the canonical published copy of the Privacy Policy for ArsLex Associate. This Privacy Policy supplements, and should be read together with, our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.

The short version

Zero-retention AI. Your work kept until you delete it.

This is a plain-language summary of how ArsLex handles your data; the numbered sections below govern. Two things are true at once, and it is worth stating them separately. No AI provider retains or trains on your content — that has never changed. And we keep your documents and work product until you delete them: auto-deletion is a feature you can switch on, not something that happens on its own.

Introduction

This Privacy Policy describes how ARSLEX LC ("ArsLex," "we," "us," "our"), a Wyoming limited liability company, collects, uses, retains, and protects personal data and other information in connection with ArsLex Associate (the "Service"). This Privacy Policy supplements, and should be read together with, our Terms of Service (the "Terms"), available at arslex.ai/terms. Capitalized terms not defined here have the meanings given in the Terms.

Geographic scope and hosting. The Service is offered primarily to customers in the United States and is hosted in the United States (Amazon Web Services, us-east-1). Where a Customer, or personal data a Customer processes through the Service, is subject to the EU General Data Protection Regulation ("EU GDPR") or the UK GDPR, our Data Processing Addendum (Schedule C to the Master Services Agreement) governs that processing and provides a lawful transfer mechanism for the resulting transfer to the United States — the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. We do not currently tailor the Service to the Swiss FADP or to data-protection laws outside the United States, the EU/EEA, and the United Kingdom. See Section 8 (Your rights, including EU/UK data subjects and international transfers) and Section 13 (Compliance posture).

1. What is ArsLex Associate

ArsLex Associate is a Microsoft Word add-in providing AI-assisted litigation support for legal professionals and legal trainees, including document upload and search, citation extraction and formatting, deposition digestion, complaint analysis, and brief drafting. The add-in runs within Microsoft Word and communicates with our backend (operated on Amazon Web Services) to process documents and generate AI-derived outputs.

The Service is not a lawyer, does not provide legal advice, and does not form an attorney-client relationship with anyone. See the Terms, Sections 7 and 16, for the full responsibility and disclaimer framing.

2. Categories of data we collect

2.1 Account data

When you create an account or are invited to a Customer account, we collect: your name; email address; organization name; role within the organization; preference flags (display settings, citation format defaults); and the timestamp and provenance of your acceptance of the Terms (IP address, user agent, version of the Terms accepted, and your responses to the acceptance attestations).

If you enable multi-factor authentication ("MFA"), we store an encrypted TOTP secret. Passwords are stored only as bcrypt hashes — we never store plaintext passwords.

2.2 Documents and Customer Content

When you upload documents through the add-in (PDFs, depositions, complaints, etc.), we extract text from each document, generate vector embeddings ("chunks") for search and retrieval, and store both the structured records (filename, document type, project association, page count, etc.) and the chunked text in our backend. Embeddings are generated on infrastructure ArsLex operates and controls; the text used to generate them is not sent to any third-party embedding service. Original PDF files are retained so that you can view, search, and re-index them, and are kept until you delete them or until an auto-deletion window you have configured expires (Section 5).

"Customer Content" as used here means the same as in the Terms: anything you upload, paste, generate, store, or transmit through the Service.

2.3 Project and matter structure

We store the client, matter, project, outline, allegation-response, and statement-of-facts records you create within the Service, along with metadata indicating when each record was created or modified and by whom.

2.4 Generated work product

We store the AI-derived outputs you generate within the Service — completed brief sections, deposition digests, complaint parses, search results, citation lists, statements of fact, and so forth — together with the inputs (chunks of Customer Content) that the Service used to produce them. We retain this record so that you can re-open prior work and so that we can comply with the Terms' integrity and audit obligations.

2.5 Billing data

If you have a paid subscription, our payment processor (Stripe) collects and stores cardholder data directly within Stripe's PCI-DSS Level 1 environment. We receive only a Stripe customer ID, a subscription ID, the last four digits of the card on file, and invoice records — we do not see or store raw card numbers, CVCs, or full billing addresses.

2.6 Operational telemetry

We collect basic operational logs from API requests (request path, response code, timestamp, request size, error events) for the purposes of debugging, security monitoring, and abuse prevention. We do not log the body of requests that contain Customer Content in production. We do not track browsing behavior, keystrokes within Word, or the content of your Word documents beyond what you explicitly upload or generate through the Service.

2.7 Local storage on your device

The add-in uses your browser's sessionStorage and in-memory state to cache authentication tokens, user preferences, and UI state. This data remains on your device and is not transmitted to our servers except as needed to authenticate API requests. We do not store long-lived tokens in browser localStorage (per the Office add-in iframe-based session architecture).

3. How we use your data

We use your data solely to operate and improve the Service for you and other Customers:

We do not use Customer Content to train AI models. We do not use Customer Content for any purpose other than to deliver the Service to you and to fulfill the obligations described in this Privacy Policy and the Terms. We do not sell, rent, or share your data with third parties for their own commercial purposes.

4. Third-party subprocessors

The Service is delivered using a small number of third-party providers ("Subprocessors") that process Customer Content or personal data on our behalf. The current list — including the role, data categories, and processing region for each — is maintained at arslex.ai/subprocessors and is also available on written request to legal@arslex.ai.

Summary as of this Privacy Policy's effective date:

Where commercially available under the applicable provider plan, we configure each Subprocessor to use available training-opt-out, enterprise-tier, modified-abuse-monitoring, or zero-retention settings. Our LLM inference runs on Amazon Bedrock, which applies AWS's zero-data-retention and zero-operator-access models: it does not use inputs or outputs to train any models and, by default, does not store them.

Embeddings are not sent to a Subprocessor. The ArsLex Discovery Suite does not generate text embeddings at all. Where other ArsLex products generate embeddings to support search, they are produced by an embedding model that runs on infrastructure ArsLex operates and controls, inside our own cloud account; the text is not transmitted to any third-party embedding API. No Subprocessor on the list above receives Customer Content for the purpose of generating embeddings.

Material additions or substitutions of Subprocessors will be communicated under Section 14 of the Terms. The Subprocessor list at arslex.ai/subprocessors is the authoritative current version.

5. Data custody, retention, and deletion

We keep your Customer Content until you delete it. We do not apply an automatic deletion schedule to your work unless you ask us to. This section describes how long data lives, what you control, and what happens when you delete something.

5.1 How long we keep your data (auto-deletion is optional)

By default, nothing expires. Documents, depositions, brief outlines, generation history, citation usage, and the records of your matters and projects are retained for as long as your account exists, until you delete them.

Auto-deletion is a feature you can turn on. A tenant administrator can set an auto-deletion window in the ArsLex admin console, choosing from 1, 7, 30, 60, 90, 120, 180, or 365 days. When a window is in force, content that has not been worked on within that window is permanently deleted by an automated purge that runs daily and writes an audit row for each deletion; those deletions propagate across the relational database, the vector index, and underlying file storage in the same way as a deletion you perform yourself. A window can be changed or removed at any time, and changing it re-applies to work already in the account.

Windows can be set per matter. An administrator may set an auto-deletion window on an individual matter, which governs everything under that matter and overrides the account-wide setting. A tenant may also configure a separate, shorter window for depositions — which frequently contain unredacted witness testimony subject to protective orders — in which case generation outputs that consumed deposition material inherit that shorter window so derivative content does not outlive its source. Neither refinement is applied by default; both must be configured.

Accounts configured before August 7, 2026. Earlier versions of the Service applied a default retention window to new accounts. Accounts that had a window in force before that date keep it, and content in those accounts continues to auto-delete on that schedule, until an administrator changes the setting. The setting and its current value are shown in the admin console.

5.2 Customer-initiated deletion

You may delete a document, a project, a matter, or your entire account at any time. Deletion is immediate and it is a hard delete: in the same operation, the record is removed from the relational database, the corresponding chunks are removed from the vector index, and the underlying file is deleted from storage. There is no soft-delete state, no archive tier, and no restore-from-trash — once deleted, we cannot return the data to you. A daily sweep serves only as a backstop in the rare event of a transient failure.

Backups. Encrypted backups created before a deletion still contain the deleted data until those backups age out. Deleted data leaves our backups within thirty (30) days. We do not restore individual documents or accounts from backup; backups exist for whole-system disaster recovery only (Section 5.4).

Because deletion is permanent, and because ArsLex is one system among the several a firm relies on, we recommend keeping your own copy of anything you cannot afford to lose. That is a matter of prudent practice, not a limit on our obligation to hold what you have entrusted to us.

5.3 Audit log retention

The audit log of deletion events, litigation-hold events, and other security-relevant actions is retained for as long as needed to support the Service's integrity obligations and is itself subject to a tenant-configurable retention window. Audit retention is independent of the content settings in Section 5.1: shortening a content window does not shorten the audit trail.

5.4 Backups and durability

We take encrypted backups nightly, covering the document store, the vector index, and the managed database. Backups are encrypted at rest using AWS-managed encryption keys, are stored with public access blocked, and are hard-deleted on a thirty (30) day lifecycle. Backup success is monitored and a failed backup raises an operational alert.

Restores are tested. We run restore drills on a recurring schedule and after any change to the storage layer, and we record the outcome of each drill. A backup that has never been restored is not a backup.

Backups support whole-system disaster recovery. We do not offer per-document or per-account restoration, including for content deleted by mistake.

5.5 Subscription-cancellation behavior

If a Customer cancels its subscription, account data and Customer Content remain accessible for the remainder of the paid period. Following cessation of access, Customer Content is handled in accordance with Section 20 of the Terms and any auto-deletion window configured under Section 5.1. Customers seeking export or deletion of their data on cancellation should contact legal@arslex.ai per Section 8.

5.6 Chat conversations (session-only)

Chat conversations with the in-app assistant are never saved. They are held only in volatile server memory so that your signed-in devices can share one live conversation, and they are wiped when your session ends (after a period of inactivity), when you log out, or when you clear the conversation: always within hours. Chat content is never written to a database or to disk, never included in backups, and message text is never recorded in server logs. The material the assistant reads to answer you (your documents, outlines, and drafts) is governed by Sections 5.1 and 5.2, not by this paragraph.

5.7 Litigation holds

A Customer may place a litigation hold on a matter from the admin console, with a reason recorded. While a hold is in force, everything under that matter is preserved: the daily auto-deletion purge skips it, auto-deletion windows cannot be re-applied to it, and deletion of a project, document, or production set within it is refused. The hold is released by the Customer, and releasing it is what allows any configured window to resume. Setting and releasing a hold are both written to the audit log, so preservation can be demonstrated after the fact.

Deciding whether a hold is required is yours, not ours. We provide the mechanism; the duty to preserve — its trigger, its scope, and its release — remains that of the attorney and the Customer. See Section 8 of the Terms.

6. Confidentiality of deposition content in logs

Our production backend logs do not include deposition transcript text, deposition filenames, witness names, or AI-derived excerpts of deposition content. Deposition operations are logged by internal UUID only. This is enforced at the logger / formatter level and tested in our continuous-integration pipeline.

7. Tenant isolation

All Customer Content and account data is isolated per tenant. Users in one Customer's tenant cannot access, search, or view data belonging to another tenant. Within a tenant, data is further scoped by project — documents uploaded to one project are not visible from another project unless the user has been explicitly added to that project. Tenant isolation is enforced at the database, file-storage, and vector-index level and is exercised by automated tests on every deployment.

8. Your rights

You may:

For rights other than self-service deletion, please contact legal@arslex.ai. We will respond to verifiable requests within a reasonable time and in any event no later than thirty (30) days from receipt.

Structured data export ("portability") is on our roadmap. In the interim, we will fulfill verifiable export requests by hand on contact.

EU and UK data subjects. Where the EU GDPR or UK GDPR applies to personal data processed through the Service, data subjects have the rights afforded by those laws — including rights of access, rectification, erasure, restriction of processing, data portability, and objection, and the right to lodge a complaint with a competent supervisory authority. For Customer Content we act as a processor on behalf of the Customer, who is the controller; we will therefore route data-subject requests we receive about Customer Content to the relevant Customer and assist that Customer in responding, as described in our Data Processing Addendum (Schedule C to the Master Services Agreement). Requests may be directed to legal@arslex.ai.

International data transfers. The Service is hosted in the United States. Where personal data subject to the EU GDPR or UK GDPR is processed through the Service, the resulting transfer to the United States is made under a lawful transfer mechanism — the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum — as incorporated by our Data Processing Addendum (Schedule C). A copy of the Data Processing Addendum, including the transfer clauses, is available to Customers on request to legal@arslex.ai.

9. Security

We protect Customer Content and personal data using industry-standard administrative, technical, and physical safeguards, including:

No system is perfectly secure. If a security incident affects your personal data, we will notify you in accordance with applicable law, as described in Section 13 of the Terms.

10. AI-specific considerations

Because the Service uses a third-party large-language-model provider (Amazon Bedrock, operated by AWS) to produce AI-derived outputs, please be aware of the following:

11. Children's privacy

The Service is intended for use by legal professionals and legal trainees and is not directed to children under thirteen (13). The Service may not be used by anyone under the age of eighteen (18) unless expressly authorized by ArsLex in connection with an approved educational or organizational account. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly.

12. ABA Model Rules alignment

The Service is architected with the American Bar Association's Model Rules of Professional Conduct in mind, particularly:

Use of the Service does not, by itself, satisfy any specific ethics obligation. You remain responsible for confirming that your use of the Service complies with the ethics rules and practice-of-law restrictions of your jurisdiction.

13. Compliance posture

14. Cookies and similar technologies

The Service uses only cookies and similar technologies strictly necessary to deliver the Service: session authentication, MFA state, CSRF protection, and similar mechanics. We do not use third-party analytics, advertising, or social-media tracking cookies on the add-in surface. The marketing site at arslex.ai may use basic, first-party server log statistics; it does not use cross-site advertising trackers.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to the address on file for your account, or via a notice within the Service, at least the notice period required by Section 25 of the Terms (Changes to These Terms) before the change takes effect. The "Version" date at the top of this document is the authoritative version reference. Continued use of the Service after a material change takes effect constitutes acceptance of the updated Privacy Policy.

16. Contact

Questions, requests under Section 8, or other matters related to this Privacy Policy:

Email: legal@arslex.ai

Mailing address:
ARSLEX LC
30 N Gould St Ste R
Sheridan, WY 82801
United States

We are a small organization. We will respond to verifiable requests within a reasonable time and in any event no later than thirty (30) days from receipt.