Legal

Privacy Policy

Effective Date: April 1, 2026 · Last updated: July 5, 2026 · Litigent AI Inc. · litigent.ca

Your Privacy Matters

Family law cases involve some of the most sensitive personal information that exists. We designed our data practices around that reality. Your account data, uploaded documents, and case content are stored at rest on Canadian infrastructure. AI inference and transactional email use US-based service providers under strict data-handling commitments — see Section 4 for specifics. We do not sell your data. We do not share your legal case information with third parties except as required to operate the service. We do not use your case content to train AI models.

1. Who We Are

Litigent AI Inc. ("Company," "we," "us," "our") operates the Litigent platform at litigent.ca. We are the data controller for personal information collected through the Service. For privacy inquiries, contact us at [email protected].

2. Information We Collect

2.1 Information You Provide

  • Account information: name, email address, province of residence, password (hashed);
  • Case information: court file numbers, party names, children's information, dates, and other case-specific data you choose to enter;
  • Uploaded documents: legal documents, evidence, affidavits, correspondence, and other materials you upload to the Service;
  • Communications: messages you send to our AI agents and support team;
  • Payment information: billing details processed through our payment processor (we do not store full card numbers).

2.2 Information Collected Automatically

  • Log data: IP address, browser type, pages visited, timestamps;
  • Device information: operating system, screen resolution;
  • Usage patterns: features used, session duration, interaction events.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Service;
  • Process AI queries using your case information as context;
  • Authenticate your identity and maintain account security;
  • Process payments and manage your subscription;
  • Send transactional communications (account notices, billing);
  • Detect and prevent fraud, abuse, and security incidents;
  • Comply with applicable legal obligations.

We do NOT use your case content, uploaded documents, or legal information to train, fine-tune, or otherwise improve any AI model. The only exception is if you explicitly opt in to contribute examples for quality evaluation — that setting is off by default and you can withdraw it at any time.

4. Data Residency and Storage

Litigent AI Inc. is a corporation incorporated in the State of Delaware, United States, which operates the Service from Canada. All personal information and case data is stored at rest on servers located in Canada, on infrastructure operated by us. What Canadian storage does and does not mean: because Litigent AI Inc. is a US-incorporated company, it may be subject to lawful requests from United States authorities for data in its possession, custody or control, even where that data is physically stored in Canada. Canadian data residency reduces, but does not eliminate, exposure to foreign legal process. We will resist any request not supported by valid legal process, and will notify affected users where we are permitted by law to do so. Apart from the foregoing, we do not transfer your personal information outside of Canada except as follows:

  • AI query processing involves transmission to OpenAI (api.openai.com, US-based). Queries are processed under OpenAI's API data handling commitments, which exclude API content from model training by default. OpenAI may retain API content for up to 30 days for abuse-monitoring purposes; we do not currently have zero-retention enabled. Voice recordings you submit for transcription are transmitted to ElevenLabs (US-based) for speech-to-text processing under its Data Processing Addendum; ElevenLabs does not use this content to train its models. Email delivery (password resets, invite emails) is processed via Resend (US-based) under similar data handling commitments;
  • Payment processing is handled by Stripe, which operates under its own privacy policy and PCI-DSS certification.

5. Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption in transit: All data transmitted to and from the Service is encrypted using TLS 1.2 or higher;
  • Encryption at rest: Uploaded documents, AI conversations, and voice recordings are encrypted at rest with AES-256-GCM, using keys derived separately for each user from a master key held by Litigent;
  • Access controls: Access to production data is restricted to authorized personnel on a need-to-know basis;
  • Authentication: Secure, salted password hashing (bcrypt), with immediate session invalidation on password change;
  • Security audit logging: Authentication, administrative access, and other security-relevant events are written to an append-only audit log, retained for 18 months and reviewed during incident response.

However, no system is 100% secure. We cannot guarantee absolute security of your information. In the event of a data breach that creates a real risk of significant harm to you, we will notify you and applicable regulators as required by the Personal Information Protection and Electronic Documents Act (PIPEDA) and any applicable provincial privacy legislation.

6. Data Retention and No Backup Guarantee

We retain your account information and case data for as long as your account is active. Upon account deletion, we will delete or anonymize your personal information within 90 days, except where retention is required by law.

Retention schedule (per data type):

  • Account profile (name, email, province): while account is active; purged within 90 days of account deletion
  • Case content (drafts, affidavits, conversations, documents): while account is active; purged within 90 days of account deletion (content you have flagged as sensitive is purged first)
  • Documents with holdRetention flag: preserved past account deletion until explicit purge request (e.g. court-order copies)
  • Security audit log: 18 months rolling, sufficient for incident-response investigation
  • Stripe billing records: 7 years (regulatory minimum for Canadian tax compliance)
  • AI conversation history: automatically purged 30 days after your last activity in that conversation, and deleted from Litigent systems immediately on account closure; any copy held by OpenAI for abuse monitoring expires on their own 30-day schedule
  • Marketing event analytics: 13 months rolling (anonymous, no PII)
  • Backup snapshots: overwritten on 30-day rolling basis

Right to deletion: You may delete your account and associated data at any time from Account Settings (PIPEDA principle 4.5/4.9). On deletion, you receive a JSON receipt itemising every collection deleted and the row counts. The deletion request triggers an immediate cascade — there is no “soft delete” staging period.

Important: our backups exist for disaster recovery only and are not a user-facing restore service. We cannot guarantee recovery of any individual file and do not accept individual restore requests. Please keep independent, local copies of all important legal documents, evidence, and case information at all times.

Backups: for up to six months after deletion, residual encrypted copies of deleted data may persist in our disaster-recovery backups until those snapshots rotate out on their normal schedule. Those backups are not reachable by the application, are never used to restore a deleted account, and are overwritten in the ordinary course.

7. Sharing of Information

We do not sell, rent, or trade your personal information. We may share your information only in the following circumstances:

  • Service providers: With trusted third-party vendors who assist in operating the Service, under contractual data protection obligations. Current providers and their data-residency posture:
    • MongoDB — primary database. Hosted at-rest on Canadian infrastructure.
    • Litigent file storage — uploaded documents (AES-256-GCM encrypted at rest). Hosted on Canadian infrastructure.
    • Cloudflare — TLS termination and edge proxy. Because TLS terminates at Cloudflare’s edge, request traffic may transit points of presence outside Canada; data at rest remains in Canada. Per Cloudflare’s published policy, request payloads are not retained.
    • OpenAI (api.openai.com, US-based) — AI inference. Content excluded from model training per OpenAI's API data-handling commitments. Subject to OpenAI's 30-day abuse-monitoring retention.
    • Stripe (US/CA) — payment processing. We never store full card numbers; Stripe is the PCI-compliant data controller for payment instruments.
    • Resend (US-based) — transactional email (password reset, invite codes). Recipients and message body transit Resend; no marketing content sent.
  • Legal requirements: When required by law, court order, or government authority with lawful jurisdiction;
  • Safety: Where necessary to prevent imminent harm to a person or to protect the rights and safety of Litigent AI Inc. or others;
  • Business transfer: In connection with a merger, acquisition, or sale of assets, with notice to affected users.

We will never voluntarily share your case information with opposing parties, their legal counsel, court authorities, government agencies, or any other third party except as strictly required by a valid legal obligation.

8. Your Rights (PIPEDA)

Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation, you have the right to:

  • Access the personal information we hold about you;
  • Request correction of inaccurate information;
  • Withdraw consent to certain uses of your information (which may affect Service availability);
  • Request deletion of your account and associated personal information;
  • Lodge a complaint with the Office of the Privacy Commissioner of Canada.

To exercise these rights, contact us at [email protected]. We will respond within 30 days.

9. Cookies

We use essential cookies required to operate the Service (authentication sessions, security tokens). We do not use advertising cookies or share cookie data with advertising networks. You may disable cookies in your browser settings, but this will impair the functionality of the Service.

10. Children's Privacy

The Service is not directed to children under 18. We do not knowingly collect personal information from minors. Information about children entered into the Service (e.g., children's names, ages, or parenting schedules) is treated as highly sensitive case information subject to all protections described herein.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email to registered users and/or prominent notice on the Service at least 30 days before taking effect.

12. Contact

Privacy Officer · Litigent AI Inc., a Delaware corporation · operating in New Brunswick, Canada
Email: [email protected]