Privacy Policy

Last updated: July 1, 2026

1. Information We Collect

We collect the following categories of information to operate the Service:

Account information: Your name, email address, firm name, and password (stored as a hashed credential by Supabase).

Case & client data: Information you enter into the Service on behalf of your practice, including client names, email addresses, phone numbers, case details, notes, status updates, time entries, and calendar events. You control this data entirely.

Uploaded documents: Files you upload to the Service (stored in Cloudflare R2, namespaced per attorney).

Usage data: Information about how you interact with the Service, including page views and feature usage, collected via PostHog analytics.

Error data: Stack traces and diagnostic information collected when errors occur, via Sentry.

Billing data: Subscription and payment information is handled directly by Dodo Payments. Clausli does not store credit card numbers or payment card data.

2. How We Use Your Information

We use the information we collect to:

  • Operate, maintain, and improve the Service.
  • Send transactional emails on your behalf (client status updates, deadline reminders, and notifications you initiate).
  • Authenticate your account and protect against unauthorized access.
  • Monitor for errors and diagnose technical issues.
  • Understand how the Service is used to improve features.
  • Process payments and manage your subscription.
  • Comply with legal obligations.

Legal basis for processing: Where applicable data protection law requires a legal basis, we process account information and Client Data to perform our contract with you (providing the Service), based on our legitimate interest in operating and improving the Service, or to comply with a legal obligation. Where we rely on consent - such as connecting Google Calendar - you may withdraw that consent at any time.

We do not sell your data or your clients' data to third parties. We do not use your client data for advertising or share it with third parties except as described in this Policy.

3. Subprocessors

We use the following third-party service providers to operate the Service. Each is bound by data processing agreements consistent with applicable privacy law:

  • Supabase (Supabase Inc.) - Database storage and user authentication. Your account data and case records are stored here with row-level security ensuring each attorney accesses only their own data.
  • Cloudflare R2 (Cloudflare, Inc.) - File storage for uploaded documents. Files are stored in a private bucket, accessible only via time-limited signed URLs.
  • Resend (Resend Inc.) - Email delivery for client notifications and system emails.
  • Google LLC - Optional two-way calendar synchronization. We access your Google Calendar only if you explicitly connect your Google account. See the Google User Data section below for full details on what we access, how we use it, and how to revoke access.
  • PostHog Inc. - Product analytics. Usage data is pseudonymized and used to understand feature adoption.
  • Sentry (Functional Software, Inc.) - Error monitoring. Stack traces and diagnostic data help us fix bugs.
  • Vercel Inc. - Hosting, infrastructure, and content delivery.
  • Dodo Payments - Subscription billing and payment processing.

4. Google User Data

Clausli integrates with Google Calendar as an optional feature. No Google account data is accessed unless you explicitly connect your Google account from Settings → Integrations.

Scope requested: https://www.googleapis.com/auth/calendar.events - the minimum necessary to create, update, and delete calendar events on your behalf. We do not request access to read your emails, contacts, or any other Google data.

How we use it:

  • Create, update, or delete Google Calendar events that correspond to case deadlines and appointments you manage in Clausli.
  • Display upcoming events from your Google Calendar inside the Clausli dashboard so you have a unified view of your schedule.

What we store: A server-side refresh token that lets Clausli act on your behalf when you are not actively using the app (for example, to update an event when a case deadline changes). This token is stored encrypted in our database, is never exposed to the browser, and is deleted immediately when you disconnect your Google account. We do not cache or persistently store the contents of your Google Calendar events - events are fetched live from Google on each dashboard load.

Sharing and transfer: We do not sell, rent, or share your Google user data with any third party. We do not use your Google data for advertising, user profiling, or to train machine-learning models. No Clausli employee accesses your Google data except (a) with your explicit consent, (b) as necessary for security investigation, (c) as required by applicable law, or (d) in aggregated, anonymized form that cannot identify you.

Revoking access: You can disconnect Google at any time from Settings → Integrations → Disconnect Google Calendar. This immediately deletes the stored refresh token. You can also revoke access directly from your Google account at myaccount.google.com/permissions.

Clausli's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Data Security

We take reasonable technical and organizational measures to protect your data, including:

  • All data is encrypted in transit using TLS.
  • Data at rest is encrypted by our infrastructure providers.
  • Row-level security in our database ensures each attorney can only access their own data. Attorney A cannot access Attorney B's cases, clients, or documents.
  • Files are stored in a private bucket, accessible only via short-lived signed URLs scoped to the owning attorney.
  • Authentication credentials are hashed and salted; Clausli staff cannot read your password.

International data transfers: Our subprocessors operate infrastructure in multiple countries, which means your data may be processed outside the country where you or your clients are located. Where this occurs, we rely on our subprocessors' own compliance safeguards (such as standard contractual clauses, where applicable) to protect the data in transit and at rest.

No security system is perfect. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.

6. Data Retention & Deletion

We retain your account data and Client Data for as long as your account is active. If you delete your account, we delete all associated data - including uploaded documents - from our systems within 30 days.

Account deletion removes: your attorney profile, all cases and case history, all client records, uploaded documents (from both the database and file storage), email history, calendar events, time entries, and Google Calendar tokens.

We may retain anonymized, aggregated usage statistics that cannot identify you. We may also retain records required by law or for legitimate legal or compliance purposes.

7. Your Rights & Data Export

You have the following rights with respect to your data:

  • Access & portability: Export all your data at any time from Settings → Account → Export your data. You will receive a ZIP file containing your cases, clients, time entries, and email history in CSV format.
  • Correction: You can edit your profile and case data directly in the Service at any time.
  • Deletion: You can delete your account from Settings → Account → Danger zone. This permanently removes all your data.

If you are located in the European Economic Area, United Kingdom, or California, you may have additional rights under applicable privacy law. To exercise any such rights, contact us at support@clausli.com.

8. Cookies & Analytics

Clausli uses cookies and similar technologies for the following purposes:

  • Authentication: A session cookie maintains your logged-in state. This cookie is essential for the Service to function and cannot be disabled.
  • Analytics: PostHog sets a cookie to track usage across sessions. This data is pseudonymized and used to improve the product. It is not shared with advertisers.

We do not use advertising cookies, cross-site tracking, or third-party targeting technologies.

9. Children's Privacy

The Service is not directed to individuals under the age of 18 and is designed for use by legal professionals. We do not knowingly collect personal information from minors. If we learn that we have collected information from a person under 18, we will delete that information promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email at least 14 days before the changes take effect and update the “Last updated” date at the top of this page.

Your continued use of the Service after the effective date of any revised Policy constitutes acceptance of that Policy.

11. Contact

For questions or concerns about this Privacy Policy or our data practices, please contact us at support@clausli.com.