exhibit.law
Privacy Policy
Last updated 2026-08-06
This policy describes what exhibit.law collects, how case evidence is handled, and who can see it. It applies to the hosted service at exhibit.law. It is written for practitioners evaluating whether to put privileged material on the platform — not as marketing fluff.
exhibit.law is operated as a hosted legal-evidence service. For the current operator contact, use the contact form at https://exhibit.law/contact. A formal legal-entity name and mailing address will be published here when finalized.
What this covers
We process (1) account and access data needed to run the service, and (2) case content you or your invitees upload. Case content is treated as confidential customer data. Free accounts may self-register with email verification; access to each case remains invite-only via a CaseAdmin grant.
This policy does not cover third-party sites you link out to, or files after an authorized user downloads or exports them (for example a vault export).
We do not sell your data
We do not sell personal information, account data, or case content. We do not sell, rent, or trade user lists for advertising or marketing, and we do not sell evidence, transcripts, or derived case artifacts to data brokers or other third parties.
We share data only as needed to operate the service (for example infrastructure hosts, transactional email, optional Google sign-in, and the AI processing described in the AI Disclosure), under those subprocessors’ terms and our instructions — not as a sale of your data.
Account and access data
For accounts we may store email address, display name, authentication material (password hash and/or Google account linkage), role and case grants, notification preferences, records of acceptance of these Terms / Privacy / AI Disclosure at signup, and basic session/security logs (for example sign-in attempts and rate-limit counters).
Self-serve signup creates an organization on the Free plan. Invitations attach additional people to a specific case.
Case content (evidence)
Case content includes uploaded files (documents, photos, audio, video, chat screenshots, zip discovery packages), derived artifacts (transcripts, metadata extracts, AI draft event text, file-analysis notes), and user-authored timeline fields (titles, descriptions, tags, people links, review status).
Access is granted per case. Users only see cases they have been invited to. Media rows and join tables are case-scoped in the database so content from one matter is not shared into another matter’s library.
AI and automated processing
Uploaded media may be processed automatically to extract text, transcribe audio/video, identify speakers, run OCR/vision on documents or images, draft suggested timeline events, and expand zip archives. AI-suggested text and dates remain marked for human review and are not treated as confirmed facts until a person approves them.
By default, and under normal load, transcription, vision/OCR, drafting, and related file analysis run on operator-controlled closed models (self-hosted speech and multimodal models on private infrastructure). During periods of peak demand, certain of those features may instead be processed using third-party frontier AI model APIs (currently OpenAI’s API tier) so turnaround times remain reasonable. Only the content needed for the requested function is sent; we do not use your case content to train public foundation models. Details, subprocessors, and the peak-demand exception are on the AI Disclosure page.
Model routing is an operator-controlled setting. Material changes to where case content is processed for AI will be reflected on the AI Disclosure and Security pages, and customers will be notified through the contact channel when appropriate.
Subprocessors and infrastructure
Services that may process limited data to run exhibit.law:
- Hosting and database on operator-controlled servers (application, media storage, PostgreSQL) — case files and transcripts reside here.
- Self-hosted AI workers on private infrastructure (speech transcription and local multimodal/text models) — primary path for case-content AI under normal load.
- OpenAI (API / enterprise tier) — transcription, OCR/vision, or drafting during peak-demand fallback only, limited to content needed for the job; retention and training governed by that API data-processing relationship (not used to train models under that tier). See AI Disclosure.
- Amazon SES — transactional email (signup verification, invites, optional notification digests). Message bodies are designed not to carry case substance beyond what that channel is meant to carry.
- Google OAuth — Google authenticates the identity. Sign-in from /login is attach-only to an existing account; Continue with Google on /signup may create a Free-tier account when none exists.
- Google reCAPTCHA v3 — bot checks on public signup and contact forms.
- Sentry — application error reporting (technical diagnostics). Configured not to send case exhibit bodies, transcript text, or email addresses; users are identified by opaque numeric id only when signed in.
- Mixpanel — product analytics for coarse usage events (for example page path, signup started, upgrade clicked). Not used to send case titles, transcript text, or email addresses.
Error reporting and product analytics
When enabled by the operator, Sentry receives crash and error diagnostics from the web app and API so we can fix outages. Mixpanel receives coarse product events (page views by path and a small fixed list of actions such as signup or upgrade clicks). Neither channel is intended to receive case file contents, transcripts, notes, or search queries.
You can block analytics cookies/scripts with standard browser controls; essential session cookies for signed-in use of the product are separate from Mixpanel.
Retention and deletion
Case content is retained while the case remains on the service and for so long as needed to provide the product and meet legal obligations. There is not yet a customer self-serve “delete all media bytes” control; case deletion removes database rows for that case, and media reclamation policy continues to evolve.
You may request account deactivation or case removal through the contact form. We will confirm scope and timing. Exports you download remain your responsibility to retain or destroy under your own policies.
Security measures (summary)
See the Security page for a fuller description. In short: session-cookie authentication, per-case access checks on API reads and writes, case-namespaced storage keys, verified self-serve Free signup plus invite-only case grants, and human review gates on AI drafts. No security program is perfect; report concerns via the contact form.
Requests and contact
Depending on your jurisdiction, you may have rights to access, correct, or delete personal information we hold about you as an account holder. Case evidence is typically controlled by the customer organization that invited you; we will coordinate with the relevant CaseAdmin where appropriate.
Contact: use the contact form at https://exhibit.law/contact.
Changes
We may update this policy as the product or infrastructure changes. The “Last updated” date at the top of the page will change when we do. Material changes to where case content is processed for AI will be called out on the AI Disclosure and Security pages as well.