exhibit.law
Privacy Policy
Last updated 2026-09-19
This policy describes what exhibit.law collects, how case evidence is handled, and who can see it. It applies to the hosted service at exhibit.law. It is written for practitioners evaluating whether to put privileged material on the platform — not as marketing fluff.
exhibit.law is operated as a hosted legal-evidence service. For the current operator contact, use the contact form at https://exhibit.law/contact. A formal legal-entity name and mailing address will be published here when finalized.
What this covers
We process (1) account and access data needed to run the service, and (2) case content you or your invitees upload. Case content is treated as confidential customer data. Free accounts may self-register with email verification; access to each case remains invite-only via a CaseAdmin grant.
This policy does not cover third-party sites you link out to, or files after an authorized user downloads or exports them (for example a downloaded exhibit or a clip export).
We do not sell your data
We do not sell personal information, account data, or case content. We do not sell, rent, or trade user lists for advertising or marketing, and we do not sell evidence, transcripts, or derived case artifacts to data brokers or other third parties.
We share data only as needed to operate the service (for example infrastructure hosts, transactional email, optional Google sign-in, optional Google Drive or Dropbox import that you initiate, and the AI processing described in the AI Disclosure), under those subprocessors’ terms and our instructions — not as a sale of your data.
Account and access data
For accounts we may store email address, display name, authentication material (password hash and/or Google account linkage), role and case grants, notification preferences, records of acceptance of these Terms / Privacy / AI Disclosure at signup, and basic session/security logs (for example sign-in attempts and rate-limit counters).
Self-serve signup creates an organization on the Free plan. Invitations attach additional people to a specific case.
Case content (evidence)
Case content includes uploaded files (documents, photos, audio, video, chat screenshots, zip discovery packages), derived artifacts (transcripts, metadata extracts, AI draft event text, file-analysis notes), and user-authored timeline fields (titles, descriptions, tags, people links, review status).
Access is granted per case. Users only see cases they have been invited to. Media rows and join tables are case-scoped in the database so content from one matter is not shared into another matter’s library.
Google Drive and Dropbox import
If you choose Import from Google Drive or Import from Dropbox on the upload page, exhibit.law requests read-only access so you can pick files from that account. We do not request write, delete, or sharing permissions, and we do not write anything back to Google Drive or Dropbox.
Only files you select are downloaded into the active case. They are stored and hashed the same way as a file you upload from your computer, then processed under this policy like any other exhibit. We do not import your entire Drive or Dropbox, and we do not keep a copy of files you did not select.
A short-lived access token is stored encrypted, scoped to your exhibit.law user (not to a case), so listing and download can finish. Disconnecting the import, or the token expiring, removes that credential. Job records store a session id, not the token. Google and Dropbox authenticate you on their own sites; we never see your Google or Dropbox password.
Google user data (Limited Use)
This section is the disclosure Google requires for apps that use Google Sign-In or Google Drive. It applies to data we receive from Google APIs, not to files you upload from your computer.
Google Sign-In (openid, email, profile): we receive your Google account email, whether it is verified, a stable subject id, and (when Google sends them) your display name and profile photo URL. We use those only to match or create your exhibit.law account, show your name, and optionally fetch the photo as your avatar. Sign-in does not request Drive access.
Google Drive import (drive.readonly), only if you click Import from Google Drive: we receive folder and file metadata (name, id, type, size) so you can browse and pick, and the bytes of files you select. We do not request write, delete, or sharing scopes. Metadata we used only to render the picker is not kept as a Drive index after you disconnect. Selected files become case exhibits: they are stored on our servers, hashed, visible to people granted on that case, and may be transcribed, OCR’d, or drafted like any other upload.
Limited Use: we use Google user data only to provide and improve these user-facing features. We do not sell it, use it for advertising or retargeting, use it to determine credit-worthiness, or transfer it to data brokers. We do not allow exhibit.law personnel to read Drive file contents except with your direction, to investigate a security or abuse issue, or to comply with law. Analytics and crash reporting are not configured to receive Drive file bodies, tokens, or Google profile photos.
AI and automated processing
Uploaded media may be processed automatically to extract text, transcribe audio/video, identify speakers, run OCR/vision on documents or images, draft suggested timeline events, and expand zip archives. AI-suggested text and dates remain marked for human review and are not treated as confirmed facts until a person approves them.
AI processing may use self-hosted models or third-party providers, depending on the feature and deployment configuration. Only the content needed for the requested function is sent to a third-party provider when that configuration is used. We do not use your case content to train public foundation models. Details about current configurations and subprocessors are on the AI Disclosure page.
Model routing is an operator-controlled setting and may occur automatically; you are not asked to approve it feature-by-feature. Material changes to where case content is processed for AI will be reflected on the AI Disclosure page, and customers will be notified through the contact channel when appropriate. Contact us to discuss closed-loop, self-hosted processing options, including supported features and deployment requirements.
Subprocessors and infrastructure
Services that may process limited data to run exhibit.law:
- Hosting and database on operator-controlled servers (application, media storage, PostgreSQL) — case files and transcripts reside here.
- Self-hosted AI workers on private infrastructure (speech transcription and local multimodal/text models) — may process case content for supported features when selected by the deployment configuration.
- OpenAI (API / enterprise tier) — may process transcription, OCR/vision, or drafting when selected by the deployment configuration, limited to content needed for the job. Under that API data-processing relationship, case content is not used to train models. See AI Disclosure.
- Amazon SES — transactional email (signup verification, invites, optional notification digests). Message bodies are designed not to carry case substance beyond what that channel is meant to carry.
- Google OAuth — Google authenticates the identity. Sign-in from /login is attach-only to an existing account; Continue with Google on /signup may create a Free-tier account when none exists.
- Google Drive (optional, user-initiated) — read-only listing and download of files you select to import into a case. We do not receive your Google password.
- Dropbox (optional, user-initiated) — read-only listing and download of files you select to import into a case. We do not receive your Dropbox password.
- Google reCAPTCHA v3 — bot checks on public signup and contact forms.
- Sentry — application error reporting (technical diagnostics). Configured not to send case exhibit bodies, transcript text, or email addresses; users are identified by opaque numeric id only when signed in.
- Mixpanel — product analytics for coarse usage events (for example page path, signup started, upgrade clicked). Not used to send case titles, transcript text, or email addresses.
- Google Tag Manager, Google Analytics 4, and Google Ads (gtag.js) — load only on public marketing and auth pages (for example the landing page, /resources, /login, /signup). Used to measure marketing and signup funnels. Not loaded on authenticated case workspaces (timeline, review, uploads, and similar).
Error reporting and product analytics
When enabled by the operator, Sentry receives crash and error diagnostics from the web app and API so we can fix outages. Mixpanel receives coarse product events (page views by path and a small fixed list of actions such as signup or upgrade clicks). Google Tag Manager, Google Analytics 4, and Google Ads may run on public marketing and auth pages only. None of these channels are intended to receive case file contents, transcripts, notes, or search queries.
You can block analytics cookies/scripts with standard browser controls; essential session cookies for signed-in use of the product are separate from Mixpanel and Google marketing tags.
Retention and deletion
Case content is retained while the case remains on the service and for so long as needed to provide the product and meet legal obligations. There is not yet a customer self-serve “delete all media bytes” control; case deletion removes database rows for that case, and media reclamation policy continues to evolve.
You may request account deactivation or case removal through the contact form. We will confirm scope and timing. Exports you download remain your responsibility to retain or destroy under your own policies.
Security measures (summary)
Access to each matter is grant-based: you only see cases you were invited to. Sessions use an HTTP-only cookie; passwords are stored with argon2; public traffic is over HTTPS. Case content is stored under case-scoped keys, and API reads and writes check the active case grant.
How AI features process case files, including self-hosted and third-party configurations, is described on the AI Disclosure page — not repeated here.
No security program is perfect. Report concerns via the contact form.
Requests and contact
Depending on your jurisdiction, you may have rights to access, correct, or delete personal information we hold about you as an account holder. Case evidence is typically controlled by the customer organization that invited you; we will coordinate with the relevant CaseAdmin where appropriate.
Contact: use the contact form at https://exhibit.law/contact.
Changes
We may update this policy as the product or infrastructure changes. The “Last updated” date at the top of the page will change when we do. Material changes to where case content is processed for AI will be called out on the AI Disclosure page as well.