Legal

Privacy Policy

Last updated August 15, 2026

What we collect

Account information. Your name, email address, optional firm or organization, and a securely hashed password. We never store passwords in readable form.

Case materials. The notes, documents, and trial-plan text you choose to put into a matter. Files you attach are read in your browser; only the extracted text you submit reaches our servers.

Usage records. Sign-ins, approvals, and administrative changes are written to an audit log, along with basic technical details such as browser type and IP address for session security.

How case materials are used

Your materials are used for one purpose: running your matter's simulations. Trial-plan text is scored once by a third-party language-model provider under our instructions; the provider processes that text to return numeric features and does not receive your identity alongside it. Simulated jurors never see your raw files, and your materials are never used to build juror cohorts, to train models, or for any other customer.

Juror composites are built from de-identified behavioral cohorts of at least 100 people. They contain no personal information about you, your clients, or any real juror.

Cookies and sessions

We use a single session cookie to keep you signed in. It is httpOnly, expires after 14 days, and only a cryptographic hash of it is stored on our servers. We do not use advertising or cross-site tracking cookies.

Sharing

We do not sell or rent your information. Data is shared only with the infrastructure providers that run the service (hosting, database, and the language-model provider described above), each bound to process it solely on our behalf, or when the law requires it.

Retention and deletion

Account data and matters are retained while your account is active. You can request deletion of your account or of specific matters at any time by contacting your administrator or writing to us; we delete the associated case materials and simulation results, keeping only the minimal audit records needed for security.

Security

Passwords are hashed with bcrypt. Session tokens are stored only as SHA-256 hashes. Administrative actions are audit-logged. Accounts require administrator approval before activation, and suspension ends live sessions immediately.

Changes and contact

If this policy changes materially, we will note the new date above and flag the change on sign-in. Questions or requests: contact your workspace administrator or the Project Scintilla team.