Privacy Policy
1. Who this covers
casewise is an AI-powered educational study tool for legal study and general legal research, operated from New South Wales, Australia by CaseWise Technologies Pty Ltd. This policy explains what personal information we collect when you use casewise, why, where it is processed, and your choices. For privacy questions, requests or complaints, contact us at info@gocasewise.com.
2. What we collect
- Account data: email address, password credentials (held by our authentication provider; we never see or store your raw password), display name, and optional profile details you choose to add (role, firm or chambers, home jurisdiction, avatar, preferences). If you sign in with Google, Apple or Microsoft, we receive your account identifier and email address from that provider instead of a password.
- Content you submit: questions and prompts, documents you upload, documents you draft in the editor, saved sources, and settings.
- Generated content: answers, memos, summaries and citation-check results produced for you.
- Billing data: your plan, subscription status, trial and billing events. Payment card details are collected and held by our payment provider (Stripe), not by us.
- Usage and technical data: authentication events, feature usage and spend metering (used to enforce fair-use limits), error reports you submit, IP address and device/browser information, and service logs.
- Acknowledgement records: timestamps of notices and terms you accept (for example the Terms of Use acceptance, the upload notice and, for practitioners, the practitioner acknowledgement).
- Optional advertising measurement: with separate permission, public campaign, ad and creative labels and recognised referring-source categories (such as search, social or email), account attribution, and signup, trial and payment outcomes. Meta receives a SHA-256 hash of your verified email for matching; hashing does not make it anonymous.
We do not ask for, and you must not submit, client-confidential or privileged material, court-restricted material, or personal information about another person.
3. Why we use it
- to provide the service: answering questions, retrieving authorities, showing evidence states, drafting and exporting;
- to operate accounts and subscriptions, enforce fair-use limits and protect the service from abuse;
- to review error reports and improve reliability;
- to communicate service messages (verification, password reset, billing notices, important changes); and
- to meet legal obligations; and
- with your separate permission, to measure which advertisements lead to signup and subscription outcomes.
When you send an error report, the text of your report is recorded against your account so we can investigate, and where a monitored support inbox is configured the report is also delivered to it. Do not include personal or confidential details in an error report.
We review conversations to find and fix problems, and keep personal details out of anything we record from that review.
We do not use your prompts, uploads or outputs to train casewise or third-party AI models. Our AI providers are engaged on commercial API terms. Provider non-training is not the same as non-retention: providers may retain request content for abuse monitoring under their own policies and service configurations, and while an answer is being written OpenAI stores its working steps, which we ask OpenAI to delete as soon as the answer is complete.
4. Who processes it (providers)
We use the following providers; Meta also processes optional advertising data under its own privacy policy:
| Provider | What it does | What it receives | Where processed |
|---|---|---|---|
| Vercel | application hosting and optional privacy-first usage measurement | requests, service logs and, only if you opt in, page-use and product-event measurements. Our analytics integration does not send legal questions, documents, sources or email addresses | Sydney region configured |
| Meta | optional advertising measurement, only with separate permission | public website visits, browser/click and connection information; consented signup, trial and payment events, payment amount/currency and a SHA-256 email hash for matching. No legal content or private workspace pages | outside Australia, including the United States |
| Supabase | database, file storage and authentication | account data, content, usage records | AWS Asia-Pacific, Sydney |
| Stripe | subscription payments and billing | your payment card details (entered directly with Stripe, never stored by us), billing contact details and subscription status | United States and other locations |
| Anthropic | AI model and web-retrieval API for enabled auxiliary features | prompts, relevant documents, retrieved sources or public source URLs when an enabled feature uses it | outside Australia, including the United States |
| OpenAI | AI model API (answers, research, drafting, checking and embeddings) | prompts, relevant documents, retrieved sources and text being processed per request | outside Australia, including the United States |
| Cohere | search re-ranking API | text snippets being ranked per request | outside Australia, including the United States |
| ZenRows / Zyte | retrieval of public legal sources on our behalf | the public URLs to fetch (not your prompts) | outside Australia |
| Cloudflare (Turnstile) | sign-in anti-abuse check | technical browser signals at sign-in | outside Australia, including the United States |
| optional Google Drive import; optional Google sign-in | the files you choose to import; your Google account identifier and email if you sign in with Google | United States and other locations | |
| Microsoft | optional OneDrive/SharePoint import; optional Microsoft sign-in | the files you choose to import; your Microsoft account identifier and email if you sign in with Microsoft | United States and other locations |
| Apple | optional Apple sign-in | your Apple account identifier and the email you choose to share | United States and other locations |
If you import a document from Google Drive or OneDrive, that file passes from your cloud account to casewise at your instruction.
Some of these providers process data outside Australia, including in the United States, as marked above. Their handling is governed by their terms and our service arrangements, but overseas processing means your information may be handled under another country's laws. If you are not comfortable with that, do not submit content to casewise. We will keep this list current; using a provider not listed here would require updating this policy first.
5. Retention and deletion
- Your account content (conversations, documents, sources, versions) is retained while your account is active so the product works.
- You can delete uploaded documents from your library in-product. Where a stored copy backs a feature (for example document versions), deletion controls are as shown in-product.
- Usage metering and abuse-guard counters are retained for service protection. For the free signup offer, we use a signed device cookie and keyed hashes of account, provider identity, device and IP information to prevent repeated claims. The cookie expires after 30 days; IP signals are removed after 7 days and device signals after 30 days by a daily cleanup job. Offer records linked to a deleted account are retained for 180 days after deletion to prevent repeat claims, then removed by that job.
- You can delete your account from Settings. Before you confirm, we show you what will be deleted. Deleting your account removes your conversations, uploaded documents and their extracted text, drafts and versions, research sessions, saved sources and collections, error reports you have sent us, preferences and profile, and we verify afterwards that no rows remain. Deletion is permanent and we cannot restore the content. Deleting your account also cancels any active subscription with our payment provider; Stripe retains billing records it is required to keep under its own policies.
- Except for the free-offer records described above, we do not currently promise automated expiry schedules.
6. Security
Traffic is encrypted in transit (HTTPS). Data is stored with our named providers with encryption at rest and row-level access controls scoped to your account. Administrative access is limited. No system is perfectly secure and we make no absolute security claims. If a data breach likely to result in serious harm occurs, we will follow the OAIC Notifiable Data Breaches scheme, notifying affected users and the OAIC where required.
7. Age
casewise accounts require you to be at least 18 years old. We collect only the information described here, do not use your content for model training, and do not run advertising based on your legal questions, documents or research activity.
8. Access, correction and complaints
You can access and correct your profile in Settings, and delete your account from Settings. For other access, correction or deletion requests, or privacy complaints, contact us at info@gocasewise.com. If you are unsatisfied with our response you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
9. Cookies and analytics
casewise uses cookies necessary to keep you signed in and to remember your preferences, including your theme and your response to our consent banner. If you choose Analytics in the consent banner, we use privacy-first Vercel Web Analytics to measure page use and a small number of product actions, such as starting checkout or exporting a document. We do not send the content of legal questions, documents, sources, emails, client names, account identifiers or matter identifiers through that analytics integration. It stays off unless you opt in, and you can change that choice in Settings at any time.
With Analytics enabled, Casewise also keeps a first-party journey record of fixed steps such as sign-in attempts, plan selection, checkout handoff and completed answers. A random, first-party session cookie lasts up to 24 hours; signed-in journeys are linked internally to your account so we can compare these steps with actual account and billing outcomes. Records expire after 90 days and linked records are removed when your account is deleted. No legal content, raw error messages, email addresses or private page addresses are included. Account identifiers are not shared with Vercel Web Analytics. Turning Analytics off stops new collection. Advertising source information is joined only where you separately allowed advertising measurement.
Advertising measurement is a separate, optional choice and is off by default. If you allow it, Meta Pixel runs on public marketing pages, and consented server events report verified signup, trial and payment outcomes. The app sends manually defined image events for public auth/chat entry and verified conversions, using fixed page addresses; it does not load Meta’s JavaScript or automatically inspect private pages. Consented source evidence can be retained before email verification, and anonymous signup-step records expire after 90 days. We do not send legal questions, documents, answers, client/matter details, raw email addresses or sign-in codes to Meta. Browser attribution and advertising preferences expire after 90 days; linked account attribution and delivery records are deleted with your account. Turning measurement off stops new collection and, when signed in, cancels pending server events. It does not recall data already delivered. See optional advertising measurement for details, retention and how to change your choice, and Meta’s Privacy Policy.
10. Changes
We show the date of the current version at the top of this page and will notify material changes in-product or by email.
See also the Terms of Use and the signup collection notice.