Privacy Policy
Last modified: April 3, 2026
We are glad to welcome you on our website. Many thanks for using our website and supporting us! Here are some formalities before you start.
Please read our Privacy policy carefully before using https://ideallegal.ai/ (the "Website").
Your access to and use of the Website is conditioned on your acceptance of and compliance with Terms of Use and Privacy Policy and License Agreement. The Terms of Use and Privacy Policy apply to all visitors, users and others who access or use the Website. By accessing or using the Website, you agree to be bound by this Privacy Policy and Terms of Use. If you disagree with any part of the Privacy policy, we kindly ask you to stop using the Website.
This Privacy Policy explains how iDeal Legal AI (the "Company," "we," "us," or "our") collects, uses, shares, and protects personal data in connection with our AI-based legal document review and contract analysis Service. It applies to our website, apps, Microsoft Word add-in, and related services (collectively, the "Service").
Controller. For end-user personal data we determine the purposes and means of processing; we act as controller under GDPR/UK GDPR. For business customers who supply personal data about others, we act as processor and will make a Data Processing Addendum available upon request.
1. How We Collect Information and How We Use It
While using the Website, we may ask you to provide us with certain personal information that can be used to contact or identify you. Personal information may include but is not limited to your name, email address, birthday, telephone.
We may use your personal information for us to:
- Provide and operate the Service (account creation, session management, document analysis, contract review, usage limits)
- Billing & payments (charge subscription, prevent duplicate charges, tax/VAT)
- Analytics & Service improvement (measure performance, debug, de-identify usage to improve the Service)
- Security & fraud prevention (abuse detection, rate-limiting, incident response)
- Marketing communications (customize our services, advertising product updates, onboarding to provide a more personalised experience)
- Compliance (enforce Terms, respond to lawful requests)
Sources of Personal Data:
- You provide it (account registration, profile, support).
- Automatically collected via cookies/SDKs/analytics and server logs.
- Third parties (payment processor provides payment status/last 4 digits/token; fraud prevention signals).
2. Data Collected
- Account Data: display name, email address, avatar.
- Payment Data: billing contact (email); payment instruments are processed by payment systems (e.g. Stripe); we do not store full card numbers.
- Usage & Device Data: pages viewed, features used, session events, IP address, device identifiers, browser/device information; collected via analytics (e.g., Google Analytics) and our logs.
- Generated Content: legal documents and contracts uploaded for analysis (Inputs), review playbooks and policies stored in your account, AI-generated review reports, redline suggestions, and risk assessments (Outputs). Source documents are automatically deleted after analysis is complete, subject to the limited support retention described in the section "Confidentiality of Legal Documents and Zero Data Retention"; only user-created playbooks and policies are retained.
- Support Data: communications with support, bug reports.
- Approximate Location: country (state).
- No Sensitive Data: we do not intentionally collect special category data under GDPR or "sensitive personal information" under CPRA unless otherwise specifically agreed with you.
Confidentiality of Legal Documents and Zero Data Retention
Given the sensitive nature of legal documents processed through our Service, we apply the following additional safeguards:
- The Service does not use the content of your uploaded legal documents to train, fine-tune, or otherwise improve our AI models or any third-party AI models.
- Source documents (contracts, agreements, and other legal files) uploaded for analysis are automatically deleted from our systems promptly after the analysis session is completed. During the initial launch period, we may temporarily retain source documents for up to fourteen (14) days solely for troubleshooting and support purposes. You may opt out of this support retention at any time through your account settings or by contacting us, and may request earlier deletion of any document at any time.
- Only user-created review playbooks, policies, and settings are stored persistently in your account to enable ongoing use of the Service.
- We enforce Zero Data Retention at the infrastructure level: requests to AI model providers are routed exclusively through endpoints that maintain zero-data-retention policies (including deployments hosted on cloud platforms such as AWS Bedrock and Google Vertex AI), under which document content is not stored, logged, or used for model training beyond the immediate processing request. Transient in-memory caching may occur during processing; such data is not written to persistent storage and expires automatically within a short period.
- Access to document content is restricted to automated processing systems on a least-privilege basis.
- We do not share, sell, or disclose the content of your legal documents to any third party except as strictly necessary to provide the Service or as required by law.
Microsoft Word Add-in
The Service is available as a Microsoft Word add-in. When you use the add-in, document content is transmitted from your local Microsoft Word environment to our servers for AI processing, subject to the same confidentiality and Zero Data Retention commitments described above. Your use of Microsoft Word is also subject to Microsoft's own terms of service and privacy policy. We do not receive or store your Microsoft account credentials.
3. Cookies
Like many websites, we use "cookies" to collect information. If you do not accept cookies, you may not be able to use the Website.
We use cookies and similar technologies to operate the Service and for analytics. Non-essential analytics cookies (e.g., Google Analytics) are used only with your consent in the EEA/UK. You may change preferences at any time via our Cookie Preferences link.
4. Sharing and Disclosures
We share personal data as follows:
- Service Providers/Processors: infrastructure and operational partners that process data on our behalf, including: Google Cloud Platform (GCP) (Cloud Run, Firestore), Firebase, Stripe (payments), OpenRouter (AI request routing), OpenAI, Anthropic (via cloud-hosted deployments on AWS Bedrock and Google Vertex AI), Google (Gemini / Vertex AI), Amazon Web Services (model hosting), Microsoft (Office 365 / Word Add-in integration), and Google Analytics (as configured).
- Affiliates and corporate transactions: in case of merger, acquisition, or asset transfer.
- Legal and safety: to comply with law or protect rights, safety, and security.
- De-identified/aggregated data: we may share insights that do not identify individuals.
No Sale or Sharing (CPRA). We do not "sell" your personal information and do not "share" it for cross-context behavioral advertising as those terms are defined by California law.
AI Training and Partners. We do not use the content of your uploaded legal documents to train or improve AI models. Where AI providers are involved, they act as service providers/processors, and we apply routing controls that restrict processing of document content to zero-data-retention endpoints, prohibiting retention, use, or disclosure of document content beyond the immediate processing request. We may use de-identified and aggregated usage metadata (not document content) to improve Service features and quality.
5. Retention
We retain personal data for as long as your account is active or as needed to provide the Service, and delete or anonymize upon request or account closure. We may retain limited records as required by law (e.g., tax, fraud prevention, security logs).
6. Security
We and our providers implement industry-standard security measures, including encryption in transit and at rest, least-privilege access control, authentication and audit logging, vulnerability management, backups, and incident response procedures. All information you provide to us is stored on our secure servers behind firewalls.
Unfortunately, the transmission of information via the internet is not 100% secure. Although we do our best to protect your private information, we cannot guarantee the security of your private information transmitted to the Website. Any transmission of personal information is at your own risk.
7. Changes to This Privacy Policy
Occasionally we may, in our discretion, make changes to this Privacy Policy. When we make material changes, we will provide prominent notice as appropriate under the circumstances, e.g., by displaying a prominent notice within the Website or by sending you an email. Your continued use of the Website after the changes have been made will constitute your acceptance of the changes.
8. Your Data Protection Rights
EU/UK (GDPR/UK GDPR). You have the right to access, rectify, erase, restrict, object (including to processing based on legitimate interests), and portability, and to withdraw consent at any time without affecting prior processing. We will respond within one month. You may lodge a complaint with your local supervisory authority.
California (CPRA). You have the right to know/access, correct, delete, opt out of sale/share (not currently applicable), and the right to non-discrimination. We recognize and honor GPC signals. We respond within 45 days.
How to Exercise. Submit requests via support email.
9. Children's Privacy
The Service is not directed to children under 18. We do not knowingly collect personal data from children under 13 (or under the applicable age of digital consent in your country). If you believe a child has provided data, contact us to delete it.
10. Subprocessors and Key Providers
- Google Cloud Platform (GCP) — hosting and infrastructure
- Google Firebase — application platform/services
- Stripe — payment processing (PCI DSS compliant)
- OpenAI — AI language model provider
- Anthropic — AI language model provider
- Google Analytics — usage analytics
- Google AI (Gemini) — AI language model provider
- OpenRouter — AI request routing layer; routes document processing requests to AI model providers under zero-data-retention policies
- Amazon Web Services (AWS Bedrock) — cloud hosting platform for AI models used for document processing
- Microsoft — Office 365/Word Add-in platform integration
11. Contact Us
If you feel like something is missing or misleading in our Terms of Use or Privacy Policy, please feel free to notify us.
You can contact us through our contact form.