Legal
Privacy policy
CaseSignal is used to hold sensitive records, so this policy is written to be read rather than to be survived. It describes what we collect, what happens to the material you upload, who else touches it, and how to get rid of it.
Last updated: July 25, 2026
This document sets out how the product operates. It is not legal advice, and it does not create rights beyond those the law already gives you.
01Scope
This policy covers the CaseSignal website and the CaseSignal application: creating an account, creating cases, uploading and importing records, running analysis, exporting briefs and publishing evidence rooms.
Two kinds of information are handled very differently, and it is worth separating them at the outset. Account information is what we need to run a service for you. Source material is what you put into a case: the documents, spreadsheets, images, transcripts, pages and notes you are investigating. Source material is treated as confidential to your workspace and is used only to operate the case it belongs to.
02What we collect
Nothing here is collected for advertising, resale or profiling, because we do none of those things.
Account details
Your name, email address, authentication identifiers from the sign-in provider, the workspaces you belong to and your role in each. If you tell us the kind of work you do during onboarding, that is stored on your profile so the product can suggest a sensible case template.
Source material you add to a case
The files you upload, the text you paste, the notes you type, and the content of public webpages you ask CaseSignal to fetch. This includes the stored copy of each file, the text extracted from it, and the excerpts the text is split into, together with the location of each excerpt — page, sheet and row, section or timecode.
Work you produce in the case
Claims, citations, entities, relationships, timeline events, discrepancies, review states, analyst notes, brief drafts and evidence-room settings. This is your material; we hold it to operate the product.
Usage counts
Counters used to apply plan limits: active cases, processed pages, AI operations, stored bytes and published evidence rooms. These are counts, not copies. Counting a page does not retain the page for any purpose other than the case it belongs to.
Audit records
A log of actions with security or accountability significance: exports, creation and modification of share links, and deletions. Each entry records who acted, what was affected and when. Deletions are written to the log before the underlying rows are removed, which means an audit entry can outlive the record it describes — by design.
Operational data
Ordinary server and error logs needed to keep the service running and secure, including request metadata and rate-limit counters. We do not run third-party advertising or cross-site tracking on this site.
Payment information
If you subscribe, checkout is handled by our payment processor. Card numbers are entered in their interface and are never received or stored by CaseSignal. We keep the subscription status, plan and billing identifiers needed to apply your entitlements.
03How source material is used
Source material is used for one purpose: to operate the case you added it to. Concretely, that means extracting its text, preserving the location of each passage, indexing it so it can be retrieved and cited, and producing the claims, events, entities and differences that make up the case map.
It is not used to improve or evaluate CaseSignal for anyone else. It is not read by our staff as a matter of routine; access for support or debugging happens only where it is necessary to resolve a problem you have reported, or where we are legally compelled. It is not sold, rented or disclosed to third parties for their own purposes.
Nothing in a case is public unless you publish it. Publishing an evidence room is an explicit act, each item in it is opted in individually, and the link can be given an expiry date, protected with a password, stripped of analyst notes and revoked at any time.
04Analysis and the AI provider
When you run an analysis step — summarising a source, extracting claims or a timeline, comparing records, answering a question, drafting a brief section — the relevant excerpts are sent to the configured AI provider so the model can produce that output.
Three points about that are worth stating plainly:
- Excerpts, not archives. What is sent is the specific passages a step needs, together with the instruction for that step — not your whole case, and not files wholesale.
- Only when you run a step. There is no background process that reads your cases. Analysis runs when you ask for it.
- Not used for training. Your source material is not used to train models, ours or anyone else’s. We use the provider’s API under terms that exclude training on submitted content.
Where no AI provider is configured for a deployment, analysis runs locally with deterministic methods and no source text leaves the deployment at all. The security overview shows which providers this deployment is configured to use.
05Sub-processors
CaseSignal relies on a small number of infrastructure providers. We describe them by function, because the specific vendor for a given deployment can differ and the function is what matters to you:
- Authentication provider — identity, sessions and organization membership. Receives account identifiers, not case content.
- Database and file storage provider — stores cases, excerpts, claims, citations, audit records and the uploaded files themselves.
- AI provider — receives excerpts at the moment an analysis step runs, as described above.
- Payment processor — handles checkout and subscription management. Receives billing details directly from you; we never see card data.
Each is engaged to provide that function and is not permitted to use your material for its own purposes. We will update this section when the set of functions changes.
07Retention and deletion
Case material is kept for as long as the case exists in your workspace. There is no automatic expiry, and there is no hidden archive: what you can see is what we hold.
- Deleting a source removes the stored file, its extracted text, its excerpts and every citation that pointed at it.
- Deleting a case removes all of its records, analysis and stored files.
- Deleting every case is available as a single control in workspace settings.
- Closing an account removes the workspaces you own, along with their cases and files.
Two things survive deletion, deliberately and in minimal form: audit entries recording that a deletion or export occurred, and billing records we are required to keep for accounting and tax purposes. Neither contains your source material. Backups are retained on a short rolling window and are overwritten in the ordinary course; material deleted from the live service is removed from backups as that window turns.
08Your rights and controls
Most of what a data-protection right entitles you to is available directly in the product, which we think is how it should be:
- Access — every record, excerpt and citation in a case is readable in the workspace, and briefs export as Markdown or PDF.
- Correction — claim wording, status, materiality, review state, notes and citations are all editable, and profile details can be changed in settings.
- Deletion — per source, per case, all cases, or the whole account, as described above.
- Portability — exports carry the citation trail with them, so what leaves is usable outside CaseSignal.
- Objection and restriction — you can stop analysis at any time by not running it; the case remains readable.
If you need something the interface does not offer, or you want confirmation that a deletion has taken effect, write to us and we will deal with it. Where you are covered by a data-protection regime that gives you a right to complain to a supervisory authority, that right is unaffected by anything in this policy.
Note that where you upload records about other people, you are the one deciding what is collected and why. We process that material on your instructions; requests from individuals named in your records should be directed to you, and we will help you respond to them.
09International transfers
Our infrastructure providers may process data in countries other than your own, including the United States. Where material is transferred internationally, we rely on the transfer mechanisms our providers make available, such as standard contractual clauses. If a deployment must keep material in a particular jurisdiction, CaseSignal can be run against providers in that region.
10Children
CaseSignal is a professional tool and is not directed at children. We do not knowingly create accounts for anyone under 16. If you believe a child has created an account, tell us and we will remove it.
11Changes to this policy
When this policy changes we update the date at the top and, for changes that materially affect how source material is handled, we notify account holders before the change takes effect. Previous versions are made available on request. Continuing to use the service after a change takes effect means the updated policy applies.
12Contact
A public contact address has not been configured for this deployment, so privacy requests should be sent to the operator running it. Security issues are handled through responsible disclosure.
Related documents: the terms of service, the acceptable use policy and the security overview.