Privacy Policy
Last updated: April 26, 2026.
Introduction
This policy describes who we are and how Circuit Law collects, uses, and protects information.
Information We Collect
We collect account information (firm name, admin name, email, team member names and emails), usage data (including login timestamps and IP addresses for security), payment metadata from Stripe (customer and subscription IDs, never card details), and client data entered by firms (including names, contact information, case details, trust records, and invoices).
How We Use Information
We use information to provide the service, send transactional emails (via Resend), manage billing and subscriptions, prevent fraud and abuse, and improve the product using only anonymized, aggregated data that is never individually identifiable.
Operator Access
Circuit Law platform operators may access firm data solely for support, security, and operational purposes. Access is logged and limited to what is necessary to provide the service. Operator access is never used for commercial purposes.
Data Storage and Security
Circuit Law is hosted on Railway infrastructure. Data is encrypted in transit via HTTPS and encrypted at rest. We align safeguards with Massachusetts 201 CMR 17.00 requirements for personal information of Massachusetts residents.
Data Sharing
We do not sell data. We share data only with required subprocessors: Stripe (payments), Resend (transactional email), Cloudflare (security and DNS), and Railway (hosting infrastructure).
Client Data and Attorney-Client Privilege
Law firms are the data controller for their client data, and Circuit Law is the data processor. Firms are responsible for client data requests. Circuit Law treats all client data as confidential and uses it only to provide service to the firm.
Aggregated Data
Circuit Law may use anonymized, aggregated data (never individually identifiable) to understand usage patterns and improve the service. No individual firm or client data is used this way.
Data Retention
Active account data is retained while a subscription is active. Data remains available for export for 30 days after termination and is permanently deleted after that 30-day window.
Your Rights
You may request access, correction, or deletion of account data by contacting legal@circuitlaw.app. We respond within 30 days.
Cookies
We use session cookies for authentication only. We do not use advertising cookies or third-party tracking cookies.
Children's Privacy
Circuit Law is not directed to individuals under 18.
Changes to Policy
For material changes to this policy, we provide at least 30 days notice by email.
Contact
Privacy questions: legal@circuitlaw.app