Privacy Policy

Last updated: April 26, 2026.

Introduction

This policy describes who we are and how Circuit Law collects, uses, and protects information.

Information We Collect

We collect account information (firm name, admin name, email, team member names and emails), usage data (including login timestamps and IP addresses for security), payment metadata from Stripe (customer and subscription IDs, never card details), and client data entered by firms (including names, contact information, case details, trust records, and invoices).

How We Use Information

We use information to provide the service, send transactional emails (via Resend), manage billing and subscriptions, prevent fraud and abuse, and improve the product using only anonymized, aggregated data that is never individually identifiable.

Operator Access

Circuit Law platform operators may access firm data solely for support, security, and operational purposes. Access is logged and limited to what is necessary to provide the service. Operator access is never used for commercial purposes.

Data Storage and Security

Circuit Law is hosted on Railway infrastructure. Data is encrypted in transit via HTTPS and encrypted at rest. We align safeguards with Massachusetts 201 CMR 17.00 requirements for personal information of Massachusetts residents.

Data Sharing

We do not sell data. We share data only with required subprocessors: Stripe (payments), Resend (transactional email), Cloudflare (security and DNS), and Railway (hosting infrastructure).

Client Data and Attorney-Client Privilege

Law firms are the data controller for their client data, and Circuit Law is the data processor. Firms are responsible for client data requests. Circuit Law treats all client data as confidential and uses it only to provide service to the firm.

Aggregated Data

Circuit Law may use anonymized, aggregated data (never individually identifiable) to understand usage patterns and improve the service. No individual firm or client data is used this way.

Data Retention

Active account data is retained while a subscription is active. Data remains available for export for 30 days after termination and is permanently deleted after that 30-day window.

Your Rights

You may request access, correction, or deletion of account data by contacting legal@circuitlaw.app. We respond within 30 days.

Cookies

We use session cookies for authentication only. We do not use advertising cookies or third-party tracking cookies.

Children's Privacy

Circuit Law is not directed to individuals under 18.

Changes to Policy

For material changes to this policy, we provide at least 30 days notice by email.

Contact

Privacy questions: legal@circuitlaw.app