Privacy Policy
Effective Date: July 1, 2026 · Last Updated: July 10, 2026
1. Who we are and scope
Juris Intelligence, Inc., a Delaware corporation ("Company," "Juris Intelligence," "we," "us," or "our"), operates BriefBank, an AI legal-research and drafting SaaS product.
This Product Privacy Policy applies to the logged-in BriefBank application and to related account, authentication, subscription, billing, support, AI, search, security, and product-operations processing. It does not cover the public marketing website's cookies, website analytics, or marketing-site browsing activity, which are addressed separately in the marketing-site Privacy & Cookie Notice.
BriefBank is U.S.-focused and designed for professional use by licensed attorneys and supervised legal staff. BriefBank offers Free, Professional, and Team tiers. A paid upgrade requires an eligibility attestation that the user is a licensed attorney or supervised legal staff.
Related documents include the Terms of Service, the Data Processing Addendum ("DPA"), the Subprocessor List, and the Security Overview.
Privacy contact: info@aibriefbank.com. Registered agent: Corporation Service Company, 251 Little Falls Drive, Wilmington, DE 19808.
2. Our dual role: controller vs. processor
BriefBank processes different types of information in different legal roles.
| Processing area | Our role | What that means |
|---|---|---|
| Account, authentication, organization administration, eligibility attestation, billing, subscription, usage, support, security, and legal/assent records | Controller / business | We determine the purposes and means of this processing to operate BriefBank, administer accounts, bill customers, secure the service, provide support, and enforce our Terms. |
| Customer Content submitted to or generated within BriefBank on a customer's behalf | Processor / service provider / contractor | We process this information on behalf of the customer to provide BriefBank features, subject to the customer agreement and, for GDPR/UK-covered personal data, the DPA. |
| Derived Data created from Customer Content, such as text chunks and embeddings | Processor / service provider / contractor | We use this information only to provide retrieval/search infrastructure for the customer. It is not used to train any model and is deleted with the related Customer Content. |
"Customer Content" includes uploaded files, documents, chat messages, prompts, and generated responses submitted to or generated within BriefBank. Customers are responsible for determining what Customer Content they submit and for providing any required notices or obtaining any required rights for personal information contained in that content.
3. Information we collect
The table below is our product notice at collection. "Sold/shared?" refers to the sale of personal information or sharing for cross-context behavioral advertising under California privacy law. We do not sell personal data or share it for cross-context behavioral advertising.
| Category | Examples | Sources | Purposes | Sold / shared? | Retention |
|---|---|---|---|---|---|
| Account, authentication, organization, eligibility, and assent information | Email address; account, user, and organization IDs; email/password authentication information; Microsoft SSO identifiers; role and tier; eligibility attestation; clickwrap acceptance and immutable assent logs | You; your organization administrators; Microsoft SSO; BriefBank systems | Create and administer accounts and organizations; authenticate users; authorize access; manage roles and tiers; verify paid-tier eligibility; enforce Terms; maintain legal records | No | Retained for the life of the account or organization and as needed for security, legal, compliance, dispute-resolution, and Terms-enforcement purposes. Certain legal/assent records may be retained as immutable records where necessary. |
| Billing and subscription information | Plan; subscription status; payment and transaction data processed through Stripe | You; your organization administrators; Stripe | Billing; renewals; subscription administration; accounting; fraud and payment security | No | Retained for the subscription relationship and as needed for accounting, tax, legal, payment, and dispute purposes. Stripe may retain payment information under applicable Stripe terms and our agreements with Stripe. |
| Customer Content | Uploaded files; documents; libraries; chat messages; prompts; generated responses | You and authorized users; generated by BriefBank at your direction | Provide product features; store libraries and chats; retrieve relevant materials; support drafting and research workflows; provide customer support when requested | No | Event-driven. Customer Content remains until deleted, account closure, or a deletion request is processed. Paid-tier deletion requests are completed within 30 days; Free-tier Customer Content is deleted promptly on account closure. Backups follow the ordinary backup cycle; AI-provider abuse/safety logs may persist under provider terms. |
| Derived Data | Text chunks and pgvector embeddings generated from ingested content (embeddings created using text-embedding-3-large) | Generated by BriefBank from Customer Content | Retrieval and search infrastructure only | No | Deleted with the related Customer Content. Not used to train any model. |
| Usage, log, and telemetry information | Numeric/ID product analytics; request identifiers; truncated console query fragments (up to 100 characters); error traces | BriefBank product and infrastructure; PostHog; application logs | Security; debugging; analytics; reliability; abuse prevention | No | Retained as reasonably necessary for security, debugging, reliability, analytics, and compliance purposes, subject to operational needs and subprocessor terms. We do not intentionally log document content. |
| AI/search provider processing data | Prompts, context, and responses sent to Azure OpenAI or Anthropic; the Perplexity query string if web search is enabled | BriefBank workflows; user prompts; Customer Content used as context; model outputs | AI inference; embeddings; retrieval; drafting; optional web search | No | BriefBank-stored prompts and responses are retained as Customer Content. Provider-side abuse, safety, or operational logs are retained under the provider terms described in Section 5. |
| Support and legal communications | Emails; support requests; legal requests; attachments | You; your organization; persons contacting us | Respond to requests; provide support; investigate issues; maintain legal, compliance, and business records | No | Retained as needed to respond and for legal, compliance, dispute-resolution, security, and business-record purposes. |
BriefBank stores account/control-plane data, data-plane records, extracted document text, and pgvector embeddings in Azure PostgreSQL. BriefBank does not retain the original uploaded file bytes: documents are processed at ingestion and the extracted text and Derived Data are stored; the source system you upload or sync from remains the system of record for the original file. Customer Content at rest is stored in the United States on Azure.
We do not request sensitive personal information. Customer Content may contain sensitive or privileged information if a customer chooses to submit it. Certain categories of regulated data must not be submitted to the Service (for example, HIPAA-protected health information absent a signed BAA, payment-card data, and export-controlled data); see Section 3.2 of the Terms of Service.
4. How we use information
We use information to:
- Provide BriefBank — create accounts, authenticate users, store libraries and chats, process uploaded documents, generate text chunks and embeddings, retrieve relevant materials, and generate AI-assisted responses and drafts.
- Administer subscriptions and billing — plan management, renewals, billing, accounting, and Stripe payment processing.
- Operate, secure, and debug the product — request identifiers, security and reliability logs, error traces, product telemetry, abuse prevention, and enforcement of our Terms.
- Provide support and communicate — respond to support requests and send operational, legal, and account-related communications.
- Maintain legal and assent records — clickwrap acceptance records, eligibility attestations, and records needed to administer and enforce our agreements.
- Analyze product usage using limited telemetry — product analytics are numeric/ID allowlisted and do not intentionally include Customer Content.
No-training commitment
BriefBank does not have any pipeline that trains or fine-tunes models on customer data. Paid-tier content is never used for training. Customer Content, prompts, generated responses, chat history, documents, and embeddings are not used to train any BriefBank, Microsoft/OpenAI, Anthropic, Perplexity, or other third-party model through BriefBank's current product data flows.
Derived Data, including text chunks and embeddings, is used only for retrieval and search infrastructure and is deleted with the related Customer Content.
The Terms reserve a future right to use de-identified and aggregated Free-tier chat to improve the service. BriefBank does not currently exercise that right and does not currently operate a de-identification or aggregation pipeline for that purpose.
5. AI features and third-party AI/search providers
BriefBank uses third-party AI and search providers as subprocessors to provide product features. Depending on the feature, prompts, retrieved context, Customer Content excerpts, generated responses, or query strings may be processed by these providers.
5.1 Azure OpenAI
BriefBank uses Azure OpenAI for inference and embeddings. Microsoft acts as processor under the Microsoft Products and Services Data Protection Addendum. Data sent to Azure OpenAI is not used to train Microsoft, OpenAI, or third-party models, and the models are stateless for inference. By default, Azure OpenAI may retain a sample of prompts and outputs for up to 30 days for abuse monitoring; those logs are logically isolated and subject to human review only if flagged. BriefBank is not currently approved for modified abuse monitoring, so the default Azure OpenAI abuse-monitoring posture applies.
5.2 Anthropic Claude via Azure AI Foundry
BriefBank uses Anthropic Claude via Azure AI Foundry. For this processing, Anthropic — not Microsoft — is the processor under Anthropic's Commercial Terms and DPA, and it is not covered by Azure OpenAI zero-data-retention arrangements. Anthropic does not train on the data by default. Anthropic may retain data for limited operational and safety purposes for approximately 30 days, and flagged content may be retained longer under Anthropic's terms.
5.3 Perplexity web search
Perplexity web search is optional and off by default. If web search is enabled, only the model-formed Perplexity query string is sent to Perplexity; BriefBank does not send documents or chat history to Perplexity for web search. BriefBank calls Perplexity's Sonar API. Under Perplexity's published Zero Data Retention Policy for the Sonar API, Perplexity does not retain the query string, and Perplexity's API terms contractually prohibit using customer content to train models. Perplexity processes the query string under its API terms and auto-incorporated Data Processing Addendum.
5.4 Logging and telemetry transparency
BriefBank does not intentionally log document content. Console logs may retain truncated query fragments of up to 100 characters. PostHog analytics are numeric/ID allowlisted and do not include content. Application error and performance telemetry is captured through Azure Monitor / Application Insights within BriefBank's own Azure tenant; it is not sent to a third-party error-monitoring provider.
6. How we disclose information
We disclose information only as described in this Policy, the Terms, the DPA, and the Subprocessor List.
6.1 Service providers and subprocessors
We use service providers and subprocessors to operate BriefBank, including: Microsoft Azure (including Azure OpenAI, Container Apps hosting, and Azure PostgreSQL); Anthropic; Perplexity, if web search is enabled; PostHog for product analytics; a transactional email provider; and Stripe for billing. These providers process information to provide their services to BriefBank and are listed on the public Subprocessor List.
6.2 Customer organizations and administrators
If you use BriefBank through an organization or team, your organization and its administrators may be able to administer your account, manage users, roles, tiers, and billing, and access information associated with the organization according to BriefBank's roles, permissions, and customer configuration.
6.3 At the customer's direction
For Customer Content, we process and disclose information as instructed by the customer, including to authorized users and to the subprocessors needed to provide BriefBank.
6.4 Professional advisers
We may disclose information to lawyers, auditors, insurers, accountants, and other professional advisers where reasonably necessary for legal, compliance, risk-management, accounting, or business purposes.
6.5 Legal, safety, and compliance reasons
We may disclose information where we believe it necessary to comply with law, legal process, or government requests; protect the rights, property, or safety of BriefBank, customers, users, or others; investigate security incidents or abuse; or enforce our Terms.
6.6 Corporate transactions
We may disclose information in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, subject to appropriate protections for the information.
6.7 No sale or cross-context behavioral advertising
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising.
7. Cookies and tracking in the product
The logged-in BriefBank product uses cookies or similar technologies that are necessary for authentication, session management, security, and operation of the application. Product analytics are limited to numeric/ID allowlisted telemetry and do not intentionally include Customer Content. The product does not use advertising cookies for cross-context behavioral advertising. Cookies and analytics on the public marketing website are addressed separately in the marketing-site Privacy & Cookie Notice.
8. Legal bases for GDPR/UK processing
Where GDPR or UK data protection law applies and BriefBank acts as controller, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Account creation, authentication, organization administration, roles, tiers, and eligibility attestation | Performance of a contract; legitimate interests in operating and securing the product |
| Billing, subscriptions, renewals, and accounting | Performance of a contract; legal obligations; legitimate interests in payment administration and fraud prevention |
| Support and operational communications | Performance of a contract; legitimate interests in responding to requests and operating the service |
| Security, debugging, reliability, abuse prevention, and Terms enforcement | Legitimate interests; legal obligations where applicable |
| Clickwrap assent logs and legal records | Performance of a contract; legitimate interests in maintaining enforceable records; legal obligations where applicable |
| Compliance with legal requests and dispute handling | Legal obligations; legitimate interests |
| Optional settings or processing where consent is required by law | Consent |
For Customer Content and Derived Data processed on behalf of a customer, the customer is the controller and determines the applicable legal basis; BriefBank processes that information as processor under the customer's instructions and the DPA, where applicable.
9. Data retention and deletion
BriefBank retains information only as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted for legal, security, accounting, dispute-resolution, or compliance reasons.
9.1 Customer Content and Derived Data
Customer Content deletion is event-driven; BriefBank does not currently run a scheduled job that deletes Customer Content after a fixed period. When an account, library, document, or chat deletion is processed, BriefBank's deletion workflow is designed to purge associated database rows and embeddings across the control plane and data plane, and it is idempotent (safe to re-run). Because BriefBank does not retain original uploaded file bytes, there are no stored raw files to delete beyond those records. For paid tiers, Customer Content deletion requests are completed within 30 days; for Free-tier accounts, Customer Content is deleted promptly on account closure. BriefBank may close Free-tier accounts that have been inactive for three or more consecutive months, with at least 30 days' advance notice, as described in Section 5.3 of the Terms of Service; Customer Content is deleted on such closure as described above. Derived Data, including chunks and embeddings, is deleted with the related Customer Content.
9.2 Backups and provider logs
Deleted Customer Content may remain in backups until those backups are overwritten or expire in the ordinary backup cycle. AI-provider abuse, safety, or operational logs may persist according to the applicable provider terms, including the Azure OpenAI and Anthropic practices described in Section 5.
9.3 Controller-side records
Account, authentication, billing, subscription, usage, support, security, and legal/assent records may be retained as needed to operate BriefBank, comply with legal and accounting obligations, investigate security issues, resolve disputes, and enforce our Terms. Immutable clickwrap assent logs may be retained where necessary to maintain legal records.
10. Data residency and international transfers
Customer Content at rest is stored in the United States on Azure. Some AI model deployments used by BriefBank are Global or multi-region; as a result, inference prompts, context, and responses may be processed in regions outside the United States, while Customer Content storage at rest remains in the United States. Where GDPR or UK data protection law applies, international transfers are handled through the DPA, including Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable.
11. Security
BriefBank maintains technical and organizational measures designed to protect information processed through the product; more detail is available in the Security Overview. These measures include:
- Azure-hosted infrastructure using Azure PostgreSQL;
- encryption controls for data in transit and at rest;
- tenant isolation using dual-database row-level security keyed on
org_id; - Azure Active Directory managed-identity service authentication;
- secrets management through Azure Key Vault;
- email/password authentication and Microsoft SSO;
- role and tier controls for account and organization administration;
- least-privilege access controls;
- audit/security logging and request identifiers; and
- immutable clickwrap assent logs.
No security program can guarantee absolute security. Users and organizations are responsible for maintaining the confidentiality of their credentials, configuring access appropriately, and ensuring that Customer Content submitted to BriefBank is authorized for processing. Security-incident handling is addressed in the Terms and, where applicable, the DPA.
12. Your privacy rights
Your rights depend on where you live, the type of information involved, and whether BriefBank acts as controller/business or processor/service provider.
To exercise rights for information where BriefBank acts as controller, email info@aibriefbank.com with enough information to identify your account, organization, and request. We may need to verify your identity or authority before responding.
For Customer Content, BriefBank generally acts as processor/service provider on behalf of the customer. If your request concerns Customer Content controlled by a customer organization, direct the request to that customer; if we receive such a request directly, we will route or assist with it as required by law and the applicable customer agreement.
12.1 California privacy rights
If California privacy law applies, California residents may have the right to: know/access the categories and specific pieces of personal information collected; correct inaccurate personal information; delete personal information; obtain a portable copy of personal information; opt out of the sale or sharing of personal information; limit the use and disclosure of sensitive personal information, where applicable; and be free from discrimination for exercising privacy rights.
BriefBank does not sell personal information or share it for cross-context behavioral advertising, so no sale/share opt-out is necessary for current product processing. Because BriefBank does not sell or share product data for cross-context behavioral advertising, a Global Privacy Control signal does not change any product sale/share setting; we will treat legally recognized opt-out preference signals in accordance with applicable law. California residents may use an authorized agent to submit a request; we may require proof of authorization and may verify the request directly with you where permitted.
12.2 GDPR and UK privacy rights
If GDPR or UK data protection law applies and BriefBank acts as controller, you may have the right to: access your personal data; rectify inaccurate personal data; erase personal data; restrict processing; receive data portability; object to processing based on legitimate interests; withdraw consent where processing is based on consent; and lodge a complaint with a supervisory authority. Where BriefBank acts as processor for Customer Content, the customer/controller is responsible for responding to data-subject requests, and BriefBank assists the customer as required by the DPA.
13. Automated decision-making and AI output
BriefBank does not make solely automated legal decisions about users or clients that produce legal or similarly significant effects. BriefBank provides AI-assisted research and drafting functionality for professional legal users. AI-generated output may be incomplete, inaccurate, or unsuitable for a particular matter, and is not legal advice. Licensed attorneys and supervised legal staff are responsible for reviewing and validating all output before relying on it. See the Terms of Service for additional terms governing AI features.
14. Children and professional use only
BriefBank is not directed to children under 13 and is not a consumer service; it is designed for professional use by licensed attorneys and supervised legal staff. We do not knowingly collect controller-side account information from children under 13. If you believe a child has provided controller-side personal information to BriefBank, contact info@aibriefbank.com. If the information is contained in Customer Content, the relevant customer/controller is responsible for handling the request, and BriefBank will assist as required by the applicable agreement and law.
15. Changes to this policy
We may update this Product Privacy Policy as our practices or legal requirements change. The current version is the version posted for the BriefBank product. If we make material changes, we will provide notice by reasonable means, such as in-product notice, email, or another legally required method. For changes to clickwrap-governed documents, re-acceptance may be required in accordance with Section 15.3 of the Terms of Service. The marketing-site Privacy & Cookie Notice may be updated separately.
16. How to contact us and complaints
For privacy questions, requests, or complaints, contact Juris Intelligence, Inc. at info@aibriefbank.com. Registered agent for service of process: Corporation Service Company, 251 Little Falls Drive, Wilmington, DE 19808.
If GDPR or UK data protection law applies, you may also have the right to lodge a complaint with your local supervisory authority. We encourage you to contact us first so we can try to resolve the issue.