Privacy Policy

Effective Date: July 1, 2026  ·  Last Updated: July 10, 2026

1. Who we are and scope

Juris Intelligence, Inc., a Delaware corporation ("Company," "Juris Intelligence," "we," "us," or "our"), operates BriefBank, an AI legal-research and drafting SaaS product.

This Product Privacy Policy applies to the logged-in BriefBank application and to related account, authentication, subscription, billing, support, AI, search, security, and product-operations processing. It does not cover the public marketing website's cookies, website analytics, or marketing-site browsing activity, which are addressed separately in the marketing-site Privacy & Cookie Notice.

BriefBank is U.S.-focused and designed for professional use by licensed attorneys and supervised legal staff. BriefBank offers Free, Professional, and Team tiers. A paid upgrade requires an eligibility attestation that the user is a licensed attorney or supervised legal staff.

Related documents include the Terms of Service, the Data Processing Addendum ("DPA"), the Subprocessor List, and the Security Overview.

Privacy contact: info@aibriefbank.com. Registered agent: Corporation Service Company, 251 Little Falls Drive, Wilmington, DE 19808.

2. Our dual role: controller vs. processor

BriefBank processes different types of information in different legal roles.

Processing areaOur roleWhat that means
Account, authentication, organization administration, eligibility attestation, billing, subscription, usage, support, security, and legal/assent recordsController / businessWe determine the purposes and means of this processing to operate BriefBank, administer accounts, bill customers, secure the service, provide support, and enforce our Terms.
Customer Content submitted to or generated within BriefBank on a customer's behalfProcessor / service provider / contractorWe process this information on behalf of the customer to provide BriefBank features, subject to the customer agreement and, for GDPR/UK-covered personal data, the DPA.
Derived Data created from Customer Content, such as text chunks and embeddingsProcessor / service provider / contractorWe use this information only to provide retrieval/search infrastructure for the customer. It is not used to train any model and is deleted with the related Customer Content.

"Customer Content" includes uploaded files, documents, chat messages, prompts, and generated responses submitted to or generated within BriefBank. Customers are responsible for determining what Customer Content they submit and for providing any required notices or obtaining any required rights for personal information contained in that content.

3. Information we collect

The table below is our product notice at collection. "Sold/shared?" refers to the sale of personal information or sharing for cross-context behavioral advertising under California privacy law. We do not sell personal data or share it for cross-context behavioral advertising.

CategoryExamplesSourcesPurposesSold / shared?Retention
Account, authentication, organization, eligibility, and assent informationEmail address; account, user, and organization IDs; email/password authentication information; Microsoft SSO identifiers; role and tier; eligibility attestation; clickwrap acceptance and immutable assent logsYou; your organization administrators; Microsoft SSO; BriefBank systemsCreate and administer accounts and organizations; authenticate users; authorize access; manage roles and tiers; verify paid-tier eligibility; enforce Terms; maintain legal recordsNoRetained for the life of the account or organization and as needed for security, legal, compliance, dispute-resolution, and Terms-enforcement purposes. Certain legal/assent records may be retained as immutable records where necessary.
Billing and subscription informationPlan; subscription status; payment and transaction data processed through StripeYou; your organization administrators; StripeBilling; renewals; subscription administration; accounting; fraud and payment securityNoRetained for the subscription relationship and as needed for accounting, tax, legal, payment, and dispute purposes. Stripe may retain payment information under applicable Stripe terms and our agreements with Stripe.
Customer ContentUploaded files; documents; libraries; chat messages; prompts; generated responsesYou and authorized users; generated by BriefBank at your directionProvide product features; store libraries and chats; retrieve relevant materials; support drafting and research workflows; provide customer support when requestedNoEvent-driven. Customer Content remains until deleted, account closure, or a deletion request is processed. Paid-tier deletion requests are completed within 30 days; Free-tier Customer Content is deleted promptly on account closure. Backups follow the ordinary backup cycle; AI-provider abuse/safety logs may persist under provider terms.
Derived DataText chunks and pgvector embeddings generated from ingested content (embeddings created using text-embedding-3-large)Generated by BriefBank from Customer ContentRetrieval and search infrastructure onlyNoDeleted with the related Customer Content. Not used to train any model.
Usage, log, and telemetry informationNumeric/ID product analytics; request identifiers; truncated console query fragments (up to 100 characters); error tracesBriefBank product and infrastructure; PostHog; application logsSecurity; debugging; analytics; reliability; abuse preventionNoRetained as reasonably necessary for security, debugging, reliability, analytics, and compliance purposes, subject to operational needs and subprocessor terms. We do not intentionally log document content.
AI/search provider processing dataPrompts, context, and responses sent to Azure OpenAI or Anthropic; the Perplexity query string if web search is enabledBriefBank workflows; user prompts; Customer Content used as context; model outputsAI inference; embeddings; retrieval; drafting; optional web searchNoBriefBank-stored prompts and responses are retained as Customer Content. Provider-side abuse, safety, or operational logs are retained under the provider terms described in Section 5.
Support and legal communicationsEmails; support requests; legal requests; attachmentsYou; your organization; persons contacting usRespond to requests; provide support; investigate issues; maintain legal, compliance, and business recordsNoRetained as needed to respond and for legal, compliance, dispute-resolution, security, and business-record purposes.

BriefBank stores account/control-plane data, data-plane records, extracted document text, and pgvector embeddings in Azure PostgreSQL. BriefBank does not retain the original uploaded file bytes: documents are processed at ingestion and the extracted text and Derived Data are stored; the source system you upload or sync from remains the system of record for the original file. Customer Content at rest is stored in the United States on Azure.

We do not request sensitive personal information. Customer Content may contain sensitive or privileged information if a customer chooses to submit it. Certain categories of regulated data must not be submitted to the Service (for example, HIPAA-protected health information absent a signed BAA, payment-card data, and export-controlled data); see Section 3.2 of the Terms of Service.

4. How we use information

We use information to:

  1. Provide BriefBank — create accounts, authenticate users, store libraries and chats, process uploaded documents, generate text chunks and embeddings, retrieve relevant materials, and generate AI-assisted responses and drafts.
  2. Administer subscriptions and billing — plan management, renewals, billing, accounting, and Stripe payment processing.
  3. Operate, secure, and debug the product — request identifiers, security and reliability logs, error traces, product telemetry, abuse prevention, and enforcement of our Terms.
  4. Provide support and communicate — respond to support requests and send operational, legal, and account-related communications.
  5. Maintain legal and assent records — clickwrap acceptance records, eligibility attestations, and records needed to administer and enforce our agreements.
  6. Analyze product usage using limited telemetry — product analytics are numeric/ID allowlisted and do not intentionally include Customer Content.

No-training commitment

BriefBank does not have any pipeline that trains or fine-tunes models on customer data. Paid-tier content is never used for training. Customer Content, prompts, generated responses, chat history, documents, and embeddings are not used to train any BriefBank, Microsoft/OpenAI, Anthropic, Perplexity, or other third-party model through BriefBank's current product data flows.

Derived Data, including text chunks and embeddings, is used only for retrieval and search infrastructure and is deleted with the related Customer Content.

The Terms reserve a future right to use de-identified and aggregated Free-tier chat to improve the service. BriefBank does not currently exercise that right and does not currently operate a de-identification or aggregation pipeline for that purpose.

5. AI features and third-party AI/search providers

BriefBank uses third-party AI and search providers as subprocessors to provide product features. Depending on the feature, prompts, retrieved context, Customer Content excerpts, generated responses, or query strings may be processed by these providers.

5.1 Azure OpenAI

BriefBank uses Azure OpenAI for inference and embeddings. Microsoft acts as processor under the Microsoft Products and Services Data Protection Addendum. Data sent to Azure OpenAI is not used to train Microsoft, OpenAI, or third-party models, and the models are stateless for inference. By default, Azure OpenAI may retain a sample of prompts and outputs for up to 30 days for abuse monitoring; those logs are logically isolated and subject to human review only if flagged. BriefBank is not currently approved for modified abuse monitoring, so the default Azure OpenAI abuse-monitoring posture applies.

5.2 Anthropic Claude via Azure AI Foundry

BriefBank uses Anthropic Claude via Azure AI Foundry. For this processing, Anthropic — not Microsoft — is the processor under Anthropic's Commercial Terms and DPA, and it is not covered by Azure OpenAI zero-data-retention arrangements. Anthropic does not train on the data by default. Anthropic may retain data for limited operational and safety purposes for approximately 30 days, and flagged content may be retained longer under Anthropic's terms.

5.3 Perplexity web search

Perplexity web search is optional and off by default. If web search is enabled, only the model-formed Perplexity query string is sent to Perplexity; BriefBank does not send documents or chat history to Perplexity for web search. BriefBank calls Perplexity's Sonar API. Under Perplexity's published Zero Data Retention Policy for the Sonar API, Perplexity does not retain the query string, and Perplexity's API terms contractually prohibit using customer content to train models. Perplexity processes the query string under its API terms and auto-incorporated Data Processing Addendum.

5.4 Logging and telemetry transparency

BriefBank does not intentionally log document content. Console logs may retain truncated query fragments of up to 100 characters. PostHog analytics are numeric/ID allowlisted and do not include content. Application error and performance telemetry is captured through Azure Monitor / Application Insights within BriefBank's own Azure tenant; it is not sent to a third-party error-monitoring provider.

6. How we disclose information

We disclose information only as described in this Policy, the Terms, the DPA, and the Subprocessor List.

6.1 Service providers and subprocessors

We use service providers and subprocessors to operate BriefBank, including: Microsoft Azure (including Azure OpenAI, Container Apps hosting, and Azure PostgreSQL); Anthropic; Perplexity, if web search is enabled; PostHog for product analytics; a transactional email provider; and Stripe for billing. These providers process information to provide their services to BriefBank and are listed on the public Subprocessor List.

6.2 Customer organizations and administrators

If you use BriefBank through an organization or team, your organization and its administrators may be able to administer your account, manage users, roles, tiers, and billing, and access information associated with the organization according to BriefBank's roles, permissions, and customer configuration.

6.3 At the customer's direction

For Customer Content, we process and disclose information as instructed by the customer, including to authorized users and to the subprocessors needed to provide BriefBank.

6.4 Professional advisers

We may disclose information to lawyers, auditors, insurers, accountants, and other professional advisers where reasonably necessary for legal, compliance, risk-management, accounting, or business purposes.

6.5 Legal, safety, and compliance reasons

We may disclose information where we believe it necessary to comply with law, legal process, or government requests; protect the rights, property, or safety of BriefBank, customers, users, or others; investigate security incidents or abuse; or enforce our Terms.

6.6 Corporate transactions

We may disclose information in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, subject to appropriate protections for the information.

6.7 No sale or cross-context behavioral advertising

We do not sell personal data, and we do not share personal data for cross-context behavioral advertising.

7. Cookies and tracking in the product

The logged-in BriefBank product uses cookies or similar technologies that are necessary for authentication, session management, security, and operation of the application. Product analytics are limited to numeric/ID allowlisted telemetry and do not intentionally include Customer Content. The product does not use advertising cookies for cross-context behavioral advertising. Cookies and analytics on the public marketing website are addressed separately in the marketing-site Privacy & Cookie Notice.

8. Legal bases for GDPR/UK processing

Where GDPR or UK data protection law applies and BriefBank acts as controller, we rely on the following legal bases:

PurposeLegal basis
Account creation, authentication, organization administration, roles, tiers, and eligibility attestationPerformance of a contract; legitimate interests in operating and securing the product
Billing, subscriptions, renewals, and accountingPerformance of a contract; legal obligations; legitimate interests in payment administration and fraud prevention
Support and operational communicationsPerformance of a contract; legitimate interests in responding to requests and operating the service
Security, debugging, reliability, abuse prevention, and Terms enforcementLegitimate interests; legal obligations where applicable
Clickwrap assent logs and legal recordsPerformance of a contract; legitimate interests in maintaining enforceable records; legal obligations where applicable
Compliance with legal requests and dispute handlingLegal obligations; legitimate interests
Optional settings or processing where consent is required by lawConsent

For Customer Content and Derived Data processed on behalf of a customer, the customer is the controller and determines the applicable legal basis; BriefBank processes that information as processor under the customer's instructions and the DPA, where applicable.

9. Data retention and deletion

BriefBank retains information only as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted for legal, security, accounting, dispute-resolution, or compliance reasons.

9.1 Customer Content and Derived Data

Customer Content deletion is event-driven; BriefBank does not currently run a scheduled job that deletes Customer Content after a fixed period. When an account, library, document, or chat deletion is processed, BriefBank's deletion workflow is designed to purge associated database rows and embeddings across the control plane and data plane, and it is idempotent (safe to re-run). Because BriefBank does not retain original uploaded file bytes, there are no stored raw files to delete beyond those records. For paid tiers, Customer Content deletion requests are completed within 30 days; for Free-tier accounts, Customer Content is deleted promptly on account closure. BriefBank may close Free-tier accounts that have been inactive for three or more consecutive months, with at least 30 days' advance notice, as described in Section 5.3 of the Terms of Service; Customer Content is deleted on such closure as described above. Derived Data, including chunks and embeddings, is deleted with the related Customer Content.

9.2 Backups and provider logs

Deleted Customer Content may remain in backups until those backups are overwritten or expire in the ordinary backup cycle. AI-provider abuse, safety, or operational logs may persist according to the applicable provider terms, including the Azure OpenAI and Anthropic practices described in Section 5.

9.3 Controller-side records

Account, authentication, billing, subscription, usage, support, security, and legal/assent records may be retained as needed to operate BriefBank, comply with legal and accounting obligations, investigate security issues, resolve disputes, and enforce our Terms. Immutable clickwrap assent logs may be retained where necessary to maintain legal records.

10. Data residency and international transfers

Customer Content at rest is stored in the United States on Azure. Some AI model deployments used by BriefBank are Global or multi-region; as a result, inference prompts, context, and responses may be processed in regions outside the United States, while Customer Content storage at rest remains in the United States. Where GDPR or UK data protection law applies, international transfers are handled through the DPA, including Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable.

11. Security

BriefBank maintains technical and organizational measures designed to protect information processed through the product; more detail is available in the Security Overview. These measures include:

No security program can guarantee absolute security. Users and organizations are responsible for maintaining the confidentiality of their credentials, configuring access appropriately, and ensuring that Customer Content submitted to BriefBank is authorized for processing. Security-incident handling is addressed in the Terms and, where applicable, the DPA.

12. Your privacy rights

Your rights depend on where you live, the type of information involved, and whether BriefBank acts as controller/business or processor/service provider.

To exercise rights for information where BriefBank acts as controller, email info@aibriefbank.com with enough information to identify your account, organization, and request. We may need to verify your identity or authority before responding.

For Customer Content, BriefBank generally acts as processor/service provider on behalf of the customer. If your request concerns Customer Content controlled by a customer organization, direct the request to that customer; if we receive such a request directly, we will route or assist with it as required by law and the applicable customer agreement.

12.1 California privacy rights

If California privacy law applies, California residents may have the right to: know/access the categories and specific pieces of personal information collected; correct inaccurate personal information; delete personal information; obtain a portable copy of personal information; opt out of the sale or sharing of personal information; limit the use and disclosure of sensitive personal information, where applicable; and be free from discrimination for exercising privacy rights.

BriefBank does not sell personal information or share it for cross-context behavioral advertising, so no sale/share opt-out is necessary for current product processing. Because BriefBank does not sell or share product data for cross-context behavioral advertising, a Global Privacy Control signal does not change any product sale/share setting; we will treat legally recognized opt-out preference signals in accordance with applicable law. California residents may use an authorized agent to submit a request; we may require proof of authorization and may verify the request directly with you where permitted.

12.2 GDPR and UK privacy rights

If GDPR or UK data protection law applies and BriefBank acts as controller, you may have the right to: access your personal data; rectify inaccurate personal data; erase personal data; restrict processing; receive data portability; object to processing based on legitimate interests; withdraw consent where processing is based on consent; and lodge a complaint with a supervisory authority. Where BriefBank acts as processor for Customer Content, the customer/controller is responsible for responding to data-subject requests, and BriefBank assists the customer as required by the DPA.

13. Automated decision-making and AI output

BriefBank does not make solely automated legal decisions about users or clients that produce legal or similarly significant effects. BriefBank provides AI-assisted research and drafting functionality for professional legal users. AI-generated output may be incomplete, inaccurate, or unsuitable for a particular matter, and is not legal advice. Licensed attorneys and supervised legal staff are responsible for reviewing and validating all output before relying on it. See the Terms of Service for additional terms governing AI features.

14. Children and professional use only

BriefBank is not directed to children under 13 and is not a consumer service; it is designed for professional use by licensed attorneys and supervised legal staff. We do not knowingly collect controller-side account information from children under 13. If you believe a child has provided controller-side personal information to BriefBank, contact info@aibriefbank.com. If the information is contained in Customer Content, the relevant customer/controller is responsible for handling the request, and BriefBank will assist as required by the applicable agreement and law.

15. Changes to this policy

We may update this Product Privacy Policy as our practices or legal requirements change. The current version is the version posted for the BriefBank product. If we make material changes, we will provide notice by reasonable means, such as in-product notice, email, or another legally required method. For changes to clickwrap-governed documents, re-acceptance may be required in accordance with Section 15.3 of the Terms of Service. The marketing-site Privacy & Cookie Notice may be updated separately.

16. How to contact us and complaints

For privacy questions, requests, or complaints, contact Juris Intelligence, Inc. at info@aibriefbank.com. Registered agent for service of process: Corporation Service Company, 251 Little Falls Drive, Wilmington, DE 19808.

If GDPR or UK data protection law applies, you may also have the right to lodge a complaint with your local supervisory authority. We encourage you to contact us first so we can try to resolve the issue.