1. Who this policy applies to
This Privacy Policy applies to the public LegalTrust website, mobile experience, report dashboard, admin-support workflow and related customer notifications.
2. Privacy design commitment
- Source documents are processed temporarily for the selected task.
- Source documents are designed to be deleted after report generation or abandoned-session expiry.
- Generated legal-report content is temporary delivery material and is automatically deleted after the configured short delivery window. Non-content My Reports metadata, invoices, payment metadata, consent records, support/audit logs and account metadata may be retained for customer support, payment reconciliation, security and tax compliance.
- Uploaded legal documents are not to be used for public AI-model training by LegalTrust.
- Personal data is not sold.
3. Legal framework
LegalTrust is intended to align with applicable Indian data-protection, information-technology, consumer, payment and tax requirements, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as applicable to the service workflow.
Where a requirement is not yet applicable to a specific feature, the LegalTrust operator may still adopt privacy-by-design controls as a contractual product commitment.
4. Data we process
| Category | Examples | Purpose |
|---|---|---|
| Uploaded content | Judgments, petitions, notices, agreements, scanned PDFs, names/facts inside files | Temporary OCR, AI analysis, translation, source/citation review and PDF report generation |
| Processing metadata | Temporary file name, size, extension, page count, language, timestamps, hashes, selected product | Run pre-scan, calculate price, troubleshoot, prevent abuse and audit deletion. Original filenames are not intended to remain in persistent post-processing records. |
| Account/contact data | Name, mobile number, optional email, billing State / UT, account ID | OTP verification, report access, customer support, notifications and invoices |
| Payment and GST data | Order ID, payment ID, invoice number, amount, tax split, gateway status | Payment processing, reconciliation, refunds, accounting and statutory records |
| Technical/security data | IP address, user agent, rate-limit events, admin actions, error logs | Security, abuse prevention, debugging and audit |
| Generated reports | Temporary HTML/JSON/PDF report during the delivery window | Screen preview, download and print during the short delivery window; report content is then deleted while non-content transaction/status metadata may remain |
5. How source documents are handled
The source document is stored only in the secure runtime processing area. After the report is generated, the product is designed to delete the uploaded source file and temporary extraction artefacts. The generated report remains available only for the configured short delivery window; non-content operational/payment/consent records may remain as described below.
6. AI/OCR and legal-source providers
Depending on configuration, the service may send extracted text, rendered page images or limited reference text to selected AI/OCR/legal-source providers solely to create the requested report or source check. Production must use approved providers, secrets management, contractual safeguards and provider settings that prevent use of customer documents for public model training where available.
7. Retention schedule
| Record type | Default retention approach | Reason |
|---|---|---|
| Uploaded source document | Deleted after report generation or abandoned-session expiry | Zero source-document retention |
| Temporary OCR/extraction artefacts | Deleted after report generation or cleanup window | Processing only |
| Generated legal-report content (HTML/JSON/PDF) | Temporary delivery window (default local build: 30 minutes), then automatically deleted | Screen preview, download and print without persistent legal-content archiving |
| Payment/order/invoice records | Retained as required for tax, accounting, payment and legal obligations | Compliance and reconciliation |
| OTP/auth sessions | Short expiry plus cleanup | Access control and fraud prevention |
| Admin/audit/security logs | Limited security/audit retention | Abuse prevention and accountability |
8. User choices and rights
- Users may avoid paid processing by stopping after free pre-scan.
- Users may request report deletion through the Data Deletion Policy process.
- Users may request correction of account/contact details where supported.
- Users may withdraw optional notification channels where available.
- Some records cannot be deleted immediately where tax, payment, security, fraud-prevention or legal retention obligations apply.
9. Cookies and local storage
The web/mobile experience may use essential browser storage for language preference, session flow, security state and UI continuity. Production analytics or marketing cookies should not be enabled without an updated cookie notice and consent approach where required.
10. Security
Security controls include HTTPS in production, restricted report access tokens, OTP-protected My Reports, admin login/roles, audit logging, rate limiting, upload limits, file-type checks and optional malware scanning. No online service can guarantee perfect security.
11. Children and sensitive content
LegalTrust is not designed for children to use directly. Do not upload documents containing protected identities, sealed records, child-sensitive information or highly sensitive personal data unless you have lawful authority and have removed unnecessary details.
12. Contact and grievance
Production must publish the verified LegalTrust support email, grievance officer/contact route, registered office and expected response timelines. Until configured, policy pages should not be treated as final public legal notices.