Privacy Policy

MedLegal AI Suite — medicalai.law

Medicolegal Intelligence LLC

Last Updated: March 14, 2026

Effective Date: March 14, 2026




1. Introduction


Medicolegal Intelligence LLC ("Company," "we," "us," or "our") is committed to protecting the privacy and security of the information entrusted to us by users of the MedLegal AI Suite ("Service"), available at medicalai.law. This Privacy Policy explains how we collect, use, store, share, and protect information when you access or use our Service.


This Policy applies to all users of the Service, including licensed attorneys and physicians. It is intended to comply with applicable privacy laws, including the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and to reflect our obligations as a potential Business Associate under the Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA").


By using the Service, you agree to the practices described in this Privacy Policy.


Questions? Contact us at: [email protected]




2. Information We Collect


We collect the following categories of information:


2.1 Account and Registration Information

When you create an account, we collect:


2.2 Uploaded Documents and User Content

To provide AI-assisted analysis, you may upload documents, medical records, case files, expert reports, and other materials ("User Content"). This may include:


Important — Transient Processing of Medical Records: Uploaded medical records and documents containing protected health information ("PHI") are processed transiently. Unless you explicitly choose to save a case within the Service, uploaded documents are not retained on our servers beyond your active session. When you end a session without saving, uploaded files are deleted from processing memory and temporary storage. If you save a case, User Content associated with that case is retained in your account until you delete it or terminate your account.


2.3 Usage Data and Log Information

We automatically collect certain information about your interaction with the Service, including:


2.4 Communications

If you contact us via email, chat, or support ticket, we retain those communications to assist you and improve our Service.


2.5 Cookies and Tracking Technologies

We use cookies and similar technologies (e.g., local storage, session tokens) for authentication, session management, security, and to understand how users interact with the Service. You can manage cookie preferences through your browser settings; disabling certain cookies may affect Service functionality.




3. How We Use Your Information


3.1 To Provide and Operate the Service


3.2 To Improve and Develop the Service


3.3 AI Training Limitations

We do not use your User Content, uploaded medical records, or case-specific AI prompts and outputs to train or fine-tune AI models without your explicit written consent. Aggregated, fully de-identified, and anonymized metadata (e.g., query volume, feature usage frequency) may be used for product improvement purposes.


3.4 To Communicate with You


3.5 Legal and Safety Purposes




4. Data Storage and Security


4.1 Storage Infrastructure

User Content and account data are stored using Amazon Web Services (AWS) Simple Storage Service (S3), a cloud storage service maintained by Amazon Web Services, Inc. We have entered into a Data Processing Agreement with AWS consistent with applicable law.


4.2 Encryption


4.3 Transient Processing

Documents not saved to a case are processed in memory and temporary storage during your session only. Upon session termination, such data is purged from active processing environments. We implement technical controls designed to ensure such purging occurs in a timely manner.


4.4 Security Measures

We implement administrative, technical, and physical safeguards designed to protect your information, including:


4.5 No Absolute Guarantee

No security measure is 100% effective. We cannot guarantee that unauthorized third parties will never be able to defeat our security measures.




5. How We Share Your Information


We do not sell your personal information. We do not sell, rent, or trade your personal data or User Content to third parties for monetary or other valuable consideration.


We may share your information only in the following limited circumstances:


5.1 Service Providers and Subprocessors

We use vetted third-party service providers to help us operate the Service. These providers are contractually bound to use your information only as directed by us and in accordance with applicable law. Key subprocessors include:


| Subprocessor | Purpose | Location |

|---|---|---|

| Amazon Web Services (AWS S3) | Cloud storage and infrastructure | United States |

| Anthropic, PBC | AI model API (text analysis and generation) | United States |

| Stripe, Inc. (or similar) | Payment processing | United States |


Note on Anthropic API: AI prompts and associated content submitted to the Service may be processed by Anthropic's API. We have executed appropriate data processing agreements with Anthropic. Anthropic's use of data submitted through the API is governed by Anthropic's enterprise data processing terms, which provide that data submitted via API is not used to train models by default.


5.2 Legal Requirements

We may disclose your information if required to do so by law, subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to: (a) comply with applicable law; (b) protect the safety of any person; (c) prevent fraud or abuse; or (d) protect the Company's legal rights.


5.3 Business Transfers

If we are involved in a merger, acquisition, financing, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Service before your information is transferred and becomes subject to a different privacy policy.


5.4 With Your Consent

We may share your information with third parties when you have given us explicit consent to do so.




6. HIPAA Considerations


6.1 Business Associate Role

When you upload PHI to the Service pursuant to a valid, executed Business Associate Agreement ("BAA"), the Company acts as a Business Associate under HIPAA. In that capacity, we use and disclose PHI only as permitted by the BAA and applicable law.


6.2 No PHI Without BAA

If you have not executed a BAA with the Company, you must not upload PHI to the Service. This Privacy Policy does not constitute a BAA.


6.3 De-identified Information

De-identified health information that does not meet the HIPAA definition of PHI is treated as non-PHI under this Policy and may be processed according to the general terms of this Policy.




7. California Privacy Rights (CCPA/CPRA)


This Section 7 applies to California residents.


7.1 Categories of Personal Information Collected

In the preceding 12 months, we have collected the following categories of personal information (as defined under the CCPA):


We do not knowingly collect Sensitive Personal Information beyond what is necessary to provide the Service (including professional license credentials, which may be treated as sensitive under applicable law).


7.2 Purposes for Collection

As described in Section 3 above.


7.3 No Sale or Sharing for Cross-Context Behavioral Advertising

We do not sell personal information. We do not share personal information for cross-context behavioral advertising purposes.


7.4 Your California Rights

California residents have the right to:


7.5 How to Submit a Request

Submit a verifiable consumer request by emailing [email protected] with the subject line "California Privacy Request." We will respond within 45 days (extendable by an additional 45 days with notice).




8. Data Retention


| Data Type | Retention Period |

|---|---|

| Account information | Duration of account plus 3 years after closure |

| Saved case files and User Content | Until you delete the case or close your account |

| Unsaved uploaded documents (transient) | Session duration only; purged upon session end |

| Usage and log data | 12 months rolling |

| Billing records | 7 years (legal/tax compliance) |

| Support communications | 3 years |


Upon account deletion, we will delete or anonymize your personal information within 90 days, except where retention is required by law.




9. Children's Privacy


The Service is intended solely for licensed professionals and is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we learn we have collected information from a minor, we will delete it promptly.




10. International Users


The Service is operated in the United States. If you access the Service from outside the United States, you acknowledge that your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those in your jurisdiction.




11. Third-Party Links


The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any information to them.




12. Changes to This Policy


We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (at the address on file) or by prominent notice on the Service at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.




13. Contact Us


If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:


Medicolegal Intelligence LLC

Email: [email protected]

Website: medicalai.law


We will respond to privacy inquiries within 30 days.




© 2026 Medicolegal Intelligence LLC. All rights reserved.