Legal
DocketBuddy Privacy Policy
Effective: August 15, 2026
Version: 2026-08-15
Buddy Labs LLC does business as DocketBuddy. It operates docketbuddy.org, public tools, the attorney workspace, client portals, and related services. This policy explains what information we handle and why. It also explains when we share it and the choices available to users.
For attorney account information and public-site data, Buddy Labs is the business or controller. A law firm controls the client and matter data it enters. Buddy Labs is the firm's service provider or processor. If an authorized staff member opens or pays for a Ready account, the firm or legal-services organization responsible for the matter still controls that client and matter data. We follow its lawful instructions for that data.
1. Information we collect
We collect only the categories needed for the selected service:
Account and firm information
This includes a name, email, phone number, firm name, mailing address, and bar number. It also includes jurisdiction, role, preferences, and account activity.
Authentication and security information
This includes password credentials managed by our sign-in provider and multi-factor settings. It also includes sign-in records, IP address, device and browser data, and security events.
Billing information
This includes subscription, invoice, payment status, and transaction details. Payment providers process full card and bank-account numbers. DocketBuddy does not store full payment-card numbers.
Client and matter information
This includes names, contact details, case numbers, deadlines, notes, and messages. It also includes court or agency records, intake answers, documents, evidence, and work product.
Immigration information
This includes USCIS receipt numbers, case status and history, form data, and immigration status. It may also include biographical details, employment, education, and supporting evidence.
Financial and property information
This includes income, expenses, debts, tax details, and bank or trust-account records. It may also include assets, property, benefits, invoices, and payment history.
Health and medical information
This includes medical records, diagnoses, treatment history, and disability or injury details. It may also include functional limits and related evidence that a user chooses to provide.
Family and relationship information
This includes household members, dependents, marital or custody details, and family history. It may also include contacts and other people named in a matter. We collect genetic details only if a user chooses to provide them.
Files, communications, and generated content
This includes uploaded files, messages sent through connected features, and call or intake notes. It also includes AI prompts, AI-assisted drafts, summaries, and user feedback.
Usage and device information
This includes pages and features used, an approximate location based on IP address, and timestamps. It also includes referring pages, error records, and performance data. We do not collect precise device location or address-book contacts by default.
Connected-service information
This includes tokens and identifiers needed for a connection the user chooses. It may also include calendar events, billing records, or matter details needed for that connection.
Information comes from users and their authorized firm staff or clients. It may also come from a connected service, a public court or agency source, or normal website use. Do not provide information about another person unless you have authority to do so.
2. How we use information
- Provide authentication, client intake, matter management, document storage, deadlines, billing, communications, and support.
- Retrieve USCIS, EOIR, court, and other official information requested by a user.
- Generate user-requested drafts, analyses, summaries, and search results. AI output remains subject to attorney review.
- Process payments and operate integrations that the user chooses to connect.
- Secure the service, prevent abuse, investigate errors, keep audit records, and meet legal obligations.
- Improve reliability and usability through limited operational measurements and user feedback.
We do not use client or matter data to train a third party's general AI model. We do not use that data to serve other customers or for advertising.
3. De-identified and aggregated information
We may create aggregated or de-identified measurements for security, reliability, capacity planning, and product quality. We remove direct identifiers and do not try to re-identify this information. We do not sell it or provide it to marketers.
Provider handling of aggregated or de-identified information depends on the applicable service terms. The provider-specific limits below also apply to this information; removing identifiers does not establish training exclusion or zero retention.
4. Service providers and integrations
Information is shared only as needed with these entities:
- Supabase: Authentication, database, and private file storage. Account, firm, client, matter, and stored-file data needed to operate the workspace. Relationship: required service provider.
- Railway: Backend application hosting and delivery. Requests sent to the backend, response metadata, and operational logs. Relationship: required service provider.
- Vercel: Website hosting and delivery. Web requests, delivery metadata, and operational logs. Relationship: required service provider.
- Anthropic: Selected AI-assisted analysis, drafting, and Preflight extraction. The prompts, client or matter context, and authorized document text needed for the feature the user runs. Relationship: selected feature or integration.
- Google Gemini API: Ready document and public voicemail processing. Authorized Ready files or public voicemail audio and the instructions needed for the requested classification, extraction, transcription, or file-quality work. Relationship: selected feature or integration.
- Resend: Transactional email and account notices. Recipient addresses, names, delivery metadata, and email content. Relationship: required service provider.
- Stripe: Subscription and invoice processing. Account billing details, payment status, and transaction records; DocketBuddy does not store full payment-card numbers. Relationship: required service provider.
- Sentry: Error detection, security diagnostics, and reliability monitoring. Error and performance reports. The main application removes request bodies, cookies and authorization headers; worker diagnostics may still contain filenames, storage paths and account identifiers.. Relationship: required service provider.
- Voyage AI: Search within material a firm deliberately adds to its knowledge base. Knowledge-base text and the search terms entered in that feature; structured client records and ordinary client-file uploads are not added automatically. Relationship: selected feature or integration.
- Twilio and Telnyx: Text messaging when a firm enables that channel. Sender and recipient phone numbers, message content, and delivery metadata. Relationship: selected feature or integration.
- LawPay/AffiniPay: Firm-enabled client payment processing. Payer, invoice, payment, and transaction details needed for the payment the user authorizes. Relationship: selected feature or integration.
- DocuSign: Electronic signatures when a firm connects the integration. Documents sent for signing, signer name and email address, and envelope status. Relationship: selected feature or integration.
- Google Calendar, Clio, and QuickBooks: Calendar, practice-management, and accounting functions a user chooses to connect. Connection tokens and the specific calendar, matter, contact, invoice, or accounting data needed for the authorized action. Relationship: selected feature or integration.
- Microsoft Clarity and Vercel Analytics: Limited usage and performance analytics on public marketing pages and the no-signup demo. Public-page interaction, referral, device, and performance data; signed-in attorney workspaces are excluded from Clarity session replay. Relationship: public-site analytics.
- USCIS and EOIR: Official immigration case-status and agency information requested by a user. The receipt number, case identifier, or credentials needed for the lookup or monitoring the user requests. Relationship: user-directed source.
- CourtListener/RECAP and PACER-related services: Court and docket information requested through bankruptcy and litigation features. The docket number, court identifier, search terms, or connected-service credentials needed for the requested court-data action. Relationship: user-directed source.
Provider contracts and terms govern their processing. Anthropic’s commercial API and Google’s paid Gemini API exclude submitted data from general model training. We have not confirmed Voyage’s production training setting and cannot promise training exclusion or zero retention for knowledge-base documents or searches. Use non-confidential reference material only for that feature. The retention table below describes the current limits. Government sources and user-directed integrations have their own terms.
5. No sale, advertising share, or monetary transfer
We do not sell personal information, client data, matter data, or de-identified data. We do not exchange it for money or any other valuable consideration. We have not sold this information in the preceding 12 months. We do not share personal information for cross-context behavioral advertising. We do not provide it to data brokers, marketers, or ad networks.
6. Your data-sharing choices
- Required processing: Hosting, authentication, security, and storage are necessary to operate an account. The account cannot operate without them.
- Optional integrations: A user chooses whether to connect services such as Clio, Google Calendar, QuickBooks, DocuSign, or LawPay. The user may disconnect them in account settings.
- Agency and court lookups: We send a receipt number or case ID to the selected official source. We do so only when the user requests a lookup or turns on monitoring.
- Communications: Users may manage optional email and text preferences. Security, billing, and account notices cannot be disabled while an account is open.
- New uses: We will request active consent before disclosing information for a materially different purpose.
Sharing can make status checks, calendars, payments, and case work faster. It also gives another provider the minimum information needed to perform that task. Disabling a connection reduces that exposure, but the connected feature will stop working or become less useful.
7. Information about other people
Legal matters may contain information about clients, relatives, or dependents. They may also name medical providers, witnesses, opposing parties, or other contacts. Sharing family history, health information, or genetic information can reveal facts about relatives. It can also reveal facts about the person named in the record.
The person or firm entering that information must consider those effects and obtain any required permission. Provider processing is subject to the terms and limitations described above, including the unresolved knowledge-base training setting.
8. Security and breach notice
We use encryption in transit and at rest. We also use tenant-level database controls, sign-in checks, optional multi-factor authentication, access limits, monitoring, backups, and secret controls. No system can guarantee perfect security.
If we confirm a breach that affects a user's information, we will give notice as required by law. We will do so without unreasonable delay. The notice will explain what happened, the information involved and the steps we took. It will list actions the user should consider and how to contact us. We will also notify law firms when their client or matter data is affected so they can meet their own duties.
9. Retention, dormant accounts, and deletion
Account and matter information is retained while the account is open, including when an open account is dormant. We do not delete an open account solely because the user has not signed in. This lets law firms maintain continuity and meet record-keeping duties.
Retention by record and provider path
A DocketBuddy deletion and a provider-controlled retention window are separate events.
Browser workpapers and the public Ready file checker
- DocketBuddy
- Entered facts and checked files stay in page memory. They are not uploaded or included in analytics.
- Provider
- No content processor receives the entered facts or checked file.
- Deletion
- Resetting or closing the page clears that page state. A Preflight destination and completeness score, not the entered facts, may remain in same-tab session storage until used or the tab session ends.
Public Ready voicemail
- DocketBuddy
- The backend holds the recording in memory for the request and does not save the recording or transcript.
- Provider
- Google may retain the prompt, context, and output for up to 55 days for abuse monitoring under its paid Gemini API terms.
- Deletion
- DocketBuddy has no stored copy after the request. Google controls its published abuse-monitoring window.
Signed-in Ready, Preflight, and matter files
- DocketBuddy
- Original files and saved workspace results remain while the account is open unless the user deletes the file, Preflight, or matter sooner.
- Provider
- A selected AI feature can create a separate provider-controlled copy for the limited windows described below.
- Deletion
- Item deletion removes the governed stored object and its linked record. Account deletion removes account-linked files and records within eight days of the request, subject to the limited exceptions below.
Anthropic API inputs and outputs
- DocketBuddy
- A saved result remains with the workspace record until that record or the account is deleted.
- Provider
- Anthropic documents deletion within 30 days for standard API inputs and outputs, with published exceptions for safety enforcement, legal obligations, feedback, and separately controlled services.
- Deletion
- Deleting the DocketBuddy record removes DocketBuddy's copy. Anthropic controls its published provider-retention window.
Google Gemini API prompts, context, files, and outputs
- DocketBuddy
- Signed-in feature results can remain with the workspace record. DocketBuddy deletes its temporary Gemini Files API upload after processing.
- Provider
- Google documents up to 55 days for prompt, context, and output abuse-monitoring logs for the paid Gemini API. Other selected Gemini features can have separate published storage behavior.
- Deletion
- Deleting the DocketBuddy record removes DocketBuddy's saved copy. Google controls its published provider-retention window.
Firm knowledge-base text and Voyage embeddings
- DocketBuddy
- Knowledge-base records and embeddings are stored in the firm workspace. Search questions, generated answers and citation previews are also saved separately as search history.
- Provider
- We have not confirmed the production Voyage organization’s training-data opt-out setting. We cannot currently promise zero retention or training exclusion for knowledge-base documents and search text. Do not add confidential material to this feature until that setting is confirmed.
- Deletion
- Item deletion requests removal of the stored file and embeddings. Saved search history is separate and is not removed by deleting an item. Contact support for help with failed removal or search-history deletion.
Operational, analytics, and error logs
- DocketBuddy
- Operational records may include account identifiers, request metadata, filenames and diagnostic details used for security, reliability and support.
- Provider
- Hosting, monitoring and analytics providers retain operational records separately from workspace files. We have not confirmed a retention period for every production provider.
- Deletion
- We cannot currently promise one deletion deadline for these records. Contact support for the status of a specific deletion request.
Billing and connected-service records
- DocketBuddy
- DocketBuddy keeps account-linked billing status, integration tokens, and transaction references while needed to operate the account.
- Provider
- Payment and integration providers retain their records under their own terms and legal obligations.
- Deletion
- Account deletion removes DocketBuddy connection tokens and reusable payment methods. Providers may retain transaction or compliance records they are legally required to keep.
Account deletion receipt and documented exceptions
- DocketBuddy
- The account is disabled when deletion is requested. Permanent deletion runs after the seven-day cancellation period and completes within eight days. A de-identified deletion receipt and a minimal documented legal, fraud, security, or dispute record may remain only while needed.
- Provider
- A provider may retain a corresponding minimal record when its terms or legal obligations require it.
- Deletion
- Retained exceptions are isolated from product use, minimized, and removed when the documented need ends.
A user may permanently close an account at any time. In the attorney workspace, open Settings, choose Security, and select Delete account. Confirm the account email, enter DELETE, and accept the deletion warning. A user may also emailhello@docketbuddy.org.
The account is disabled when the request is submitted. The user has seven days to cancel through support. Permanent deletion runs within 24 hours after that period, so deletion is completed within eight days of the request. It removes the authentication account and client or matter records. It also removes stored files, connection tokens, and other account-linked data.
Before requesting deletion, the user must export records that professional rules require the user to keep. The user must also return or transfer any client trust funds. We may retain a minimal record only when law requires it. We may also keep a minimal record to prove deletion, prevent fraud, resolve a dispute, or enforce an agreement. Such records are isolated, not used for the service, minimized, and deleted when the legal need ends.
10. Business closure, sale, or change of ownership
We will notify users before client or matter information is transferred. This applies to a sale, merger, closure, or change of control. A successor must agree in writing to protections that align with this policy. We will not transfer the information for a materially different use without active consent.
Before a transfer, users will be offered a reasonable way to export their information or request permanent deletion. Health and medical information may be securely downloaded or destroyed. It may also be sent to a destination chosen by the lawful controller. We will notify users when the ownership change takes effect and identify the new responsible entity.
11. Privacy rights and California rights
Users may ask to know, access, correct, or export their personal information. They may request deletion or limit use of sensitive information. They may also object to a sale or advertising share. We do not sell or share information for advertising. We will not discriminate against a user for exercising a privacy right.
These choices are available whether or not the California Consumer Privacy Act currently applies to Buddy Labs. California residents may also use an authorized agent and may appeal a denied request by replying to our decision. We honor browser-based opt-out signals when applicable. This includes Global Privacy Control, even though we do not sell or share data for advertising.
Submit a request through account settings, emailhello@docketbuddy.org, or write to the address below. We verify requests to protect the account. We respond within the time required by applicable law and explain any request we cannot complete.
12. Material policy and terms changes
We show registered users a plain-language summary before a material privacy policy or terms change takes effect. The user must open the notice and check an acceptance box. The user must then select Accept and continue. We record the policy versions and acceptance time. Continued use alone is not treated as active consent to a material change.
A user who does not accept may stop using the service and request export or deletion. Minor changes, such as correcting a typo or updating contact details, may be posted without a new acceptance request.
13. Children
DocketBuddy accounts and public tools are not directed to children under 18. A legal matter may contain information about a minor. An authorized adult or legal professional must provide it for that matter.
14. Contact
Buddy Labs LLC, d/b/a DocketBuddy
1445 Woodmont Ln NW #613
Atlanta, GA 30318
hello@docketbuddy.org
See the DocketBuddy Terms of Service.