Legal

DocketBuddy Privacy Policy

Effective: July 13, 2026

Version: 2026-07-13

Buddy Financial LLC does business as DocketBuddy. It operates docketbuddy.org, public tools, the attorney workspace, client portals, and related services. This policy explains what information we handle and why. It also explains when we share it and the choices available to users.

For attorney account information and public-site data, Buddy Financial is the business or controller. A law firm controls the client and matter data it enters. Buddy Financial is the firm's service provider or processor. We follow the firm's lawful instructions for that data.

1. Information we collect

We collect only the categories needed for the selected service:

Account and firm information

This includes a name, email, phone number, firm name, mailing address, and bar number. It also includes jurisdiction, role, preferences, and account activity.

Authentication and security information

This includes password credentials managed by our sign-in provider and multi-factor settings. It also includes sign-in records, IP address, device and browser data, and security events.

Billing information

This includes subscription, invoice, payment status, and transaction details. Payment providers process full card and bank-account numbers. DocketBuddy does not store full payment-card numbers.

Client and matter information

This includes names, contact details, case numbers, deadlines, notes, and messages. It also includes court or agency records, intake answers, documents, evidence, and work product.

Immigration information

This includes USCIS receipt numbers, case status and history, form data, and immigration status. It may also include biographical details, employment, education, and supporting evidence.

Financial and property information

This includes income, expenses, debts, tax details, and bank or trust-account records. It may also include assets, property, benefits, invoices, and payment history.

Health and medical information

This includes medical records, diagnoses, treatment history, and disability or injury details. It may also include functional limits and related evidence that a user chooses to provide.

Family and relationship information

This includes household members, dependents, marital or custody details, and family history. It may also include contacts and other people named in a matter. We collect genetic details only if a user chooses to provide them.

Files, communications, and generated content

This includes uploaded files, messages sent through connected features, and call or intake notes. It also includes AI prompts, AI-assisted drafts, summaries, and user feedback.

Usage and device information

This includes pages and features used, an approximate location based on IP address, and timestamps. It also includes referring pages, error records, and performance data. We do not collect precise device location or address-book contacts by default.

Connected-service information

This includes tokens and identifiers needed for a connection the user chooses. It may also include calendar events, billing records, or matter details needed for that connection.

Information comes from users and their authorized firm staff or clients. It may also come from a connected service, a public court or agency source, or normal website use. Do not provide information about another person unless you have authority to do so.

2. How we use information

  • Provide authentication, client intake, matter management, document storage, deadlines, billing, communications, and support.
  • Retrieve USCIS, EOIR, court, and other official information requested by a user.
  • Generate user-requested drafts, analyses, summaries, and search results. AI output remains subject to attorney review.
  • Process payments and operate integrations that the user chooses to connect.
  • Secure the service, prevent abuse, investigate errors, keep audit records, and meet legal obligations.
  • Improve reliability and usability through limited operational measurements and user feedback.

We do not use client or matter data to train a third party's general AI model. We do not use that data to serve other customers or for advertising.

3. De-identified and aggregated information

We may create aggregated or de-identified measurements for security, reliability, capacity planning, and product quality. We remove direct identifiers and do not try to re-identify this information. We do not sell it or provide it to marketers.

A provider may process de-identified information only for the limited service it performs for us. The provider must not re-identify it. The provider must not use it for an unrelated purpose or disclose it without the user's active consent.

4. Service providers and integrations

Information is shared only as needed with these entities:

  • Supabase: authentication, database, and private file storage.
  • Railway and Vercel: backend and website hosting, delivery, and operational logs.
  • Anthropic and Voyage AI: AI-assisted drafts, analysis, and document search for features a user chooses to run.
  • Stripe and LawPay/AffiniPay: subscription, invoice, and payment processing.
  • Resend, Twilio, and Telnyx: transactional email, text messages, and account notices when those channels are enabled.
  • Sentry: error detection, security diagnostics, and reliability monitoring.
  • Microsoft Clarity and Vercel Analytics: usage analytics on public marketing pages and the no-signup demo; signed-in attorney workspaces are excluded from Clarity session replay.
  • USCIS and EOIR: official immigration case-status and agency information requested by the user.
  • CourtListener/RECAP and PACER-related services: court and docket information requested through bankruptcy and litigation features.
  • Google Calendar, Clio, QuickBooks, DocuSign, and other user-connected integrations: the specific calendar, practice-management, accounting, signature, or workflow function the user authorizes.

Service providers are bound by contract or binding provider terms. They must protect information and use it only for the service described here. They may not independently use or disclose personal, pseudonymized, anonymized, or de-identified user information for another reason. That use or disclosure requires active user consent. Government sources and user-directed integrations also have their own terms.

5. No sale, advertising share, or monetary transfer

We do not sell personal information, client data, matter data, or de-identified data. We do not exchange it for money or any other valuable consideration. We have not sold this information in the preceding 12 months. We do not share personal information for cross-context behavioral advertising. We do not provide it to data brokers, marketers, or ad networks.

6. Your data-sharing choices

  • Required processing: Hosting, authentication, security, and storage are necessary to operate an account. The account cannot operate without them.
  • Optional integrations: A user chooses whether to connect services such as Clio, Google Calendar, QuickBooks, DocuSign, or LawPay. The user may disconnect them in account settings.
  • Agency and court lookups: We send a receipt number or case ID to the selected official source. We do so only when the user requests a lookup or turns on monitoring.
  • Communications: Users may manage optional email and text preferences. Security, billing, and account notices cannot be disabled while an account is open.
  • New uses: We will request active consent before disclosing information for a materially different purpose.

Sharing can make status checks, calendars, payments, and case work faster. It also gives another provider the minimum information needed to perform that task. Disabling a connection reduces that exposure, but the connected feature will stop working or become less useful.

7. Information about other people

Legal matters may contain information about clients, relatives, or dependents. They may also name medical providers, witnesses, opposing parties, or other contacts. Sharing family history, health information, or genetic information can reveal facts about relatives. It can also reveal facts about the person named in the record.

The person or firm entering that information must consider those effects and obtain any required permission. A provider or other third party may not reuse or disclose it for an unrelated reason. That use requires active consent from the affected user or the lawful controller.

8. Security and breach notice

We use encryption in transit and at rest. We also use tenant-level database controls, sign-in checks, optional multi-factor authentication, access limits, monitoring, backups, and secret controls. No system can guarantee perfect security.

If we confirm a breach that affects a user's information, we will give notice as required by law. We will do so without unreasonable delay. The notice will explain what happened, the information involved and the steps we took. It will list actions the user should consider and how to contact us. We will also notify law firms when their client or matter data is affected so they can meet their own duties.

9. Retention, dormant accounts, and deletion

Account and matter information is retained while the account is open, including when an open account is dormant. We do not delete an open account solely because the user has not signed in. This lets law firms maintain continuity and meet record-keeping duties.

A user may permanently close an account at any time. In the attorney workspace, open Settings, choose Security, and select Delete account. Confirm the account email, enter DELETE, and accept the deletion warning. A user may also emailhello@docketbuddy.org.

The account is disabled when the request is submitted. The user has seven days to cancel through support. Permanent deletion runs within 24 hours after that period, so deletion is completed within eight days of the request. It removes the authentication account and client or matter records. It also removes stored files, connection tokens, and other account-linked data.

Before requesting deletion, the user must export records that professional rules require the user to keep. The user must also return or transfer any client trust funds. We may retain a minimal record only when law requires it. We may also keep a minimal record to prove deletion, prevent fraud, resolve a dispute, or enforce an agreement. Such records are isolated, not used for the service, minimized, and deleted when the legal need ends.

10. Business closure, sale, or change of ownership

We will notify users before client or matter information is transferred. This applies to a sale, merger, closure, or change of control. A successor must agree in writing to protections that align with this policy. We will not transfer the information for a materially different use without active consent.

Before a transfer, users will be offered a reasonable way to export their information or request permanent deletion. Health and medical information may be securely downloaded or destroyed. It may also be sent to a destination chosen by the lawful controller. We will notify users when the ownership change takes effect and identify the new responsible entity.

11. Privacy rights and California rights

Users may ask to know, access, correct, or export their personal information. They may request deletion or limit use of sensitive information. They may also object to a sale or advertising share. We do not sell or share information for advertising. We will not discriminate against a user for exercising a privacy right.

These choices are available whether or not the California Consumer Privacy Act currently applies to Buddy Financial. California residents may also use an authorized agent and may appeal a denied request by replying to our decision. We honor browser-based opt-out signals when applicable. This includes Global Privacy Control, even though we do not sell or share data for advertising.

Submit a request through account settings, emailhello@docketbuddy.org, or write to the address below. We verify requests to protect the account. We respond within the time required by applicable law and explain any request we cannot complete.

12. Material policy and terms changes

We show registered users a plain-language summary before a material privacy policy or terms change takes effect. The user must open the notice and check an acceptance box. The user must then select Accept and continue. We record the policy versions and acceptance time. Continued use alone is not treated as active consent to a material change.

A user who does not accept may stop using the service and request export or deletion. Minor changes, such as correcting a typo or updating contact details, may be posted without a new acceptance request.

13. Children

DocketBuddy accounts and public tools are not directed to children under 18. A legal matter may contain information about a minor. An authorized adult or legal professional must provide it for that matter.

14. Contact

Buddy Financial LLC, d/b/a DocketBuddy
1445 Woodmont Ln NW #613
Atlanta, GA 30318
hello@docketbuddy.org

See the DocketBuddy Terms of Service.