Privacy Architecture

Built for the standards your clients expect.

Your documents, prompts, and AI responses are never stored or logged on our servers. Choose the privacy configuration that fits your practice.

0
documents, prompts, or responses stored
256-bit
AES-256-GCM client-side encryption
100%
document processing on your device

Three routes to the AI. You choose how private.

Document processing always happens on your device. What differs is how the AI request travels. With your own key it goes straight to the provider and we're never in the path. On AI-included plans it passes through our relay, which streams and discards it. With a firm-hosted gateway it routes through your firm's own relay, on your infrastructure.

BRING YOUR OWN KEY Your device client-side · encrypted direct · your key we are not in the path AI provider the model you choose AI INCLUDED (PLATFORM / FREE) Your device client-side · encrypted inchambers relay pass-through · fire-and-forget streamed, then discarded AI provider pooled subscription ENTERPRISE (FIRM-HOSTED GATEWAY) Your device client-side · encrypted Your firm's gateway single-tenant · your infrastructure your firm is in the path, not us AI provider your firm's credentials

To be clear: on AI-included plans, your request does pass through our relay, so we are in the request path for those plans. The relay is pass-through and fire-and-forget. It is never stored, never logged, and never used for training. For zero involvement on our side, bring your own key or run a firm-hosted gateway.

What we never do.

Privacy by architecture, not by policy. Whichever route your AI request takes, these three never change.

Never store documents

Your documents are never written to our servers. Content is processed transiently and discarded.

Never log content

We don't log prompts, documents, or AI responses. Only anonymous usage analytics.

Never train on your data

Your work product is never used to train or improve any AI model, ours or anyone else's.

Pick the configuration that fits your practice.

Every configuration is fully private. They differ only in how the AI request is routed.

Maximum separation

Direct provider connection

Your own AI provider account.

  • Direct connection to the AI provider
  • We are never in the data path
  • Credentials stored locally on your device

For maximum data separation

Enterprise governance

Firm-hosted gateway

Deployed on your firm's own infrastructure.

  • A single-tenant relay your firm runs
  • AI credentials and audit in your own database
  • Centralized governance and SSO

For firms with data residency requirements

Instant access

Private relay

AI included, no setup required.

  • Your request passes through our relay (we're in the path)
  • Never stored, logged, or used for training
  • Multiple AI models included, zero setup

For solo practitioners and small firms

Built for legal obligations.

Designed to support confidentiality duties and professional responsibility requirements.

Confidentiality

Minimal data exposure

Compliance

Easy to explain to clients

Data residency

Your cloud, your region

Vendor risk

Minimal dependency

Common questions.

Which configuration should I choose?

Direct Provider Connection for maximum separation. Firm-Hosted Gateway for organizational governance. Private Relay for instant access without setup.

Can I switch configurations later?

Yes. Switch anytime from Settings. A Firm-Hosted Gateway requires IT setup; the others are instant.

Where are templates stored?

Locally on your device. Optional cloud backup uses client-side encryption.

Privacy you can explain to a client.

Tell us your confidentiality and data-residency requirements, and we'll map them to the right configuration.