Legal execution made effortless, in every language.      Legal execution made effortless, in every language.      
Trust & Transparency

Privacy & Data Policy

At LawKraft AI, transparency is paramount. This Privacy Policy details how we collect, process, protect, and utilize your information, document inputs, queries, and interactions to deliver and continuously enhance our legal intelligence ecosystem.

Last Updated: September 2026Enterprise Grade Encryption (TLS 1.3 & AES-256) Powered by Third-Party AI Models

How LawKraft Uses AI With Your Data

LawKraft's AI features (research, drafting, summarisation) are powered by third-party large language model providers — your queries and documents are sent to them to generate a response. LawKraft does not currently train or own any proprietary AI model. See Section 3 below for what that means today and what we reserve the right to do in the future.

01

1. Overview & Commitment

LawKraft AI ("LawKraft", "we", "us", or "our") is committed to protecting the privacy of legal practitioners, law firms, enterprises, and individual users who interact with our AI legal workspace and services.

This policy explains our practices regarding the collection, handling, processing, and application of personal data, legal inputs, prompts, document materials, and telemetric information.

02

2. Information We Collect

We collect information through your direct interactions with LawKraft, including:

User & Account Data

Name, work email, phone number, law firm / organization name, designation, billing records, and authentication tokens.

Legal Queries & Inputs

Search terms, case facts, legal queries, citations, draft text, uploaded court petitions, PDFs, and prompt parameters.

AI Interaction & Feedback

Draft revisions, accepted suggestions, thumbs up/down feedback, prompt iteration history, and output ratings.

Telemetry & System Logs

IP addresses, browser type, device identifiers, session timestamps, latency logs, and error diagnostic traces.

Messages & Attachments

Direct messages exchanged between lawyers and firm admins on the platform, plus any files or images attached to those messages, which are stored with our media hosting sub-processor.

Uploaded Case Documents

PDFs and other documents you upload for AI-assisted research, drafting, or OCR extraction, which may be converted into vector embeddings so our research and drafting tools can retrieve and reference them.

03

3. AI Processing & Model UtilizationAI Training

3.1 How AI Processing Actually Works Today

LawKraft's AI features (legal research, drafting assistance, summarisation, and argument generation) are powered by third-party large language model providers, not a model LawKraft has built or trained itself. When you submit a query, prompt, or document for AI-assisted processing, that content is sent to these third-party providers to generate a response, subject to their own data-handling and retention terms as passed through by LawKraft under contract.

Separately, documents you upload for research or drafting are converted into vector embeddings stored in our own database, so our tools can retrieve and reference your own documents when assisting you. These embeddings are tied to your account and case records — they are not merged into, or used to train, any AI model.

3.2 Model Training — Not Active Today, Rights Reserved for the Future

LawKraft does not currently train, fine-tune, or own any proprietary AI model, and does not currently run an automated de-identification or anonymization pipeline over user data for that purpose.

We reserve the right to build such a capability in the future. If we do, we will apply appropriate de-identification and anonymization safeguards to aggregated data before using it to train or improve any model, and we will update this Privacy Policy to describe that pipeline, what data it uses, and how to opt out, before it takes effect. Any model weights, embeddings, or other technical artifacts LawKraft creates through such future development, if any, would be LawKraft's property.

04

4. How We Use Information

In addition to AI model refinement, we use the collected information for the following business purposes:

  • Core Service Execution: Generating automated legal research, drafting notices, managing case files, client rosters, and court calendar schedules.
  • Account Management: Authentication, access control, role-based permissions, and subscription lifecycle management.
  • Communications: Sending critical platform updates, security alerts, billing invoices, and feature announcements.
  • Quality Assurance & Troubleshooting: Resolving technical glitches, debugging model latency, monitoring API gateway throughput, and preventing fraudulent activity.
05

5. Data Security & Storage

We implement robust technical and organizational measures designed to protect your data against accidental loss, unauthorized access, destruction, and alteration:

  • Encryption in Transit: All web traffic and API calls are secured via TLS 1.3 encryption.
  • Encryption at Rest: Databases and file storage are protected with AES-256 standard encryption.
  • Role-Based Access Control (RBAC): Strict access controls ensure only authorized personnel and enterprise admins access specific organization scopes.
  • Secure Cloud Infrastructure: Application and database infrastructure run on ISO/IEC 27001 and SOC 2 Type II certified hosting providers, with continuous uptime monitoring.
06

6. Sharing & Sub-Processors

We do not sell your personal contact records to third-party advertisers. We only share information with trusted third parties under strict confidentiality obligations:

  • Cloud & Compute Providers: Infrastructure providers hosting our databases, AI inference clusters, and caching layers.
  • Media & File Hosting: Cloudinary hosts files and images you upload to case records, client records, and chat attachments.
  • Payment Processors: PCI-DSS certified payment gateways (e.g., Razorpay) for handling subscription transactions securely.
  • Legal Compliance: When required by a valid court order, government subpoena, or applicable statutory mandate.
07

7. User Rights & Data Controls

Subject to applicable legal constraints, you have the following rights regarding your account data:

  • Access & Correction: Review and update your profile, organization details, and account settings directly in the dashboard.
  • Data Export: Request an export of your saved cases, clients, and draft records.
  • Account Deletion: Delete your own account from your profile settings, or request deletion by contacting support. See Section 8 below for exactly what happens when an account is deleted.
08

8. Data Retention & Archival

We retain personal data for as long as your account is active or as necessary to provide services, comply with tax/legal obligations, and enforce agreements. Case document embeddings used for your own account's research and drafting retrieval (see Section 3.1) are retained for as long as the related case or your account remains active. We do not currently retain any data as part of an AI model training corpus; if that changes under Section 3.2, retention for that purpose will be described here before it takes effect.

What actually happens when an account is deleted: your account is deactivated and your email and username are anonymized so they can no longer identify you, rather than the underlying record being erased outright — this preserves the integrity of case, billing, and audit history that other users or the firm may still rely on. If the deleted account is a Chamber (law firm) admin, the firm's shared workspace is deactivated and every other lawyer in that firm is automatically moved to an individual Free plan rather than losing access to their own cases and clients. Colleagues you previously messaged retain access to that message history even after your account is deactivated.

09

9. Cookies & Tracking Technologies

We use session cookies and local storage tokens strictly to maintain authenticated user sessions, remember UI theme preferences, and protect against Cross-Site Request Forgery (CSRF). You can manage cookie settings in your browser, though disabling essential cookies may impact platform functionality.

10

10. Statutory & Regulatory Compliance

LawKraft's data handling practices are designed in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the principles of the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.

11

11. Policy Modifications

We may periodically revise this Privacy Policy to reflect advancements in our AI architecture, product features, or regulatory standards. Any material changes will be notified via email or a prominent banner on the platform. Continued use of LawKraft after such revisions constitutes your acceptance of the updated policy.

12

12. Grievance Officer & Contact

For any grievances, privacy concerns, or data protection queries, please reach out to our team:

LawKraft Privacy & Grievance Cell
Official Website: lawkraft.in

Review our Terms & Conditions

Understand the legal framework and license agreements governing LawKraft.

View Terms & Conditions