Effective Date: 27 August 2026 (first published 20 March 2026)
This Privacy Policy describes how Legalise ("we", "us", "the platform") collects, uses, stores, and protects information from users of the Legalise platform. By using this platform, you consent to the data practices described in this policy.
1. Information We Collect.
- Account Data: Email address, display name, phone number (optional), bar council number (optional), firm name (optional), preferred court (optional), and verification status.
- Authentication Data: Password hash (never stored in plain text), Google OAuth identifier if using Google sign-in, session identifiers, login timestamps, IP address, and user agent information.
- Usage Data: Pages visited, features used, document generation history, reviewer and compiler usage, template type, timestamps, token counts, instrument counts, and related service metadata.
- Generated Outputs and Case Files: Document content, uploaded inputs, compiled briefings, reviewer reports, research reports, attachments, notes, and Desk case-file material are processed to provide the service. They are stored only where the service requires it, such as when you save them to Desk, generate a persisted output, attach material to a case file, or create a share link. Template filing data that is not saved is not retained as document content. We store generation metadata such as template used, timestamp, and instrument count for billing, service records, and abuse prevention.
- Sharing Data: If you create a Desk share link, we store the information necessary to make that link work, including the shared item, recipient-access state, limits, expiry or revocation status, and access metadata. Shared-link recipients may be able to view the material you choose to share until the link expires, is revoked, or otherwise becomes unavailable.
- Notification and Communication Data: Service notices, account alerts, Complimentary allowance and subscription reminders, payment confirmations, Gazette or newsletter preferences, opt-out status, suppression status, delivery metadata, and support correspondence.
- Payment Data: Transaction references, payment amounts, approval status, member number, contract dates, and payment confirmation records. We do not store bank account numbers, card numbers, or financial credentials.
2. How We Use Your Information.
- To provide and maintain document generation, matter review, case compilation, Desk storage, sharing, and legal research services.
- To manage your account, verification status, subscription status, Complimentary access, instrument cycle, instrument allowance, carryover, renewals, refunds, and payment records.
- To send service-related communications, including Complimentary allowance notices, subscription reminders, security alerts, payment confirmations, account notices, and support responses.
- To operate optional or administrative communications such as the Gazette or similar updates. Members are enrolled in the Gazette by default; every edition carries a one-click opt-out link, and the preference can also be changed from the account page at any time. Opting out never affects necessary service, security, payment, or account notices.
- To monitor platform health, detect abuse, enforce usage limits, maintain service quality, and protect the integrity of member accounts and case files.
- To comply with applicable Pakistani law, including the Prevention of Electronic Crimes Act 2016 (PECA), and lawful requests from competent authorities.
3. AI Processing and Third-Party Infrastructure.
Document generation, matter review, case compilation, authentication, analytics, email delivery, hosting, and related platform functions may rely on carefully selected third-party infrastructure and service providers. These functions include hosting and content delivery, transactional email delivery, newsletter delivery, and analytics. When you generate, compile, review, upload, or share material through Legalise, the data necessary to perform that action may be transmitted to such providers for processing, delivery, storage, security, or availability purposes.
For AI-assisted drafting and review, the providers currently in use include:
- Google AI (Gemini API)
- OpenRouter
Content transmitted to AI providers is used to generate, compile, or review the requested output. Whether that content may be retained depends on which model handles your request, and this differs by plan:
- Paid memberships draft on models operated under an arrangement in which your inputs and the resulting outputs are not retained by the provider and are not used to train any model.
- Complimentary accounts run on lighter third-party models. The providers of those models may retain the text you submit under their own terms. If a matter is sensitive, draft it on a paid membership rather than a Complimentary account. Deleting a draft removes it from Legalise at once, but that cannot reach anything a Complimentary-tier model provider may already hold.
Each provider operates under its own privacy policy:
- Google AI / Gemini API: https://ai.google.dev/terms
- OpenRouter: https://openrouter.ai/privacy
4. What We Do Not Do.
- We do not sell, rent, license, or trade your personal data or document content to any third party.
- We do not share your advocate profile data (bar number, firm, court preference) with AI providers unless a specific workflow requires a user-supplied field to be included in the requested output.
- We do not use your generated documents, uploaded matter material, compiled briefings, reviewer reports, Desk case files, or shared-link contents for marketing, advertising, or model training purposes.
- We do not retain unsaved template filing data as document content beyond what is necessary to provide the requested service, maintain saved case files, operate share links, comply with legal obligations, and preserve service records.
5. Cookies, Local Storage, and Analytics.
We use browser cookies for authentication session management and local storage for user preferences, form state, and interface settings. We use Google Analytics 4 to collect visitation and usage information to improve the service, understand traffic patterns, and diagnose platform issues. Analytics relies on pseudonymous identifiers such as a random client identifier and, for signed-in members, the member number; your email address and your document contents are never sent to analytics services. Analytics data is used for service improvement and is not used to sell personal data or target advertising.
6. Data Retention.
- Account data is retained for the duration of your account. Deleted accounts are permanently removed from active account records, subject to limited retention of email, IP, security, payment, or abuse-prevention logs where necessary.
- Generation and usage metadata (template, timestamp, instrument count, token count, feature used, and related service metadata) is retained for billing records, allowance enforcement, security, and service analytics.
- Case file documents, attachments, notes, compiled briefings, reviewer reports, and research reports are retained as long as your account is active. A completed research inquiry is kept as a research report containing your question, the answer, and the authorities it cited, so that you can return to it. When you delete one, it is removed from our systems immediately, including any file you uploaded with it. Deletion is not reversible and we cannot restore a deleted item for you.
- Shared-link records are retained while the share is active and for a reasonable period after expiry or revocation for security, audit, and abuse-prevention purposes.
- Communication and opt-out records are retained as needed to honour opt-outs, suppressions, subscription notices, legal notices, and support history.
- Session logs (IP address, user agent, timestamps) are retained for up to 90 days for security auditing unless a longer period is reasonably required for abuse prevention, dispute handling, or legal compliance.
- Backups are kept for service continuity, security, and abuse prevention for up to 30 days, after which no data persists in them.
7. Data Security.
We implement technical and organizational measures to protect your data, including password hashing, HTTPS transport encryption, session-based authentication, rate limiting, IP-based abuse detection, access controls, and regular backups. No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security. In the event of a data breach that materially affects your personal data, we will notify affected members and, where required by law, the competent authorities without undue delay. Members are responsible for keeping their credentials safe and for sharing Desk links only with intended recipients.
8. Data Location and International Transfer.
Legalise is operated from Pakistan, but the third-party infrastructure described in this policy, including hosting, content delivery, email delivery, analytics, and AI processing, operates on servers that may be located outside Pakistan. Information handled by those providers may accordingly be stored or processed outside Pakistan under the safeguards described in this policy and each provider's own terms. By using the platform you consent to this transfer, storage, and processing.
9. Children and Eligibility.
Legalise is a professional tool intended for adults aged 18 and over engaged in legal practice, legal education, or legal research. The platform is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has provided personal data to the platform, contact [email protected] and the data will be deleted.
10. Your Rights.
We voluntarily extend the following rights to you as a matter of platform policy:
- Request correction of inaccurate account data.
- Request deletion of your account and associated data, subject to lawful retention requirements and abuse-prevention records.
- Revoke Desk share links where the interface permits revocation.
- Opt out of Gazette, newsletter, or non-essential update emails while continuing to receive necessary service, security, payment, and account notices.
- Contact support for account recovery after reasonable verification if login credentials are lost or compromised.
To exercise these rights, contact: [email protected]
11. Changes to This Policy.
We may update this Privacy Policy as our infrastructure, services, or legal obligations change. Material changes will be communicated via email, in-app notification, or an updated policy page. Continued use of the platform after notification constitutes acceptance of the updated policy.
12. Governing Law.
This Privacy Policy is governed by the laws of the Islamic Republic of Pakistan, with particular reference to the Prevention of Electronic Crimes Act 2016 and any subsequent data protection legislation applicable in Pakistan or the Islamabad Capital Territory.
13. Contact.
For privacy-related inquiries, account requests, or support issues, email [email protected].