A client’s papers are privileged. We hold them that way.
What follows is what the product actually does. Where a control does not exist, it is not listed - a security page that promises something the code has not got is worse than no page at all.
The controls
Six of them, and all six are in the product today.
One workspace, checked in one place
Every record - a matter, a date, a clock, a note, a draft - carries the firm it belongs to, and the workspace is read from the session rather than from anything the browser sends. It is enforced by one module that every write goes through, so it cannot be forgotten on the eighth screen.
Row level security, with no policies
Every table has row level security on and no policy granting access, which means the anonymous and signed-in database roles read nothing at all. Reads and writes happen through our server with the service role, after the workspace check above. A leaked public key gets a stranger nothing.
A matter can be closed to the firm
By default everybody in a practice can reach its matters, which is how a practice works. A sensitive file can be set to named people only, and then it does not appear in lists, in search, or in anybody else’s answer - it returns "not found" rather than "forbidden", because the existence of the matter is itself the thing being kept.
Papers open through links that expire
Documents are stored in object storage that is not publicly readable. Opening one mints a short-lived link for that one file, so nothing is left lying around in a browser history or a shared address.
Two factors, and a way to shut the others out
An account can require a code from an authenticator app as well as a password, and every other signed-in device can be signed out in one press from Settings.
Everything that happened, written down
Who opened a matter, who moved a clock, who approved a draft, who invited whom, and what arrived by email and from where. An admin can read the log and download it. A firm can also choose how long the question log is kept - a year, six months, three, one - and the rest is deleted nightly.
What we do not do
Three things, plainly.
We do not train any model on your papers.Your documents are read to answer your own firm’s question at the moment it is asked, and that is the whole of their use. They are not used to answer another firm’s question and they are not used to improve a model.
We do not keep the text of an answer. The question is logged, because that is what lets a firm see what it is spending on; the prose of the answer is not stored, because that would be a second copy of privileged material in a table an admin can read.
We do not read your messages. An admin can decide who in the firm may message whom. They still cannot read what was written.
Who else is involved
Every processor, and what it sees.
Running this service means using other people’s infrastructure. This is all of it, and what each one handles. We use them under their business terms and we do not permit content sent through them to be used for training.
Processor
What it does for us
What it handles
Vercel
Runs the application
Requests, and whatever is in them while they are being served
Supabase
The database, authentication and sessions
Your firm’s records, your account, your sessions
Cloudflare R2
Document storage
The files you upload, and the files that arrive by email
Qdrant
The search index
Passages of documents, as numbers and text, for retrieval
Google (Gemini / Vertex AI)
Writes the readings, the summaries and the drafts
The passages and papers a question needs, at the moment it is asked
Cohere
Re-ranks search results
The titles and passages of candidate documents
ZeptoMail / Resend
Sends email
Addresses and the text of notifications and reminders
Dialog Axiata (eSMS)
Sends text messages in Sri Lanka
A telephone number and the reminder’s own sentence
Meta (WhatsApp Business)
Sends WhatsApp reminders, where a firm uses them
A telephone number and the reminder’s own sentence
PayHere
Takes card payments
What you type into their checkout. Card details never reach us
Reporting something
If you believe you have found a way to reach data that is not yours, write to hi@lawpal.lk with enough detail to reproduce it. We will confirm we received it, and we will tell you what we did.
Taking your data out
Settings has an export of everything the firm holds - matters, notes, dates, clocks, drafts and the ledger - and a separate, final button that deletes the account. The export is offered before the deletion on purpose.
The rest in writing
The privacy notice says what we hold and why, and the terms say what we owe each other.