Skip to main content
Back to Home

Privacy Policy

Last Updated: March 2026

1. Introduction

Welcome to CiteRight. LexAggregator("we," "our," or "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

2. Information We Collect

Personal Information

We may collect personal information that you voluntarily provide when you:

  • Create an account (name, email address, phone number)
  • Use our services (case information, legal documents)
  • Contact our support team
  • Subscribe to our newsletters

Automatically Collected Information

When you access our services, we may automatically collect:

  • Device information (browser type, operating system)
  • Usage data (pages visited, features used)
  • IP address and approximate location
  • Cookies and similar tracking technologies

3. How We Use Your Information

We use the information we collect to:

  • Provide and maintain our services
  • Process your requests and transactions
  • Send you service-related communications
  • Improve and personalize your experience
  • Analyze usage and optimize our services
  • Comply with legal obligations

4. Artificial Intelligence and Automated Processing

CiteRightuses artificial intelligence ("AI") and machine learning technologies to provide certain features. This section describes how AI is used and what data may be processed.

How We Use AI

  • Document drafting assistance (e.g., commutation applications, legal briefs)
  • Legal research and case law analysis via our copilot feature
  • Citation verification and cross-referencing
  • Summarization of legal documents and court records
  • Voice transcription of dictated content

Data Sent to AI Providers

When you use AI-powered features, portions of your input (such as case details, document text, or voice audio) may be transmitted to third-party AI providers for processing. We minimize the data sent to only what is necessary for the requested function. AI providers are contractually prohibited from using your data to train their models.

Human Review Requirement

All AI-generated output is provided as a draft and requires human review before submission or reliance. AI output does not constitute legal advice. You are responsible for verifying the accuracy, completeness, and appropriateness of any AI-generated content before use.

5. Information Sharing and Subprocessors

We do not sell your personal information. We may share your information with:

  • Service providers who assist in our operations
  • Legal authorities when required by law
  • Business partners with your consent

Subprocessor List

The following third-party service providers process data on our behalf. Each subprocessor is bound by data processing agreements that limit how your data may be used.

Subprocessors
ProviderPurposeData Processed
SupabaseDatabase and authenticationAccount data, case metadata, application data
RailwayBackend hosting and APIAPI requests, server-side processing data
VercelFrontend hosting and analyticsPage views, performance metrics, client-side data
AnthropicAI language model (Claude)Document text, prompts, case context for AI features
OpenAIAI language model and embeddingsDocument text, prompts, text for vector embeddings
StripePayment processingBilling information, payment method details, transaction records
BackBlaze B2Document storageUploaded documents, generated PDFs, case files
DeepgramVoice transcriptionAudio recordings for speech-to-text conversion
Mem0Agent memoryCopilot conversation context and session data
Neo4jCitation graph databaseCase citation relationships and legal reference data
Upstash RedisCaching and job queuesTemporary cached data, background job metadata

6. Data Retention

We retain your data only as long as necessary for the purposes described in this policy or as required by law. The following retention periods apply:

  • Case data and legal documents: 7 years from last activity, or as required by applicable record-retention laws
  • AI and copilot interaction logs: 90 days, then automatically purged
  • Payment and billing records: 7 years, as required by tax and financial regulations
  • Audit and security logs: 3 years
  • Account profile data: Retained until you delete your account or request erasure

When data reaches the end of its retention period, it is securely deleted or anonymized so that it can no longer be associated with you.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet is 100% secure. In the event of a data breach affecting your personal information, we will notify you in the most expedient time possible and without unreasonable delay, consistent with applicable law.

8. Your Rights

Depending on your location, you may have the right to:

  • Access your personal information
  • Correct inaccurate data
  • Request deletion of your data
  • Object to or restrict processing
  • Data portability

California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information:

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purpose for collection, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of your personal information, subject to certain legal exceptions. You can initiate deletion from your account settings or by contacting us.
  • Right to Correct: You may request correction of inaccurate personal information we hold about you.
  • Right to Opt-Out of Sale or Sharing: We do not sell your personal information and do not share it for cross-context behavioral advertising. Therefore, no opt-out mechanism is required; however, you may contact us at any time to confirm this status.
  • Right to Limit Use of Sensitive Personal Information: We only use sensitive personal information (such as case details) for the purposes of providing the services you requested.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

To exercise any of these rights, contact us at security@lexaggregator.com or use the account deletion feature in your account settings. We will respond to verifiable consumer requests within 45 days.

9. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience. You can control cookie preferences through your browser settings. By using our services, you consent to our use of cookies as described in this policy.

Analytics Services

We use the following analytics services to understand how our platform is used and to improve performance:

  • Vercel Analytics: Privacy-focused web analytics that collects aggregated page view and performance data. No personally identifiable information is tracked.

We do not use third-party advertising trackers or sell data to ad networks. Session cookies are used solely for authentication and are deleted when you close your browser or log out.

10. Children's Privacy

Our services are not intended for individuals under 13 years of age, in compliance with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will promptly delete that information. If you believe a child under 13 has provided us with personal information, please contact us at security@lexaggregator.com.

Additionally, users must be at least 18 years of age to create an account and use our legal services platform.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last Updated" date.

12. Contact Us

If you have questions about this Privacy Policy, please contact us at: security@lexaggregator.com