AI Usage and Data Handling Policy
Takes effect when the beta ends · Version v0.19
This policy is published ahead of time so you can read it now. It takes effect on the day the Octicase beta ends.
Version v0.19 · Published September 15, 2026
Takes effect when the beta ends · Version v0.19
This policy is published ahead of time so you can read it now. It takes effect on the day the Octicase beta ends.
Version v0.19 · Published September 15, 2026
This policy explains, in one place, how Octicase uses artificial intelligence, what data reaches the AI systems, what those systems will and will not do, and what we commit to in operating them. It is written for everyone the systems touch: the law firms and professionals who subscribe, the consumers who use our public tools, and the injured people whose records move through the platform. The Privacy Policy governs personal information generally; the Terms of Service and Consumer Terms of Service govern the contractual relationship; this policy is the detailed statement both of them point to for AI.
One sentence matters more than the rest: the AI assists; it does not decide. No output of any AI feature is legal or medical advice, none substitutes for the judgment of the professional who uses it, and no decision that produces legal or similarly significant effects for a person is taken by a system alone.
For every feature that processes your matter content, Octicase does not train, fine-tune, or host AI models of its own: we send content to models operated by third-party providers under contract and use what comes back, the role ISO/IEC 42001 calls a deployer. Separately from those features, Separately from those features, Octicase will develop and train models of its own. It has trained none to date, and when it does it will train them on three things only:: information that has already been de-identified, where the customer has agreed to that use; platform usage data, which carries no matter content at all; and the case-level records that a consumer has separately permitted us to keep, described in Section 5. Sections 5 and 6 describe all three, and none of them involves sending your matter content to a model of ours. Toward the firms and individuals who use the platform, we are the provider of the AI capability: you contract with Octicase, not with the model companies, and we answer for the intended purpose, the limits, the changes, and the failures of the features we supply.
The platform's AI features fall into five areas. The authoritative, current list of AI systems is maintained internally in our AI system inventory; this section describes them by area and purpose.
Document analysis and summarization - helping a person find and understand what is already in a file, including medical records and correspondence.
Legal work product - drafts and checks (summaries, demand letter drafts, classifications, research briefings) that the lawyer who requested them then verifies and adopts as their own.
Case management support - organizing what is in a matter: search, tagging, routing, briefings.
Voice interaction and transcription - a conversational agent that handles and records calls so a person can act on them, with the disclosures described in Section 8.
Processing of faxed material - bringing documents that arrive by fax, which in this market routinely includes medical records, into the file in usable form.
Settlement valuation and estimation features that produce an output about a particular claim are available to law firm users only - never to consumers. Where a consumer service shows what cases of a general type have settled for, that is a published statistic about a category and not an estimate of anyone's claim, as Section 4.7(b) of the Terms of Service, Section 4 of the Website Terms of Use and Section 6 of the Consumer Terms of Service describe. Where the platform applies an internal, advisory classification to a consumer submission, or flags possible fraud signals, a person reviews it before any consequence follows, it is not shown to the consumer, and it does not by itself determine anyone's access to anything. Automated fraud checks at registration are the exception: where a check reaches the threshold we set, an account may be suspended automatically and our staff are notified afterwards, and the person may ask for a human review of that suspension, as Section 6 of the Consumer Terms of Service describes., it is not shown to the consumer, and it does not by itself determine anyone's access to anything.
These limits hold across every feature, and a use of AI that would cross them is outside what the platform may do without a new assessment and a revised public statement:
No output is legal advice, medical advice, or professional advice of any kind, and none is held out as such.
No output substitutes for the professional judgment of the lawyer or other professional who uses it. Their obligations to their own clients are unaffected by the fact that a machine produced a first draft.
Nothing generated is filed with a court or served as the work of an attorney until that attorney has reviewed and adopted it.
No system decides anything about a person - not whether a person is represented, what a claim is worth, which treatment or record matters to it, or whether a matter proceeds. No decision producing legal or similarly significant effects for a person is taken on a solely automated basis. The one exception is an automated fraud check at registration, which may suspend an account before a person has looked at it; a person reviews that suspension on request, as Section 6 of the Consumer Terms of Service provides.
The AI processors are identified in our Subprocessor List: Google Cloud Vertex AI as the primary processor, Amazon Bedrock as failover for real-time features, and Retell AI for the conversational voice agent. Each of those is engaged under a Business Associate Agreement. Retell engages speech vendors of its own; we are obtaining from Retell, in writing, the list of the vendors permitted on a HIPAA-enabled account and confirmation of the Business Associate Agreement it holds with each. Until we hold it, the voice configured on each agent is restricted to a vendor Retell has confirmed is covered, and we do not enable an AI feature for PHI beyond that point in the chain. Planned or disabled processors are disclosed in the Subprocessor List before they are enabled.
The content sent to these providers is customer matter content and, for Understand My Options, what the consumer submits, and in a personal-injury practice that ordinarily includes health information and material protected by the attorney-client privilege. We state that plainly because everything else follows from it:
It is not used to train, fine-tune, or improve any model, ours or anyone's, with one exception that we set out below rather than bury: the case-level records that a consumer has separately permitted us to keep, described in Section 5, with which we would train our own models where that consumer has also given the separate training permission described below, and on which no model of ours has yet been trained. Outside that exception the prohibition is contractual, not a setting someone could change, and it is stated in our Data Processing Addendum (Section 4.9), Business Associate Agreement (Section 2) and Terms of Service (Section 7.3(d)), each of which also states how a customer may agree to training on de-identified data and how that agreement is withdrawn.
Providers retain content only as long as needed to return the output and meet their own abuse-monitoring obligations - not for any purpose of their own.
AI features run only where the customer has enabled them. Where a customer has not, none of that customer's matter content is sent to any model provider. A platform-level and per-organization stop control can halt all AI processing.
Information a consumer submits to Understand My Options is sent to the same processors and on the same retention terms, as Section 4.7 of the Privacy Policy states. Those processors do not train on it. We would, but only on the case-level records a consumer separately permitted us both to keep and to use for training, and only as this Section describes; no such training has taken place to date. Deliverables and communications of experts and consultants engaged through the platform are treated as the engaging firm's matter content for every purpose in this section, and the same de-identification rules apply to them, except that they are never used to train, fine-tune or improve any model: the training permission described in Screen B1 of our Consent Screens does not reach them, and Section 7.3 of the Expert and Consultant Services Agreement and Section 8.3 of the Partner Agreement govern them.
De-identified information derived from customer content is not used to train, retrain, or fine-tune any model either, unless the customer agrees in writing - a restriction we state expressly because de-identified data would otherwise fall outside the ordinary definitions. That agreement is asked for on a screen of its own, at onboarding and at any time afterwards in account settings. It names what is covered, says plainly that the models trained on it are ours and serve our other customers, and explains how to withdraw. Withdrawal takes effect for data created after it; it does not require us to retrain or discard a model already trained, except where a court, a regulator or applicable law requires it, in which case we will, and we say so on that screen rather than leave it to be discovered. We record which version of that text you were shown and when, and we never apply an agreement backwards to data created before you gave it. That restriction is about training only. Customers own their content and license Octicase to create de-identified and aggregated data from it, which Octicase may use for analytics and data products and license to third parties under the conditions of Section 7.3 of the Terms of Service and as Section 4.8 of the Privacy Policy describes; that data never identifies a customer, a client or a patient, and Octicase does not re-identify it or attempt to (method, public commitment not to re-identify, and a written no-re-identification clause in every license). From what consumers submit to Understand My Options we keep two things, governed differently. Aggregated counts, by type of situation, county and month, with no record-level identifier: those may be published or licensed only where each cell covers at least ten people, cells below that being combined into a wider area or period or dropped, and they are the only consumer information we would ever sell, apart from the platform usage data described in the next section, which carries no matter content and would be licensed only in aggregate. We sell no consumer information today. And case-level records, the facts of a situation under an identifier that is not a name, kept only where the consumer said yes on a screen of its own, and used for training only where that consumer said yes again on the separate training screen: those are personal information, and where both permissions are given we would train our own models on them, which we have not yet done; a consumer who allows the record and refuses the training keeps the record for their own use and it enters no training at all, we do not sell or license them today and would sell or license them only under the separate signed authorization described in Section 4.8(g) of the Privacy Policy, we delete them when the consumer asks, from active systems within thirty days and from archival backups within six months, on the terms of the Data Retention and Deletion Policy, and we put the record on a suppression list at once so that nothing of it enters a model, a statistic or a data product; a model already trained is not undone by that request and we are not required to retrain or discard it, except where a court, a regulator or the law requires it, in which case we will, we keep none for anyone under eighteen, and they never include what videos anyone watched. Section 4.8(f) of the Privacy Policy and Section 8.5 of the Consumer Terms of Service set out both, in the same terms.
Customer matter content, described above, is never training material in the form you gave it to us. Platform usage data is a different thing entirely: how the product is used, how long each step takes, that a search happened, what is offered and accepted and at what price, how often something succeeds or fails. It contains no matter content, no document, no message and no record of any client, patient or consumer. It is our own data and we own it. We use it to run and improve the platform, we may publish or license it in aggregated form, and we may train our own models on it, as Section 7.3A of the Terms of Service sets out. Before an event becomes usage data we strip the free text a person typed, including what they searched for, and keep only that the event happened, of what type and when. Anything in it that relates to an identifiable person is de-identified first, and anything we publish or license is aggregated so that each figure covers at least ten customers and ten people. The engagement data of experts, consultants and partners is not covered by this: their own agreements govern it, and those agreements say we do not train on it.
Separately, some research features draw on an open legal corpus aggregated from public-domain sources - CourtListener (Free Law Project), OpenStates, and the Caselaw Access Project - as Section 18 of the Terms of Service describes. The corpus is retrieved from, not trained on: it contains published legal material, not any person's data, and it changes no model's parameters. It is assembled on a best-effort basis and may not reflect the most recent decisions or statutes; that limitation is disclosed wherever the corpus is used, and that limitation is disclosed wherever the corpus is used, and the attorney who uses the output remains responsible for verifying every legal authority in it before relying on it, as Section 18.3 of the Terms of Service provides. Where we put an automated citation check into production we will say so here, with the date.. Beyond that corpus, Octicase does not acquire, purchase, or scrape external datasets for any AI function.
These are the controls we commit to operate from the day the Services launch. None has yet been exercised in production; from that date each is something an auditor, a customer or a court can test, and we will state here when our internal evaluation program first verifies them; they are what turns the limits above from statements into something an auditor, a customer, or a court can test:
Provenance - every AI-produced artifact carries a record of how it was produced. Labeling - every such artifact is labeled as requiring attorney review until a person with authority verifies it. Consent gate - before client information reaches a model, the platform requires a recorded consent for that client and blocks the request if it is absent or withdrawn. Minimization - identifiers are removed from prompts where the feature does not need them. Traceability - figures and dates in output must trace to a source in the record.
Citation checking - we are building a check of the legal authorities in generated work product against a public legal database; until it is in production and stated here, verification of every citation remains the attorney's, as Section 18.3 of the Terms of Service provides. Bias testing - the settlement valuation and estimation features are tested on a schedule for divergent output across proxies for protected characteristics. Logging - every generation is written to the audit log with the model, the surface, and the timing. Stop control - AI processing can be halted platform-wide and per organization.
Where you interact with an AI assistant - by voice or in the product - we tell you before the interaction begins, in plain words, that you are speaking with an automated system and not a person. If you ask it whether it is a person, it answers honestly that it is not. You can reach a person. Calls are recorded only with the consent of everyone on the call, obtained before recording begins.
For consumers specifically: Understand My Options gives general educational information, which may draw on the open legal corpus described in Section 6. It does not show you any score, rating, or valuation of your situation, does not tell you whether you have a valid claim, and does not give you your filing deadline - those are legal judgments, and making them for you would be practicing law. Only a licensed attorney who has reviewed your specific facts can make them.
You remain solely responsible for independently reviewing, verifying, and approving AI output before using it in professional work, as the Terms of Service provide. Your own rules of professional conduct may require you to disclose your use of AI to clients, courts, or others; this policy and the audit records the platform keeps (which log each generation, and each per-action confirmation for corpus-backed features) exist in part so you can meet those obligations - meeting them remains yours to do. AI features are configured by you: you choose what to enable, and you can turn any of it off.
Octicase operates an AI management system aligned to ISO/IEC 42001, with certification on our roadmap. In that framework we act in two roles, and we say which is which. For every feature that processes matter content we are a deployer of models built by others. For the models we train ourselves, described in Section 2, we are the provider of the AI system, and that carries more: each of those models is entered in our AI system inventory before it is used, is covered by an impact assessment before deployment, carries a record of what it was trained on and of the permissions that allowed it, and is tested before release so that it does not reproduce the training data it was built from. Every AI system in scope, in either role, is covered by an impact assessment before deployment that considers its effect on the people it touches - above all the injured persons whose records it processes - and is reassessed quarterly. Accuracy and bias checks run at least semi-annually and after any material change of model or provider. Any use of matter content, or of de-identified data derived from it without the customer's written agreement, to train a model would be treated as an incident, not a policy question. Suspected problems with an AI feature can be reported to security@octicase.com; questions about this policy go to legal@octicase.com.
Octicase operates in the United States, for United States customers. We have determined that Regulation (EU) 2024/1689 (the EU Artificial Intelligence Act) does not apply to our services as offered; we will make that determination again, before the fact, if that ever changes.
We update this policy when a provider is added or replaced, when a feature materially changes, or when the law moves. Material changes are posted before they take effect, and prior versions remain available. The commitments in Section 5 - no training on your content or on de-identified data derived from it without your written agreement, provider BAAs where PHI is involved, and your control over enablement - do not weaken by update; a change that would weaken them would be presented for your affirmative acceptance under the agreement that governs your relationship with us.
-- END OF AI USAGE AND DATA HANDLING POLICY --