Effective September 15, 2026 · Version v2.27
Version v2.27 · Effective September 15, 2026 · Published September 15, 2026
This Privacy Policy explains how OCTICASE, INC. ("Octicase," "Provider," "we," or "us") collects, uses, shares, and protects personal information when you visit our websites, use the Octicase platform and its portals, or otherwise interact with us. We provide the platform to a range of users in the personal-injury legal ecosystem, and the way we handle information depends on which Customer Type and user role applies to you. This Policy is written so that any user can find their situation and understand it.
Octicase supports six Customer Types, the first five defined in our Terms of Service and the sixth in our Consumer Terms of Service: (i) Law Firm Customers; (ii) Medical / Case-Review Customers; (iii) Records / Vendor Customers; (iv) Settlement / Claims Customers; (v) Independent Case Manager / Unverified Customers (support professionals who subscribe in their own name under Schedule E); and (vi) Consumer Customers (individuals using the platform on their own behalf, including pro se claimants). Within each Customer's organization, individual Authorized Users may be attorneys, paralegals, nurses, doctors, vendors, settlement staff, or end users such as injury claimants and the loved ones authorized to assist them. This Policy applies to all of the above; where a section applies only to a particular Customer Type or user role, we say so explicitly. A support professional who subscribes in its own name under Schedule E of the Terms of Service (an Unverified Customer) is a business customer for its own account data and handles a law firm's data for that firm.
This Policy is written to comply with the privacy laws of the United States that apply to us, including the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), the California Online Privacy Protection Act, and the comprehensive consumer privacy statutes of other states as they take effect, including those of Virginia, Colorado, Connecticut, Utah and Texas. New subscriptions are available to United States customers only. Where a specific jurisdiction grants you additional rights, those rights are described in Section 8 below. Washington and Nevada work differently: if you are a resident of either state, or your consumer health data was collected while you were in either state, that data is covered by our Consumer Health Data Privacy Policy, a separate policy that the law of those two states requires, and that policy prevails over this Policy for the information it covers. Our transfer safeguards, described in Section 9, apply because personnel outside the United States access data hosted in the United States, and are independent of where our customers are located.
Our role depends on whose information is at issue and how it reached us.
We act as the business, also called the controller, for: (a) information about Customer accounts, including billing, business contact details, and authentication; (b) information about Authorized Users that we collect directly to operate the Services (logins, IP addresses, device info, audit logs); (c) marketing and prospect information for our own commercial purposes; (d) information about website visitors; (e) the registration details and access trace of a person who registers to view a link sent through the Services; (f) information about professionals listed in the Directory, including pre-loaded profiles (Section 4.12). For this information, your privacy rights are addressed to us at privacy@octicase.com.
For information that a Customer puts onto the platform about its end users (for example, a Law Firm Customer's client information, a Medical Customer's case-review subjects, a Settlement Customer's claimant records), the Customer is the business, or controller, and we are the service provider, or processor. We process that information only on the Customer's documented instructions, as set forth in the Data Processing Addendum and (where PHI is involved) the Business Associate Agreement. If you are an end user and want to exercise rights regarding information that a Customer placed on the platform, please contact that Customer first; we will assist them as required by law.
If you signed up for Octicase directly as a Consumer Customer (a pro se claimant or other individual using the platform on your own behalf), we are the controller of your information, and you may contact us directly to exercise your rights.
The categories of personal information we may collect, organized by reference to the categories the CCPA/CPRA enumerates, are set forth in the table below. Whether a particular category is collected depends on Customer Type and user role; the third column indicates which.
| Category | Examples | Whose, By Type |
|---|---|---|
| A. Identifiers | Name, alias, postal address, email, phone, IP address, account ID, government ID where required for compliance. | All Customer Types and end users. Also: a person who registers (name, phone, verified email) to view a link a consumer sent them, for the access trace only; and professionals whose pre-loaded Directory profile we compile (Section 4.12). |
| B. Customer Records | Billing info, payment method, business address, business registration, tax ID, signature. | Paying Customers (B2B and Consumer). Where payouts are made through the platform, for experts, consultants and partners: the payout account, tax identification and beneficial-owner information is collected by our payment processor as an independent controller (Section 5.2); we hold only the status of that verification and the payout records. |
| C. Protected Classifications | Age, citizenship, marital status (if voluntarily provided in case intake). | End users of Customers, where relevant to the matter. |
| D. Commercial Information | Subscription tier, transaction history, usage records. | Paying Customers. |
| E. Internet Activity | Browsing on the Service, IP, device, log data, cookies. | All users of the Services. |
| F. Geolocation Data | Approximate location from IP; precise location only with consent. | All users. |
| G. Sensory Data | Voice intake recordings (Retell), uploaded images and audio, video share access logs. | Where users use voice intake or media features. |
| H. Professional or Employment Information | Bar admission status, NPI, license numbers, professional qualifications, employer. | Law Firm, Medical/Case-Review, Records/Vendor, Settlement/Claims Customers (NOT collected from Consumer Customers). Also professionals listed in the Directory, including pre-loaded profiles compiled from public registries and licensed directories (Section 4.12). |
| I. Education Information | Degrees, certifications, CLE credits (where voluntarily provided). | Where users provide it. |
| J. Inferences | Inferences drawn from the above to characterize preferences and behavior, including from AI features. | Where AI features are enabled by Customer. |
| K. Sensitive Personal Information (CPRA) | Government ID, financial account info, precise geolocation, racial/ethnic origin, religious beliefs, contents of communications, genetic data, biometric data (not currently processed), health information. | Where the Customer's matter or user role involves SPI; see Section 7. |
We collect information from the following sources: (a) directly from you, when you sign up, configure your account, upload documents, communicate through the platform, or contact us; (b) automatically, when you use the Services (logs, cookies, analytics, error reports); (c) from your employer or organization, when a Customer adds you as an Authorized User; (d) from third-party verification services, when your role requires verification (for example, NPI Registry for medical licensure or state bar APIs for attorneys, where applicable -- see Section 4.5); (e) from public sources, such as public bar disciplinary records or public business registrations; (f) from healthcare providers, courts, or other third parties, when a Customer's matter requires a records request and the third party transmits records through our records-retrieval workflow; (g) from public registries (the National Provider Identifier registry and licensing-board records) and from business directories licensed for that use, for the pre-loaded Directory profiles described in Section 4.12; (h) from a consumer, or from a Customer sharing a video, who sends a link to your email address or phone number, so that we can let you register to view it; (i) from another Customer that transfers, shares or collaborates on a matter with the Customer that holds your information, on that Customer's instruction (Section 5.3).
We use information for the purposes set out below. Some purposes apply to all users; others apply only to specific Customer Types or user roles, as indicated. We do not use Customer Data outside the scope necessary to provide the Services, as further described in the Data Processing Addendum and (where PHI is involved) the BAA, and to create de-identified and aggregated data under Section 4.8, as Section 7.3 of the Terms of Service, Section 4.9 of the Data Processing Addendum and Section 2 of the BAA permit.
Authenticate users, host content, render features (case management, portals, e-signature, fax, voice intake, AI-assisted tooling), facilitate communications between Customer and end user, process Customer-initiated workflows (such as records requests), and provide customer support. Applies to all Customer Types.
Process payments, send invoices, manage renewal, dispute resolution, fraud prevention. Applies to paying Customers.
Authentication, audit logging, intrusion detection, vulnerability management, response to security incidents, enforcement of our Acceptable Use Policy. Applies to all users.
Compliance with our legal obligations under HIPAA (where the BAA applies), tax law, US state law, and law enforcement requests where lawful. Applies as relevant.
If you are an Authorized User of a Law Firm Customer, we may verify your bar admission status against publicly available state bar records. If you are an Authorized User of a Medical / Case-Review Customer, we may verify your NPI or relevant medical license. If you are a Vendor or Settlement Customer Authorized User, we may verify business licensure. If you are a Consumer Customer, we do not collect or verify professional credentials. This Section 4.5 applies only to the Customer Types stated; we do not verify bar admission or RPC compliance for users who are not attorneys.
The professional Directory and the consumer self-assessment, Understand My Options, are separate products and we do not connect them. We do not use anything you enter into Understand My Options to filter, sort, rank, or personalize Directory results, and we do not send your Understand My Options answers, your case summary, or any other information about your situation to any attorney, law firm, or other professional - by any channel, including email, and including manual sending by our staff. You can browse the entire Directory without using Understand My Options. If you download or email yourself a copy of your Understand My Options summary, that copy is yours; we do not supply recipients for it and we do not send it anywhere on your behalf, except a link you create under the Consumer Terms of Service, which we deliver only to the person you name, and a transmission you direct to a firm you have already hired, as those Terms provide. Understand My Options keeps your intake answers, summary and uploads for thirty (30) days unless you create an account, and then deletes them, a deletion we run by hand until the automatic process is in place. The advance notice and the option to extend the period once will be offered from the day that automatic process is running, as Section 10 and the Consumer Terms of Service describe; what remains afterwards are your account record, if you created one, the aggregated counts that carry no identifier (Section 4.8), and, only where you gave the separate permission described in Section 4.8(f), the case-level record, which we keep while that permission stands and delete when you ask.
Where Customer enables AI features, and when a consumer uses Understand My Options, we send Customer Data or the information the consumer submitted to our AI processors for the limited purpose of generating outputs (summaries, drafts, classification, search, briefings). The primary processor is Google Cloud Vertex AI; Amazon Bedrock acts as a failover for real-time features and Retell AI provides the conversational voice agent. Where Protected Health Information may be processed, each is engaged under a Business Associate Agreement, and we do not enable an AI feature for PHI until that is in place throughout the processing chain. Prompts and responses are not used to train foundation models. Section 6 and our AI Usage and Data Handling Policy describe this in full.
Customers own their Customer Data and license us to create de-identified and aggregated data from it, under Section 7.3 of the Terms of Service, Section 4.9 of the Data Processing Addendum and, for Protected Health Information, Section 2 of the Business Associate Agreement. We use that data to operate, secure and improve the Services, for industry benchmarking, and for our own commercial purposes, which include creating data products and licensing them to law firms, insurers, researchers and other third parties. De-identified and aggregated data is not personal information. This is how we make sure of that: (a) Method. Health information is de-identified under 45 CFR 164.514(b), by the method stated in (d), and medical information under the California Confidentiality of Medical Information Act to the same standard; all other information is de-identified so that it cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable person or household, with technical measures that prevent such linkage (Cal. Civ. Code Section 1798.140(m)). (b) Our public commitment. We maintain and use de-identified data only in de-identified form and we do not attempt to re-identify it, except solely to test whether our de-identification process meets this standard; no one outside the de-identification process receives the keys, parameters or other details that would permit re-identification. (c) Contractual flow-down. Anyone we license de-identified data to signs a written contract that prohibits re-identification and any attempt at it, requires the same of their own recipients, and, where the data was derived from patient information, contains the terms Cal. Civ. Code Section 1798.148 requires. (d) De-identified patient information, and the method we use. Cal. Civ. Code Section 1798.146(a)(4) exempts information of this kind only where both of its conditions are met, and we state here how we meet them. We may license de-identified information derived from patient information; today we license none, and where we do it will be aggregated statistics and no record-level data; it is de-identified under 45 CFR 164.514(b) by the safe-harbor method of Section 164.514(b)(2): we remove all eighteen identifiers that method lists, which means that from information derived from health records we keep no name, no geography smaller than the state, no element of a date other than the year, no age above eighty-nine other than as a single group, and no unique identifying number, characteristic or code. Two consequences follow and we state them rather than leave them implied. First, the free text of a medical record never enters our de-identified data at all, because the eighteen identifiers cannot be removed from narrative with the reliability that method assumes; only structured fields do. Second, information derived from health records carries the state and the year, not the county and the month. That rule is the safe-harbor method applied to record-level de-identified data. It does not govern the aggregated counts described in paragraph (f) of this Section, which are not records about any person, are never derived from a de-identified record set, and are protected instead by the minimum-cell rule stated there. If we ever adopt the expert determination method of Section 164.514(b)(1) instead, which would allow finer detail, we will say so here before we rely on it, and we will document and retain the determination and the analysis supporting it. (e) Training. De-identified data is not used to train, retrain or fine-tune any machine-learning or artificial-intelligence model unless the Customer it came from agrees in writing, on the separate screen that Section 7.3(d) of the Terms of Service describes, whose wording is Screen B1 of our Consent Screens. Where that agreement is given, the models trained are ours and serve our other customers; withdrawing it stops any further use of that Customer's data and does not require us to retrain or discard a model already trained, except where a court, a regulator or the law requires it, in which case we will. We also train our own models on platform usage data, which carries no matter content and is described in Section 7.3A of the Terms of Service. (f) Consumers who use Understand My Options: two layers, and they are not governed the same way. The first is aggregated counts. When you use Understand My Options we write counts by type of situation, county and month at intake, with no identifier of any kind for each record; those counts are aggregate consumer information, cannot be linked to anyone, are published or licensed only where each cell covers at least ten people, counted on the full combination of type of situation, county and month rather than on any one of them alone (cells below ten are combined into a wider area or period, or dropped), are not deleted when your data is deleted, and are the only information about consumers we would ever license or sell, apart from two things we name here rather than leave implied: the platform usage data described in Section 7.3A of the Terms of Service, which carries no matter content, is de-identified before we use it and is published or licensed only in aggregate; and the case-level record described below, which we do not sell today and which we could sell only under the separate signed authorization described in paragraph (g). We license and sell nothing about consumers today. The second is case-level records, and they exist only if you give us separate permission on a screen of its own. They are the facts of your situation, and only these: the type of situation, the type of injury and its extent, the case factors we record, each one named, the county and the month, kept under an identifier that is not your name. They contain no free text you wrote, no document, image, audio or video you uploaded, no name and no contact detail. We keep a record no longer than twenty-four months, after which we ask you again. Keeping it and training on it are two separate permissions, asked on two separate screens: you may allow us to keep the record and refuse the training, and if you do, the record stays for your own use and enters no training at all. We tell you plainly what that means: this is personal information and not de-identified data; we use it to build and train our own models; we do not sell or license it today, and we would sell or license it only to a buyer you have named and agreed to in a separate signed authorization, as paragraph (g) of this Section describes; you can ask us to delete it at any time and we will delete it, including from our backups within the period stated in the Data Retention and Deletion Policy; and if you do not give that permission we do not keep it at all. Paragraphs (b) and (c) of this Section apply to the aggregated counts in the same terms as they apply to de-identified data: we do not attempt to re-identify them, and every license of them carries the written no-re-identification clause. Deleting a case-level record removes it from our systems within thirty days and from our backups within six months, takes it out of the set we train on, and puts you on a list so that nothing of yours enters any future training; software we had already trained is not undone by your request, and your request does not require us to retrain it or to discard it. We would retrain or withdraw it only where a court, a regulator or the law required it, and then we would. We tell you this on the screen where we ask, rather than leave it to be discovered. We keep no case-level record of anyone under eighteen, the permission screen is not shown at all in the guardian flow described in Section 12, and a guardian cannot give this permission on a minor's behalf. What videos you have watched is never part of it: those records are governed by the Video library viewing records row of the Data Retention and Deletion Policy, are destroyed within one year of ceasing to be necessary, as 18 U.S.C. Section 2710(e) requires, are not disclosed to anyone other than the person concerned without that person's written consent, as Cal. Civ. Code Section 1799.3 requires, are never reported to a law firm and are never sold or licensed. De-identified and aggregated data survives the deletion of the data it came from and is not subject to deletion, access or export requests, because it is not personal information. (g) Selling the case-level record. We do not sell the case-level record described in paragraph (f) today, and we have never sold it. Three provisions require your written authorization before we could: Cal. Civ. Code Section 56.10, and subdivision (d) in particular, which does not permit us to sell medical information about you without your express authorization and which applies to us because Section 56.06(b) makes us a provider of health care for the information you manage through the Services; RCW 19.373.070 in Washington; and NRS 603A.535 in Nevada. We would sell it only where you have signed our Authorization to Sell Your Health Information, a separate authorization that names the company buying it, states what that company may do with it, and says plainly that we are paid and you are not. It is not the Authorization to Share Your Medical Information described in Section 15: that one sends your own information where you ask, nobody is paid for it, and signing one is not signing the other. No attorney, law firm, or other legal or medical professional is an eligible buyer of the case-level record, and we would not name one on that authorization, so that the commitment in Section 4.6 holds without exception. That authorization is a document of its own: it is not part of this Policy and not part of any terms you have accepted, it expires one year after you sign it and does not renew by itself, and you may withdraw it at any time by emailing privacy@octicase.com or from your account settings, after which we stop selling and instruct the buyer to delete what it holds. The same instruction goes to the buyer when the authorization expires, when you ask us to delete the record, when the record reaches the twenty-four month limit in paragraph (f), and when you direct us to limit the use of your sensitive personal information. Signing it is not a condition of anything: your access, your features and your price are identical whether you sign it or not. It is never asked for in the guardian flow described in Section 12, and because we keep no case-level record of anyone under eighteen, no record of a minor can be sold. This paragraph reaches nothing else. It does not reach Protected Health Information, which the Business Associate Agreement forbids us to sell; it does not reach anything a law firm or other Customer placed on the platform; and it does not reach your name, your contact details, your free text, any document, image, audio or video you uploaded, what videos you have watched, or the internal classification our software produces about your situation, which we keep for our own use and do not sell. One thing does carry your name, and we say it here rather than leave it to be discovered: the authorization itself carries your signature and your printed name, and Cal. Civ. Code Section 1798.148 aside, RCW 19.373.070(5) requires the buyer to keep a copy of it. The buyer therefore holds that signed page as well as the record. We keep our own copy of it for six years, counted from the latest of the day you signed it, the day you withdrew it and the day it expired, because both the Washington and the Nevada periods require the seller to keep it too; our Data Retention and Deletion Policy states that period. The record reaches the buyer under an identifier that is not your name, and the buyer's contract forbids it from linking the two, from identifying you, and from contacting you. Before any such sale begins we will state in this Policy the categories of personal information sold and the categories of buyer, and we will publish the opt-out route that Cal. Civ. Code Sections 1798.120 and 1798.135 require.
We may use business contact information to market our Services to Customers and prospects. In marketing email addressed to a business, we measure whether the message was opened and which links were followed, using an invisible image and links that pass through our email provider; every such message carries an unsubscribe link, and unsubscribing stops the measurement as well as the mail. We do not do this in any other message we send. We are switching off the open-tracking image and the rewritten link on transactional and operational email and on every message to a consumer, because whether a person opened a message from us, and which link they followed, would itself say something about their situation. Until that change is confirmed we describe it as work in progress and not as something already in place. We set advertising cookies only on our marketing and campaign landing pages, which address prospective business customers and on which no case information is entered, and only where you consent. We set none on the Directory, Understand My Options, any intake form or any signed-in area. We will honor the Global Privacy Control signal; automatic handling of it is still being built. See our Cookie Policy for the detail. Business outreach: when our team emails, calls or texts a law practice or other business, every email identifies us, carries our postal address and an unsubscribe link (CAN-SPAM; Cal. Bus. & Prof. Code Section 17529.5), calls are placed and texts are sent by a person to business lines without an automatic dialer or prerecorded or artificial voice, and the person tells you if the call is recorded. Link recipients: if you register to view a link sent to you through the Services, whether a video link from a Customer or a summary link from a consumer, we use your email address to send you that link and its access notices only; we add it to our own marketing list only if you tick a separate box saying so, and every marketing email you then receive has an unsubscribe link.
Some browsers transmit a "Do Not Track" signal. There is no industry or legal standard for how a website must respond to that signal, and we do not currently alter our practices in response to it. What we do instead is structural and does not depend on your browser settings: we do not permit third-party advertising or analytics trackers to load on any page where you enter injury, medical, or claim information, on any page that plays video, or in authenticated areas of the Services, and we do not authorize third parties to collect personally identifiable information about your activity over time and across third-party websites when you use the Services. This disclosure is provided under the California Online Privacy Protection Act (Cal. Bus. & Prof. Code sections 22575 et seq.).
Our Directory includes profiles of attorneys, medical and other professionals and service providers that we compile before the professional has joined, from public registries (the National Provider Identifier registry and state licensing-board records) and from business directories licensed for that use. A pre-loaded profile contains professional information only: name, practice or specialty, business address and telephone, license or registration identifiers, and the source category and refresh date. The listing is marked as unclaimed, shows the source category and refresh date, states that you have not confirmed the information and that it may be out of date, and carries a correction link. A business telephone number in the source is held to invite you to claim the listing and is not necessarily displayed. We do this so that Customers and consumers can find a professional and so that the professional can claim the listing with a unique identifier, at no charge, and take it over; and to invite you, by email, telephone or text message to business contact details, to claim it. We do not use automated dialing or an artificial voice for those invitations, every email has an unsubscribe link, and we honor a request not to be contacted as the Portal Terms state. We do not sell or share this information; it is displayed in the Directory and used for nothing else. Some of it comes from government records and is outside the CCPA; we honor correction and removal requests for all of it regardless. We do not add ratings, reviews or any information from a consumer's self-assessment to a pre-loaded profile. If your profile appears and you want it corrected, claimed or removed, write to support@octicase.com or use the link on the listing (statutory privacy requests go to privacy@octicase.com, Section 8): we correct a factual error within ten (10) business days of a request with the correct information, and we remove a listing from the Directory within five (5) business days of your objection and delete it from active systems within thirty (30) days, keeping only a record that you asked not to be listed. Profiles are refreshed at each update of the source and deleted within thirty (30) days after we stop using that source or after that source's terms no longer permit us to display the profile. This Section is the notice at collection for that information; your rights under Section 8 apply to it.
We share information only as described below, and nothing in this Section permits us to disclose medical information governed by the Confidentiality of Medical Information Act otherwise than as Section 15 describes: a corporate transaction, the protection of rights or property, and a general consent are not among the disclosures Cal. Civ. Code Sections 56.10(b) and (c) allow, and we do not treat them as if they were. We do not sell personal information for money or other valuable consideration today, and we do not share personal information for cross-context behavioral advertising. The one sale these documents provide for, and which is not in use today, is the sale of the case-level record described in Section 4.8(f), which can happen only under the separate signed authorization described in Section 4.8(g); if it begins we will say so in this Section before it does, naming the categories sold and the categories of buyer. De-identified and aggregated data that we create under Section 4.8 is not personal information, and licensing it is not a sale or sharing of personal information; Section 4.8 states the method, our commitment not to re-identify and the contract terms every recipient signs.
We share information with the Customer that controls it and with the Authorized Users designated by that Customer.
We share information with the subprocessors listed in our Subprocessor List (including Amazon Web Services, Google Cloud Vertex AI, SendGrid, SRFax, Retell AI and the speech and voice vendors it engages, Twilio, Microsoft Azure, Vimeo, and our payment processor) under written agreements that restrict their use of the information to providing the Services to us, except where the Subprocessor List records that such an agreement is not yet in place, in which case no personal information is shared with that provider until it is. The Subprocessor List is the authoritative record of who those providers are and is updated before a new provider is engaged; this sentence is illustrative and may lag it. Payment processor. Where payouts are made through the platform, the payment processor named in the Subprocessor List collects the identity, beneficial-owner, tax and bank-account information of experts, consultants and partners who receive payouts through the platform, and uses it for identity verification, sanctions and anti-money-laundering screening, tax reporting and payouts under its own obligations; for that information it is an independent controller under its own privacy notice, not our service provider, and the Subprocessor List names it.
Where a Customer's workflow requires sharing information with another Customer or party (for example, a Law Firm Customer requesting records from a Medical Customer), we facilitate that sharing on the Customer's instruction. This includes a Customer transferring a matter to another Customer, giving another Customer view-only access to it, or collaborating with another Customer on it: that happens only on the first Customer's instruction, the first Customer can revoke access at any time, and we record who granted, accepted, changed and revoked access and when. It also includes a Customer transmitting case material to an expert, consultant, vendor or partner it engages through the platform; the expert processes it for the Customer under the Customer's instructions and its own obligations, including a Business Associate Agreement where health information is involved.
We may share information if required by law, court order, or government request, or to protect the rights, safety, or property of Octicase, our Customers, or third parties. Where lawful, we notify the affected Customer.
We may share information in connection with a corporate transaction, subject to appropriate confidentiality and to applicable law.
We share information for any other purpose with the Customer's or user's consent.
Octicase uses AI features across document analysis, legal work product, case management, communications and voice. The primary processor is Google Cloud Vertex AI (Gemini family models). Amazon Bedrock (Anthropic Claude models) acts as a failover for real-time features, and Retell AI provides the conversational voice agent. Where Protected Health Information may be processed, each is engaged under a Business Associate Agreement, and we do not enable an AI feature for PHI until that is in place throughout the processing chain, down to the speech and voice vendors Retell AI engages. The Subprocessor List records the current status of each. The full feature list and the controls that apply to them are set out in our AI Usage and Data Handling Policy. Important points:
We may collect and process Sensitive Personal Information (SPI) under CPRA and analogous categories under other state laws, including: government identifiers (driver's license, passport, SSN where lawfully required), financial account information, precise geolocation, racial or ethnic origin (only where voluntarily provided in matter intake), religious or philosophical beliefs (only where relevant to a matter and voluntarily provided), the contents of mail, email, and text communications (where you communicate through our platform), genetic data, biometric data for unique identification (we do not currently process biometric identifiers), and health information (extensively, in matters that involve medical injury or claims).
We use SPI as needed to provide the Services, including to enable Customer workflows, to comply with HIPAA and other privacy laws, and for security and fraud prevention. There is one further use and it is not necessary to provide the Services, so we ask for it separately and you are free to say no: where you give the permission described in Section 4.8(f), we use the case-level record to build and train our own models. You may withdraw that permission, or direct us to limit our use of your sensitive personal information, at any time and by the same route by which you gave it. We do not use SPI to infer characteristics about you for marketing. We also de-identify SPI, including health information, to create the de-identified and aggregated data described in Section 4.8; the result is not personal information. California residents may at any time direct us to limit our use and disclosure of SPI by contacting privacy@octicase.com. Where you manage your own medical information through the Services, the California Confidentiality of Medical Information Act (Cal. Civ. Code sections 56 et seq.) also protects it, and it protects it against us and not only against others: Section 56.06(b) deems a business that offers software to consumers designed to maintain medical information so that a person can manage their own to be a provider of health care, and that is what we are for that information. Section 15 sets out what follows from that and how it sits alongside HIPAA.
Depending on where you live and your relationship to the Services, you may have the following rights:
How to exercise your rights depends on your role:
| Your Role | Who to Contact for Privacy Rights |
|---|---|
| Paying Customer (B2B) | Contact us at privacy@octicase.com for rights regarding your account/business information that we control. |
| Consumer Customer (pro se) | Contact us at privacy@octicase.com for rights regarding your case data and account that we control. |
| End user of a Customer (e.g., a plaintiff client of a Law Firm Customer; a patient whose records are on the platform) | Contact the Customer first (the law firm, vendor, or other organization that put your data on our platform). They are the data controller. We will reasonably assist them on request. |
| Authorized expert / vendor / settlement-staff user | Contact us at privacy@octicase.com for your professional account; for case-related data, contact the engaging Customer. |
| Professional with a Directory listing, including a pre-loaded profile | Contact us at support@octicase.com (or the link on the listing) to correct, claim or remove the listing; statutory privacy requests go to privacy@octicase.com. Section 4.12 describes the sources and what we do. |
| Person who registered to view a link a consumer sent | Contact us at privacy@octicase.com; we hold only your registration details and the access trace. For the content of the link, contact the person who sent it. |
| Support professional subscribing in its own name (Unverified Customer, Schedule E) | Contact us at privacy@octicase.com for your own account and billing information; for data you handle for a law firm, that firm is the controller and you contact it. |
To submit a request, email privacy@octicase.com with the subject "Privacy Rights Request," or use the form at https://trust.octicase.com/privacy-request. We will verify your identity in a manner proportionate to the sensitivity of the request, respond within 45 days under the CCPA/CPRA and within the period each other applicable state law allows, which is generally 45 days, and notify you if we need additional time. There is no fee for verified requests, except for excessive or repetitive requests.
California residents may use an authorized agent to submit requests. The agent must provide written permission and proof of identity; we may also verify directly with you.
California residents may request information regarding disclosures of personal information to third parties for those parties' direct marketing purposes during the prior calendar year. As of the Effective Date, we do not make such disclosures. De-identified data we license is not personal information for this purpose.
Octicase is operated by OCTICASE, INC., a corporation organized under the laws of the State of Delaware. We host the Services in the United States (AWS, us-east-1). Our own personnel, located outside the United States, access data hosted in the United States for support, administration and security operations. We engage no supplier of personnel. That access is subject to the confidentiality obligations and to the technical and organizational measures described in our Data Processing Addendum, Section 5 of which states it. If we later engage a contractor whose personnel access personal information, that contractor is a subprocessor, is added to our Subprocessor List, and the notice and objection process described there runs before the access begins.
We retain personal information only as long as necessary for the purposes described in this Policy, in accordance with our Data Retention and Deletion Policy. Brief summary by category:
Consumer Customers. If you use Understand My Options without an active account, or do not return after submitting, your intake answers, summary and uploads (documents, images, audio and video) will be deleted from active systems thirty (30) days after submission. That deletion is not automated today. Until the automated schedule is in place we will carry these deletions out manually, so the thirty (30) day period is the period we work to and a given deletion may complete after that date. The notice and the extension described next will be offered once that schedule is running: where you have given us an email address or phone number you have not asked us to stop using, we will tell you seven days before the first period ends, and you will then be able to create an account, or extend the period once by a further thirty (30) days, to keep them. Your account record, if you created one, is removed within thirty (30) days of your deleting the account or asking us to. What remains are the aggregated counts described in Section 4.8, which carry no identifier, and, where you gave the separate permission described in Section 4.8(f), the case-level record, which we keep while that permission stands and delete when you ask, including from backups within six (6) months of the request. Other categories, with the periods the Data Retention and Deletion Policy states: link recipients' registration details (name, phone, verified email), six (6) years aligned with audit logs, as an access record; Platform Engagement transaction records, invoices and receipts, seven (7) years after the later of the end of the Customer's subscription and of the seller's agreement with us; engagement deliverables and messages, as the engaging Customer's data; access and transfer records for shared matters, six (6) years; Portal inquiries that did not become an engagement, ninety (90) days; Directory listing data, for the life of the listing and forty-five (45) days after a removal request; pre-loaded profiles, until claimed or removed, and thirty (30) days after your objection or after we stop using the source; do-not-contact and opt-out records, at least five (5) years and for as long as needed to honor them; records of consent to be contacted, five (5) years after the last message sent under that consent; deletion-request records, six (6) years; mailbox or calendar content synchronized but not matched to a matter, thirty (30) days after the connection is revoked; phone numbers used for two-factor authentication, thirty (30) days after you disable it. All are subject to legal exceptions (legal hold, ongoing investigation, compulsory process). Where a forum or question-and-answer feature is offered: a professional's forum post, for the life of the forum account plus one (1) year; an answer to a consumer's question, at least one (1) year after posting, as the Acceptable Use Policy provides.
We implement administrative, physical, and technical safeguards designed to protect personal information, including encryption at rest and in transit, access controls, multi-factor authentication available on accounts and enforced on those that enable it, audit logging, vulnerability management, and incident response. Our HIPAA Privacy and Security Policies (internal) and Information Security Policy describe controls in detail; a summary is at https://trust.octicase.com/security. No system is perfectly secure; we encourage users to use strong, unique passwords and to enable MFA. If a breach of security affects your unencrypted personal information, or encrypted personal information where the key was also acquired, and we are the controller of it, we notify you in the most expedient time possible and without unreasonable delay, as Cal. Civ. Code Section 1798.82 and the breach-notification law of your state require; where a Customer is the controller, we notify that Customer within seventy-two (72) hours under the Data Processing Addendum and the Business Associate Agreement, and the Customer notifies you.
The Services are not directed to children under thirteen, and we do not knowingly collect personal information from children under thirteen. At intake we ask for age. A person who indicates they are under thirteen is blocked from submitting, and we collect nothing further from them.
A person who indicates they are between thirteen and seventeen is routed to a guardian flow: a parent or legal guardian completes the intake and gives consent. We record that the guardian consented, the date, and a coarse age bracket. We do not collect the minor's date of birth. Where a personal injury matter involves a minor and the matter is managed by a Customer, the minor's information is provided by that Customer on behalf of the minor's authorized parent or legal guardian.
If you believe we have inadvertently collected information from a child, please contact us at privacy@octicase.com and we will delete it. We are not subject to FERPA (we are not a school or school service).
We use cookies and similar technologies as described in our Cookie Policy. Where required by law, we present a consent banner. We will honor the Global Privacy Control (GPC) signal as an opt-out of sale and sharing under CCPA/CPRA. Automatic handling of that signal is still being built, so we state this commitment in the future and not as something already running.
Octicase offers optional SMS (text message) and voice communications. This section describes how phone numbers are collected, used, and protected when you opt in.
A phone number is collected only when you voluntarily provide it - for example, when you enable SMS-based two-factor authentication (2FA) on your account, when you opt in to receive case-related notifications from your law firm, or when you initiate contact with us via text message. We do not obtain the phone number of a consumer or an end user from a third party or from public sources, except a number a consumer gives us to send a link, which we use only to deliver that link. Separately, and only for the professional Directory, we may obtain business contact details for professional listings from public business sources; that process never involves consumers or end users and is described in Section 4.12. Where Understand My Options asks for a phone number, we ask for it so that we can let you back into your saved information, tell you before your uploads are deleted, and deliver a link you ask us to send; giving it to us, or creating an account, is not consent to marketing calls or texts, or to automated or artificial-voice calls, from us or from any law firm; we use the number only for sign-in, the deletion notice, and a link or a call you ask for, unless you tick the separate box for other messages (that box is the prior express written consent described below), and you can withdraw that consent at any time.
Two-factor authentication (2FA): to send one-time 6-digit verification codes when you sign in. Frequency is tied to your sign-in activity.
Case notifications: to send transactional updates from your attorney or firm (e.g., appointment reminders, document-ready alerts, settlement notifications, signature requests, follow-up reminders) -- only if you have opted in. These messages are worded generically, so the message itself reveals no diagnosis, treatment, or case detail.
Voice: if you telephone us, or if you ask us to call you, we use your number to conduct that conversation and to create or update the associated record. Where a law firm using the platform calls you, that firm is the caller and is responsible for the consent required for that call; we provide the tooling and keep the record.
Automated voice calls, recording, and consent
Calls handled by our voice system are conducted by an artificial-intelligence agent, not a person. The agent identifies itself as automated at the start of every call, and answers truthfully if you ask whether it is a person. It does not give legal advice.
Calls are recorded. Before the conversation proceeds, the agent tells you that the call is being recorded and asks whether that is acceptable. If you decline, the call ends without a recording being retained. We apply this two-party consent procedure on every call regardless of where you are, because a number of states - including California under Cal. Penal Code section 632 - require the consent of all parties.
Where we place an outbound call or send an SMS to you using an automated or artificial voice or an automated dialing system, we do so only where you have given prior express written consent for that contact, or where the contact falls within a recognized exception such as a message you requested. You may withdraw that consent at any time, on the call itself or by replying STOP to any message, and we maintain a do-not-call record. Federal Communications Commission guidance treats AI-generated voices as artificial voices for the purposes of the Telephone Consumer Protection Act, and we apply that standard.
Recordings and transcripts are retained as set out in Section 10 and in our Data Retention and Deletion Policy. You may request a copy or deletion of a recording of your own call by contacting privacy@octicase.com.
We use Twilio (for 2FA verification codes and certain magic-link delivery) and Retell AI (for voice intake, case notifications, and other product communications) as our SMS providers. These providers receive only the message content, sender and recipient phone number necessary to deliver the message. Each is engaged under a written agreement that restricts its use of that information to providing the service to us and, where the provider may handle Protected Health Information, under an executed Business Associate Agreement.
We do not sell, rent, lease, or trade your phone number.
We do not share your number with marketing partners, advertisers, or third parties for marketing purposes.
We do not use SMS to advertise third-party products or services.
Your mobile information will not be shared with third parties or affiliates for marketing or promotional purposes.
After opt-out we stop sending immediately and remove your number from active sending lists. We retain a suppression record containing your number for as long as necessary to honor your opt-out, because deleting it would make it impossible to know not to contact you, and we retain the record of any consent you previously gave for as long as required to evidence that the earlier contact was lawful. Those records are used for no other purpose. Your number is removed from 2FA records within thirty (30) days of your disabling SMS two-factor authentication.
Standard message and data rates from your mobile carrier may apply to all SMS we send and to your STOP/HELP replies. Message frequency is tied to your account activity and the notifications you opt into.
You may request access to, correction of, or deletion of any phone number we have on file by contacting privacy@octicase.com.
Important boundaries on what HIPAA covers:
We may update this Policy from time to time. We will notify Customers of material changes by email or in-app notice at least thirty days before the change takes effect, unless the change is required by law. The Effective Date at the top of this Policy reflects the version currently in effect.
Questions, requests, or complaints about this Policy or our handling of personal information should be directed to:
OCTICASE, INC. -- Privacy Office
Email: privacy@octicase.com
Mailing address: 2140 S Dupont Highway, Camden, Kent County, Delaware 19934, c/o PARACORP Incorporated
If you are a California or other state-law-protected resident and we have not resolved your privacy concern, you may file a complaint with the relevant state attorney general or data protection authority.
-- END OF PRIVACY POLICY --