Privacy Policy — Trial Commander
Effective Date: September 1, 2026 Last Updated: October 9, 2026
Changes taking effect on 30 October 2026. On 30 October 2026, the wording quoted below replaces the text of this policy that it names. Until then, the current text below stays in force. Notice of these changes was emailed to the administrators of every customer firm; to object to any of them, or to ask about them, write to privacy@trialcommander.com before 30 October 2026.
In § 6, the first “Summary” bullet becomes: “Customer Data: retained during active subscription and for at least 30 days after cancellation, then deleted — never sooner than 30 days after cancellation”
In § 6, after the “Backups” bullet, a new bullet: “Pre-deletion export: the one encrypted export of a canceled firm's records made immediately before its data is deleted is itself deleted once more than 30 days have passed since that deletion, by the same weekly sweep (up to about 37 days). See Terms of Service § 8.3.”
Changes taking effect on November 9, 2026. On November 9, 2026, the wording quoted below replaces or adds to the text of this policy that it names. Until then, the current text below stays in force, and none of the new information it describes is collected. The administrators of every customer firm are emailed notice of these changes at least thirty days before they take effect; to object to any of them, or to ask about them, write to privacy@trialcommander.com before November 9, 2026.
The “Last Updated” date becomes: “November 9, 2026”
In § 2.2, after the “Visits to our website” bullet, two new bullets:
- On our public website only (trialcommander.com, never inside the Service), we also record, for each visit: which of our buttons and links you press and which of our videos you play — the button, link or video, the page it is on, and when; never anything you type — and the approximate location of your IP address: the state or region and the country only, never the city or anything more precise. We work that location out on our own servers, from a location database we keep ourselves; your IP address is not sent to anyone else to look it up. IP geolocation by DB-IP.
- The Trial Readiness Self-Check. Your answers to the free self-check on our website never leave your browser: they are not saved or sent. We count only that a check was completed, and when — not your answers, not your result, and not which visit or browser it came from.
In § 2.2, in the Global Privacy Control and Do Not Track paragraph, the words “sets no
tc_vidcookie, records no visit, and removes” become: “sets notc_vidcookie, records no visit (and so no location, button press or video play), does not count a completed self-check, and removes”In § 2.2, the
tc_vidcookie bullet becomes: “tc_vid— a random identifier set by our own website so we can tell that visits came from the same browser, 90 days from when it is first set; it is not renewed when you come back. First-party; not used for advertising; not set if your browser sends Global Privacy Control or Do Not Track. An identifier set before November 9, 2026 with a longer lifetime is no longer recognised once 90 days have passed since the first visit we recorded with it: we give that browser a new one.”In § 2.4 (“Why we use it”), the last sentence becomes: “We also measure our campaigns — how many people answer each advertisement and campaign, and how many of them go on to try Trial Commander — so we can tell which of our advertisements are useful to people.”
In § 2.4 (“How long we keep it”), the opening words become: “We keep a lead's details — in every place listed below — for as long as we are in conversation with you and for 24 months after our last contact, and then delete them”
In § 2.4 (“Who we share it with”), the last two sentences become: “We keep it in our own business records: in Microsoft 365 (a spreadsheet in our company's Microsoft OneDrive / SharePoint, and the email notifications of each new lead sent to us) and in Trial Commander's own systems, in our operator console, which only Trial Commander's operator can open — never inside any customer firm's account, and never shown to a customer. We do not keep it in a third-party customer-relationship management (CRM) service.”
In § 2.4 (“Opting out and deletion”), the last sentence becomes: “To have your lead details deleted, write to privacy@trialcommander.com from the email address you gave the form, or tell us that address; we will delete them from every place we keep them and confirm.”
In § 6, the opening sentences of the “Visit records” bullet become: “Visit records (website and, for firms that opted in, Service usage): deleted 180 days after the visit's last activity, by a daily sweep. The one exception: a visit to our public website made by someone not signed in to Trial Commander, and begun on or after November 9, 2026, is deleted 365 days after its last activity. Records of a firm's staff — their use of the Service and their signed-in visits to our website — always stay at 180 days, and so do the visits a browser made before sign-up once they are linked to the new firm (§ 2.2). The link between a firm and the browser it signed up from is removed 180 days after sign-up.”
In § 6, the LinkedIn Lead Gen bullet becomes: “LinkedIn Lead Gen form answers (§ 2.4), in Microsoft 365 and in Trial Commander's own systems alike: kept while we are in conversation with you and for 24 months after our last contact, then deleted; sooner on request.”
A new § 11.2, after § 11.1:
11.2 The update of November 9, 2026 (visits and LinkedIn leads)
On November 9, 2026: visits to our public website by people not signed in to Trial Commander are kept 365 days instead of 180 (§ 6); the
tc_vidcookie lasts 90 days instead of about a year (§ 2.2); on our public website we also record the button presses, video plays and approximate location described in § 2.2, and count completed self-checks; and LinkedIn lead details are also kept in Trial Commander's own systems (§ 2.4).
- Before November 9, 2026 the policy as it stood before this update governs everyone: none of the new items is recorded, and every visit is deleted after 180 days.
- Records made before November 9, 2026 keep the 180-day deletion they were made under; only website visits that begin on or after that date are kept 365 days.
- Customer firms. Nothing changes in how long we keep records about a customer firm: its staff's use of the Service, its staff's signed-in visits to our website, and the visits linked to it at sign-up are still deleted after 180 days. We emailed notice of this update to the administrators of every customer firm at least thirty days before it took effect, as this section requires.
1. Who We Are
Trial Commander ("Service") is operated by iHOST LABS, LLC ("we," "us," "our"). This Privacy Policy describes how we collect, use, store, and disclose information in connection with the Service.
Controller and Processor Roles:
- For Customer Data (client information, matter details, time entries, trust records), the law firm customer is the data controller and we act as the data processor.
- For Account Data (user account info, billing info), we are the controller.
See our Data Processing Agreement for details on our obligations as a data processor.
2. Information We Collect
2.1 Information You Provide
Account Information:
- Firm name, address, email, phone
- Attorney name, Florida Bar number, role
- Authentication credentials (managed by Clerk)
- Billing information (managed by Stripe — we never see credit card numbers)
Customer Data (entered by you into the Service):
- Client information (name, contact info, case details)
- Matter information (court, judge, case number, strategy notes)
- Time entries, invoices, payments
- Trust account transactions and reconciliations
- Documents you upload (fee agreements, exhibits, pleadings), and documents synced from a OneDrive or SharePoint library your firm connects (§ 4)
- What a client or prospective client enters through the client portal, an intake link or a booking page your firm shares — for example questionnaire answers, messages to the firm and consultation requests
- Identity documents — an image or PDF of a client's government-issued ID (for example a driver's licence) that the firm uploads to the client's record, which can show the ID number, date of birth, address and photograph. Only firm administrators, attorneys and staff the firm grants it to can view one. Identity documents are not sent to AI features and are not shown in the client portal, and they are deleted automatically as § 6 describes.
- Email filed from Microsoft 365 (Outlook) — only if a user connects their Outlook mailbox for email filing. We then read the messages in that mailbox's inbox and sent items, and file to a matter the conversations with that matter's client, its linked contacts or opposing counsel, and any conversation a user files by hand: each message's sender, recipients, date, subject and body, and its attachments, which become documents on the matter. Bodies filed this way are stored encrypted, and reach our AI provider only on a matter whose email-AI setting is switched on (it is off by default). For the mailbox's other conversations we keep only an index entry — the subject, the participants' email addresses and the time of the latest message, never a message body — which only the mailbox owner can see (retention in § 6). A user can also file a single email from the Outlook add-in, which stores that email's sender, recipients, date, subject and body, and the names and sizes of its attachments, on the matter.
- Text messages and call records — only for a firm that connects its own Twilio or RingCentral account. Text messages a client sends to the firm's Twilio number are recorded on the client's most recent matter: the sending number, the message and the time; replies of STOP and START are honoured. (Sending text messages to clients from Trial Commander is not yet switched on.) For phone calls, we receive a record of each completed call — the phone number, the direction, the start time and the length — so an attorney can review and bill it; we do not receive the call's audio or content. These messages and records reach us through the firm's own Twilio or RingCentral account, under the firm's own agreement with that provider; Twilio and RingCentral are not Trial Commander sub-processors, as the Sub-processors page explains.
- Voice memos — when a member of a firm's staff records a voice memo, the audio is sent to be transcribed (§ 4) and only the transcript is kept. We do not store the audio.
- Deposition testimony in Crucible — the transcript lines an attorney types, pastes or dictates during a deposition session, kept on the matter. If an attorney records deposition audio for transcription on our servers, the audio is used only to produce the transcript and is not stored by us; only the transcript is kept. From the effective date given in our notice of this change to customer firms (thirty days after that notice was sent), that audio is sent to Microsoft's Azure AI Speech service to produce the transcript (§ 4); until then, Trial Commander sends deposition audio to no outside transcription provider. Audio from a matter set to keep all AI features on the attorney's computer is never sent. Dictation through the browser's own speech recognition is described in § 4.2.
2.2 Information Collected Automatically
Usage Data:
- IP address, browser type, device type
- Performance metrics (page load times, errors)
- Visits to our website. When you visit trialcommander.com, we record each visit: its date and time, your IP address, your browser and operating system, the pages you open (the address of the page only, without most of the query string — we keep only campaign tags such as
utm_sourceandsrc), the site that referred you, the campaign link or QR code that brought you (if any), and how long you actively spent — counted only while the page is on your screen and you have used the keyboard, mouse or screen in the last minute. A random identifier in a first-party cookie (tc_vid) lets us tell that two visits came from the same browser. It does not identify you by name. - If you sign up, the visits your browser made before sign-up are linked to your new firm and your account, so we can understand which pages and campaigns led to it. The
tc_vidcookie is removed at that moment: visits you make to our website later, while signed out, are measured like any visitor's and are not linked to you or your firm. - Use of the Service by a firm's staff — only if the firm opts in. If a firm administrator opts the firm in (Settings → Usage analytics), we also record, for each member of the firm's staff, the same visit details inside the Service. Pages inside the Service are recorded as page types only — for example "a matter's documents page" — never which matter, client, document or other record, and never anything typed or searched. This covers staff members' visits to our website while they are signed in, too. Client-portal users and outside collaborators are never recorded. If the firm does not opt in, we record none of this for its staff; a member of its staff who visits our website signed out is measured like any other visitor, anonymously, and that visit is not linked to the firm. If the firm opts out later, every record made under its opt-in is deleted at once.
- The calendar days on which each member of a firm's staff uses the Service. We record the date only — not the time of day, and not which pages, features or records were used, or for how long. We record these days only during a firm's first 30 days and delete that day-by-day record after about six months; we also keep the most recent day each person used the Service. Trial Commander uses this to see whether new firms are getting started. It is not shown to the firm in the Service and is not included in the firm's data export.
- When someone opens a feature that their firm's plan does not include, we record which user it was, which feature, the page it was opened from, and when. Trial Commander uses this to learn which features firms want.
These visit records are used only by Trial Commander, to understand and improve the website and the Service. They are not shown to the firm in the Service (a firm administrator cannot see staff activity) and are not included in the firm's data export.
We do not use third-party analytics. The Service (app.trialcommander.com) embeds no third-party analytics or advertising trackers of any kind. On our public website only, and only if you accept the LinkedIn cookie, we use the LinkedIn Insight Tag described in § 2.5.
We honour Global Privacy Control and Do Not Track. If your browser sends either signal, our website sets no tc_vid cookie, records no visit, and removes a tc_vid cookie set earlier (on the next page you load), and does not load the LinkedIn Insight Tag (§ 2.5).
Audit Log Data:
- Records of significant actions, kept for compliance and security. Each entry records who acted, what they did and to which record, and when. Some entries also record the IP address and browser (user agent) of the request, and some record selected values of the record before and after the change — for example a client's name, an email subject line or a file name — so an audit entry can contain Customer Data.
- For users who belong to a firm: sign-ins, sign-outs, revoked sessions, second-factor and password changes, and account lockouts and unlocks, each with the IP address and browser reported by our authentication provider (Clerk). The city and country Clerk associates with a sign-in are not stored.
- When you accept the End User License Agreement or sign a document electronically, the record of that acceptance or signature stores the IP address and, where available, the browser of the request.
Cookies and Similar:
- Session cookies (required for authentication — managed by Clerk)
- Preference cookies (remember UI settings)
tc_src— remembers which campaign link or QR code brought you to our website, so a sign-up can be credited to it: it holds the campaign code, the time you first arrived and, when the link carried them, itsutm_source,utm_medium,utm_contentandutm_termtags, 90 daystc_vid— a random identifier set by our own website so we can tell that visits came from the same browser, about 1 year. First-party; not used for advertising; not set if your browser sends Global Privacy Control or Do Not Track.tc_consent— remembers your cookie choice ("Accept" or "No thanks") and when you made it, 12 months. First-party; holds no identifier.- Advertising cookies set by LinkedIn (§ 2.5) — only on our public website, and only if you accept them in our cookie choice. Without that, no advertising or third-party tracking cookies.
2.3 Information from Third Parties
- Clerk (authentication): email address, MFA status
- Stripe (billing): subscription status, payment history metadata
- Microsoft 365 (only where your firm or a user connects it): filed email (§ 2.1), documents synced from OneDrive or SharePoint, and Outlook calendar events (§ 4)
- Google Calendar (only where a user connects it): see "Google user data" in § 4
- Twilio and RingCentral (only where your firm connects its own account): text messages and call records (§ 2.1)
2.4 Information from LinkedIn Lead Gen Forms
Some of our advertisements on LinkedIn include a LinkedIn Lead Gen Form: a short form, shown inside LinkedIn, that lets you ask us for something (for example a walkthrough, a guide or a call) without leaving LinkedIn. LinkedIn may fill in parts of the form from your LinkedIn profile; you can change them before you submit, and nothing is sent to us unless you press Submit.
What we receive. When you submit a form, LinkedIn passes us what the form asked for and you submitted — your name, email address, firm or company name, job title and, if that form asked for it, your phone number — together with the date and time you submitted it and which of our advertisements, campaigns and forms it came from. If the form included a box for our marketing emails, we also receive whether you ticked it.
Why we use it. To respond to you, to send you what you asked for, and to follow up with you about Trial Commander — for example to offer you a walkthrough. We also count how many people answer each advertisement, so we can tell which of our advertisements are useful to people.
Your consent to marketing email. A form that offers our marketing emails does so with a box that is not ticked unless you tick it. We send you marketing email only if you ticked it. Answering the form without ticking it means we will reply to what you asked for, and we may follow up with you about that request, but we will not add you to our marketing emails.
How long we keep it. We keep a lead's details for as long as we are in conversation with you and for 24 months after our last contact, and then delete them — unless you become a customer, in which case your account information is kept as § 6 describes. You can ask us to delete them sooner at any time (below).
Who we share it with. LinkedIn collects the form on our behalf, as the platform the form runs on. We do not sell your information, and we do not give it to anyone else for their own marketing. We keep it in our own business records in Microsoft 365: a spreadsheet in our company's Microsoft OneDrive / SharePoint, and the email notifications of each new lead sent to us. We do not keep it in a customer-relationship management (CRM) service.
Opting out and deletion. To stop our marketing email, use the unsubscribe link in any of them, or write to privacy@trialcommander.com. To have your lead details deleted, write to privacy@trialcommander.com from the email address you gave the form, or tell us that address; we will delete them and confirm.
LinkedIn's own policy. What LinkedIn itself holds about you — your LinkedIn profile, your activity on LinkedIn, and LinkedIn's own copy of the forms you submit — is governed by LinkedIn's privacy policy (https://www.linkedin.com/legal/privacy-policy), not this one. You can manage it in your LinkedIn settings.
2.5 LinkedIn Insight Tag — only if you accept the LinkedIn cookie
Our website can use the LinkedIn Insight Tag, a tool provided by LinkedIn, to measure how our LinkedIn advertisements perform and to show our advertisements on LinkedIn to people who have visited our website. It runs only if you choose "Accept" in our cookie choice. Until you do — and if you choose "No thanks", or your browser sends Global Privacy Control or Do Not Track — the tag is not loaded and LinkedIn receives nothing from our website. We do not offer the choice, and the tag does not run, while you are signed in to Trial Commander.
What LinkedIn receives, if you accept. The address of each page of our public website you open, the page that referred you, the date and time, your IP address, your browser and device details, and LinkedIn's cookie identifiers (if you are signed in to LinkedIn, LinkedIn can link the visit to your LinkedIn account). LinkedIn uses this under its own privacy policy and gives us only aggregate reports — for example how many visitors came from an advertisement, or the job titles and firm sizes of visitors in general — not who you are. The tag is used only on our public website (trialcommander.com), never inside the Service (app.trialcommander.com), and never receives Customer Data.
Cookies. If you accept, LinkedIn's cookies are set on your browser. LinkedIn lists each one, with its purpose and lifetime, in its cookie table (https://www.linkedin.com/legal/l/cookie-table). As that table stood on August 26, 2026, they include li_fat_id, lms_ads, lms_analytics, UserMatchHistory and AnalyticsSyncHistory (30 days), li_sugr and _guid (90 days), ln_or (1 day), lidc (24 hours) and bcookie (1 year).
Changing your mind. You can withdraw your consent at any time with the Cookie settings link at the bottom of every page of our website; the tag then stops loading. Cookies LinkedIn has already set are controlled by LinkedIn and your browser: you can delete them in your browser, and you can turn off LinkedIn's use of data from other websites for advertising in your LinkedIn settings (Settings → Data privacy / Advertising data, https://www.linkedin.com/psettings/advertising).
California residents. Letting LinkedIn receive information about your visits for advertising may be "sharing" under the California Consumer Privacy Act. You can opt out of it by choosing "No thanks" (or the Cookie settings link), and we treat a Global Privacy Control signal as that opt-out.
3. How We Use Information
We use information to:
- Provide, maintain, and improve the Service
- Measure how our website and the Service are used — which pages, campaigns and features people use, and for how long — so we can improve them and understand which of our campaigns bring firms to us
- Process transactions (subscription billing, feature access)
- Send transactional emails (invitations, invoices, payment failures)
- Respond to support requests
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations (tax records, court orders)
- Send product updates and service announcements (not marketing, which requires separate opt-in)
We do NOT:
- Sell Customer Data or Account Data
- Use Customer Data to train machine learning models
- Share Customer Data for advertising purposes
- Access Customer Data except as necessary to provide support (with your authorization), investigate abuse, or comply with law
Support requests. When you ask Trial Commander for help (from the feedback box, "Ask a person", or the sign-in form on our contact page), we keep your question and our reply to answer it and to improve our help material. A member of our team may use AI, through our AI provider listed on the Sub-processors page, to draft a reply from our own help material, and a person reviews and sends every reply. If your firm requires zero-retention AI, its questions are never sent to an AI provider. We delete support questions 24 months after they are closed, or with your firm's data when it is deleted. When we add a question to our help material, we rewrite it as a general answer with no information about you, your firm or your clients.
4. AI Features and Third-Party Processors
When you use AI features (fee petition drafting, AI assistant, legal research), relevant data is sent to Anthropic, Inc. via the Claude API.
In every retention mode:
- Customer Data sent to Claude is processed to generate responses
- Anthropic does NOT use your data to train models
- The data is encrypted in transit and is not disclosed to third parties
Retention. Trial Commander currently operates on Anthropic's standard API retention: Anthropic may hold API inputs and outputs for a limited operational period — approximately 30 days — for abuse and safety monitoring, after which they are deleted. We have requested Zero Data Retention (ZDR) on our Anthropic account, under which nothing is retained after the response is generated, and we will operate under it once Anthropic confirms activation. The mode that is live is always shown in the app at Settings → AI Limits → Data retention.
Your firm's choices. A firm that requires zero retention before using cloud AI may switch on "Require zero retention" in Settings, which pauses that firm's cloud AI until ZDR is live; connect its own Anthropic API key, in which case requests run under the firm's own agreement with Anthropic; or use per-matter local AI, which never sends matter content off the firm's machine.
Other providers used by specific features.
- Voice memos are to be transcribed by OpenAI (model whisper-1). Transcription runs only once it is set up on the Service, and the voice-memo page says whether it is; until then, voice memos can be recorded but are not transcribed, and no audio is sent to OpenAI. When it runs, the recorded audio is sent to OpenAI and the transcript comes back. OpenAI's published API data controls state that API data is not used to train its models unless the customer opts in (we have not), and list the transcription endpoint with no abuse-monitoring retention and no application-state retention.
- Deposition transcription in Crucible uses Microsoft Azure AI Speech (East US 2) from the effective date given in our notice of this change to customer firms (thirty days after that notice was sent), and only when a firm uses transcription on our servers; it is never used for a matter set to keep all AI features on the attorney's computer. The recorded audio, in parts of a few minutes, is sent with the deponent's name and the matter's name (including the parties named in its caption) as recognition hints, and the transcript comes back; we do not store the audio. Microsoft's published documentation ("Data, privacy, and security for Speech to text", read 9 October 2026) states that for fast transcription, the kind we use, "Microsoft does not retain or store the data provided by customers." Microsoft is already our hosting provider; this is a new purpose for it. Until the effective date, deposition audio is sent to no outside transcription provider.
- Search by meaning is not yet connected. Search in the Service matches words: the firm-wide search and the Brief Bank find the words you type, and similar-matter matching compares matter fields. No text is sent to an outside provider to be searched by meaning.
Legal Research and citation check query CourtListener (Free Law Project), a public case-law service, and docket tracking will too once it is available. They send only the words a user types into the research search, the case citations found in a draft (never the draft itself; citation check sends nothing until it is switched on), and, once docket tracking is available, the case numbers a firm tracks. Statute check looks up the statute and regulation sections cited in a draft on public law sites (Cornell's Legal Information Institute and the Florida Senate), requesting only the public page for each section and never sending the draft. Details for each provider are on the Sub-processors page.
See our AI Disclosure for full detail.
4.1 Connecting Your Own AI Assistant (Optional)
Trial Commander lets a user connect an AI assistant the user already has — for example Claude, ChatGPT or Microsoft Copilot — to their Trial Commander account through a standard connector (the Model Context Protocol). Nothing is connected unless a user chooses to connect it, signs in, and approves a consent screen. A firm administrator can turn off connections by non-administrator members.
What is disclosed, and to whom. When a connected assistant asks Trial Commander for something, Trial Commander returns the answer to that assistant's provider — the company the user chose (for example Anthropic, OpenAI or Microsoft). What can be returned depends on the firm's plan:
- Read-only connector (Starter, Bronze and Silver plans): matter names and numbers, deadlines, matter contacts, matter health indicators and trial status.
- Working connector (Gold, Platinum and Enterprise plans, and trials): the above, plus matter notes, communications, documents, time entries, billing summaries and trust balances; and, where the user granted it, the ability to add or change records.
Every request is limited to the matters the connecting user is already permitted to see.
Purpose. To answer the user's own requests inside the assistant they chose. Trial Commander does not use connector traffic for advertising, profiling or any other purpose.
Whose terms apply. The provider receives that information under the user's own agreement with that provider, not under an agreement with Trial Commander, and handles it under its own privacy policy — including whether conversations are retained or used to improve its models. For that reason these providers are not listed as Trial Commander sub-processors for connector traffic. (Anthropic appears in the sub-processor list above for a different thing: the AI features built into Trial Commander, where we send the request on your firm’s behalf under our agreement with Anthropic. A connector you attach is the other direction — your own assistant, under your own agreement.) Before connecting, a firm should confirm that the AI plan it uses is consistent with its confidentiality obligations to its clients.
What Trial Commander receives and keeps. Trial Commander receives the individual requests the assistant makes (which tool, for which matter, with what parameters). It does not receive the user's conversation with the assistant. Each request, and a summary of what was returned, is recorded in the firm's audit log and kept on the audit-log schedule in Section 6.
Your controls. A user or a firm administrator can revoke any connection at any time under Settings → MCP Access; a connection can also be removed from inside the assistant. Disabling a user ends that user's connections. Access granted through the consent screen expires and must be renewed by the assistant: access tokens last one hour and are renewed automatically with a refresh token, which changes on every use, and a connection ends 90 days after it was approved, whether or not it is used. A firm administrator may also create a connection token by hand; it lasts until the expiry the administrator chose, or until it is revoked.
Other Third-Party Processors:
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Clerk | Authentication | User identity, credentials | USA |
| Stripe | Payment processing | Billing info, payment methods | USA |
| Anthropic | AI features | Matter data sent to AI (no training; retention as described above) | USA |
| Postmark | Transactional email | Recipient email, subject, body | USA |
| Sentry | Error monitoring | Stack traces, request metadata (PII-scrubbed) | USA |
| Cloudflare R2 | File storage and backup storage | Uploaded documents (encrypted); and the Service's daily per-firm database backups, which contain all Customer Data | USA |
| Upstash | Rate limiting | IP addresses, user IDs (hashed) | USA |
| Intuit (QuickBooks Online) | Accounting sync, only if your firm connects QuickBooks | Client name and billing email, invoice and payment amounts and dates, matter reference | USA |
| Microsoft Azure (and Microsoft Graph) | Hosting and database; document sync and email filing if your firm connects them; calendar sync if a user connects their own Outlook calendar (pushing deadlines and consultations to it, and reading that user's own events back to show them in the Service, as the Google row describes); from the effective date of our notice of this change, speech-to-text transcription of deposition audio (Azure AI Speech) for firms that use transcription on our servers | All Customer Data (encrypted at rest); where connected, also matter documents and filed client email bodies and attachments; where a user connects their Outlook calendar, pushed deadlines and consultations (the same details as the Google row); for deposition transcription, the recorded audio and, as recognition hints, the deponent's and matter's names (audio not stored by us) | USA (East US 2 — Virginia) |
| OpenAI | Voice-memo transcription (only once set up on the Service) | Voice-memo audio, when set up | USA |
| Free Law Project (CourtListener) | Case-law research, citation check, docket tracking (docket tracking not yet available) | Research search terms; case citations extracted from a draft (not the draft); tracked case numbers, once docket tracking is available | USA |
| Google (Google Calendar) | Calendar sync, only if a user connects their own Google Calendar (and only once connecting is set up on the Service): pushing deadlines and consultations to that calendar, and reading that user's own events back to show them in the Service (see "Google user data" below) | Pushed deadlines (title, date, matter, client name) and consultations (time, location, prospective client's name, contact details and stated reason) | USA |
All processors are contractually obligated to protect Customer Data, except that Free Law Project is engaged only under its public API terms; and Intuit (QuickBooks Online) and Google (Google Calendar) act as independent controllers, under their own terms and the firm's or user's own agreement with them, as the Sub-processors page explains. See DPA for the full list of sub-processors.
Google user data (Google Calendar). When a user connects their own Google account in Settings → Calendar Sync, Trial Commander receives from Google the account's email address (to show which account is connected), access to that user's calendar events, and read-only access to the list of their calendars. We use this access only to provide calendar sync to that user:
- Push. We create, update and delete the calendar events Trial Commander itself adds (deadlines and consultations from matters the user can open), so they stay current in the user's calendar.
- Show. We read the title, start and end time, all-day flag and link of the user's own events for a date range (for example the next 60 days on the Deadlines page) to show them beside matter deadlines, and we read the start and end times to keep a booking page from offering a time the user is already busy. These reads are made when the page is opened and are not stored, except as follows.
- Choose a calendar per matter. On a matter's calendar routing card we read the names and ids of the calendars the user can add events to, so they can pick which one that matter's deadlines go to. The list is read when the card is opened and not stored; we store only the id of the calendar the user picks for that matter.
- Chronicle import. If the user chooses Import from calendar in Chronicle, each timed event of that day becomes a time block the user reviews, and its title, times and link are stored with that block. If the user then asks for an AI-drafted time narrative for that block, the event's title is sent to our AI provider as described in our AI Disclosure.
We store the connected account's email and its encrypted access and refresh tokens, the ids of the events we pushed so we can update them, and the id of any calendar the user picked for a matter. We do not sell Google user data, use it for advertising, let people read it except as the user asks or as security or the law requires, or use it to develop, improve or train AI or machine-learning models. A user can disconnect at any time in Settings → Calendar Sync, or revoke Trial Commander's access in their Google Account settings. Trial Commander's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.2 Dictation Through Your Browser's Speech Recognition
Trial Commander can take dictation through the speech-recognition service built into the user's web browser: in Crucible, Trial Commander's deposition workspace (when no transcription on our servers is set up), and in the matter notes, time-entry narratives, the Ask Trial Commander and Atticus boxes, and the staff intake description fields. Nothing is dictated unless a user starts it. Where the browser can transcribe on the user's own computer, Trial Commander asks it to, and the audio does not leave the device; Trial Commander receives only the text.
What is disclosed, and to whom. When the browser cannot transcribe on the device, the browser — not Trial Commander — captures the audio from the microphone and may send it to the browser's vendor (for example Google for Chrome, Microsoft for Edge or Apple for Safari) to be transcribed. Trial Commander receives only the resulting text, which is added where the user is writing. We never receive or store that audio.
Whose terms apply. The vendor handles that audio under the user's own agreement with the vendor and under the vendor's privacy policy, not under an agreement with Trial Commander, and Trial Commander cannot see or control what the vendor does with it. For that reason browser vendors are not listed as Trial Commander sub-processors. Trial Commander says which mode applies, and names the vendor, before dictation starts. Crucible recommends browser dictation for testing, not for a real deposition. On a matter set to keep all AI on the user's computer, only on-device dictation is offered. A firm that does not want deposition audio handled by a browser vendor can type or paste testimony instead.
5. Data Security
We implement industry-standard security practices:
Technical:
- TLS 1.2+ for all data in transit
- AES-256 encryption at rest (database + field-level for privileged data)
- Passwordless and multi-factor authentication options
- Role-based access control with least privilege
- Tamper-evident audit log with Merkle-chain integrity
- Automated daily backups with tested restore procedure
- Security headers (HSTS, CSP, X-Frame-Options)
- Rate limiting and abuse prevention
- Regular security updates and dependency scanning
Administrative:
- Production access is limited to the principal of iHOST LABS, LLC. Trial Commander has no other personnel with access to production systems or Customer Data.
- Principle of least privilege for access within the Service
- Incident response plan with 72-hour notification commitment
Trial Commander has not undergone a third-party security audit or a SOC 2 examination, and does not hold a SOC 2 report of its own. Where this policy describes a sub-processor as SOC 2 certified, that certification is the sub-processor's and not ours.
Physical:
- SOC 2 compliant hosting (Microsoft Azure)
6. Data Retention
See Terms of Service § 8 for retention schedule.
Summary:
- Customer Data: retained during active subscription + 30 days post-cancellation
- Backups: the database's point-in-time restore backups are kept for 35 days; the Service's own daily per-firm backups are deleted once more than 30 days old, by a weekly sweep (up to about 37 days); backups a firm administrator creates on demand are not deleted automatically. See Terms of Service § 8.3.
- Audit logs: kept for as long as the firm's account exists, with no automatic deletion, and deleted together with the firm's other Customer Data when that data is deleted after cancellation. See Terms of Service § 8.5.
- Account/billing data: kept for as long as the firm's account exists, and deleted together with the firm's other Customer Data when that data is deleted after cancellation. Trial Commander does not keep a separate seven-year billing archive. Our payment processor keeps its own records independently: Stripe retains transaction records under its own retention policy and its own legal obligations, and deleting a firm from Trial Commander does not delete them from Stripe. See the Sub-processors list.
- Visit records (website and, for firms that opted in, Service usage): deleted 180 days after the visit's last activity, by a daily sweep. The link between a firm and the browser it signed up from is removed on the same schedule. When a user account is deleted, the visits recorded as that user's are deleted with it. You can ask us to delete your visit records sooner by writing to privacy@trialcommander.com. Because we do not know an anonymous visitor's name, tell us the IP address you visited from and roughly when (or, if you have an account, your account's email address); we will find and delete the matching records. We may be unable to find visits from an address shared by many people, and we will not delete records that appear to belong to someone else.
- LinkedIn Lead Gen form answers (§ 2.4): kept while we are in conversation with you and for 24 months after our last contact, then deleted; sooner on request.
- Identity documents (§ 2.1): deleted automatically, by a daily sweep, once the client has no open matter and the firm's retention period — 12 months by default, which the firm can change — has passed since the client's last matter closed; each deletion is recorded in the firm's audit log. An identity document on a client who has never had a matter is not deleted by the sweep: it stays until the firm removes it, or until the firm's Customer Data is deleted.
- Email index entries (§ 2.1): an entry for a conversation that was not filed is deleted once 90 days pass with no new message in it. An entry for a conversation a user marked as not to be filed is kept, so that it is not offered for filing again. Filed email is Customer Data and is kept as Customer Data.
- Voice-memo and deposition audio (§ 2.1, § 4.2): not stored.
7. Your Rights
7.1 As a Law Firm Customer
You can at any time:
- Access your data via the Service
- Correct inaccuracies in your Account Data
- Export your data (time records, trust records, matter data)
- Delete your data (via account cancellation)
7.2 As a Client User (Client Portal)
You can:
- View your own matter information, invoices, and trust balance
- Contact your attorney's firm for corrections or deletions
- Request your information be transferred to a different firm (via your attorney)
7.3 Privacy Rights by Jurisdiction
Florida residents — We comply with FL Stat. § 501.171 (data breach notification) and Florida Bar Rule 4-1.6(e) (attorney confidentiality).
California residents — Under CCPA, you have rights to know, delete, correct, and opt out of sale and sharing. We do not sell personal information. If you accept the LinkedIn cookie on our public website, LinkedIn receives information about your visits (§ 2.5), which may be "sharing"; you can opt out with the Cookie settings link, and we treat Global Privacy Control as that opt-out.
EEA/UK residents — Under GDPR/UK GDPR, you have rights of access, rectification, erasure, restriction, portability, and objection. The lawful basis we rely on for each purpose is set out in § 7.4 — for example, contractual necessity for account data and legitimate interest for security data. Where we rely on your consent, you may withdraw it at any time; withdrawing does not affect what we did with your consent before you withdrew it. Contact privacy@trialcommander.com to exercise rights. You also have the right to lodge a complaint with a data protection supervisory authority — in particular in the EEA country where you live or work, or where you believe your rights were infringed — or, in the UK, with the Information Commissioner's Office. We would welcome the chance to address your concern first, at privacy@trialcommander.com, but you do not have to contact us before you complain.
All U.S. residents — If you have a concern about how we handle your personal information, write to privacy@trialcommander.com. You may also file a complaint with the attorney general of your state or, where your state has one, its privacy regulator.
7.4 Lawful Basis for Each Purpose
For Customer Data we act as the law firm's processor (§ 1): the firm, as controller, decides why that data is processed and is responsible for having a lawful basis for it (see DPA § 4.1). For the information we handle as controller, we rely on the following:
- Providing the Service (accounts, sign-in, features, and the integrations a firm or user chooses to connect — § 2.1, § 2.3, § 4): performance of our contract with the firm. For a member of the firm's staff, or another person the firm gives access, who is not a party to that contract: our and the firm's legitimate interest in providing the access the firm arranged.
- Billing and transactions: performance of our contract with the firm; and legal obligation, for the tax and accounting records the law requires us to keep.
- Transactional emails and service announcements: performance of our contract with the firm.
- Support requests (§ 3): performance of our contract with the firm, and our legitimate interest in answering questions and improving our help material.
- Security, fraud and abuse prevention, rate limiting, and audit logs (§ 2.2): our legitimate interest, and the firm's, in keeping the Service and its data secure; and legal obligation, where the law requires a record.
- Measuring visits to our website and, for firms that opt in, use of the Service; the days of use during a firm's first 30 days; and requests for features a plan does not include (§ 2.2): our legitimate interest in understanding and improving our website and the Service. You can object (§ 7.3), and we honour Global Privacy Control and Do Not Track as described in § 2.2.
- Responding to a LinkedIn Lead Gen form (§ 2.4): steps you asked us to take before any contract, and our legitimate interest in following up on your request.
- Marketing email: your consent — the box you ticked (§ 2.4). You can withdraw it at any time with the unsubscribe link.
- The LinkedIn Insight Tag and LinkedIn's cookies (§ 2.5): your consent — choosing "Accept". You can withdraw it at any time with the Cookie settings link.
- Complying with the law (for example tax records and court orders): legal obligation.
7.5 Automated Decision-Making
We do not make decisions about you that produce legal effects, or that similarly significantly affect you, based solely on automated processing, including profiling. The AI features in the Service (§ 4) prepare drafts, summaries and suggestions for a law firm's attorneys and staff; a person at the firm reviews that output and decides what, if anything, to use, file or send (see our AI Disclosure). AI agents in the Service cannot file anything with a court, send anything to a client, opposing counsel or a court, move funds, or sign anything. Some security protections run automatically — for example, limits on repeated requests and locking an account after repeated failed sign-ins — to protect accounts and the Service. If one of them affects you, write to security@trialcommander.com.
8. Security Incidents
If we experience a data breach affecting your information, we will:
- Notify affected customers within 72 hours of confirmation
- Provide details about the scope, data affected, and remediation
- Assist you in your own breach-notification obligations under FL Stat. § 501.171 or other applicable law
These steps follow our documented internal incident response plan.
9. Children
The Service is not intended for use by anyone under 18. We do not knowingly collect information from minors. If you believe a minor has provided information to us, contact privacy@trialcommander.com for removal.
10. International Transfers
Trial Commander is hosted in the United States. If you access the Service from outside the U.S., your information will be transferred to, stored, and processed in the U.S. For EEA/UK users, we rely on Standard Contractual Clauses (SCCs) where applicable.
11. Changes to This Policy
We may update this Privacy Policy on 30 days' notice. Material changes require customer opt-in; minor changes take effect automatically.
The update of October 9, 2026 (privacy contact, complaints, lawful bases, automated decisions). This update names in § 2.1 kinds of information the Service already handles that this policy did not list — identity documents, email filed from Microsoft 365, text messages and call records, voice memos, deposition testimony captured in Crucible, what clients enter through the client portal, intake links and booking pages, and documents synced from OneDrive or SharePoint — with their sources in § 2.3 and their retention in § 6; adds § 4.2 (dictation through the browser's own speech recognition, on the user's device where the browser can); adds, in § 2.1 and § 4, deposition transcription by Microsoft Azure AI Speech, from the effective date of the notice; states in § 4 that Intuit and Google act as independent controllers; adds to § 7.3 the right to lodge a complaint with a supervisory authority (EEA/UK) and with a state attorney general or privacy regulator (U.S.), and the right to withdraw consent; adds § 7.4 (the lawful basis for each purpose) and § 7.5 (automated decision-making); names our privacy contact in § 12; and removes a closing line that described this policy as a template awaiting counsel review. Apart from that new transcription purpose, it describes practices already in place and does not change what we collect, use, share or keep. Firms that already had an account when this update was published are being emailed notice of it, and it takes effect for those firms thirty days after that email, on the date the email states.
11.1 The update of October 5, 2026 (LinkedIn)
On October 5, 2026 we added § 2.4 (LinkedIn Lead Gen forms) and § 2.5 (the optional LinkedIn cookie); changed § 2.2 and § 7.3 to match; added the LinkedIn lead line to § 6; and corrected the tc_src line in § 2.2, which is now set on any page of our website that a campaign link opens and also keeps the link's utm_content and utm_term tags.
- New visitors and new customers. This update applies from October 5, 2026 to everyone who visits our website, to everyone who answers one of our LinkedIn forms, and to every firm that signs up on or after that date.
- Firms that signed up before October 5, 2026. We are emailing notice of this update to your firm's administrators. It takes effect for your firm thirty days after that email, on the date the email states. Until then, the policy as it stood before this update governs your firm's account, and we do not track your firm or its users in any new way: we do not offer the LinkedIn cookie to anyone signed in to Trial Commander (§ 2.5), and the new
utm_contentandutm_termtags are kept only for firms that sign up on or after October 5, 2026 — we never add them to the records of a firm that signed up before. (Someone who visits our public website signed out is a website visitor like any other: we cannot tell that they belong to your firm, and they are asked, like any other visitor, whether to accept the LinkedIn cookie.)
12. Contact
Our privacy contact answers questions about this policy and about how we handle personal information, and handles requests to exercise the rights described in § 7. Write to privacy@trialcommander.com, or by post to the address below, marked for the attention of the privacy contact.
- Privacy Requests: privacy@trialcommander.com
- Security Issues: security@trialcommander.com
- General Support: support@trialcommander.com
- Postal: iHOST LABS, LLC, 66 West Flagler St, 6th Floor, Miami, FL 33130