Privacy & data handling

Your firm’s data is yours.

Legal Codex is the shared, vetted AI library for law firms. The whole product rests on a single promise: what your firm puts in stays your firm’s — never used to train a model, never visible to another firm, and provable from the system itself rather than from a policy you have to take on faith.

Last updated 14 June 2026

Where we are today

Legal Codex is a pre-launch product running early design-partner pilots. This page describes the data practices in place now and the commitments we hold ourselves to. As we move toward general availability we’ll formalize these into a full privacy policy and data-processing terms — and we’ll tell design partners directly when that happens.

What we collect

  • Account information. Your name, work email, firm, and role — handled through our authentication provider so you sign in with a magic link, no password to store.
  • The assets your firm creates. The prompts, skills, and workflows your lawyers author, along with their metadata (author, tested date, model, trust status).
  • Usage events. Product analytics — what gets searched, viewed, and reused — so a firm can see adoption spreading. These events carry no asset content and no client data.

How your data is isolated

Every firm is a separate tenant. Isolation is enforced at the database layer with row-level security, so a query can only ever return your own firm’s rows — cross-firm access isn’t a setting that can be misconfigured, it’s a property of the system. Every asset carries a safe-for-client-data flag, and every state-changing action is written to an append-only audit log: who did what, to which asset, when.

We don’t train on your content

Your library is never used to train, fine-tune, or improve any AI model — ours or anyone else’s — and is never shared with or made visible to another firm. Legal Codex doesn’t run AI models on your behalf; it’s where the proven way to do a task lives, which you then run in the AI tools you already use.

Who we rely on

We use a small set of established infrastructure providers to operate the service. Each processes data only to provide its function:

  • Supabase — managed Postgres database and storage.
  • WorkOS — authentication and magic-link sign-in.
  • Vercel — application hosting and delivery.
  • PostHog — product analytics (usage events, no asset content).

We’ll keep this list current as the product grows, and design partners can ask for the specifics of where their data lives at any time.

Your choices and contact

Your firm owns its data and can request an export or deletion. For any privacy question — what we hold, how it’s handled, or to exercise a request — reach us at hello@legalcodex.com.