Privacy Policy
The Matter Vault exists to hold privileged legal material. This policy describes the small amount of information the vault collects about the people who use it, why, and what happens to it. It is deliberately short because the vault deliberately collects little.
Who we are
The vault is operated by LITICUS Legal Intelligence, a division of Alpha Source Technologies Inc., 701 5th Ave, Suite 4200, Seattle, WA 98104. Contact contact@liticus.ai.
Where a law firm has licensed a vault for its own use, that firm decides who may access it and what is stored in it. In privacy terms the firm is the controller (or "business") and we act as its processor (or "service provider"). Requests about your personal information may therefore be routed through the firm that invited you.
What we collect
About you, as a user:
- Your email address and, if an administrator entered one, your name.
- Sign-in events — when a sign-in link was requested, sent, used or refused, and from which IP address.
- Your activity — every file you upload, download or delete; every matter you open; every change an administrator makes to access or settings. Each entry records the time, your email, your IP address and, for sessions, your browser's user-agent string.
- Your second-factor secret, if you enrol an authenticator app. It is stored so that codes can be verified and is never displayed again after enrolment.
About the files placed in a matter:
- We store them encrypted, each matter under its own key. We do not open, read, index or analyse their contents in the course of operating the vault.
- We record each file's name, size, type and a cryptographic fingerprint (SHA-256) of its contents, so integrity can be verified and so a certificate of destruction can identify what was destroyed.
We do not collect anything else. There are no analytics, no advertising identifiers, no tracking pixels, no third-party scripts and no "share" widgets anywhere in the vault.
Why we collect it
- To run the service — an email address is the only way to reach you with a sign-in link; a session cookie is the only way to keep you signed in.
- Security — IP addresses and sign-in events let us rate-limit abuse, detect compromised accounts and investigate incidents.
- The access log itself is a feature. Firms use this vault precisely because it produces a tamper-evident record of who accessed what, and when. That record is part of the service you and your firm have asked for, and in many cases it is evidence.
The access log cannot be edited or erased
This is the point most privacy policies do not have to make, and this one does. Every logged event is cryptographically chained to the one before it and mirrored to storage that permits appending only. Nobody — not you, not your firm, not us — can alter or remove an entry without breaking every seal that follows, and the break would be detectable. This is by design and it is the reason the vault is trusted with privileged material.
A consequence is that requests to delete your personal information cannot extend to the access log. We will honour such requests for everything else, including disabling your account, but the record that you signed in on a given date and downloaded a given file is retained for as long as the vault exists.
How long we keep things
- Files — until the matter is destroyed. Destruction discards the matter's encryption key, after which the live data is permanently unreadable. Encrypted system backups taken before that moment may still hold a wrapped copy of the key; they expire on a fixed schedule, and the certificate of destruction states the date by which no copy remains.
- Account details — until your firm removes you or the firm's vault is closed.
- Access log — indefinitely, as above.
- Sign-in links — fifteen minutes, single use. Sessions — thirty days at most, twelve hours idle.
Who can see it
Administrators of your firm's vault can see the access log for that firm. LITICUS Legal Intelligence staff can see the log across all vaults in order to operate and secure the service. Where a firm administrator has authorised analysis for a matter, that matter's documents are also processed by our AI provider for the duration of the request; the provider does not train on them and retains them only briefly for abuse monitoring. Nobody else. We do not sell personal information, we do not share it for advertising, and we have never been asked to. If we receive legal process compelling disclosure, we will notify the affected firm unless the law forbids it.
Payments
Subscriptions are bought and managed at billing.liticus.ai, a separate service from the vault. Card details are entered on pages hosted by our payment processor, Stripe, and are never sent to or stored by LITICUS Legal Intelligence. The billing service holds only your billing email, the plan, and an opaque reference that links the subscription to your firm's vault; the vault receives from it nothing more than whether your firm's subscription is current. Stripe's handling of payment data is governed by Stripe's privacy policy.
Where it lives
The vault and the billing service run on servers we control in Amazon Web Services (AWS) data centres in the United States (US East, Northern Virginia). Every file is encrypted by the vault under its matter's own key before it is written to storage, and stored again under the storage service's own encryption at rest; all connections use TLS. Backups are encrypted and kept in the same region.
Who processes data for us
- Amazon Web Services — hosting, encrypted file storage, backups, and delivery of the vault's emails (sign-in links and notices). AWS operates the infrastructure; it does not hold the keys to your files.
- Stripe — payments, on Stripe's own pages (see Payments above).
- Our AI provider — only for a matter where a firm administrator has switched analysis on, as described under Who can see it.
Each processes data only to provide its service to us. We will update this list before adding a provider that handles vault data.
Your choices and rights
You may ask what we hold about you, ask us to correct it, or ask your firm to disable your account at any time. Depending on where you live you may have additional rights under laws such as the California Consumer Privacy Act or the GDPR, and we will honour them subject to the access-log limitation described above. Write to contact@liticus.ai.
Changes
If this policy changes materially we will update the date at the top and, for signed-in users, say so on the next sign-in. We will not weaken the encryption or logging commitments described here without notice.
LITICUS Legal Intelligence · a division of Alpha Source Technologies Inc. · 701 5th Ave, Suite 4200, Seattle, WA 98104 · contact@liticus.ai · (206) 222-6418