Privacy Policy
Last updated: July 15, 2026
This Privacy Policy describes how BarNone AI ("we", "us", "our") collects, uses, and shares information when you use the BarNone AI service ("Service"). It applies to law firms and their users; data flowing through the Service that belongs to your firm's clients is "Customer Data" and is processed under our Terms of Service plus any executed data processing addendum (DPA).
1. Data we collect
- Account data: name, email, firm name, password hash (handled by Supabase Auth), TOTP enrollment metadata for two-factor authentication.
- Prospect data: name, work email, phone number, firm size, practice areas, and any notes submitted through our pricing-request form.
- Customer Data: matter records, contacts, invoice metadata, calendar events, and email drafts/sends generated through the Service. Some of this is mirrored from PracticePanther via OAuth.
- Integration tokens: OAuth refresh tokens for Google Workspace, Microsoft 365, PracticePanther, and Slack, stored encrypted at rest.
- Usage data: pages viewed, actions taken (approvals, sends, drafts), AI token consumption, and timing.
- Device data: user-agent, IP address, and approximate location (for trusted-device records and security monitoring).
- Cookies: session cookies (Supabase Auth), our session-timeout cookies (
sb-session-started,sb-last-active), the MFA trust cookie (sb-mfa-trust), and product analytics cookies (PostHog).
2. How we use the data
- Operate, maintain, and improve the Service.
- Respond to pricing requests and other sales inquiries.
- Authenticate users and enforce security policies (suspension, MFA, session timeouts).
- Generate AI-drafted communications on your behalf — drafts are reviewed by a human before send.
- Send transactional emails (alerts, password resets, integration expiration notices, AI budget threshold warnings).
- Provide platform-administration features to internal BarNone AI staff: cross-firm observability, usage metrics, and incident response.
- Comply with legal obligations and enforce our Terms.
3. Third-party processors
- Supabase — authentication, database, file storage.
- AWS Bedrock (Anthropic Claude) — AI inference. Prompts and Customer Data passed to the model are processed under AWS Bedrock's terms.
- PracticePanther — source of truth for firm/matter/contact/invoice data; connected via OAuth at the firm's authorization.
- HubSpot — alternative source of truth (contacts, companies, deals, meetings, tasks) for firms that connect it; connected via OAuth at the firm's authorization.
- Google Workspace / Microsoft 365 — email sending and reading (restricted Gmail scopes
gmail.compose+gmail.readonly; Microsoft GraphMail.ReadWrite) and calendar events. - Slack — approval cards and assistant interactions inside the firm's workspace.
- Resend — transactional email delivery (alerts, password reset, etc.).
- Sentry — error monitoring. Stack traces and request metadata are sent; we scrub PII from error payloads where possible.
- PostHog — product analytics. Configured WITHOUT autocapture or session replay; we capture only explicit events.
- Inngest — background job orchestration (durable execution of scheduled and event-driven tasks).
- Cloudflare Turnstile — CAPTCHA on login/signup/password-reset forms.
- Vercel — application hosting.
4. Data retention
5. Security
6. Your rights
Two limits we would rather state plainly than leave you to discover. First, requests are fulfilled manually by our team today, so complex requests may take longer than the acknowledgement window — we will keep you informed of progress. Second, much of the personal data in the Service is Customer Data belonging to a law firm that uses us: it reaches us from that firm's own systems, and the firm — not BarNone AI— decides what may be corrected or erased, and may be legally obliged to retain it. Where we act as that firm's processor, we will forward your request to the firm and support them in responding, rather than acting on their records unilaterally.