Privacy Policy

Last updated: July 15, 2026

This Privacy Policy describes how BarNone AI ("we", "us", "our") collects, uses, and shares information when you use the BarNone AI service ("Service"). It applies to law firms and their users; data flowing through the Service that belongs to your firm's clients is "Customer Data" and is processed under our Terms of Service plus any executed data processing addendum (DPA).

1. Data we collect

  • Account data: name, email, firm name, password hash (handled by Supabase Auth), TOTP enrollment metadata for two-factor authentication.
  • Prospect data: name, work email, phone number, firm size, practice areas, and any notes submitted through our pricing-request form.
  • Customer Data: matter records, contacts, invoice metadata, calendar events, and email drafts/sends generated through the Service. Some of this is mirrored from PracticePanther via OAuth.
  • Integration tokens: OAuth refresh tokens for Google Workspace, Microsoft 365, PracticePanther, and Slack, stored encrypted at rest.
  • Usage data: pages viewed, actions taken (approvals, sends, drafts), AI token consumption, and timing.
  • Device data: user-agent, IP address, and approximate location (for trusted-device records and security monitoring).
  • Cookies: session cookies (Supabase Auth), our session-timeout cookies (sb-session-started, sb-last-active), the MFA trust cookie (sb-mfa-trust), and product analytics cookies (PostHog).

2. How we use the data

  • Operate, maintain, and improve the Service.
  • Respond to pricing requests and other sales inquiries.
  • Authenticate users and enforce security policies (suspension, MFA, session timeouts).
  • Generate AI-drafted communications on your behalf — drafts are reviewed by a human before send.
  • Send transactional emails (alerts, password resets, integration expiration notices, AI budget threshold warnings).
  • Provide platform-administration features to internal BarNone AI staff: cross-firm observability, usage metrics, and incident response.
  • Comply with legal obligations and enforce our Terms.
We do not sell your data or Customer Data. We do not use Customer Data to train AI models that are made available to other customers.

3. Third-party processors

We use the following third parties to deliver the Service. Each handles only the categories of data necessary for its function.
  • Supabase — authentication, database, file storage.
  • AWS Bedrock (Anthropic Claude) — AI inference. Prompts and Customer Data passed to the model are processed under AWS Bedrock's terms.
  • PracticePanther — source of truth for firm/matter/contact/invoice data; connected via OAuth at the firm's authorization.
  • HubSpot — alternative source of truth (contacts, companies, deals, meetings, tasks) for firms that connect it; connected via OAuth at the firm's authorization.
  • Google Workspace / Microsoft 365 — email sending and reading (restricted Gmail scopes gmail.compose + gmail.readonly; Microsoft Graph Mail.ReadWrite) and calendar events.
  • Slack — approval cards and assistant interactions inside the firm's workspace.
  • Resend — transactional email delivery (alerts, password reset, etc.).
  • Sentry — error monitoring. Stack traces and request metadata are sent; we scrub PII from error payloads where possible.
  • PostHog — product analytics. Configured WITHOUT autocapture or session replay; we capture only explicit events.
  • Inngest — background job orchestration (durable execution of scheduled and event-driven tasks).
  • Cloudflare Turnstile — CAPTCHA on login/signup/password-reset forms.
  • Vercel — application hosting.

4. Data retention

We retain Customer Data for the duration of your subscription. After termination, we delete Customer Data on request, and in any case within a reasonable wind-down period — unless a longer period is required by law or by an executed agreement. Deletion of a terminated account's data is performed by our team as an operational procedure rather than automatically; contact us to request it and we will confirm when it is complete. Pricing-request prospect data is retained for twenty-four (24) months after submission and is then deleted automatically. Audit logs are retained for at least one year for security and compliance.

5. Security

We use industry-standard practices: TLS in transit, encrypted storage at rest, row-level security on the database, JWT-claim-based tenant isolation for headless workers, two-factor authentication (TOTP), session timeout enforcement, and bot mitigation via CAPTCHA. We monitor errors and alert on credential expirations and AI cost anomalies. No system is perfectly secure; you are responsible for safeguarding your own credentials.

6. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or port your personal data. To exercise these rights, contact privacy@bar-none.ai. We will acknowledge your request within thirty (30) days and tell you how we intend to handle it. We will not retaliate against you for exercising your rights.

Two limits we would rather state plainly than leave you to discover. First, requests are fulfilled manually by our team today, so complex requests may take longer than the acknowledgement window — we will keep you informed of progress. Second, much of the personal data in the Service is Customer Data belonging to a law firm that uses us: it reaches us from that firm's own systems, and the firm — not BarNone AI— decides what may be corrected or erased, and may be legally obliged to retain it. Where we act as that firm's processor, we will forward your request to the firm and support them in responding, rather than acting on their records unilaterally.

7. International transfers

Our service infrastructure is located primarily in the United States. If you access the Service from outside the United States, you consent to the transfer of your data to the United States and other jurisdictions where our processors operate.

8. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it.

9. Changes

We may update this Privacy Policy. Material changes will be communicated by email or in-app notice with at least thirty (30) days' notice. Continued use of the Service after the effective date constitutes acceptance.

10. Contact

Privacy questions or requests: privacy@bar-none.ai. For enterprise customers requiring a Data Processing Addendum (DPA), reach out to the same address.
Placeholder notice: this document is a pilot-grade template and is not a substitute for legal review. Replace the bracketed placeholders, update contact addresses, confirm processor lists are accurate, and have qualified counsel review before signing paying customers. Sections 4 and 6 were revised on 2026-07-27 to describe the deletion and data-subject-request process we actually operate (manual, team-performed) rather than an automated one; revisit this wording once per-record erasure/export tooling ships.