This policy explains what BriefAudit collects, what it does with it, and — most importantly for a legal brief — what happens to the document you upload.
Your brief
An uploaded brief is written to a private temporary directory, read once to extract its citations and quotations, and deleted when the verification response ends, whether it succeeds, fails or is cancelled. The text of your brief is not indexed, used to train anything, or shown to another customer.
The report, the CSV audit and the extraction log are returned directly in the response and are not stored on our servers. If you close the tab without downloading them, they are gone.
Verification lookups
To verify a result, BriefAudit may send one extracted citation, bibliographic identifier or quoted passage at a time to Evidite's GenieCore service and to the source indexes needed for that lookup, such as Stacks or CourtListener. We do not send the whole brief, its filename or your account details with those lookups.
What we collect
At registration: your email address, and optionally your name, firm or court, and role. We also keep the authentication, Terms acceptance, credit and payment records needed to operate your account; those records may include timestamps, IP address and user agent.
If Usage statistics is on, we collect session-level aggregate metrics: the product and document type, citation counts by result, and processing time. These records contain no account ID, role, filename, citation text, quotation or other document content.
If you separately opt in to Citation research, we may retain de-identified citation-level mismatch data: the submitted citation metadata, the canonical record it resolved to and which fields differed. This does not include the brief, its filename, surrounding prose or quoted passages. Turning the setting off stops future contributions.
How we use it
To operate the service, to send transactional email such as receipts and account confirmations, and to understand aggregate usage. We do not sell your data and we do not share it with third parties for advertising.
Who we share it with
Only the providers needed to run BriefAudit: cloud hosting, payment processing, and transactional email, plus the source indexes described above. If you separately opt in to marketing communication, account contact fields may be sent to our CRM provider. We do not sell personal information or share it for third-party advertising.
Cookies and storage
Your sign-in tokens are kept in your browser's localStorage. We do not use tracking cookies and we do not run third-party analytics.
Retention
Account data is retained while your account is active. Usage records are retained for accounting, fraud prevention and legal compliance. Uploaded documents and derived files are retained only for the active verification response. Aggregate telemetry stored without an account ID and de-identified, opt-in research records may be retained to measure and improve verification quality because they are not linked to an account.
Security
Passwords are hashed, never stored in plain text. All traffic is carried over TLS. Verification runs in an isolated container with a per-run temporary directory. Operational logs may retain service events, errors, and limited citation or quotation lookup text for up to 90 days, but not the complete uploaded brief or its filename.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, export or delete your personal data. Write to us and we will act on the request.
Children
BriefAudit is not directed at children under 13, and we do not knowingly collect data from them.
Contact
For any privacy question, email info@evidite.com.
Questions about your data?
Write to info@evidite.com. The button below opens a pre-addressed message.
Email us about privacy