Court Ledger is built around a simple principle: your client documents are yours. This policy explains exactly what we collect, what we don't, and how your documents are processed.
By default, Court Ledger retains nothing about your clients. Input documents are deleted from our servers as soon as processing finishes. Extracted data and output files are deleted within an hour of your first download unless you have enabled data retention. Extraction runs on Amazon Bedrock, which under AWS's terms does not store your document content after a request completes or use it to train models; we also keep Bedrock's optional request logging switched off (see Section 7). We do not sell your data and it is never used to train AI models.
This Privacy Policy explains how Court Ledger, a sole proprietorship owned and operated by Anden Beers ("Court Ledger," "we," "us," or "our"), handles information in connection with the Court Ledger application and the court-ledger.com website (together, the "Service"). It describes the personal information we collect from account holders and how your documents are handled during processing.
Unless you have enabled data retention in your account settings, we do not store or retain on our servers:
Input documents are deleted from our servers as soon as processing completes, regardless of your data retention setting and whether the run succeeded or failed. Extracted data and output files are deleted within an hour of your first download unless data retention is enabled. With retention off, no run log is written at any point, so no record of the payees, amounts, or account names in your documents is created.
Two exceptions we would rather state than let you discover.
We also do not use your documents or extracted data to train AI models, and our AI provider does not retain them (see Section 7).
When you submit a document for processing:
We describe the temporary working area explicitly rather than claiming documents are never written anywhere, because reading a scanned PDF requires rendering its pages. What we commit to is that this storage is transient and per-run, and that it is deleted when the run ends.
Document content is never used to train any AI model, by us or by our AI provider.
By default, extracted data and output files are deleted within an hour of your first download. If you enable data retention in your account settings, we will store your extracted transaction data and output files on our servers so you can access prior accountings within the application. Retained runs are kept until you delete them or close your account, and we do not impose an expiry - if you would prefer an automatic one, tell us and we will set it for your account. You can disable data retention at any time, which will stop future storage; you may also request deletion of any previously retained data by emailing [email protected]. Input documents are never retained regardless of this setting.
We use the limited information we collect to provide and maintain the Service, process payments and manage subscriptions, provide support, secure the Service and prevent abuse, and comply with legal obligations.
We do not sell or rent personal information. We share limited information only with the service providers below, each of which is necessary to operate the Service:
We do not use advertising networks, analytics providers that profile individuals, or data brokers. We may also disclose information where required by law or to protect our legal rights, and in connection with a merger, acquisition, or sale of assets (with notice to affected users).
We retain account, billing, and subscription information for as long as your account is active. After you close your account we delete account records within 30 days, except for billing and transaction records, which we keep for seven years because tax and accounting rules require it. Input documents are never retained. Extracted data and output files are retained only if you have enabled data retention in your account settings, with one exception we would rather state than have you discover: an output workbook that is never downloaded has no deletion timer set on it, so it stays in the database until you ask us to remove it.
Backups. Your uploaded documents are never written to our database. Figures extracted from them are – as your finished workbook, and while a run is in progress or paused, as the extraction itself – and those are covered by the retention terms above. The documents themselves are not. They exist only in a temporary working area on the processing container, and container storage is not backed up by our infrastructure provider, so your client documents cannot appear in any backup at any point. When that working area is deleted at the end of a run, the documents are gone.
Our database is separate, and it is backed up automatically for disaster recovery. What the database holds is your account record, your run history (matter and account labels only, as described in Section 2), any output file waiting to be downloaded, and output files you have chosen to retain. Those can persist in a backup for a period after you delete them from the live system. We do not edit backups in response to a deletion request, because doing that reliably is not possible; backups age out on a rolling schedule and no one restores one except to recover from an infrastructure failure. When we say something is deleted, we mean it is removed from the live system and ages out of backups thereafter.
You may request deletion of your account information at any time (see Section 10).
Because the Service handles confidential client material, we describe our safeguards specifically rather than in generalities.
We are a small team and do not currently hold SOC 2 or ISO 27001 certification; we would rather state that plainly than imply an audit we have not undergone. No method of transmission or storage is completely secure. If we become aware of a security incident affecting your personal information or document content, we will notify you without undue delay and in any event within 72 hours of confirming it, describing what happened, what data was involved, and what we are doing about it. We commit to that timeline whether or not a particular law requires it, because a firm with its own notification duties cannot meet them on information it does not have.
Many of our users are attorneys, professional fiduciaries, and CPAs with independent duties of confidentiality, and the documents processed may be subject to attorney-client privilege or similar protections. We want you to be able to assess this accurately rather than rely on marketing language:
If your firm requires a written description of this data flow, a subprocessor list, or a data processing agreement in order to satisfy its own professional-responsibility obligations, email [email protected] and we will provide one.
Depending on where you live, you may have the right to access, correct, or delete personal information we hold about you, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA). California residents may also use an authorized agent to make a request and are entitled to non-discrimination for exercising their rights. To make a request, email [email protected] from the address on your account. If we cannot match the request to an account we will ask you to verify it from that address before we act, since acting on an unverified deletion request is itself a way to lose someone's data. We respond within 45 days, extendable once by a further 45 days where the law permits and we tell you why. An authorised agent must provide written permission signed by you.
Residents of other states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, and Texas) have comparable rights and may use the same address. We honour these requests regardless of where you live rather than checking whether your state obliges us to.
Where your data is handled. Court Ledger is operated from the United States. Your account record, your run history, and any output files you have chosen to retain are stored in the United States.
Document extraction is different, and we would rather be precise than reassuring. Page images from your statements are sent to Amazon Bedrock through a global inference profile, which means AWS may carry out any given request in any of its regions, including regions outside the United States. We use that profile because AWS prices it below the US-only equivalent.
AWS's terms for Bedrock apply in every region: your document content is not stored after the request completes and is not used to train any model, and we keep Bedrock's optional request logging switched off (see Section 7). So what changes with region is where a page is read, not what is kept afterwards, which is nothing. Nothing else about your data leaves the United States - documents are never stored outside the transient per-run working area described in Section 4, and the database holding your account and run history is US-hosted.
If your firm has a data-residency obligation this does not meet, email [email protected] before you upload anything. Processing region is a configuration setting and we can move the service back to US-only regions; we would rather hear from you than have you assume one way or the other.
If your firm requires a data processing agreement (DPA) for its use of the Service, contact us at [email protected] and we will make our standard DPA available.
We may update this policy from time to time. We will post the updated version with a new effective date and, for material changes, give you notice by email or within the application at least 14 days before they take effect. A change is material if it broadens what we collect, adds a purpose for using your information, adds a subprocessor that receives document content, weakens a retention or deletion commitment, or reduces your rights under this policy. Fixing a typo or clarifying existing wording is not. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
Questions or requests? Email us at [email protected].