Privacy Policy
1. Who this policy covers
This policy explains how Nomos Engine ("we", "us") handles information when you use the Service at nomosengine.com. It covers the attorneys and staff who hold accounts with us. It is not a description of how your firm handles its own clients' information — that remains your responsibility, and this policy does not alter it.
Using the Service is also governed by our Terms of Use.
2. What we collect
| Category | What it is | Why |
|---|---|---|
| Account information | Your name, email address, role, and the firm your account belongs to. | To create your account, apply permissions, and let colleagues invite you. |
| Sign-in credentials | A password verifier or access token, never a readable password; or a Google account identifier if you use Google sign-in (see section 4). | To authenticate you and keep sessions separate. |
| Audit records | A record of security- and custody-relevant events — sign-ins and failed sign-in attempts, permission changes, exports, and deletions — with a timestamp and the acting account. | Attorneys have supervisory and record-keeping duties; an honest audit trail is part of the product, not incidental telemetry. |
| Matter metadata | Names and labels you give matters, and structural records such as which of your users may see which matter. | To organise your workspace and enforce access controls. |
| Operational logs | Ordinary server logs, including IP address, request path, and timing. | To keep the Service running, diagnose faults, and detect abuse. |
3. What we deliberately do not receive
Client file contents. This deployment runs in a non-custodial configuration. Custody is forced to device-only for every firm, which means the parts of the Service that would otherwise accept client file bytes refuse them. A firm may choose to be device-only on a custodial server, but on this server no firm can opt out of it. The practical consequence is that your clients' documents are not pooled in a vendor-controlled repository here.
Where the software is instead run on equipment you control, and you enable server-side storage there, client material is encrypted at rest with a key held on that equipment. If that key is lost, the encrypted material is permanently unrecoverable and we cannot restore it for you.
We also do not collect special categories of personal information about you for advertising, and we do not sell personal information or share it for cross-context behavioural advertising.
4. Signing in with Google
Google sign-in is optional. If you use it, we ask Google only for the openid, email, and profile scopes — enough to know who you are and to show your name. We do not request access to your Gmail, Drive, Calendar, or Contacts.
From that sign-in we store a stable Google account identifier and the email address associated with it, linked to your Nomos Engine user record. We request short-lived access only and do not ask Google for offline access, so we do not hold a long-lived refresh token for your Google account. We ask Google to prompt you to choose an account each time, so a shared machine does not silently reuse the last one.
Google's own handling of your data is governed by Google's privacy policy. You can review and revoke Nomos Engine's access at any time in your Google account's security settings; doing so does not delete your Nomos Engine account, which you can remove separately under section 11.
5. Research queries
When you ask a legal research question, we process the text of that question in order to answer it, and we retain it as part of your workspace so the answer remains reviewable and auditable. Treat a research query the way you would treat any other work product: do not paste client-identifying detail into a query unless you have determined that doing so is consistent with your confidentiality obligations.
Legal coverage is limited to Texas authorities. Answers are generated against authorities we hold, and every published proposition is bound to verbatim supporting text from a cited authority; where no such support exists, the Service abstains rather than guessing. That is a correctness measure, not a privacy measure, but it is why answers are traceable.
6. Depositions and recordings
Where the deposition feature is available to you, audio is transcribed locally by the software rather than being sent to a third-party transcription service. On this deployment, which is device-only, the server does not accept recording bytes at all.
Transcripts produced this way are rough, AI-generated, and uncertified. You are responsible for obtaining any consent or notice that recording requires, and for the retention and destruction of recordings and transcripts.
7. How we use information
- To provide the Service, authenticate you, and enforce access controls.
- To maintain the audit trail described above.
- To keep the Service secure — detecting failed sign-in attempts, abuse, and faults.
- To communicate with you about your account, billing, and material changes to the Service.
- To meet legal obligations, and to establish or defend legal claims.
We do not use your information to build advertising profiles, and we do not sell it.
8. Who we share it with
We share personal information only in these circumstances:
- Within your firm. Colleagues on your firm's account can see the matters and records their permissions allow.
- Service providers. Vendors that host and deliver the Service on our behalf, bound to handle the information only for that purpose — including our hosting provider and our network and TLS provider.
- Google, if and only if you choose Google sign-in, and then only to complete the sign-in exchange described in section 4.
- When the law requires it, or to protect rights and safety. If we receive a demand for information relating to your account, we will give you notice unless we are legally prohibited from doing so.
We do not sell personal information, and we do not disclose it to data brokers.
9. How long we keep it
Account and matter records are kept while your account is active and for as long as needed for the purposes above. Audit records are retained longer than ordinary content, because an audit trail that can be trimmed is not an audit trail — see section 11 for how deletion interacts with it. Operational logs are kept for a limited period for security and diagnostics.
You remain responsible for the retention and destruction schedule your own ethical and contractual obligations require.
10. Security
- Traffic to the Service is encrypted in transit with TLS.
- Where the Service stores documents at rest it encrypts them with AES-256-GCM, bound to the firm and matter they belong to, so material cannot be silently moved between tenants.
- Passwords are never stored in readable form.
- Access is scoped by firm and by matter membership, and privileged actions are audit-logged.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your information, we will notify you as required by applicable law.
11. Your choices, access, and deletion
You may review and correct your account information from within the Service. You may export a complete case file for any matter at any time.
You may ask us to delete your firm's data. Deletion removes firm content while preserving the audit trail of what was deleted and by whom — a record that something was destroyed is itself part of an honest audit history, and it does not retain the deleted content. Where you have a statutory right to access, correct, delete, or port your personal information, or to appeal a refusal, contact us at the address in section 15 and we will respond as the applicable law requires. We will not discriminate against you for exercising those rights.
Revoking Google's access, as described in section 4, is independent of account deletion.
12. Confidentiality and privilege
We understand that material passing through a legal practice may be privileged or confidential. Nothing in this policy is intended to waive any privilege, and our access controls and device-only custody posture are designed to reduce the occasions on which we hold such material at all. You remain responsible for determining whether placing particular information into the Service is consistent with your obligations to your clients.
13. Children
The Service is intended for legal professionals and is not directed to children. We do not knowingly collect personal information from children.
14. Changes to this policy
If we change this policy we will update the date at the top of this page, and we will give notice of material changes through the Service or by email before they take effect.
15. Contact
Questions about this policy, or requests concerning your information: hello@nomosengine.com.