How It Works Privilege & Ethics OpenRouter & AI Models Data & Security Billing & Plans Installation & Setup Firm & Enterprise

How It Works

The mechanics behind local PII stripping and why the sequence matters.

Privilege Protector works entirely on your computer. Before any AI prompt leaves your machine, the software identifies and removes client-identifying information, replaces it with neutral placeholders, and adds a formal work-product protection header. The AI model receives a clean, anonymized version of your prompt. When the AI responds, the software restores the original client information locally before you see the answer.

The result: you write your prompts normally, using real names and real facts. Your client's identity never reaches the AI service. The analysis you get back is complete and accurate — the client is just restored at the end, on your machine.

The entire protection process runs on your computer. Privilege Protector's servers never see your prompt content, your client's information, or the AI's response.

When you use an AI service without Privilege Protector, your prompt travels to Anthropic, OpenAI, or Google's servers exactly as you typed it — client name, case number, facts, and all. Those companies are governed by their own terms of service and data practices, over which you have no control.

With Privilege Protector, your client's identifying information never leaves your office. The AI service receives only the legal question, stripped of everything that would identify whose matter it is. The quality of the analysis is the same. The client's exposure is not.

Privilege Protector identifies and removes a broad range of client-identifying information, including names of parties, witnesses, and attorneys; case and docket numbers; contact information; government identification numbers; financial figures; dates tied to the matter; and business names that would identify the specific client or opposing party.

The software is designed to be conservative — when something could be identifying, it removes it. The goal is that the AI receives a legally coherent question about a matter it cannot identify.

No automated system catches everything. Before sending any prompt, you can review what the software identified and confirm it before proceeding. That review step is part of your professional responsibility, and the software is designed to make it easy.

Privilege Protector is a desktop application. It installs on your Windows machine and runs quietly in the background whenever you're working. It protects prompts across all major browsers — Chrome, Edge, Safari, Firefox — and all AI web interfaces, without requiring you to install separate extensions for each one.

Every session is logged on your machine with a record sufficient to produce a court-ready exhibit if privilege is ever challenged. That log stays on your computer. Privilege Protector's servers never receive it.

The Solo plan includes a Chrome and Edge extension that adds a convenient one-click workflow for sending prompts directly through PP from within your browser.

Privilege & Ethics

The legal framework and what it means for your professional responsibility obligations.

In United States v. Heppner, the court found that transmitting privileged communications to a third-party service — even without intending to waive privilege — constituted a disclosure that destroyed the protection. The attorney's intent was irrelevant. What mattered was that the information reached a third party governed by that party's own terms and policies.

United States v. Heppner, 384 F. Supp. 2d 1180 (D. Minn. 2005)

Every AI prompt that includes a client's name, case facts, or identifying details travels to a third-party server — Anthropic, OpenAI, Google — governed by that company's terms of service. Those terms typically permit the company to use submitted content for model training, product improvement, or other purposes. The moment your client's information reaches that server, the privilege analysis begins, and it may not end in your client's favor.

Privilege Protector addresses this by ensuring that the identifying information never reaches the third-party server in the first place. The AI receives only anonymized text.

No. No software product can guarantee a legal outcome, and we don't. The law governing AI-assisted legal work is developing rapidly, jurisdiction-specific, and not fully settled.

What Privilege Protector does is implement a documented, technically defensible protection measure: client PII is stripped locally before transmission, a formal work-product assertion is prepended to every prompt, and a cryptographically verifiable audit log records each session. If privilege is challenged, you have a contemporaneous record of the steps you took and a technical architecture grounded in Heppner, Hickman v. Taylor, Fed. R. Civ. P. 26(b)(3), and the Kovel framework.

You remain solely responsible for evaluating your professional responsibility obligations in your jurisdiction, for the particular matter, on the particular facts. Privilege Protector is a tool that supports that analysis — not a substitute for it.

Review the EULA's Section 5 for the full disclosure. It matters.

Before your anonymized prompt is sent to any AI service, Privilege Protector prepends a formal legal header that:

  • Asserts Federal Rule of Civil Procedure 26(b)(3) work-product protection
  • Cites Hickman v. Taylor, 329 U.S. 495 (1947) as foundational authority
  • Asserts California absolute work product doctrine (Cal. Code Civ. Proc. §§ 2018.020–2018.070)
  • Invokes the Kovel framework — treating the AI as an agent of counsel rather than a third-party disclosure
  • Instructs the model not to use the communication for training, product improvement, or secondary purposes
  • Identifies your firm, attorney name, email, and phone number as counsel

The header is generated dynamically from your firm profile settings and is different from a generic disclaimer you might type manually — it is tied to your specific credentials and prepended to every single transmission, not just the ones you remember to add it to.

Bar associations in California, New York, Florida, Texas, and elsewhere have issued formal guidance addressing attorneys' duty of competence (Model Rule 1.1) and confidentiality (Model Rule 1.6) in the context of AI tools. Most of that guidance focuses on two questions: does the AI service receive client confidential information, and what are its data practices?

Privilege Protector directly addresses both questions. Client information is stripped locally before transmission (Rule 1.6 confidentiality), and the work-product header asserts privilege protections and withholds consent to secondary use (data practices). The audit log provides a record that you took documented steps to protect confidentiality, which is relevant to the competence analysis under Rule 1.1.

You should review your specific jurisdiction's guidance. We recommend consulting the ethics opinions from your state bar before using any AI tool in client matters, with or without Privilege Protector.

Every session is logged locally on your machine. Each entry records the timestamp, the number and categories of information removed from the prompt (for example, "3 names, 1 case number, 1 email address"), whether the work-product disclaimer was transmitted, and cryptographic identifiers that allow you to prove, after the fact, that the prompt you sent to the AI was not the same as the prompt you originally typed.

Privilege Protector does not store your prompts, your client's information, or the content of the AI's responses. The log records only what was withheld — enough to construct a defense, not enough to reconstruct the matter. Your original prompt and your client's identifying information remain solely on your machine and are never transmitted to Privilege Protector's servers.

From the Settings menu, you can export a court-ready audit exhibit — a plain-language document suitable for attachment to a declaration in opposition to a motion to compel production of AI prompts. It shows each session, the categories of information removed, and an attestation explaining what the cryptographic record proves.

🤖 OpenRouter & AI Models

How the AI model access works, what it costs, and which models attorneys find most useful.

OpenRouter is a routing service that gives you access to 200+ AI models — Claude, ChatGPT, Gemini, Grok, Llama, DeepSeek, and more — through a single account and a single API key. Instead of maintaining separate accounts and billing relationships with Anthropic, OpenAI, and Google, you pay OpenRouter and use whichever model fits the task.

We use OpenRouter rather than connecting directly to individual AI providers because it gives you model flexibility without requiring you to manage multiple API relationships. You choose the model; we protect the prompt.

OpenRouter accounts are free to create. You add credits as you use them (pay-as-you-go), and you set your own spending limits. You pay OpenRouter directly — Privilege Protector does not handle or mark up your AI usage costs. We never see your OpenRouter API key or your usage data.

Create a free OpenRouter account at openrouter.ai. The setup wizard in Privilege Protector walks you through generating a key and connecting it.

AI usage is billed by OpenRouter on a pay-per-use basis, measured in tokens (roughly words). For typical legal work — drafting, research, document review — costs per query range from under a cent to about fifteen cents depending on the model you choose. A working attorney might spend $10–$30/month on AI usage through OpenRouter for moderate daily use.

  • Claude Sonnet 4.6 — recommended default, approximately $0.03 per query
  • Claude Opus 4.8 — highest capability, approximately $0.15 per query
  • Gemini 2.5 Flash — fast research tasks, approximately $0.01 per query
  • GPT-4o — general research, approximately $0.05 per query
  • DeepSeek V4 Flash — high-volume document review, approximately $0.001 per query

OpenRouter requires a minimum credit purchase (typically $5) before you can access paid models. Free-tier models are available with no credit purchase required, but they have rate limits and are not recommended for production legal work.

You control your spending cap in your OpenRouter account dashboard. We recommend setting a monthly limit when you first sign up.

Privilege Protector's setup wizard presents a curated list of five models recommended for legal work. Our default recommendation is Claude Sonnet 4.6 (Anthropic) — it has the strongest track record for following complex legal instructions accurately, handles long documents and multi-party fact patterns well, and the per-query cost is reasonable for daily use.

General guidance:

  • For most matters — Claude Sonnet 4.6. Drafting, research, deposition prep, contract review.
  • For high-stakes analysis — Claude Opus 4.8. Complex litigation strategy, expert cross-prep, matters where a mistake has real consequences. Higher cost is justified.
  • For quick lookups — Gemini 2.5 Flash. Citation checks, quick summaries, routine correspondence. Fast and inexpensive.
  • For document-heavy review — DeepSeek V4 Flash. Processing large production sets. Very low cost per token. See the note on DeepSeek below.

You can switch models at any time from the Settings window. The model selection does not affect the PII protection — all prompts go through the same stripping process regardless of which model receives them.

OpenRouter and the AI model receive only the anonymized prompt — the version from which client PII has been replaced with tokens. They never see your client's name, case number, address, or other identifying information. That information never leaves your machine.

What OpenRouter does receive: the anonymized prompt text, your API key (used for billing), and metadata about which model was called. OpenRouter's own privacy policy is available at openrouter.ai/privacy.

The work-product header prepended to every prompt instructs the AI model not to use the communication for training, product improvement, or other secondary purposes. We make no representations about whether individual AI providers honor that instruction — their actual data practices are outside our control, and you should review their terms of service. The Kovel framework and Heppner analysis provide the legal grounding; the technical protection is the PII stripping itself.

DeepSeek is operated by a Chinese company. Privilege Protector strips your client's PII before any prompt reaches DeepSeek's servers, so the identifying information does not leave your machine regardless of which model you use. However, the anonymized legal analysis itself does reach DeepSeek's infrastructure, which is subject to Chinese data governance laws.

For most general legal work — contract review, research, drafting — the anonymized prompt contains no identifying information and the risk profile is similar to any other model. For matters involving:

  • Government contracts or federal agencies
  • National security considerations
  • Foreign adversary parties
  • Sensitive intellectual property or trade secrets

Use Claude or GPT-4o instead. The cost difference is small relative to the risk. We display this note in the model picker within the application.

🔒 Data & Security

What leaves your machine, what stays on it, and what Privilege Protector itself can see.

Two things leave your machine when you send a prompt through Privilege Protector:

  • The protected prompt — your text with all identifying information removed, plus the work-product header. This goes to OpenRouter, which routes it to the AI model you selected.
  • Your OpenRouter API key — used to authenticate your request with OpenRouter for billing purposes. This key is stored in your operating system's secure credential store and is transmitted only to OpenRouter via encrypted HTTPS.

What does not leave your machine: the original prompt text, your client's name and identifying information, the record of what was removed and restored, the session log, and your Privilege Protector license key (which checks in only with our license server to confirm your subscription is active).

No. The PII stripping, work-product header generation, and prompt routing all run locally on your machine. Privilege Protector's servers never receive your prompt content — anonymized or otherwise.

The only information that reaches Privilege Protector's servers is what is necessary to manage your subscription: your name, email, firm name, billing information (processed by Stripe — we never see your full card number), and a license check-in that confirms your subscription is active. That check-in contains your license key and device fingerprint. It contains nothing about what you asked the AI, which client it involved, or what the AI answered.

This architecture is described in detail in our Privacy Policy.

No automated system catches everything, and we say so clearly in the EULA. Before you send any prompt, Privilege Protector shows you what it identified and intends to protect. You can review that list, and if something was missed, you can remove it manually before the prompt is sent.

The software is designed to err on the side of caution — if something could be identifying, it removes it. This occasionally catches things that don't need protection. That is the right tradeoff for legal work.

Structured identifiers — case numbers, Social Security numbers, phone numbers, email addresses, dates — are handled with high reliability. Person names in flowing prose are harder, particularly unusual names or names that appear as common words. That is where careful review matters most.

Reviewing what the software identified before you send is a professional responsibility, not an optional step. The software is designed to make that review fast and clear.

$ Billing & Plans

Subscription terms, the free trial, cancellation, and what each plan includes.

The 10-day free trial gives you full access to every feature in your selected plan starting from the day you sign up. A valid credit card is required to start the trial, but no charge is made until Day 11.

On Day 8, we send you an email reminder that your trial ends in two days. If you cancel before Day 10, your card is never charged and you have no obligation. If you do nothing, your subscription begins automatically on Day 11 at the rate shown at checkout.

OpenRouter usage during the trial is separate — you pay OpenRouter directly for any AI queries you send. Those costs begin immediately and are not part of the trial. You can start with a small OpenRouter credit ($5) and see what actual usage costs you before the trial ends.

Monthly subscriptions require 30 days written notice to cancel. Email support@privilegeprotector.com. Cancellation takes effect 30 days from the date of your notice, and you will be billed for any amounts that fall within that 30-day notice period. For example, if you notify us on the 5th of the month and your billing date is the 15th, you will be charged for the billing cycle that starts on the 15th before your cancellation becomes effective.

Annual subscriptions are locked for 12 months from the date of the first charge (Day 11 of your trial). Early cancellation of an annual plan does not reduce the amount owed for the full annual term.

To cancel, email billing@privilegeprotector.com with your account email and plan details. We process all cancellation requests within one business day and confirm in writing.

Monthly billing lets you pay month to month. Annual billing, paid upfront for 12 months, saves 15% on the per-seat rate. Annual plans are locked for 12 months — you cannot cancel mid-term for a refund.

For a solo practitioner using the product consistently, annual billing saves roughly $144/year. For a 5-seat firm, the savings are roughly $360/year. If you are uncertain whether the product fits your workflow, start monthly — you can switch to annual at any renewal.

A seat is one activated installation of Privilege Protector on one device. If you use PP on your office desktop and your home laptop, that is two seats. If you deactivate one device (in Settings) before activating another, you can transfer a seat without using an additional one.

  • Solo — 1 seat (one device at a time)
  • Firm — 2 to 10 seats
  • Firm Plus — 11 to 25 seats
  • Enterprise — 25+ seats, custom terms

Seats are counted by activated devices, not by users. If two attorneys share a single machine (uncommon but possible), that is one seat. If one attorney uses three machines, that is three seats.

Yes. Firm and Firm Plus plans include paralegal seat support. Paralegal use counts toward your seat total. Each paralegal who uses the product on their own machine uses one seat.

Privilege Protector does not distinguish between attorney and paralegal users at the software level — both get the same PII protection and work-product header on every transmission. Whether paralegal use of an AI tool under attorney supervision satisfies your jurisdiction's professional responsibility rules is a question for your ethics counsel, not for us.

Solo plans are limited to one seat and are intended for individual attorney use.

💻 Installation & Setup

Getting Privilege Protector installed and connected to your AI account.

About 10 minutes for the full setup, including the OpenRouter account creation.

  • Download and install — 3–5 minutes depending on your connection. The installer is about 66 MB.
  • Activation wizard — 2–3 minutes. Enter your license key, firm profile (name, bar number, email), and your OpenRouter API key.
  • OpenRouter account — 2–3 minutes if you don't have one. Sign up at openrouter.ai, generate an API key, add credits (minimum $5), and paste the key into the wizard. The wizard links directly to the OpenRouter key page.

After that, PP runs in your system tray and protects every prompt automatically. There is no ongoing configuration required.

No. Privilege Protector installs to your personal user folder and does not require administrator rights or an IT department. No system-wide changes are made. No administrator password prompt appears during installation.

The application runs as a local-only service on your machine — it is bound to your computer and is not accessible from the network or from the internet. If your firm has an IT policy that restricts locally-running services, that would need to be addressed with your IT team, but most standard firm policies do not restrict this type of application. Contact support@privilegeprotector.com and we can provide documentation for your IT department if needed.

Not yet. The current version supports Windows 10 and Windows 11 (64-bit). A Mac version supporting macOS 12 (Monterey) and later — on both Apple Silicon (M1/M2/M3) and Intel — is in development and expected in Q3 2026.

To be notified when the Mac version is available, email support@privilegeprotector.com with "Mac waitlist" in the subject line.

Yes, it is safe. The flag is a false positive. Privilege Protector does exactly what antivirus heuristics are trained to watch for: it is a self-contained executable that runs a local HTTP service and makes outbound HTTPS connections to third-party servers. That behavioral profile is identical to certain types of malware — but it is also identical to thousands of legitimate applications.

The application does not modify any system files, does not capture keystrokes from other applications, does not access any data outside your Privilege Protector prompts, and does not communicate with any server other than OpenRouter (for your AI queries) and our license server (for your subscription status).

To resolve the flag:

  • In Windows Defender: go to Virus & threat protection → Exclusions → Add an exclusion for the Privilege Protector installation folder
  • In other AV products: add a similar exclusion or allow the application explicitly
  • Contact support@privilegeprotector.com if you need help with a specific AV product

If your firm's IT policy requires AV clearance before installation, contact us and we can provide documentation for your IT team.

🏛 Firm & Enterprise

Multi-attorney deployment, firm-wide settings, and enterprise options.

On a Firm plan, one account holder (typically the managing partner or IT administrator) holds the subscription and manages seats. Each attorney installs Privilege Protector on their own machine and activates with the firm's license key. Each installation uses one seat from the firm's allotment.

Firm plans include firm-wide PII settings, so the practice area, custom entity names, and firm-specific identifiers (your firm's own name, case management system IDs) can be configured uniformly across all seats. Each attorney's firm profile (their individual name, bar number, contact information) is set on their own machine and appears in their work-product header.

The Firm Plus plan (11–25 seats) adds dedicated onboarding support and quarterly review sessions. Enterprise (25+ seats) includes custom deployment options, SLA commitments, and white-glove onboarding. For Enterprise inquiries, contact enterprise@privilegeprotector.com.

Yes, subject to your seat limit. A Solo plan allows one activated device at a time. If you want to move from one machine to another, deactivate the old device in Settings before activating the new one — this transfers the seat rather than consuming a new one.

If you regularly use two machines (office desktop and home laptop, for example), you need two seats — which means a Firm plan with a minimum of 2 seats. Firm plans start at 2 seats and go up to 10.

Privilege Protector works with any AI web interface accessed through your browser — it is not integrated with practice management software. It intercepts at the browser level, so when you open Claude.ai, ChatGPT, Gemini, or any other AI tool to analyze a matter, the protection applies regardless of where the underlying client data lives.

If your workflow involves copying text from Clio, MyCase, or another cloud system and pasting it into an AI prompt, Privilege Protector protects that pasted text before it reaches the AI — the source of the text does not matter.

PDF, Word, and Excel document upload features let you anonymize entire documents before AI analysis, which covers workflows that involve attaching client files rather than pasting text.

Still have questions?

Use the support assistant — it resolves most issues instantly, and opens a pre-filled ticket if it can't.

Open Support Assistant →

Or email support@privilegeprotector.com directly  ·  start your free trial