AI Privacy Shield for Legal Professionals

Privacy Policy

Effective Date: July 1, 2026  ·  Version 1.1  ·  privilegeprotector.com

The most important thing to know: The Privilege Protector desktop application is designed so that your clients’ names, case numbers, and other identifying information do not reach our servers. The application is designed to process that information locally on your device. We receive only account and billing information, as described in detail in this Policy. This design description reflects our intent; please read this Policy in full for important qualifications.

This Privacy Policy (“Policy”) describes how IB4E, LLC, a Wyoming limited liability company (“Licensor,” “we,” “us,” or “our”), collects, uses, shares, and protects information in connection with your use of the Privilege Protector website at privilegeprotector.com, the customer account portal, the desktop application (“Software”), and any related services (collectively, the “Services”). This Policy applies to information collected by Licensor. It does not govern the data practices of third-party AI Providers or OpenRouter Technologies, Inc. (“OpenRouter”), which are governed by their own privacy policies.

By using the Services, you consent to the data practices described in this Policy. If you do not agree to this Policy, do not use the Services.

1. Information We Collect

1.1 Account Information. When you create an account or purchase a Subscription, we collect: your name; email address; billing address (for tax and payment purposes); law firm name; and subscription history.

1.2 Payment Information. Payment card information is collected and processed by Stripe, Inc., our authorized payment processor, pursuant to Stripe’s own terms of service and privacy policy. We receive from Stripe only a tokenized card reference, last four digits of the card number, card type, and expiration date. We do not store your full payment card number on our servers.

1.3 License and Activation Data. Our license server receives and stores: your license key identifier; a one-way hardware fingerprint of each activated device (a hash of device identifiers that we believe does not, standing alone, constitute personally identifiable information, though we cannot guarantee this characterization in all jurisdictions); hostname of activated devices; operating system type and version; Software version; and activation timestamp and last check-in timestamp.

1.4 Compliance Check-In Data. The Software is designed to transmit periodic compliance check-in data to our license server in connection with the license validation process. This check-in data is designed to include session counts and compliance status indicators but not Client Data, prompt content, or session log content. As with all software, the actual data transmitted may vary from the design intent; we describe our intent accurately to the best of our knowledge.

1.5 Website and Support Data. When you visit our website or contact our support team, we may collect: browser type and version; IP address; pages visited; referring URL; and the content of communications you send to us.

1.6 Information We Are Designed NOT To Collect. To the best of our knowledge and consistent with our design intent, we do not collect: the content of your prompts or documents; client names, case numbers, addresses, or any other Client Data as defined in the EULA; the text or content of AI Provider responses; or the session log maintained on your device. These descriptions reflect our design intent. We cannot guarantee that no such information reaches our servers in all circumstances, including in the event of a software error or security incident.

2. How We Use Your Information

We use the information we collect for the following purposes, each of which is necessary for the performance of our contract with you or for our legitimate business interests:

3. How We Share Your Information

3.1 No Sale. We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

3.2 Service Providers. We share information with third-party vendors who assist in operating the Services, including:

These service providers are contractually required to: (a) use your information only to perform services for us; (b) maintain administrative, technical, and physical safeguards designed to protect your information; and (c) not further disclose your information except as required by law. We require service providers to maintain security standards that are, in our reasonable judgment, appropriate for the nature of the information shared.

3.3 Legal Process. We may disclose your information if required to do so by court order, subpoena, search warrant, or other valid legal process. Where legally permitted, we will make reasonable efforts to notify you of any such required disclosure before complying, so that you may seek a protective order or other appropriate relief. In criminal or national security matters, we may be legally prohibited from notifying you. We do not have access to and cannot disclose Client Data, as that information is designed not to reach our servers.

3.4 Business Transfers. If we are involved in a merger, acquisition, asset sale, or reorganization, your information may be transferred as part of that transaction. We will notify you by email and by posting a notice on our website prior to any such transfer and will provide you with an opportunity to opt out of the transfer of your personal information where required by law.

3.5 Protection of Rights. We may disclose your information if we believe in good faith that such disclosure is necessary to protect the rights, property, or safety of Licensor, IP Owner, our users, or the public, or to detect, prevent, or address fraud, security, or technical issues.

3.6 Aggregate Data. We may share aggregate, de-identified information (which does not identify any individual) with third parties for research, marketing, or other purposes.

4. Third-Party AI Providers

4.1 Transmission of De-Identified Payloads. When you use the Software, De-Identified Payloads (from which Client Data has been processed by the Software prior to transmission) are transmitted to AI Providers that you select via OpenRouter. These De-Identified Payloads are governed exclusively by the AI Provider’s own terms of service and privacy policy, not by this Policy.

4.2 Work-Product Header. The Software prepends a work-product protection header to each De-Identified Payload, which instructs AI Providers not to use the communication for training, product improvement, or other secondary purposes. We make no representation regarding whether any AI Provider will comply with such instruction or whether any AI Provider’s actual data practices conform to the instruction. You are encouraged to review each AI Provider’s privacy policy and to configure any available privacy settings.

4.3 No Responsibility for AI Provider Data Practices. We are not responsible for the data practices, security measures, or policies of any AI Provider or OpenRouter. If an AI Provider suffers a data security incident that involves De-Identified Payloads, we are not responsible for that incident, provided that it did not result from our gross negligence or willful misconduct.

4.4 OpenRouter Privacy Policy. OpenRouter’s privacy policy is available at openrouter.ai/privacy.

5. Data Retention

5.1 Account Information. We retain account information for as long as your account is active and for a period of four (4) years after account closure. We retain account information for four years to preserve our ability to respond to disputes, enforce our agreements, and comply with applicable law, including the four-year California statute of limitations for written contracts.

5.2 License and Activation Data. We retain license and activation records for the duration of your Subscription plus four (4) years to support license verification, dispute resolution, and fraud prevention.

5.3 Payment Records. We retain payment records as required by applicable tax and financial regulations, generally seven (7) years.

5.4 Website and Support Data. We retain web server logs for ninety (90) days. We retain support communications for four (4) years from the date of the last communication in a support thread.

5.5 Deletion Requests. Upon a verified deletion request (see Section 7), we will delete or anonymize your personal information within forty-five (45) days, subject to our legal retention obligations under Sections 5.1 through 5.4 and any obligation to preserve information in connection with pending or reasonably anticipated litigation.

6. Data Security

6.1 Security Measures. We implement commercially reasonable administrative, technical, and physical safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction, including TLS encryption for data in transit between the Software and our servers, and access controls limiting employee access to account data on a need-to-know basis.

6.2 No Absolute Security. No method of electronic transmission or storage is 100% secure. We cannot guarantee the absolute security of information transmitted to or stored by us. By using the Services, you acknowledge and accept this risk.

6.3 Security Incidents. In the event of a security incident affecting your personal information, we will notify you as required by applicable law, including the California data breach notification requirements under Cal. Civ. Code §§ 1798.29 and 1798.82. Our target for notifying affected individuals following discovery of a qualifying breach is within seventy-two (72) hours, subject to the time needed to investigate the scope of the incident and identify affected individuals. Notification timelines may vary based on the nature of the incident and applicable legal requirements.

7. Your Rights and Choices

7.1 Access and Correction. You may access and update your account information at any time through your account portal at privilegeprotector.com/account or by contacting us at privacy@privilegeprotector.com.

7.2 Deletion. You may request deletion of your personal information by emailing privacy@privilegeprotector.com. We will process verified deletion requests within forty-five (45) days, subject to our legal retention obligations. Deletion of your account data will terminate your ability to access the Services.

7.3 Data Portability. Upon request, we will provide you with a copy of the personal information we hold about you in a commonly used, machine-readable format, to the extent technically feasible and legally required.

7.4 Marketing Opt-Out. You may opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email or by emailing privacy@privilegeprotector.com. You will continue to receive transactional communications (such as receipts, license keys, and renewal notices) even after opting out of marketing communications.

7.5 Do Not Track. Our website does not currently respond to “Do Not Track” signals from browsers.

8. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information.

8.1 Categories of Personal Information Collected. In the preceding twelve (12) months, we have collected the following categories of personal information: (a) Identifiers (name, email address, IP address, device identifiers); (b) Commercial information (subscription history, payment records); (c) Internet or electronic network activity information (website usage data); (d) Professional or employment-related information (law firm name, bar membership if provided); and (e) Inferences drawn from the above to create a profile about a consumer.

8.2 No Sale or Sharing for Cross-Context Behavioral Advertising. We do not sell or share your personal information for cross-context behavioral advertising purposes as defined by the CCPA/CPRA.

8.3 Sensitive Personal Information. To the extent that bar membership, professional license information, or other professional information constitutes “sensitive personal information” under the CPRA, we use such information only as necessary to provide the Services. You have the right to limit our use of sensitive personal information to the purposes specified in the CPRA.

8.4 Your California Rights. California residents have the right to: (a) know what personal information we collect, use, disclose, and sell; (b) request deletion of personal information, subject to certain exceptions; (c) correct inaccurate personal information; (d) opt out of the sale or sharing of personal information (not applicable here, as we do not sell or share); (e) limit the use of sensitive personal information; and (f) non-discrimination for exercising these rights.

8.5 Exercising California Rights. To exercise your California rights, submit a verifiable consumer request to privacy@privilegeprotector.com. We will respond within forty-five (45) days, with one forty-five (45)-day extension if necessary. We will verify your identity before processing any request. You may designate an authorized agent to make a request on your behalf; we require written authorization and identity verification for authorized agent requests.

9. Children’s Privacy

The Services are not directed to, and we do not knowingly collect personal information from, individuals under the age of eighteen (18). If we become aware that we have collected personal information from a person under eighteen (18), we will take steps to delete such information promptly. If you believe we have inadvertently collected information from a minor, please contact us at privacy@privilegeprotector.com.

10. Changes to This Policy

We may update this Policy from time to time. We will notify you of material changes by: (a) sending an email to the address associated with your account; and (b) posting the updated Policy on our website with a new effective date, at least thirty (30) days before material changes take effect. Non-material changes (such as clarifications, corrections, or formatting updates) may be made without prior notice. Material changes include any change that reduces your rights or increases our data collection in a manner that could adversely affect you. Your continued use of the Services after the effective date of any updated Policy constitutes acceptance of the updated Policy.

11. Contact Us

For questions, concerns, or requests related to this Privacy Policy:

IB4E, LLC — Privilege Protector Privacy Team
privacy@privilegeprotector.com

© 2026 Bell & Bird LLC. All rights reserved. Exclusively licensed to IB4E, LLC for worldwide distribution.