Draft document
Privacy Policy
Last updated: September 10, 2026
1. Overview
This Privacy Policy describes how CoClient collects, uses, stores, and protects information when you use the CoClient website and Mac application.
2. Information We Collect
We may collect account information (such as your email address), billing information processed by Stripe, ordinary workspace metadata needed to operate the web app, and limited diagnostic or usage information about the CoClient Mac app. Case files and case memory remain stored locally on your Mac by default. Case-derived content or queries leave your Mac only when you authorize the exact request once or grant a scoped approval for the current case session.
Private validation workspace
The web Case Check keeps matter titles, source files, extracted passages, findings, conversations and written feedback encrypted on your device by default. Optional cloud storage receives ciphertext encrypted in your browser with your recovery key. CoClient does not hold that key. Losing it makes this private content irrecoverable; a password reset or payment cannot restore it. Account email, billing, opaque record identifiers, sizes and timestamps are separate operational metadata.
The default document scan runs locally. Optional hosted AI shows the exact excerpts and question and asks for approval for each request. Approved text is readable by CoClient and Fireworks during processing. Fireworks may temporarily cache prompts in memory. This flow does not upload original files or your key. Stored results are encrypted in your browser. Choose the local scan if you do not want this disclosure.
First-party usage measurement records fixed event names, random visitor/session identifiers, account-linked opaque matter identifiers, counts and selected feedback categories. A signed visitor identifier lasts up to 90 days. We do not put filenames, questions, case text, source quotes, written feedback or recovery keys into product analytics. You can delete your account from the private workspace even while it is locked; this removes its primary records and associated product events. Device copies and exported encrypted backups must be deleted separately. Infrastructure backup retention must be finalized and disclosed before public launch.
Earlier encrypted web-vault records
When the encrypted web-vault feature is available, your browser creates a recovery key and encrypts protected vault records before CoClient stores them. CoClient receives encrypted envelopes and limited operational metadata, such as the record type, time, and an opaque case-deletion scope; it does not receive the recovery key or the readable protected payload. The recovery key remains only in the browser while the vault is unlocked. If you lose it, CoClient cannot recover or decrypt those protected records. This vault protection does not cover ordinary account and case metadata that the web workspace needs to operate.
Read-only Gmail refresh
The browser Gmail connector is not enabled for general use until the required Google, privacy, security, and release reviews are complete. If it is enabled, you choose exact sender addresses for a case and start each refresh yourself. The browser asks Google only for read access, reads matching Gmail updates directly from Google, and encrypts selected text-only updates before CoClient stores an encrypted envelope. CoClient does not receive a reusable Google credential or a raw Gmail response through this connector, and the connector cannot send email, create Gmail drafts, change mailbox data, import attachments, or render imported HTML. Our enabled release will provide the disclosures and privacy-policy configuration required by the Google API Services User Data Policy.
3. How We Use Information
We use the information we collect to provide and improve CoClient, process payments, communicate with you about your account or the alpha, and comply with legal obligations.
4. Data Security
We take reasonable measures to protect information stored on our servers. The encrypted web vault is designed so that protected vault payloads cannot be decrypted by CoClient without your recovery key. Browser origin isolation does not protect against a compromised device, harmful browser extension, or malicious code running with access to this site, so keep your device and browser updated and protect your recovery key. Because privileged case material stays local on your Mac by default, you remain in control of your most sensitive files.
5. Your Choices
You may delete your account from Settings. That removes the account and its primary CoClient records, including workspace/case data, encrypted web-vault envelopes, access/waitlist records, and in-app audit and analytics records; deleting a case removes its case-scoped vault envelopes. Where a record belongs to another customer or business process, CoClient removes your identifying reference without deleting that other record. You may also contact us for account questions. Optional OpenAI, DuckDuckGo, CourtListener, public-source, and server-rules lookups show the finalized outbound URL or request body before transmission. You may keep the request local, authorize that exact request once, or authorize matching requests for the current case session. Session approvals are held only in memory, are scoped by case, provider, operation, destination, and data class, and may be revoked for future requests. Revocation cannot recall information already sent. Outside providers may retain authorized requests under their own policies or disclose them when legally required.
Advanced users may enter their own OpenAI API key in the Mac app. The key is held for the running app session, is sent only to OpenAI as required to authenticate an approved request, and is not sent to CoClient. Approved requests travel directly from the Mac app to OpenAI. OpenAI usage is billed to and governed by the key owner's OpenAI account.
Authorizing a transmission may affect confidentiality or attorney-client privilege. CoClient does not determine whether privilege exists or whether a particular disclosure legally waives it.
6. Draft Status
This privacy policy is a draft and has not been reviewed by legal counsel. It will be finalized before CoClient is released to the general public.