Cedent AI
Legal

Privacy Policy

Cedent AI, Inc. Effective: September 3, 2026 · Version 3.1 Supersedes Version 3.0 (September 1, 2026), which superseded the policy dated July 2026


Summary — The Things Most People Want to Know

  • We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
  • We do not use your clients’ data to train AI models. All AI inference runs on Amazon Bedrock inside AWS. No third-party model provider ever receives your clients’ information.
  • Your matter data belongs to your firm, not to us. For that data we act only as your processor, on your instructions.
  • If you connect a calendar, we ingest every event on it — including personal events — and run a classifier over each one. This surprises people, so it has its own section. See Section 6.
  • Microsoft’s permissions are broader than what we use. Connecting a Microsoft mailbox grants access we deliberately do not exercise. See Section 7.
  • Deleting a document in the app soft-deletes it — it leaves your view but we retain it for 30 days. See Section 11.
  • Your scratchpad lives in your browser, not on our servers. We can’t back it up, export it, or delete it. See Section 9.

This summary is not the policy. Please read the rest.


1. Who We Are and What This Covers

Cedent AI, Inc. (“Cedent,” “we,” “us”) provides an AI matter assistant for U.S. law firms. This Policy explains how we handle personal information across:

  • the marketing website at cedent.ai;
  • the application at app.cedent.ai; and
  • our communications with prospective and current customers.

The Service is offered only to law firms and licensed attorneys in the United States. It is not offered to consumers or to people seeking help with their own legal matters. If you are a client of a firm that uses Cedent and you want to exercise privacy rights over your information, contact your attorney — see Section 13.6.


2. The Three Roles — Who Decides What Happens to Your Data

This is the most important structural point in this Policy.

2.1 Where the firm decides (we are a processor)

For everything relating to a firm’s representation of its clients — Matter Data — the firm is the controller and the “business” under the CCPA. We are its processor and “service provider.” We act only on the firm’s documented instructions and never for our own purposes.

This covers: emails and attachments ingested from connected mailboxes; calendar events and their classifications (Section 6); uploaded documents; extracted facts, chronologies, and trust rankings; drafts and AI outputs; populated court forms including FL-150 and FL-142 financial disclosures; matter deadlines; and time-entry narratives.

Our commitments as processor are contractual and are set out in the Data Processing Addendum, which every customer accepts.

2.2 Where we decide (we are a controller)

For Account Data and website visitor data, we are the controller. This covers firm name and address; user names and work email addresses; seat assignments and role; authentication records; billing metadata; support communications; product usage telemetry; and marketing-site analytics.

2.3 Where a third party decides (independent controller)

Payment data. Payments are processed by Stripe, Inc. Your full card number and payment credentials are transmitted directly to Stripe and never reach Cedent’s systems. Stripe processes payment data as an independent controller under its own terms and privacy policy. We receive only limited transaction metadata — last four digits, card brand, expiry, and status.


3. Website Visitors

3.1 What we collect

IP address, browser and device type, pages viewed, referring URL, approximate location derived from IP, and timestamps. We also collect interaction data — which elements of a page are clicked and how far down it visitors scroll — and page performance timings such as how long a page took to render. We use Google Analytics 4 and PostHog for this. We do not record or replay browsing sessions on this website.

3.2 Why

To understand which content is useful, diagnose problems, and measure the effectiveness of our marketing.

3.3 We do not use analytics for advertising

We have disabled Google Signals and all Google Ads linkage in our Google Analytics configuration. We do not use analytics data to build advertising audiences, to personalize advertising, or to enable any third party to do so. We therefore do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are defined by the CCPA, and we do not offer a “Do Not Sell or Share My Personal Information” link, because there is nothing to opt out of.

3.4 Cookies

We use strictly necessary cookies, plus analytics cookies as described above. You can control cookies through your browser. Blocking analytics cookies does not affect site functionality.

3.5 Do Not Track

We honor Global Privacy Control (GPC) signals as opt-out requests where applicable. If your browser sends a GPC signal, our analytics do not start and no analytics cookie is set — the signal is acted on before anything loads, not recorded as a preference afterwards. We do not respond to legacy Do Not Track headers, which have no agreed standard.


4. Account Information

4.1 What we collect

Name, work email, firm name and address, job role, seat assignment, password or SSO identifiers (through Clerk), billing contact, transaction metadata from Stripe, support correspondence, and product usage telemetry (features used, error events, volumes — through PostHog and Axiom).

4.2 Why

To provide and secure the Service, authenticate users, bill, provide support, send service and security notices, meet legal obligations, and improve the product.

4.3 Marketing

We may send product and company email to business contacts. Every marketing message has an unsubscribe link. Unsubscribing does not stop transactional and security messages, which we must send.

We collect Account Data to perform our contract with the firm and for our legitimate business interests in operating and securing the Service. Providing it is necessary to use the Service.


5. Matter Data — Email and Documents

5.1 What is ingested

When an Authorized User connects a mailbox, the Service ingests email messages and their attachments, and users may additionally upload documents directly. The Service reads, performs OCR on, and organizes this content into matter workspaces; extracts facts and builds chronologies; identifies deadlines; drafts correspondence and court forms; and produces draft time entries.

5.2 What it contains

Matter Data routinely contains highly sensitive information about people who are not our customers — opposing parties, children, extended family, witnesses, and third parties. In California family law this predictably includes financial account details, income and tax information, medical and mental-health records, substance-abuse history, allegations of abuse, immigration status, and information about minors.

We treat all Matter Data as attorney-client privileged material by default. We do not distinguish between “sensitive” and “ordinary” Matter Data — the same protections apply to all of it.

5.3 We are not the right party to ask about it

Because the firm is the controller, we cannot give a third party access to, correct, or delete their information in a firm’s matter files at their request. Those requests go to the firm. See Section 13.6.

5.4 Court form data

The Service auto-populates official court forms, including the FL-150 Income and Expense Declaration and the FL-142 Schedule of Assets and Debts. This is the most sensitive data in the system: complete income, employment, expense, asset, debt, and account information for both parties to a dissolution.

This data is processed only to populate forms at the firm’s direction, is stored as Matter Data, is never used for training, and is never disclosed for any purpose of ours. The attorney is responsible for verifying every figure before a client signs the form under penalty of perjury — see Terms of Service Section 9.4.


6. Calendar Data — Please Read This Section

This section corrects a materially inaccurate description in our previous policy. We describe the actual behavior here.

6.1 What actually happens

If you connect a calendar, the Service ingests and stores every event on that calendar. For each event we store the title, description, location, attendees, and timing, and we run an automated AI classifier over it to determine whether it relates to a matter and, if so, which one.

6.2 This includes your personal events

The Service cannot know in advance which events are matter-related, so it processes all of them. That includes medical appointments, family and childcare events, therapy, religious observances, social plans, and any other personal entry on a connected calendar — including events belonging to other people who invited you.

We store these events and their classifications. Events classified as unrelated to a matter are still stored.

6.3 What we do not do with it

We do not use Calendar Data to train models; do not use it for advertising or profiling; do not disclose it to anyone outside the disclosed subprocessors needed to provide the Service; and do not use it for any purpose of our own. It is Matter Data, held under the same protections, with the firm as controller.

6.4 Your controls

  • Do not connect a calendar. Calendar connection is optional; the rest of the Service works without it.
  • Connect a dedicated work calendar rather than one holding personal events.
  • Configure exclusion rules in Account settings so matching events are not ingested.

How exclusion decides — this is better than you might assume. Exclusion rules are evaluated against event metadata, not event content. Cedent does not need to read the substance of an event in order to exclude it, and an excluded event’s content is never stored, classified, or associated with a matter.

The one exception is the keyword rule, which matches against terms you supply yourself. So the only content matching that happens is matching you explicitly asked for. If you would rather no content matching occur at all, use the other rule types and leave the keyword rule unset.

  • Disconnect at any time through your Account settings or your Google/Microsoft account.
  • Request deletion of ingested Calendar Data at privacy@cedent.ai. Disconnecting stops future ingestion but does not delete what was already ingested.

6.5 Tell your users before you connect them

Firms: please tell each Authorized User what happens before connecting their calendar. An attorney may not expect a work tool to read their spouse’s medical appointment. We surface this at the connection step, but the firm is the controller and the conversation is yours to have.


7. Connected Accounts — Google and Microsoft

7.1 What “narrowest permission” means, accurately

We request the narrowest permission scope each provider makes available for the functionality involved. That is not the same as the narrowest scope you might imagine, because the two providers offer very different granularity. We describe each honestly below rather than making a single claim that is only true of one.

7.2 Google Workspace and Google APIs

Cedent’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we:

  • use Google user data only to provide and improve user-facing features of the Service;
  • do not transfer it except as necessary to provide those features, with your consent, for security purposes, or to comply with applicable law;
  • do not use it for advertising or serve advertising from it;
  • do not sell it; and
  • do not allow humans to read it, except with your affirmative consent for specific messages, as necessary for security or to comply with law, or where it has been aggregated and de-identified.

Scopes we request: Gmail read (and send, where you enable outbound email); Calendar read and write; Drive access limited to files the Service creates or you select. Revoke at any time at myaccount.google.com/permissions.

7.3 Microsoft 365 — Broader Than We Use

Microsoft’s permission model is coarser than Google’s, and you should understand exactly what you are granting.

When you connect a Microsoft 365 account, the consent Microsoft requests confers:

  • read and write access to the connected user’s mail; and
  • read access to the entirety of that user’s OneDrive, and to every SharePoint site that user can reach.

The Service uses only the mail, calendar, and the specific files you select. But — and this is the part we will not obscure — that limitation is enforced by Cedent’s application logic, not by Microsoft’s permission model. Microsoft does not offer a narrower grant for this functionality. Technically, the token permits more than we use.

We commit contractually that we access, retrieve, and process only what is necessary to provide the Service, and that we do not access other OneDrive or SharePoint content notwithstanding the technical ability. That commitment is enforceable under the Terms of Service and the DPA.

If you require the narrower scope to be enforced at the identity-provider layer rather than by us, do not connect a Microsoft account. Your Microsoft administrator may revoke consent at any time in the Entra admin center.

7.4 Practice management systems

Where you connect Clio or MyCase, data flows in both directions at your direction and is governed by your agreement with that provider once delivered to it.


8. Automated Processing and AI

8.1 What is automated

The Service uses AI to classify and route email, associate calendar events with matters, extract and rank facts, build chronologies, propose deadlines, draft correspondence and court forms, flag apparently missing documents, prepare action briefs, and draft time entries.

8.2 Your firm controls how much is automatic

Automated behavior is configurable per firm. Your Administrator controls whether the Service drafts automatically, whether it proposes actions, and how much runs without a prompt. No configuration causes the Service to send communications or file documents without an attorney’s authorization.

8.3 Human review is required, by design and by contract

Every output is a draft for attorney review. The Service does not make decisions that produce legal effects about anyone — the attorney does. Under our Terms, the firm must independently verify all output before use.

8.4 No training on your data

We do not use Matter Data, Calendar Data, or any client information to train, fine-tune, or improve any machine learning model, and we do not permit any subprocessor to do so.

All AI inference runs on Amazon Bedrock inside Amazon Web Services. Prompts and completions are not retained after a request is served and are not used to train or improve any model — ours, AWS’s, or any model provider’s. No third-party model provider receives your clients’ information.

Scope note, stated precisely: this concerns model inference. Document text extraction and OCR are performed by Modal, and database hosting by Neon. These are disclosed subprocessors under written obligations at least as protective as this Policy and the DPA. We describe this accurately rather than claiming that no matter content ever leaves AWS.


9. Scratchpad — Stored in Your Browser

The Service’s scratchpad stores notes in your browser on your device. Content is transmitted to us transiently for AI processing when you invoke a feature needing it, and is not stored by Cedent unless you save it to a matter.

Consequences:

  • we hold no copy, so we cannot back it up, export it, or delete it;
  • it is not included in your firm’s export or in any deletion certification;
  • it is permanently lost if browser storage is cleared, the profile is deleted, or you switch browsers or devices; and
  • your firm cannot retrieve the unsaved scratchpad of a departed user.

Because client confidences may rest on the device, securing the device is the firm’s responsibility. If scratchpad content matters, save it to the matter.


10. Data We Write Outside the Service

At your direction the Service delivers data outside its own boundary:

OutputDestinationNotes
Matter handover packagesGoogle DriveFull matter file, written to the Drive location you specify
Email export archives (ZIP)DownloadRetained 14 days to enable download, then automatically deleted
Word and PDF exportsDownload / your deviceDrafts, briefs, populated court forms
Outbound emailYour mailbox and its recipientsSent from your account, in your name
Calendar eventsYour connected calendarCreated or modified by the Service
Practice management syncClio / MyCaseGoverned by your agreement with that provider

Once data leaves the Service at your direction, our security and confidentiality obligations do not follow it. You control the destination, its access controls, and its retention. A matter handover package placed in a broadly shared Drive folder is a confidentiality problem we cannot see or prevent.


11. Retention and Deletion

11.1 You can request deletion at any time

A firm may request deletion of its data at any point — during the subscription, after cancellation, or at any time in between — and we will honor it. On written request we provide a certification of deletion. Requests go to privacy@cedent.ai.

11.2 Soft-delete — stated precisely

When you delete a document inside the Service, it is soft-deleted: removed from your view but retained in our systems, so an accidental deletion can be reversed. A soft-deleted document is not gone.

  • Soft-deleted documents are purged after 30 days.
  • They remain fully protected — encrypted, access-controlled, never used for training — while retained.
  • If you need a document destroyed immediately and irreversibly, email privacy@cedent.ai. Do not rely on in-app deletion alone.

We state this because “you can request deletion at any time” and “deleted documents are retained for 30 days” are both true, and the second is the part that gets omitted.

11.3 Default retention schedule

DataRetention
Matter Data while subscription activeUntil you delete it, or the subscription ends
Post-cancellation export window30 days — read-and-export access to retrieve everything
Matter Data after the export windowDeleted from production within 30 days; purged from encrypted backups within 90 days
Soft-deleted documentsPurged 30 days after deletion
Email export archives (ZIP)14 days from generation
Time-entry ledger narrativesRetained permanently as a business record, not cleared after review; deleted with the account
Unsaved scratchpad contentNever held by us
Account DataWhile the account is active, then as needed for tax, accounting, and legal records — generally 7 years
Application logs (Axiom)30 days
Infrastructure audit trail (AWS CloudTrail)24 months
Website analytics14 months

11.4 Backups

Backups are encrypted and rotate on a fixed cycle. Deleted data persists in backups until rotated out, within 90 days, and is not restored to production after a deletion request.

We may retain data longer where required by law or to preserve evidence under a litigation hold. Data retained on hold stays under full protection and is deleted when the obligation lapses.


12. Security

  • Encryption: TLS 1.3 in transit; AES-256 at rest. Keys managed in AWS KMS; secrets in AWS Secrets Manager.
  • Access control: least privilege, MFA enforced for all personnel with production access, role-based authorization, logical tenant separation. Firm data is never combined across firms.
  • Logging: application logs through Axiom; infrastructure and administrative audit trail through AWS CloudTrail.
  • Residency: all production data is stored and processed in the United States.
  • Personnel: written confidentiality obligations; access only where required to operate or support the Service.
  • Compliance: we are pursuing SOC 2 Type II. We will not claim certification before the report is issued.
  • Incidents: we notify affected firms without undue delay and no later than 72 hours after becoming aware of a breach affecting Matter Data.

Full detail is in the Security Schedule to the DPA.


13. Your Privacy Rights

13.1 California (CCPA/CPRA)

If you are a California resident whose personal information we hold as a controller — that is, Account Data or website data — you have the right to know what we collect and how we use it; to access it in portable form; to correct inaccuracies; to delete it; to opt out of sale or sharing (we do neither — Section 3.3); to limit use of sensitive personal information (we do not use SPI for purposes triggering this right); and to non-discrimination for exercising any of these.

13.2 Categories we collect as a controller

Identifiers (name, email, IP); commercial information (subscription and transaction records); internet activity (usage and analytics); professional information (firm, role, bar jurisdiction); and inferences limited to product usage. Sources: you, your firm, Stripe, and our analytics providers. Purposes: as in Sections 3 and 4. Disclosures: to the subprocessors in Section 14, for business purposes only. We have not sold or shared personal information, and have not disclosed sensitive personal information for any purpose triggering the right to limit, in the preceding twelve months.

13.3 How to exercise

Email privacy@cedent.ai or write to the address in Section 16. We verify by matching against account records and may request additional confirmation. We respond within 45 days, extendable once by 45 days with notice. There is no charge for a reasonable request.

13.4 Authorized agents

An authorized agent may submit a request with written permission signed by you; we may ask you to verify directly.

13.5 Other states

We extend the same rights to residents of every U.S. state with comprehensive privacy legislation, without regard to whether a threshold applies to us.

13.6 If you are a client of a firm that uses Cedent — read this

We cannot act on your request about your matter file. Your information is in the Service because your attorney put it there, and your attorney is the controller. We are their processor and have no authority to access, correct, disclose, or delete their client files at a third party’s request — and doing so could interfere with their obligations to you.

Please contact the law firm. If a firm directs us to act on your request, we will act on that instruction promptly. If you do not know which firm holds your information, write to privacy@cedent.ai and we will help you identify the right contact where we can do so without disclosing anything we should not.

If we receive a subpoena, warrant, or other legal process seeking Matter Data, we notify the firm before disclosing anything, unless legally prohibited; object on the ground that the material may be privileged and that the firm is the proper custodian; and cooperate with the firm’s efforts to quash or limit. We do not voluntarily disclose Matter Data to any government authority.


14. Subprocessors

We maintain a versioned, dated Subprocessor List at cedent.ai/subprocessors. Current version as of this Policy’s effective date:

14.1 Processing Matter Data

SubprocessorPurposeLocation
Amazon Web Services, Inc. (ECS, S3, Bedrock, ElastiCache, KMS, Secrets Manager)Hosting, storage, all AI inference, caching, key and secret managementUnited States
Neon, Inc.Database hostingUnited States
Modal Labs, Inc.Document text extraction and OCRUnited States
Clerk, Inc.Authentication and identityUnited States
Resend, Inc.Platform notification emailUnited States
PostHog, Inc.Product analyticsUnited States
Axiom, Inc.Application and audit log ingestionUnited States

14.2 Not processing Matter Data

SubprocessorPurpose
Stripe, Inc.Payments and subscription management — independent controller for payment data (Section 2.3)
Netlify, Inc.Marketing website hosting — marketing site only
Google LLC (Google Analytics 4)Marketing website analytics — marketing site only, no advertising linkage (Section 3.3)
PostHog, Inc.Marketing website analytics — marketing site only, no session recording (Section 3.1). PostHog also appears in Section 14.1 for product analytics; these are separate uses of one provider

14.3 Pending — not yet in production

These will be added to the versioned list with 30 days’ notice before they begin processing Matter Data:

SubprocessorPurposeStatus
Functional Software, Inc. (Sentry)Application error monitoringNot enabled. Pending DSN configuration and executed DPA
Clio (Themis Solutions Inc.)Practice management synchronizationNot launched. Pending partner agreement review

Railway was listed in our previous policy. It is used for staging and test environments only, never production, and does not process Matter Data. It has been removed.

14.4 Change notice

We give at least 30 days’ advance notice before adding or replacing a subprocessor that processes Matter Data, by email to firm Administrators and by publishing a new version of the list. Customers may object on reasonable data-protection grounds within that period; if we cannot accommodate an objection, the customer may terminate the affected subscription without penalty and receive a pro-rata refund. Every subprocessor is bound by written terms at least as protective as those we owe our customers.


15. Changes to This Policy

We will post any change with a new effective date and version number. For material changes we give at least 30 days’ notice by email to firm Administrators before the change takes effect.

We will not weaken our commitments on training (Section 8.4), on Matter Data protection, or on legal process (Section 13.7) as applied to data already in the Service without affirmative customer opt-in. Continued use will never constitute consent to a weakening of those three commitments.


16. Contact

PurposeContact
Privacy questions and rights requestsprivacy@cedent.ai
Security incidents and vulnerability reportssecurity@cedent.ai
Legal, contracts, DPAlegal@cedent.ai
Supportsupport@cedent.ai
MailCedent AI, Inc., 7901 Stoneridge Dr, Suite 108, Pleasanton, CA 94588

If you are not satisfied with our response, you may complain to the California Privacy Protection Agency or your state Attorney General.