Security and Data Handling
Law Dog AI - Security and Data Handling
Last Updated: March 4, 2026
This page summarizes how Law Dog AI (DocuDash Inc.) handles data and the safeguards we use.
1) What we store
Conversations
- We store conversation text (messages and conversation items) in our primary database to provide the Service.
Uploaded documents
- We store file metadata (e.g., filename/title and related identifiers) in our database.
- File contents are uploaded to our AI infrastructure provider's file/vector store system to enable file search, unless a feature is disabled.
Durable generations and downloadable artifacts
- Deep Research and certain Drafting tasks may run as durable background work. We store the associated mode, status, stage history, model/settings, usage and cost data, and generated result so progress and results can be recovered.
- When a drafting task produces downloads, versioned DOCX and PDF contents and related metadata (such as file size, checksum, page count, and verification status) are stored in our primary database.
Logs
- Operational logs may include filenames and document titles and technical diagnostics.
- Log retention: up to 90 days.
2) What we do NOT do
- We do not use your content to train or fine-tune machine learning models.
- We configure our primary AI provider not to use your content for training.
- We do not use a separate OCR-only subprocessor.
3) Where data is processed
- Primary database hosting is on Neon-managed PostgreSQL (United States).
- AI processing, web research, and file/vector search are performed by our primary AI infrastructure provider.
- Application hosting, durable workflow processing, and upload blob/object storage are provided via Vercel.
4) AI and third-party research processing
Features may send the prompt, relevant conversation or file context, and tool query to third-party providers as needed to perform the task:
- AI generation, web research, file search, and OCR (when enabled) via our primary AI infrastructure provider
- Legal research and citation checks/searches via CourtListener when used
Selecting Deep Research or Drafting may result in multiple AI and tool calls over the life of a durable run. Do not submit content you are not authorized to have these providers process.
5) Retention and deletion
- Default conversation retention target: up to 90 days, unless you delete sooner.
- Generation-run status/result metadata and stored DOCX/PDF artifacts are associated with the conversation and have a retention target of up to 90 days, unless deleted sooner.
- If you delete a conversation, we delete it from your account and primary systems, including its generation runs and artifacts, and delete associated AI file/vector assets used for that conversation as part of the deletion process.
- Residual copies may persist briefly in backups or third-party systems consistent with their retention practices.
6) AI output and professional review
Durable processing, citation checks, verification labels, and generated downloads do not guarantee that an answer, authority, or filing is complete or correct. A qualified lawyer must independently review the work product and verify citations, quotations, deadlines, and governing law before reliance or filing.
7) Security safeguards (high level)
- TLS encryption in transit
- Encryption at rest for stored data (including infrastructure-provider managed encryption controls)
- Network controls (firewalls and restricted database access paths)
- Secure session cookies (secure/HttpOnly in production) and session timeouts
- Restricted administrative access (limited to the service owner)
- Request rate limiting and concurrency controls on key API routes
8) Contact
Security questions or incident reporting: logan.lathrop@yahoo.com