Privacy Policy

Last Updated: August 2026

This Privacy Policy explains how AI Attorney Tech (Private) Limited ("AI Attorney," "we," "our," or "us") collects, uses, discloses, stores, and protects information when users access or use AI Attorney, including our website, web application, mobile application, legal research tools, legal drafting tools, document review tools, case diary tools, APIs, integrations, and Model Context Protocol ("MCP") connector made available through compatible platforms such as ChatGPT, Claude, or other supported clients.

AI Attorney provides legal research assistance, legal information retrieval, legal drafting support, document review support, case-law search, statute search, case diary assistance, and related legal workflow features. AI Attorney is not a law firm and does not replace independent advice from a licensed legal professional. Users are responsible for reviewing all outputs, verifying legal authorities, and obtaining professional legal advice where required.

1. Scope of this Privacy Policy

This Privacy Policy applies to information processed when users:

  • Create or use an AI Attorney account;
  • Use AI Attorney's website, application, APIs, or legal tools;
  • Search legal cases, judgments, statutes, legal provisions, or other legal materials;
  • Submit legal questions, prompts, facts, instructions, or documents;
  • Use AI Attorney's drafting, document review, legal research, or case diary features;
  • Access AI Attorney through ChatGPT, Claude, or another MCP-compatible client;
  • Connect supported third-party services, such as calendar or productivity integrations;
  • Contact support, subscribe to a plan, or otherwise interact with AI Attorney.

This Privacy Policy does not apply to websites, platforms, or services operated by third parties, including ChatGPT, Claude, payment processors, app stores, calendar providers, or other external services. Their own terms and privacy policies govern those services.

2. Information We Collect

We collect only the information reasonably necessary to provide, secure, monitor, support, and improve AI Attorney.

2.1 Account and Profile Information

When a user creates or uses an AI Attorney account, we may collect:

  • Name;
  • Email address;
  • Phone number, where provided;
  • Organization, law firm, institution, department, role, or professional category, where provided;
  • Login and authentication identifiers;
  • Account status, plan type, subscription status, billing status, and usage limits;
  • User preferences, settings, and consent choices;
  • Support requests and related communications.

We do not ask users to provide passwords, private keys, API keys, OTPs, multi-factor authentication codes, or other authentication secrets through AI prompts, MCP tool inputs, legal queries, or chat messages.

2.2 Legal Queries, Prompts, and Search Instructions

When a user uses AI Attorney for legal research, case-law search, statute search, drafting, document review, or MCP-based legal retrieval, we may process:

  • Legal questions or prompts submitted by the user;
  • Case titles, citations, party names, court names, judge names, years, statutes, provisions, legal topics, jurisdictions, or search filters provided by the user;
  • Case facts, matter descriptions, hearing details, legal issues, procedural history, or user instructions;
  • Drafting instructions for notices, contracts, pleadings, applications, petitions, legal opinions, clauses, or other legal documents;
  • Search preferences, selected filters, and user-requested result limits;
  • AI-generated, system-generated, or retrieval-generated outputs returned to the user.

Legal queries may reveal sensitive legal interests or confidential matter information. Users should avoid submitting unnecessary personal information and redact any information not needed for the requested legal task.

2.3 Documents and User-Uploaded Content

If a user uploads, pastes, or submits documents or text to AI Attorney, we may process:

  • File name, file type, file size, upload date, folder name, and document metadata;
  • Document text, clauses, tables, images, attachments, and extracted content;
  • User instructions relating to the document;
  • Document summaries, clause reviews, extracted issues, drafting suggestions, comparison results, and related outputs;
  • Saved folders, document library structure, and document notes where such features are used.

Uploaded documents may contain confidential, privileged, commercial, personal, or sensitive information. AI Attorney processes such content only to provide the user-requested service and related security, support, compliance, and operational functions.

2.4 MCP Connector Data for ChatGPT, Claude, and Other Compatible Clients

When AI Attorney is accessed through ChatGPT, Claude, or another MCP-compatible client, AI Attorney receives only the specific legal research request, search instruction, or tool input that the user intentionally submits for processing. This may include:

  • A legal question;
  • A case title or citation;
  • A court name, year, judge name, statute name, jurisdiction, or legal topic;
  • Search filters or retrieval instructions;
  • A document excerpt or user-provided legal text, where the user intentionally provides it;
  • Authentication status and limited account identifiers required to verify access and apply usage limits.

The AI Attorney MCP connector does not access the user's full ChatGPT or Claude conversation history, private platform profile, unrelated files, emails, contacts, calendar events, payment card information, passwords, API keys, OTPs, or authentication secrets.

The connector uses the submitted request to retrieve relevant legal materials from AI Attorney's legal database and return structured legal research results. Returned results may include:

  • Case titles;
  • Citations;
  • Court names;
  • Years;
  • Judge names, where available;
  • Judgment summaries or snippets;
  • Statute or provision references;
  • Source links or reference identifiers;
  • Cases referred to or cases citing a judgment;
  • Relevance indicators or presentation metadata necessary to display the result;
  • Error or status messages where a request cannot be completed.

The MCP connector is designed as a read-only legal research and retrieval interface. It does not create, update, delete, publish, email, upload, or modify user records through the public MCP connector unless a separate feature is clearly introduced, disclosed, and authorized by the user.

2.5 Authentication, Access Control, and Usage Metering Data

For authenticated users, AI Attorney may process limited authentication and account information to:

  • Verify that the user is authorized to access AI Attorney;
  • Confirm subscription or plan eligibility;
  • Apply usage limits, rate limits, and fair-use controls;
  • Prevent abuse, fraud, unauthorized access, and misuse;
  • Record usage events necessary for account administration, billing, subscription enforcement, and service reliability.

This may include account identifiers, authentication status, plan status, usage counters, tool-call counts, timestamps, and related operational metadata. AI Attorney does not use authentication credentials submitted in prompts, and users should never provide passwords, OTPs, API keys, private keys, or authentication secrets in legal queries or chat messages.

2.6 Calendar and Third-Party Integration Data

If a user connects a calendar, productivity, or other third-party service, AI Attorney may process only the information required to provide the requested integration. This may include:

  • Connected account identifier;
  • Calendar event title, date, time, description, reminder, location, or attendee information where needed for case diary or deadline synchronization;
  • Hearing dates, limitation dates, matter names, deadlines, reminders, and related notes;
  • Authorization tokens or permissions required to operate the integration.

AI Attorney uses such integration data only to provide the user-requested functionality and related security, support, and compliance functions.

2.7 Payment, Subscription, and Billing Information

Where users subscribe to paid services, we may process:

  • Plan name and subscription status;
  • Billing history, invoice status, and transaction identifiers;
  • Payment confirmation and limited billing metadata;
  • Tax, accounting, or compliance records where applicable.

We do not store full payment card numbers. Payment transactions may be processed by third-party payment processors under their own security and privacy standards.

2.8 Technical, Usage, Log, and Security Data

When users access AI Attorney, we may collect technical and operational information such as:

  • IP address;
  • Approximate location derived from IP address;
  • Browser, device type, operating system, and application version;
  • Timestamp, request status, feature used, tool name, and usage count;
  • Authentication status and rate-limit information;
  • Error class, diagnostic status, and security events;
  • Audit logs and abuse-prevention signals;
  • Performance, reliability, and availability metrics.

Where feasible, AI Attorney avoids storing raw prompt text in operational logs and redacts or minimizes personal information in logs. We do not intentionally log passwords, OTPs, API keys, private keys, or authentication secrets as part of normal operations.

3. How We Use Information

We use collected information for the following purposes:

  • To create, authenticate, and manage user accounts;
  • To provide legal research, case-law search, statute search, legal drafting, document review, and legal workflow features;
  • To operate AI Attorney through ChatGPT, Claude, and other MCP-compatible clients;
  • To retrieve, rank, format, and return relevant legal research results requested by the user;
  • To process uploaded documents, user prompts, and legal instructions for user-requested outputs;
  • To synchronize case diary events, reminders, hearings, and deadlines where the user enables such features;
  • To verify user access, apply subscription limits, meter usage, and prevent unauthorized access;
  • To provide customer support, respond to inquiries, and troubleshoot issues;
  • To process subscriptions, billing, invoices, and account administration;
  • To improve reliability, security, retrieval quality, performance, and user experience;
  • To detect, prevent, and investigate fraud, abuse, security incidents, and misuse;
  • To comply with applicable legal, tax, accounting, audit, regulatory, and dispute-resolution obligations.

4. AI Processing and Automated Assistance

AI Attorney may use artificial intelligence systems, retrieval systems, search infrastructure, ranking systems, and automated processing to provide legal research assistance, drafting support, document review, summarization, and related outputs.

To provide relevant results, AI Attorney may process the user's search query, legal instruction, document excerpt, or derived search text using trusted service providers that support functions such as:

  • AI model processing;
  • Embeddings or semantic processing;
  • Search and retrieval;
  • Result ranking;
  • Authentication and access control;
  • Cloud hosting;
  • Logging, monitoring, and security;
  • Usage metering and abuse prevention.

We do not publicly disclose detailed internal infrastructure, vendor configuration, index names, server names, ports, environment variables, internal endpoints, or security-sensitive implementation details. However, we disclose the categories of service providers that may process user information.

AI Attorney does not sell user-submitted legal queries, prompts, documents, or legal content to third parties. AI Attorney does not use user-submitted content to train generalized artificial intelligence or machine learning models for unrelated users.

Where a third-party AI or platform provider processes user data, that provider may process the data according to its own terms, privacy policy, enterprise controls, and data-retention settings. Users should review the terms and privacy settings of the platform through which they access AI Attorney.

5. ChatGPT, Claude, and MCP-Compatible Platform Processing

When users access AI Attorney through ChatGPT, Claude, or another MCP-compatible client, the platform provider may process information exchanged with the AI Attorney connector according to that platform's own terms, privacy policy, and data controls.

AI Attorney is responsible for the information it receives from the platform and the information it returns to the platform. The platform provider may separately process the user's conversation, connector request, tool call, or response according to the user's account settings and the platform's applicable policies.

Users should review the privacy controls of the platform they use. AI Attorney cannot control the data practices, retention settings, or account controls of third-party platforms.

6. Google API Services and Limited Use Disclosure

Where AI Attorney uses information received from Google APIs, AI Attorney's use and transfer of that information will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

AI Attorney uses Google Workspace or Google Calendar data only to provide user-requested functionality, such as calendar synchronization, case diary reminders, legal deadline management, or related scheduling features.

AI Attorney does not use Google Workspace API data to develop, improve, or train generalized artificial intelligence or machine learning models.

7. Disclosure of Information

We may disclose information to the following categories of recipients where necessary.

7.1 Service Providers and Subprocessors

We may use trusted service providers to operate, secure, support, and improve AI Attorney. These providers may support:

  • Cloud hosting and infrastructure;
  • Authentication and access control;
  • Search and retrieval;
  • AI processing, semantic processing, and result ranking;
  • Database, storage, and backup services;
  • Logging, monitoring, diagnostics, and security;
  • Email, notification, and customer support;
  • Payment processing and billing;
  • Analytics and product reliability;
  • Legal, accounting, compliance, and audit support.

These providers are permitted to process information only as necessary to provide services to AI Attorney, comply with legal obligations, protect platform security, prevent abuse, and support the user-requested functionality.

7.2 Third-Party Platforms Used by the User

When a user accesses AI Attorney through ChatGPT, Claude, or another supported client, information required for the requested interaction may be exchanged with that platform. This may include tool inputs, tool outputs, authentication status, and connector interaction metadata.

7.3 Connected Services

If a user connects a calendar, productivity, or other third-party service, AI Attorney may exchange information with that service only as needed to provide the requested integration and subject to the user's permissions.

7.4 Legal, Compliance, and Safety Disclosures

We may disclose information where we reasonably believe disclosure is necessary to:

  • Comply with applicable law, regulation, legal process, court order, or governmental request;
  • Enforce our terms, agreements, and policies;
  • Detect, prevent, or address fraud, abuse, unauthorized access, or security incidents;
  • Protect the rights, safety, property, or security of AI Attorney, users, or others;
  • Investigate disputes, claims, audits, or technical incidents.

7.5 Business Transfers

If AI Attorney is involved in a merger, acquisition, investment, restructuring, financing, sale of assets, or similar transaction, user information may be transferred as part of that transaction, subject to appropriate confidentiality and privacy protections.

We do not sell, rent, or trade personal information for third-party advertising.

8. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required for legal, tax, accounting, audit, billing, security, fraud-prevention, dispute-resolution, or compliance purposes.

Our standard retention approach is as follows:

8.1 Account Information

Account information is retained while the account remains active. After account deletion, account information is deleted or de-identified within 90 days, unless longer retention is required for legal, security, billing, tax, accounting, audit, dispute-resolution, or compliance purposes.

8.2 Saved Legal Queries, Chats, Drafts, Notes, and User History

Saved legal queries, chats, drafts, matter notes, and user history are retained until deleted by the user or account administrator, or until the account is deleted. After deletion, we take reasonable steps to remove such information from active systems within 30 days, subject to backup cycles and legal or security limitations.

8.3 Uploaded Documents and Document Library Files

Uploaded documents and document library files are retained until deleted by the user or account administrator, or until the account is deleted. After deletion, we take reasonable steps to remove such files from active systems within 30 days, subject to backup cycles and legal or security limitations.

8.4 MCP Legal Research Prompts and Outputs

MCP legal research prompts and outputs are not intended to be permanently stored by AI Attorney unless needed for authenticated user history, user-requested saved features, usage metering, security, abuse prevention, troubleshooting, legal compliance, billing, or account administration.

Where MCP prompts or outputs are processed temporarily to complete a request, they are retained only for the period reasonably necessary to provide the service and maintain security and reliability.

8.5 Temporary Processing Files

Temporary processing files are deleted or de-identified within 30 days after processing, unless saved by the user or required for security, troubleshooting, legal, or compliance reasons.

8.6 Technical Logs, Security Logs, and Audit Logs

Technical logs, security logs, and audit logs are generally retained for 30 to 90 days for security, reliability, abuse prevention, troubleshooting, and compliance. Longer retention may apply where necessary to investigate security incidents, fraud, abuse, billing disputes, legal claims, or regulatory matters.

8.7 Authentication and Integration Tokens

Authentication and integration tokens are retained only while the relevant account or integration remains connected, or as needed to provide the user-requested service. Tokens are deleted, invalidated, or made unusable when the user disconnects the integration or deletes the account, subject to technical and legal limitations.

8.8 Billing and Transaction Records

Billing, invoice, and transaction records are retained as required for tax, accounting, audit, legal, and financial compliance. This period may be longer than general account retention where required by applicable law.

8.9 Backups

Backups are retained for a limited backup cycle and deleted or overwritten according to our backup and disaster-recovery procedures. Deleted user information may remain in encrypted backups for a limited period before being overwritten, unless restoration is required for security, legal, or disaster-recovery purposes.

When a user requests deletion, we will take reasonable steps to delete or de-identify applicable information, subject to legal, security, backup, fraud-prevention, billing, and operational limitations.

9. User Controls and Rights

Subject to applicable law and identity verification, users may request to:

  • Access personal information we hold about them;
  • Correct inaccurate or incomplete information;
  • Delete account information;
  • Delete uploaded documents or saved user content where available;
  • Delete saved legal queries, drafts, history, or matter notes where available;
  • Export or receive a copy of certain information;
  • Object to or restrict certain processing activities;
  • Disconnect third-party integrations;
  • Revoke authorization through the connected platform or service;
  • Disconnect the AI Attorney MCP connector from ChatGPT, Claude, or another compatible client;
  • Opt out of non-essential marketing communications;
  • Request information about our data practices and service-provider categories.

Requests may be sent to support@aiattorney.com.pk. We may need to verify the requester's identity before processing a request. Some information may be retained where required for legal, security, fraud-prevention, billing, audit, dispute-resolution, or compliance purposes.

Additional instructions for managing saved content, connector access, integrations, and deletion requests are available in our Privacy & Data Controls FAQ.

10. Security

We use technical and organizational safeguards designed to protect user information, including:

  • Encryption in transit;
  • Encryption at rest where supported by our infrastructure;
  • Access controls and role-based permissions;
  • Authentication and authorization controls;
  • Rate limiting and abuse-prevention controls;
  • Audit logging and security monitoring;
  • Network and server security controls;
  • Backup and recovery procedures;
  • Restricted access to production systems;
  • Confidentiality obligations for personnel and service providers;
  • Security reviews and operational monitoring;
  • Redaction or minimization of personal information in logs where feasible.

Users should avoid submitting unnecessary sensitive information and should maintain the security of their own accounts, devices, and credentials.

11. Confidentiality of Legal Content

Users may submit legal, commercial, privileged, confidential, or sensitive information. AI Attorney processes such information only to provide the requested service and related support, security, compliance, and operational functions.

AI Attorney does not claim ownership over user-submitted legal content, uploaded documents, prompts, legal facts, or generated outputs. Users remain responsible for determining whether use of AI Attorney is appropriate for confidential, privileged, regulated, or sensitive matters.

12. Restricted and Sensitive Information

Users should not submit the following information unless strictly necessary for the requested legal workflow and legally permitted:

  • Payment card numbers or card security codes;
  • Passwords, API keys, private keys, OTPs, or authentication secrets;
  • Government identification numbers, unless directly required for a user-requested legal document;
  • Medical or highly sensitive health information, unless directly required for a user-requested legal task;
  • Children's personal information;
  • Highly sensitive personal information unrelated to the requested legal task;
  • Any information the user is not authorized to disclose.

If such information is included incidentally in a prompt or document, AI Attorney will process it only to provide the requested service and related security, support, compliance, or operational functions. We may reject, restrict, or delete content that creates unacceptable legal, security, privacy, or compliance risk.

13. Children

AI Attorney is intended for professional, educational, business, and adult users. It is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we become aware that such information has been collected, we will take reasonable steps to delete it.

14. International Processing

AI Attorney may process and store information in Pakistan and in other jurisdictions where our service providers operate. Data protection laws in those jurisdictions may differ from the laws of the user's location. Where required, we use appropriate safeguards for cross-border processing.

15. Cookies and Similar Technologies

AI Attorney uses strictly necessary cookies, local storage, session storage, and similar browser technologies where required to operate the platform securely and reliably. These technologies support login, account protection, fraud prevention, session security, essential preferences, and core platform functionality.

On public website pages, AI Attorney may request permission for optional functional, analytics, and marketing or personalization cookies. Optional cookies are disabled by default until the user accepts them or saves custom preferences through the cookie consent banner.

Analytics cookies help us understand public-site performance and improve the user experience. Marketing or personalization cookies, if enabled by the user, may help measure campaigns or tailor public-site messaging. Users can reject optional cookies without losing access to essential platform functionality.

Users may also control cookies and browser storage through their browser settings. Disabling necessary browser storage or cookies may affect login, security, or platform functionality.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, integrations, technology, legal requirements, or data practices. The updated version will be posted on our website with a revised "Last Updated" date. Where required by law or where changes are material, we may provide additional notice.

17. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or AI Attorney's data practices, contact us at:

Email: support@aiattorney.com.pk

Website: https://aiattorney.com.pk