Last Updated: August 2026
This Privacy Policy explains how AI Attorney Tech (Private) Limited ("AI Attorney," "we," "our," or "us") collects, uses, discloses, stores, and protects information when users access or use AI Attorney, including our website, web application, mobile application, legal research tools, legal drafting tools, document review tools, case diary tools, APIs, integrations, and Model Context Protocol ("MCP") connector made available through compatible platforms such as ChatGPT, Claude, or other supported clients.
AI Attorney provides legal research assistance, legal information retrieval, legal drafting support, document review support, case-law search, statute search, case diary assistance, and related legal workflow features. AI Attorney is not a law firm and does not replace independent advice from a licensed legal professional. Users are responsible for reviewing all outputs, verifying legal authorities, and obtaining professional legal advice where required.
This Privacy Policy applies to information processed when users:
This Privacy Policy does not apply to websites, platforms, or services operated by third parties, including ChatGPT, Claude, payment processors, app stores, calendar providers, or other external services. Their own terms and privacy policies govern those services.
We collect only the information reasonably necessary to provide, secure, monitor, support, and improve AI Attorney.
When a user creates or uses an AI Attorney account, we may collect:
We do not ask users to provide passwords, private keys, API keys, OTPs, multi-factor authentication codes, or other authentication secrets through AI prompts, MCP tool inputs, legal queries, or chat messages.
When a user uses AI Attorney for legal research, case-law search, statute search, drafting, document review, or MCP-based legal retrieval, we may process:
Legal queries may reveal sensitive legal interests or confidential matter information. Users should avoid submitting unnecessary personal information and redact any information not needed for the requested legal task.
If a user uploads, pastes, or submits documents or text to AI Attorney, we may process:
Uploaded documents may contain confidential, privileged, commercial, personal, or sensitive information. AI Attorney processes such content only to provide the user-requested service and related security, support, compliance, and operational functions.
When AI Attorney is accessed through ChatGPT, Claude, or another MCP-compatible client, AI Attorney receives only the specific legal research request, search instruction, or tool input that the user intentionally submits for processing. This may include:
The AI Attorney MCP connector does not access the user's full ChatGPT or Claude conversation history, private platform profile, unrelated files, emails, contacts, calendar events, payment card information, passwords, API keys, OTPs, or authentication secrets.
The connector uses the submitted request to retrieve relevant legal materials from AI Attorney's legal database and return structured legal research results. Returned results may include:
The MCP connector is designed as a read-only legal research and retrieval interface. It does not create, update, delete, publish, email, upload, or modify user records through the public MCP connector unless a separate feature is clearly introduced, disclosed, and authorized by the user.
For authenticated users, AI Attorney may process limited authentication and account information to:
This may include account identifiers, authentication status, plan status, usage counters, tool-call counts, timestamps, and related operational metadata. AI Attorney does not use authentication credentials submitted in prompts, and users should never provide passwords, OTPs, API keys, private keys, or authentication secrets in legal queries or chat messages.
If a user connects a calendar, productivity, or other third-party service, AI Attorney may process only the information required to provide the requested integration. This may include:
AI Attorney uses such integration data only to provide the user-requested functionality and related security, support, and compliance functions.
Where users subscribe to paid services, we may process:
We do not store full payment card numbers. Payment transactions may be processed by third-party payment processors under their own security and privacy standards.
When users access AI Attorney, we may collect technical and operational information such as:
Where feasible, AI Attorney avoids storing raw prompt text in operational logs and redacts or minimizes personal information in logs. We do not intentionally log passwords, OTPs, API keys, private keys, or authentication secrets as part of normal operations.
We use collected information for the following purposes:
AI Attorney may use artificial intelligence systems, retrieval systems, search infrastructure, ranking systems, and automated processing to provide legal research assistance, drafting support, document review, summarization, and related outputs.
To provide relevant results, AI Attorney may process the user's search query, legal instruction, document excerpt, or derived search text using trusted service providers that support functions such as:
We do not publicly disclose detailed internal infrastructure, vendor configuration, index names, server names, ports, environment variables, internal endpoints, or security-sensitive implementation details. However, we disclose the categories of service providers that may process user information.
AI Attorney does not sell user-submitted legal queries, prompts, documents, or legal content to third parties. AI Attorney does not use user-submitted content to train generalized artificial intelligence or machine learning models for unrelated users.
Where a third-party AI or platform provider processes user data, that provider may process the data according to its own terms, privacy policy, enterprise controls, and data-retention settings. Users should review the terms and privacy settings of the platform through which they access AI Attorney.
When users access AI Attorney through ChatGPT, Claude, or another MCP-compatible client, the platform provider may process information exchanged with the AI Attorney connector according to that platform's own terms, privacy policy, and data controls.
AI Attorney is responsible for the information it receives from the platform and the information it returns to the platform. The platform provider may separately process the user's conversation, connector request, tool call, or response according to the user's account settings and the platform's applicable policies.
Users should review the privacy controls of the platform they use. AI Attorney cannot control the data practices, retention settings, or account controls of third-party platforms.
Where AI Attorney uses information received from Google APIs, AI Attorney's use and transfer of that information will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AI Attorney uses Google Workspace or Google Calendar data only to provide user-requested functionality, such as calendar synchronization, case diary reminders, legal deadline management, or related scheduling features.
AI Attorney does not use Google Workspace API data to develop, improve, or train generalized artificial intelligence or machine learning models.
We may disclose information to the following categories of recipients where necessary.
We may use trusted service providers to operate, secure, support, and improve AI Attorney. These providers may support:
These providers are permitted to process information only as necessary to provide services to AI Attorney, comply with legal obligations, protect platform security, prevent abuse, and support the user-requested functionality.
When a user accesses AI Attorney through ChatGPT, Claude, or another supported client, information required for the requested interaction may be exchanged with that platform. This may include tool inputs, tool outputs, authentication status, and connector interaction metadata.
If a user connects a calendar, productivity, or other third-party service, AI Attorney may exchange information with that service only as needed to provide the requested integration and subject to the user's permissions.
We may disclose information where we reasonably believe disclosure is necessary to:
If AI Attorney is involved in a merger, acquisition, investment, restructuring, financing, sale of assets, or similar transaction, user information may be transferred as part of that transaction, subject to appropriate confidentiality and privacy protections.
We do not sell, rent, or trade personal information for third-party advertising.
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required for legal, tax, accounting, audit, billing, security, fraud-prevention, dispute-resolution, or compliance purposes.
Our standard retention approach is as follows:
Account information is retained while the account remains active. After account deletion, account information is deleted or de-identified within 90 days, unless longer retention is required for legal, security, billing, tax, accounting, audit, dispute-resolution, or compliance purposes.
Saved legal queries, chats, drafts, matter notes, and user history are retained until deleted by the user or account administrator, or until the account is deleted. After deletion, we take reasonable steps to remove such information from active systems within 30 days, subject to backup cycles and legal or security limitations.
Uploaded documents and document library files are retained until deleted by the user or account administrator, or until the account is deleted. After deletion, we take reasonable steps to remove such files from active systems within 30 days, subject to backup cycles and legal or security limitations.
MCP legal research prompts and outputs are not intended to be permanently stored by AI Attorney unless needed for authenticated user history, user-requested saved features, usage metering, security, abuse prevention, troubleshooting, legal compliance, billing, or account administration.
Where MCP prompts or outputs are processed temporarily to complete a request, they are retained only for the period reasonably necessary to provide the service and maintain security and reliability.
Temporary processing files are deleted or de-identified within 30 days after processing, unless saved by the user or required for security, troubleshooting, legal, or compliance reasons.
Technical logs, security logs, and audit logs are generally retained for 30 to 90 days for security, reliability, abuse prevention, troubleshooting, and compliance. Longer retention may apply where necessary to investigate security incidents, fraud, abuse, billing disputes, legal claims, or regulatory matters.
Authentication and integration tokens are retained only while the relevant account or integration remains connected, or as needed to provide the user-requested service. Tokens are deleted, invalidated, or made unusable when the user disconnects the integration or deletes the account, subject to technical and legal limitations.
Billing, invoice, and transaction records are retained as required for tax, accounting, audit, legal, and financial compliance. This period may be longer than general account retention where required by applicable law.
Backups are retained for a limited backup cycle and deleted or overwritten according to our backup and disaster-recovery procedures. Deleted user information may remain in encrypted backups for a limited period before being overwritten, unless restoration is required for security, legal, or disaster-recovery purposes.
When a user requests deletion, we will take reasonable steps to delete or de-identify applicable information, subject to legal, security, backup, fraud-prevention, billing, and operational limitations.
Subject to applicable law and identity verification, users may request to:
Requests may be sent to support@aiattorney.com.pk. We may need to verify the requester's identity before processing a request. Some information may be retained where required for legal, security, fraud-prevention, billing, audit, dispute-resolution, or compliance purposes.
Additional instructions for managing saved content, connector access, integrations, and deletion requests are available in our Privacy & Data Controls FAQ.
We use technical and organizational safeguards designed to protect user information, including:
Users should avoid submitting unnecessary sensitive information and should maintain the security of their own accounts, devices, and credentials.
Users may submit legal, commercial, privileged, confidential, or sensitive information. AI Attorney processes such information only to provide the requested service and related support, security, compliance, and operational functions.
AI Attorney does not claim ownership over user-submitted legal content, uploaded documents, prompts, legal facts, or generated outputs. Users remain responsible for determining whether use of AI Attorney is appropriate for confidential, privileged, regulated, or sensitive matters.
Users should not submit the following information unless strictly necessary for the requested legal workflow and legally permitted:
If such information is included incidentally in a prompt or document, AI Attorney will process it only to provide the requested service and related security, support, compliance, or operational functions. We may reject, restrict, or delete content that creates unacceptable legal, security, privacy, or compliance risk.
AI Attorney is intended for professional, educational, business, and adult users. It is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we become aware that such information has been collected, we will take reasonable steps to delete it.
AI Attorney may process and store information in Pakistan and in other jurisdictions where our service providers operate. Data protection laws in those jurisdictions may differ from the laws of the user's location. Where required, we use appropriate safeguards for cross-border processing.
AI Attorney uses strictly necessary cookies, local storage, session storage, and similar browser technologies where required to operate the platform securely and reliably. These technologies support login, account protection, fraud prevention, session security, essential preferences, and core platform functionality.
On public website pages, AI Attorney may request permission for optional functional, analytics, and marketing or personalization cookies. Optional cookies are disabled by default until the user accepts them or saves custom preferences through the cookie consent banner.
Analytics cookies help us understand public-site performance and improve the user experience. Marketing or personalization cookies, if enabled by the user, may help measure campaigns or tailor public-site messaging. Users can reject optional cookies without losing access to essential platform functionality.
Users may also control cookies and browser storage through their browser settings. Disabling necessary browser storage or cookies may affect login, security, or platform functionality.
We may update this Privacy Policy from time to time to reflect changes in our services, integrations, technology, legal requirements, or data practices. The updated version will be posted on our website with a revised "Last Updated" date. Where required by law or where changes are material, we may provide additional notice.
If you have questions, concerns, or requests regarding this Privacy Policy or AI Attorney's data practices, contact us at:
Email: support@aiattorney.com.pk
Website: https://aiattorney.com.pk