Privacy Notice
Last updated: 30 July 2026
This notice explains how ClauseCast Ltd handles personal information in connection with its website, user accounts and legal-claim evaluation service.
Law firms and regulated legal professionals: unless the firm’s authorised compliance or information-security function has approved identifiable use, submit only anonymised or appropriately pseudonymised commercial case material. Do not upload raw client matter files, privileged communications, witness evidence, or unnecessary special-category or criminal-offence information.
1. Who we are and how to contact us
ClauseCast Ltd is registered in England and Wales under company number 17289539. Its registered office is 124 City Road, London, United Kingdom, EC1V 2NX.
Privacy enquiries and requests may be sent to admin@clausecast.com or by post to the registered office, marked “Data Protection”.
ClauseCast is generally the controller of account, customer-relationship, credit, support, security and website-administration information. Where a business customer submits personal information about other people in case materials, the customer will generally be the controller and ClauseCast will generally act as its processor under the Terms and Data Processing Schedule.
2. Information we process
- Account and authentication information: name, email address, profile image, Kinde identifiers, token claims, authentication events and account status.
- Service administration information: a pseudonymous authenticated user identifier, credit balance, plan or contract information, and usage or support records where applicable.
- Case inputs: narratives, documents, correspondence, filenames, notes and other information submitted for evaluation. These may contain confidential information, special-category data, criminal-offence data or information about third parties.
- Outputs and interaction information: clarification questions, evidence ledgers, feature-extraction material, probability outputs, timestamps and information about use of the service.
- Technical and security information: IP address, browser and device information, request metadata, rate-limit information, diagnostic records and security logs.
- Communications: enquiries, complaints and other correspondence sent to ClauseCast.
Where information about a party, witness, employee or other person is submitted by a business customer rather than by that individual, the information comes from that customer and the documents or communications the customer supplies.
3. Why we use information and our lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Create and secure accounts; authenticate users. | Contract; and legitimate interests in operating a secure B2B service, verifying authorised users and preventing unauthorised access. |
| Provide evaluations, clarification questions and outputs. | Contract with the customer; where ClauseCast acts as processor, the customer determines the lawful basis. |
| Administer credits, contracts and customer relationships. | Contract; legitimate interests in administering customer relationships, service entitlements and support; and legal obligation where applicable. |
| Prevent misuse, enforce terms, investigate incidents and maintain security. | Legitimate interests in preventing fraud and misuse, protecting systems and users, investigating incidents and enforcing contractual rights; and legal obligation where applicable. |
| Respond to enquiries, complaints and legal claims. | Contract; legitimate interests in communicating with customers, resolving complaints and establishing, exercising or defending legal claims; and legal obligation where applicable. |
| Keep accounting, tax and corporate records. | Legal obligation. |
Customers must have a lawful basis for personal information they submit and, where needed, an applicable UK GDPR Article 9 condition or Data Protection Act 2018 Schedule 1 condition for special-category or criminal-offence information. Where the law requires an appropriate policy document, the customer is responsible for creating and maintaining it. ClauseCast asks users to minimise, anonymise or pseudonymise personal information where practicable.
When ClauseCast relies on legitimate interests, those interests are operating and securing a business service, authenticating authorised users, preventing fraud and misuse, administering customer relationships and credits, responding to enquiries, and establishing, exercising or defending legal rights. ClauseCast considers the necessity and impact of this processing and does not rely on legitimate interests where an individual’s rights and interests override them.
4. How the evaluation service processes case information
- Conversation content is held in the active browser page and sent to ClauseCast’s authenticated backend when the user submits a message.
- Uploaded files are read and converted to text in backend memory. The application does not deliberately save the uploaded file bytes or extracted document text to Firestore.
- Extracted text, evidence notes, case narratives and relevant conversation context are sent to the paid Gemini Developer API to create factual evidence ledgers, clarification questions and structured inputs used by ClauseCast’s statistical model.
- The current supplied integration uses Gemini’s Generate Content API. It does not request Google Search grounding, Google Maps grounding, the Gemini File API or explicit context caching.
- For a clarification, a compact document evidence ledger is returned to and retained in the active browser page so the user can continue without uploading the same documents again.
- ClauseCast’s application database stores the authenticated user identifier and credit balance. The supplied backend does not write case narratives, uploaded documents, evidence ledgers or probability outputs to that database.
5. AI-assisted and automated processing
The service uses natural-language processing to structure supplied information and a statistical or machine-learning model to estimate an outcome probability. The result may be inaccurate and cannot reliably account for every legal, evidential, procedural or human factor.
ClauseCast does not itself make a legal or similarly significant decision about an individual solely from the output. Customers must not use an output as legal advice or as the sole basis for litigation, funding, employment, insurance, credit or another decision producing legal or similarly significant effects.
Use by law firms and regulated legal professionals
A law firm remains responsible for professional duties, client confidentiality, privilege, supervision and the accuracy of work produced using the Service. Before identifiable client or matter information is submitted, the firm should complete its own legal, confidentiality, information-security and data-protection assessment; approve the relevant matter types and users; update client-facing information where needed; and determine whether client consent or another authority for disclosure is required.
ClauseCast’s default recommended use for legal-sector customers is anonymised or appropriately pseudonymised commercial case material. The output must be reviewed by a suitably qualified person and must not be used as the sole basis for legal advice, litigation strategy, funding, employment, insurance, credit or another decision producing legal or similarly significant effects.
6. Who receives information
- Kinde: authentication, account access and related security services. ClauseCast’s Kinde business data region is UK—London. Passwordless email sign-in is enabled; self-service sign-up, social login, SMS authentication, multi-factor authentication and Kinde billing are disabled. The hosted session is persistent with a 24-hour timeout; configured token lifetimes are one hour for ID tokens, 24 hours for access tokens and 15 days for refresh tokens. Actual retention can be shorter following sign-out, revocation or security action.
- Contracted email-delivery provider: delivery of ClauseCast’s passwordless sign-in emails using ClauseCast’s own email-provider configuration. This provider may receive the recipient email address and delivery, routing and security metadata needed to send the message.
- Google Cloud: backend hosting through Cloud Run and persistent user-ID and credit records through Firestore. Both resources are configured in
europe-west2(London). The project’s only Cloud Logging sinks are the system-created_Defaultand_Requiredsinks; both log buckets are in thegloballocation. - Google Gemini Developer API: processing of case prompts and responses. ClauseCast uses a billing-enabled paid project. Google states that paid-service prompts and responses are not used to improve its products by default.
- Professional advisers and authorities: insurers, auditors, legal advisers, regulators, courts, law-enforcement bodies and transaction parties where disclosure is lawful and necessary.
- Payments: ClauseCast does not currently operate an online payment provider or Kinde billing. Any commercial fees are arranged directly under the applicable contract or invoice.
The current public service-provider list is available on the Subprocessors page. Customers may request further contracting-entity, location and transfer information by emailing admin@clausecast.com.
7. Gemini logging and retention
ClauseCast has enabled Gemini API project logging with a seven-day retention setting. These project logs may include prompts, responses and related metadata and are private to ClauseCast’s Google Cloud project unless ClauseCast deliberately saves them to a dataset or shares them. ClauseCast does not intend to contribute case-data logs or datasets to Google for model improvement.
Google may separately retain limited prompts, responses and associated information for abuse monitoring and required legal or regulatory disclosures under the Gemini API terms. ClauseCast has not obtained project approval for Gemini zero data retention, so the service must not be described as zero-retention.
Google also documents project-isolated implicit in-memory caching, used by default to reduce latency and cost, with a maximum 24-hour time-to-live. ClauseCast does not use the separate explicit context-caching feature.
8. Other retention periods
- Active browser session: conversation content and reusable document context remain in browser memory until the evaluation is reset, the page is refreshed, or the tab or browser process is closed.
- Backend request processing: case content is processed in application memory for the time needed to answer the request. The supplied application code does not persist it to Firestore.
- Gemini project logs: configured for seven days, after which Google marks the logs for deletion, unless a log is deliberately saved into a longer-lived dataset.
- Cloud Logging
_Defaultbucket: located globally and retained for 30 days. It normally includes Cloud Run request logs, container/application logs, Cloud Run system logs and policy-denied records. Data Read, Data Write and Admin Read audit logging is currently disabled. Cloud Run request logs contain request metadata rather than the submitted HTTP body. The application is designed not to write case narratives, document text or uploaded filenames to its own logs, although diagnostic exceptions and infrastructure metadata may still be recorded. - Cloud Logging
_Requiredbucket: located globally and retained for 400 days under Google’s non-configurable policy. It contains specified mandatory administrative, system-event and access-transparency audit records rather than ordinary ClauseCast requests or case submissions. - Log routing: there are no custom log buckets, linked exports or additional sinks beyond the system-created
_Defaultand_Requiredsinks. - Firestore: user identifiers and credit balances remain for the account/customer-record period described below. Cloud Run and Firestore are in London (
europe-west2). Scheduled backups and point-in-time recovery are disabled. Firestore nevertheless supports access to document versions from within the preceding hour when point-in-time recovery is disabled. - Account and credit records: for the life of the account or customer relationship and afterwards where needed for legal, accounting, fraud-prevention or dispute purposes, normally no longer than six years unless a longer period is required.
- Support and legal correspondence: for as long as needed to handle the matter and establish, exercise or defend legal claims.
9. International transfers
ClauseCast’s Kinde business region, Cloud Run service and Firestore database are configured in London, United Kingdom. This does not mean that every support, security, telemetry, Gemini or subprocessor operation is confined to the United Kingdom. Kinde and Google may use group companies or subprocessors in the United Kingdom and other countries. Where a restricted transfer occurs, ClauseCast relies on an applicable lawful mechanism and safeguards, such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, together with the relevant provider contract and data processing terms. You may request further information, including a copy or summary of the relevant safeguards where disclosure is permitted, by emailing admin@clausecast.com.
10. Security
ClauseCast uses measures intended to protect information, including authenticated access, token verification, rate limiting, encryption in transit, in-memory document parsing, response no-cache controls and data minimisation. No internet service is completely secure. Customers should avoid unnecessary identifiers and must not submit material they are not authorised to disclose.
11. Your rights
Depending on the circumstances and lawful basis, individuals may have rights to access, correct, erase, restrict or object to processing and to receive certain information in a portable format. Rights may be limited in some circumstances, including where information is needed for legal claims.
Where ClauseCast processes case information solely for a business customer, requests about that information may need to be handled by that customer as controller. ClauseCast will provide reasonable assistance as required by its Data Processing Schedule.
Right to object: you may object to processing based on legitimate interests. ClauseCast will stop the processing unless it demonstrates compelling legitimate grounds or the processing is required for legal claims.
You may complain to the Information Commissioner’s Office. ClauseCast would appreciate the opportunity to address a concern first, but this does not affect the right to complain.
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF · Helpline: 0303 123 1113 · ICO complaint information.
12. Cookies and similar technologies
See the Cookies and similar technologies notice.
13. Changes
ClauseCast may update this notice when its service, providers, legal obligations or processing practices change. Material changes will be brought to customers’ attention where appropriate.