LawMighty Privacy Policy

Effective August 18, 2026

Effective date: August 18, 2026

This Privacy Policy explains how LawMighty LLC, a Tennessee limited liability company ("LawMighty," "we," "us") collects, uses, and shares information in connection with the LawMighty platform (the "Service"). It applies to law-firm account holders and their staff ("Firms") and to the Firm's clients who use the client portal at the Firm's invitation ("Client Users").

1. Our Two Roles

For Firm account information (registration details, billing, usage), LawMighty decides how and why the information is processed.

For content Firms put into the Service — client and matter records, documents, form submissions by Client Users, billing and trust entries, and content submitted to AI features (collectively, "Firm Content") — the Firm controls the information and LawMighty processes it on the Firm's behalf and at its direction. Client Users with questions about how their information is handled should contact their law firm; the firm, not LawMighty, controls that data.

2. Information We Collect

•  Account and registration information: firm name, subdomain, practice areas, jurisdictions, names and email addresses of the administrator and staff users, bar number, and password credentials (stored hashed).

•  Firm Content: whatever the Firm and its Client Users submit through the Service, which may include sensitive personal, family, financial, and health-related information relevant to the Firm's representation of its clients.

•  Payment information: processed by Stripe, Inc. We receive subscription status, transaction identifiers, and card metadata (such as last four digits) but never full card numbers.

•  Usage and log information: IP addresses, browser and device information, pages and features used, and activity logs (which the Service also surfaces to the Firm as its own audit trail).

•  Mobile app information: if you use the LawMighty mobile apps, we receive device platform and model information for session management, and — if you enable push notifications when that feature is available — a device notification token. Entries made offline (for example, time entries) are stored on the device until they sync to the Firm's account. Biometric unlock, if you enable it, is processed entirely on your device by its operating system; we never receive or store biometric data.

•  Communications: messages you send us, and delivery metadata for emails the Service sends (such as bounce and delivery status from our email provider).

We do not collect information from data brokers, and we do not use third-party advertising cookies.

3. How We Use Information

•  to provide, operate, secure, and support the Service, including authentication, firm-level data isolation, and backups;

•  to process subscriptions and credit purchases and send transactional emails (verification, notifications, receipts, billing notices);

•  to power features the Firm invokes, including generating documents and running AI-assisted features;

•  to monitor, troubleshoot, and improve the Service, using aggregated or de-identified information where practical;

•  to enforce our Terms of Service and protect the rights, safety, and security of the Service, our users, and others; and

•  to comply with law.

We do not sell personal information, and we do not use Firm Content to train AI models.

4. AI Processing

When the Firm runs an AI feature, the content it submits (for example, an uploaded document to be converted into a module, or case context for a draft) is transmitted to our AI provider, Anthropic, PBC, to generate the output. This processing occurs under commercial API terms that restrict use of the data to providing the service and prohibit its use for training the provider's models. AI features run only when a Firm user initiates them.

5. Service Providers (Subprocessors)

We share information with vendors who process it for us, only as needed to run the Service:

•  Render — application hosting and database infrastructure (application and Firm Content).

•  Netlify — web hosting, content delivery, and DNS for the application front end.

•  Twilio SendGrid — transactional email delivery (recipient addresses and email content).

•  Stripe — payment processing (billing contact and payment details).

•  Anthropic — AI processing, as described in Section 4.

•  Expo (EAS) — mobile app build infrastructure and delivery of app updates (application code only; Firm Content does not pass through this service).

•  Apple and Google — distribution of the mobile apps through the App Store and Google Play and, if push notifications are enabled, delivery of notifications through their notification services.

•  Microsoft — business email for correspondence sent to or from our staff mailbox.

6. Other Sharing

We may also disclose information: (a) to comply with law, legal process, or enforceable governmental requests — where the request seeks Firm Content, we will, unless legally prohibited, notify the Firm so it can assert any objection or privilege; (b) to protect the rights, property, or safety of LawMighty, our users, or the public; (c) in connection with a merger, acquisition, financing, or sale of assets, in which case this Policy continues to apply to previously collected information; and (d) with the Firm's direction or consent. Because Firm Content routinely includes privileged and confidential material, we treat requests for it with heightened care.

7. Data Retention

We retain account information and Firm Content for as long as the Firm's account is open. After an account is closed, the Firm has a limited export window described in the Terms of Service (currently 30 days), after which we may delete Firm Content from production systems. Residual copies may persist in encrypted backups for a limited period before they cycle out, and we may retain information as required by law, for billing records, or to resolve disputes.

8. Security

We use safeguards designed to protect information, including encryption in transit (TLS), encryption at rest of database storage and backups (AES-256), hashed password storage, role- and permission-based access controls within each firm, and database-level isolation of each firm's data in our multi-tenant architecture. No method of transmission or storage is completely secure; we cannot guarantee absolute security. We will notify affected Firms of a confirmed breach of security of their information as required by applicable law, including applicable state breach-notification statutes.

9. Your Choices and Rights

•  Firm users can review and update account information in the Service, and can contact us at mail@lawmighty.com for access, correction, or deletion requests concerning information we control.

•  Client Users: because your law firm controls the information in the portal, requests to access, correct, or delete it should go to your firm. We support Firms in fulfilling those requests.

•  Email: transactional emails (verification, billing, case notifications) are part of the Service. Any marketing email we send will include an unsubscribe mechanism.

Depending on your state of residence, you may have rights under state privacy laws (such as access, correction, deletion, or portability). We honor rights requests as required by the laws that apply to us, and we do not discriminate against anyone for exercising them.

10. Mobile Applications

The LawMighty mobile apps for iOS and Android provide access to the same Firm account and are covered by this Policy. In addition:

•  App stores. The apps are distributed through the Apple App Store and Google Play. Apple and Google may collect their own information in connection with app installation, updates, crashes, and diagnostics under their own privacy policies; aggregate crash and performance diagnostics may be made available to us by those platforms.

•  Biometric unlock. If you enable fingerprint or face unlock, authentication is performed entirely on your device by its operating system. Biometric data never leaves your device and is never transmitted to, or stored by, LawMighty.

•  On-device storage. The apps store sign-in session data in the device's secure storage, and hold entries made offline on the device until they sync to the Firm's account. Uninstalling the app removes this local data from the device.

•  App updates. The apps may receive over-the-air updates through our app-delivery infrastructure. Updates carry application code only; Firm Content is not transmitted through the update service.

•  Push notifications. If and when push notifications are offered and you enable them, delivery uses Apple's and Google's notification services and a device token; you can disable notifications at any time in your device settings.

11. Children

The Service is a professional tool and is not directed to children, and we do not knowingly collect personal information directly from children. Firm Content may lawfully include information about minors (for example, in family-law matters) that a Firm enters in the course of representation; the Firm controls that information.

12. Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy with a new effective date and, for material changes, provide notice within the Service or by email before the changes take effect.

13. Contact

Questions or requests: mail@lawmighty.com, or by mail at LawMighty LLC, a Tennessee limited liability company, 600 Georgia Avenue, Suite 1-B, Chattanooga, TN 37402.