Privacy Policy

Last updated 2026-05-27 · Aligned with PIPEDA and BC PIPA.
Pilot draft. Material changes will be announced at least 30 days in advance via email and in-app. If your firm needs a custom Data Processing Agreement, contact [email protected].

1. Scope

This policy describes how Anchor collects, uses, discloses, and protects personal information in connection with the Anchor application at anchorlegal.ca. It applies to information about firm users (lawyers, paralegals, staff) and to client and counterparty information that firm users enter into Anchor in the course of running matters.

2. Categories of information we handle

Account information (about your firm's users)

  • Name, work email, role, language preference.
  • Authentication credentials (passwords are hashed; sessions are signed cookies).
  • Sign-in audit log: IP address, user agent, timestamp.

Matter information (about your firm's clients and counterparties)

  • Party identifiers (name, contact information, role) as entered by firm users.
  • Documents, drafts, comments, deadlines, time entries, retainer ledger, billing data.
  • Search history within the firm.

Operational data

  • Application logs, error traces, performance metrics.
  • AI-feature audit log (concepts sent, model used, token count, cost).

3. How we use information

  • To provide the service. Storing and serving matter data to authenticated firm users.
  • To secure the service. Sign-in audit logs, rate limiting, abuse detection.
  • To improve the service. Aggregated, anonymized usage metrics (e.g. average search latency). We do not use matter content to train models, and we do not send matter content to third-party model providers (see §5 below).
  • To assist research. When you use Anchor's AI-assisted research or drafting features, public legal materials (case text, citations, statutes, your typed research concepts) are sent to a third-party LLM provider for inference. Personal information about your clients, counterparties, matter content, drafts, comments, deadlines, and billing data are never sent.
  • To communicate with you. Transactional email (sign-ins, password resets, signature requests). Product news email is opt-in and CASL-compliant; you can unsubscribe at any time.

4. Legal basis (PIPEDA / BC PIPA)

For account holders we rely on consent given at signup. For matter content we act as a service provider to your firm — your firm is the privacy controller and you remain responsible to clients and counterparties under BC PIPA and the Law Society's confidentiality obligations.

5. Where data lives

  • Primary database: a managed relational database hosted in Canada.
  • Backups: encrypted daily snapshots, stored both on the database host and in Canadian-region object storage.
  • Email transit: transactional email is sent over TLS through a third-party email provider.
  • AI inference: requests to LLM providers contain only public legal material (case text, citations, statutes, your research concepts). They do not contain client names, party identifiers, matter content, document uploads, drafts, comments, deadlines, or billing data. Anchor does not retain the AI request body beyond the audit-log row needed to attribute cost. See §6 of the Terms of Service for the full carve-out.

6. Retention

  • Matter data: retained for the life of your subscription plus 30 days after cancellation to allow export. Backups age out within 90 days of deletion from production.
  • Audit logs: retained for 24 months by default.
  • You may request earlier deletion of specific records, subject to your firm's own retention obligations under LSBC rules and applicable law.

7. Your rights

Subject to PIPEDA and BC PIPA, you may request:

  • Access — a copy of the personal information Anchor holds about you.
  • Correction — to update information you believe is inaccurate.
  • Withdrawal of consent / deletion — closure of your account and deletion of associated personal information, subject to backup retention windows above.
  • Export — a structured export of your matters and drafts (CSV + ZIP of attachments).

Send requests to [email protected]. We will respond within 30 days.

8. Security

  • All traffic is HTTPS-only with HSTS enforced; an edge / DDoS-protection layer sits in front of the origin.
  • Passwords are hashed using an industry-standard adaptive hash; sessions are signed; cookies are HttpOnly + Secure + SameSite=Lax.
  • Database access is restricted to the application user; no public database port.
  • Backups are encrypted at rest.
  • Rate limits and brute-force protection on the sign-in endpoint.
  • LLM requests carry no personal or matter information — only public legal material (see §5 and Terms §6).
  • Incidents are disclosed to affected firms without undue delay (target: 72 hours).

9. Cookies

We use a single first-party session cookie for authentication. We do not use third-party analytics or advertising cookies.

10. Children

Anchor is not directed at children. Family-law matters routinely involve information about minors; that information is treated as confidential matter content under §2.

11. Changes to this policy

Material changes will be announced at least 30 days in advance via email and the in-app "What's new" panel.

12. Contact

Privacy questions or requests: [email protected].

← Back to sign in Anchor v0.0.2-pre · Terms · Privacy