Privacy Policy
Effective: 2025
Overview
AnrakLegal is designed to be privacy‑first. We do not store your research queries or document contents. All requests are processed ephemerally and proxied to upstream providers.
What we don’t collect
- No prompts, queries, or judgment texts are persisted.
- No personal content or customer document uploads are stored.
Operational metadata
We retain only minimal operational metadata necessary for reliability and abuse prevention (e.g., timestamps, endpoint names, and status codes). This metadata does not include your query content and is not shared or sold.
Security
- Transport encryption by default (HTTPS end‑to‑end).
- Secrets are stored in environment managers and rotated as needed.
- Principle of least privilege for infrastructure access.
Data retention
Request payloads are processed in memory and not retained. Operational metadata is kept only as long as needed for reliability and billing, then discarded.
Third‑party processors
We use reputable infrastructure providers (e.g., hosting, logging, email) that meet industry security standards. These providers do not receive query contents.
Your choices
- Use API keys specific to environments (dev, staging, prod).
- Rotate keys at any time from the console.
Contact
Questions? Email kapil@anrak.io.