Privacy Policy
Effective Date: October 7, 2025 | Last Updated: October 7, 2025
1. Introduction
Starboard Labs LLC ("we," "us," or "our") operates the Atticus legal AI platform ("Service"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service.
Contact Information:
- Company: Starboard Labs LLC
- Email: [email protected]
- Phone: 850-501-2834
- Privacy Officer: [email protected]
2. Information We Collect
2.1 Personal Information
We collect the following personal information:
- Account Information: Name, email address, professional credentials
- Payment Information: Billing details processed through Stripe (we do not store payment card information)
- Professional Verification: Information provided during our manual verification process
- Communication Records: Support emails and correspondence
2.2 Usage Information
- Service Usage: AI queries, document analysis requests, and system interactions
- Technical Data: IP addresses, browser information, and system performance logs
- Conversation History: AI interactions and analysis results (user-deletable)
2.3 Document Data
- Uploaded Documents: Legal documents temporarily processed for AI analysis
- Document Metadata: File names, upload timestamps, and processing results
- Analysis Results: AI-generated summaries, research, and legal analysis
Important: Documents are processed but not permanently stored. Document management features are planned for future releases.
3. How We Use Your Information
3.1 Service Provision
- Provide AI-powered legal analysis and research tools
- Process and analyze uploaded legal documents
- Maintain user accounts and authentication
- Process payments through Stripe
- Provide customer support and training
3.2 Communication
- Send service-related notifications and updates
- Provide customer support and technical assistance
- Send marketing communications (with consent)
- Notify users of policy changes and service updates
3.3 System Operations
- Monitor system performance and reliability
- Ensure data security and prevent unauthorized access
- Comply with legal obligations and regulatory requirements
- Improve service quality and user experience
4. Information Sharing and Disclosure
4.1 Service Providers
We share information with trusted third-party service providers:
- Amazon Web Services (AWS): Cloud infrastructure with signed Business Associate Agreement (BAA)
- Stripe: Payment processing (PCI DSS compliant)
- EmailJS: Email communication services
- AWS Bedrock: AI model access with HIPAA-compliant BAA
4.2 Legal Requirements
We may disclose information when required by law:
- Court orders and subpoenas
- Regulatory investigations
- Law enforcement requests with proper legal authority
- Emergency situations involving immediate physical harm
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, user information may be transferred to the acquiring entity with equivalent privacy protections.
4.4 No Cross-Client Sharing
Important: We never share client data between different law firms or users. Each client's data remains completely isolated.
5. Data Security
5.1 Security Measures
- Encryption: AWS-provided encryption at rest and in transit
- Access Controls: Restricted access to authorized personnel only
- Infrastructure Security: AWS SOC 2 compliant infrastructure
- HIPAA Compliance: Business Associate Agreement with AWS ensuring PHI protection
- Regular Monitoring: Continuous security monitoring and threat detection
5.2 AI Model Security
- No Training Data: Your data is never used to train, fine-tune, or improve AI models
- Temporary Processing: Documents are processed in memory and not permanently stored
- Secure APIs: All AI processing through HIPAA-compliant AWS Bedrock services
6. Data Retention and Deletion
6.1 Retention Period
- Account Information: Retained for 6 years after account closure (HIPAA compliance requirement), but can be deleted earlier upon user request subject to legal obligations
- Conversation History: Retained for 6 years for HIPAA compliance, but users can request deletion at any time (we will delete unless retention is required by law)
- Uploaded Documents: Retained for 6 years for HIPAA compliance, but users can request deletion at any time (we will delete unless retention is required by law)
- Audit Logs: Retained for 6 years as required by HIPAA regulations (cannot be deleted during retention period)
- Payment Records: Retained for 7 years for tax compliance and fraud prevention (managed by Stripe)
- Technical Logs: Retained for 90 days for security and troubleshooting purposes
Note: While we retain data for HIPAA compliance, users have the right to request deletion at any time. We will honor deletion requests except where retention is required by law, regulation, or for fraud prevention.
6.2 User Control
- Conversation Deletion: Users can delete individual conversations through the platform interface
- Account Deletion: Email [email protected] with subject line "Privacy Request - Account Deletion"
- Data Portability: Request a copy of your data by emailing [email protected] with subject line "Privacy Request - Data Export"
- Data Correction: Email [email protected] to correct inaccurate personal information
- Processing Restriction: Request limitation of data processing by emailing [email protected]
Response Time: We will respond to all privacy requests within 45 days as required by law.
7. User Rights and Choices
7.1 Access Rights
- Review your account information and usage history
- Request copies of your personal data
- Update or correct inaccurate information
- Request deletion of your account and associated data
7.2 Communication Preferences
- Opt out of marketing communications
- Control service notification preferences
- Update contact information and preferences
7.3 California Privacy Rights (CCPA/CPRA)
California residents have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Right to Know (CCPA §1798.100)
Request disclosure of:
- Categories and specific pieces of personal information we collected
- Categories of sources from which we collected your information
- Our business purpose for collecting your information
- Categories of third parties with whom we share your information
- A copy of all your personal information in a portable format
You may make this request twice per 12-month period.
Right to Delete (CCPA §1798.105)
Request deletion of your personal information, subject to certain exceptions for:
- Completing the transaction for which the information was collected
- Detecting and preventing security incidents or fraud
- Debugging and repairing functionality
- Complying with legal obligations (e.g., HIPAA 6-year retention)
- Internal uses reasonably aligned with your expectations
Right to Correct (CPRA §1798.106)
Request correction of inaccurate personal information we maintain about you.
Right to Opt-Out of Sale/Sharing (CCPA §1798.120)
We do NOT sell or share your personal information for monetary or other valuable consideration.
We do not engage in cross-context behavioral advertising or data sales.
Right to Limit Use of Sensitive Personal Information (CPRA §1798.121)
You have the right to limit our use of sensitive personal information (such as SSN, financial data, precise geolocation, health information, or private communications contained in legal documents) to only what is necessary to provide the Atticus service.
Note: All sensitive information we process is used solely to provide our legal AI services. We do not use sensitive information for any secondary purposes.
Right to Non-Discrimination (CCPA §1798.125)
We will not discriminate against you for exercising any of your CCPA rights, including by:
- Denying goods or services
- Charging different prices or rates
- Providing different levels of service quality
How to Exercise Your California Privacy Rights:
Email: [email protected]
Subject Line: "Privacy Request" followed by your specific request
Verification: We will verify your identity before processing your request by confirming your email address and account details.
Response Time: We will respond within 45 days (extendable by 45 days if reasonably necessary).
Authorized Agents: You may designate an authorized agent to submit requests on your behalf by providing written authorization.
7.4 Other State Privacy Rights
Residents of Virginia, Colorado, Connecticut, and Utah have similar privacy rights under their respective state laws:
- Virginia (CDPA): Right to access, delete, correct, and opt-out of targeted advertising and sales
- Colorado (CPA): Right to access, delete, correct, opt-out, and universal opt-out recognition
- Connecticut (CTDPA): Right to access, delete, correct, and opt-out
- Utah (UCPA): Right to access, delete, and opt-out
We honor privacy rights for residents of all U.S. states. To exercise your rights, email [email protected] with subject line "Privacy Request".
8. International Data Transfers
Currently, Atticus operates within the United States only. All data is processed and stored within AWS's US-based infrastructure under our HIPAA-compliant Business Associate Agreement.
9. Children's Privacy
Atticus is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If we discover that a minor has provided personal information, we will delete it immediately.
10. Professional Use Context
10.1 Legal Professional Focus
While not required, Atticus is designed for legal professionals including attorneys, paralegals, legal clerks, and legal assistants. Our security measures and data handling practices are designed to support professional legal work.
10.2 Attorney-Client Privilege
We implement measures to help preserve attorney-client privilege:
- Complete data isolation between different law firms
- No cross-contamination of client information
- Secure processing of potentially privileged communications
- HIPAA-compliant handling of protected health information
11. Cookies and Tracking
Atticus does not use third-party cookies or tracking technologies for advertising purposes. We use only essential authentication cookies required for the service to function. We do not collect information through persistent identifiers or engage in behavioral advertising.
Analytics: We do not use Google Analytics, Facebook Pixel, or any other third-party analytics services that track user behavior across websites.
12. Do Not Sell or Share My Personal Information
We Do NOT Sell Your Personal Information
Starboard Labs LLC does not sell or share your personal information for monetary or other valuable consideration as defined by the California Consumer Privacy Act (CCPA) and other state privacy laws.
What this means:
- We never sell your data to data brokers or advertisers
- We do not share your data for cross-context behavioral advertising
- We do not participate in ad networks or retargeting programs
- Your legal research and documents remain confidential to our service
Because we do not sell or share personal information, there is no need to opt-out. This disclosure is provided for transparency and compliance with state privacy laws.
13. Limit the Use of My Sensitive Personal Information
Sensitive Personal Information Disclosure
What Sensitive Information We May Process:
Legal documents uploaded to Atticus may contain sensitive personal information including:
- Social Security numbers
- Financial account information
- Health or medical information (for medical malpractice or healthcare law cases)
- Precise geolocation data (from IP addresses)
- Private communications (attorney-client privileged content)
How We Use Sensitive Information:
All sensitive personal information is used ONLY for the following purposes:
- Providing our legal AI service - Processing documents and generating legal analysis
- Security and fraud prevention - Detecting unauthorized access
- Compliance with legal obligations - HIPAA, subpoenas, court orders
We do NOT use sensitive information for:
- Marketing or advertising
- Training AI models (your data never trains our models)
- Cross-context behavioral profiling
- Any purpose unrelated to providing the Atticus service
Your Right to Limit Use:
Under California law (CPRA §1798.121), you have the right to limit our use of sensitive personal information. However, because we only use sensitive information for purposes necessary to provide the Atticus service, there are no additional uses to limit.
If you have concerns about how we process sensitive information, email [email protected] with subject line "Privacy Request - Sensitive Information".
14. Third-Party Services and Data Sharing
14.1 AWS Services (Infrastructure Provider)
Our infrastructure is provided by Amazon Web Services under a signed Business Associate Agreement ensuring HIPAA compliance and data protection.
- Services Used: EC2 (compute), RDS (database), S3 (storage), CloudTrail (audit logs)
- Data Shared: All platform data (encrypted at rest and in transit)
- Purpose: Cloud infrastructure and data storage
- Location: United States data centers only
14.2 AWS Bedrock (AI Model Provider)
AI analysis is powered by AWS Bedrock, Amazon's HIPAA-compliant AI service covered under our Business Associate Agreement.
- Services Used: Large language models for legal analysis
- Data Shared: Legal queries and documents submitted for AI analysis (temporarily processed, not stored)
- Purpose: Generate AI-powered legal research and document analysis
- Data Usage: Your data is NEVER used to train or improve AI models
Future AI providers will be disclosed in this section and will be required to sign equivalent data protection agreements.
14.3 Stripe (Payment Processing)
Stripe processes all payments. We do not store credit card information on our servers.
- Data Shared: Name, email, billing information
- Purpose: Process subscription payments
- Compliance: PCI DSS Level 1 certified
Please review Stripe's Privacy Policy for their data handling practices.
14.4 EmailJS (Email Communications)
EmailJS facilitates transactional emails (welcome messages, password resets, notifications).
- Data Shared: Email address, name, message content
- Purpose: Deliver service-related emails
- Limitation: We do not share legal documents or sensitive content via EmailJS
14.5 No Other Third Parties
We do not share data with:
- Analytics providers (no Google Analytics, Mixpanel, etc.)
- Advertising networks or data brokers
- Social media platforms
- Marketing automation tools
15. Data Breach Notification
In the event of a data breach involving your personal information, we will:
- Notify you without unreasonable delay - Typically within 72 hours of discovery
- Notify the California Attorney General - If breach affects 500+ California residents
- Notify affected state authorities - As required by state breach notification laws
- Provide breach details - What happened, what data was affected, what we're doing
- Offer remediation - Credit monitoring or identity theft protection if appropriate
Our incident response plan includes immediate containment, forensic investigation, and notification procedures compliant with HIPAA and state breach notification laws.
16. Policy Updates
We may update this Privacy Policy to reflect changes in our practices or applicable law. We will notify users of material changes through:
- Email notification to registered users (at least 30 days before changes take effect)
- Prominent notice on our website
- In-service notifications where appropriate
Continued use of Atticus after policy updates constitutes acceptance of the revised terms. You may request deletion of your account if you do not agree to updated terms.
Version History: Previous versions of this Privacy Policy are available upon request by emailing [email protected].
17. Contact Information
For privacy-related questions, concerns, or requests:
- Privacy Officer: [email protected]
- Support Email: [email protected]
- Phone: 850-501-2834
- Company: Starboard Labs LLC
Privacy Requests (CCPA, CPRA, and other state laws):
Email: [email protected]
Subject Line: "Privacy Request" followed by your specific request type:
- "Privacy Request - Data Export" (Right to Know)
- "Privacy Request - Account Deletion" (Right to Delete)
- "Privacy Request - Correct Information" (Right to Correct)
- "Privacy Request - Sensitive Information" (Limit Use of Sensitive PI)
Response Time: We will respond within 45 days of receiving your verified request.
This Privacy Policy is effective as of October 7, 2025, and governs the collection, use, and protection of personal information through the Atticus platform operated by Starboard Labs LLC.