Legal
Privacy Policy
Effective August 20, 2026
This Privacy Policy explains what Casezy (“Casezy,” “we,” “us,” or “our”) collects when you use the Casezy website and chat product (the “Service”), why we collect it, who processes it, and the choices you have. It is written to match how the Service actually works today.
It should be read together with our Terms of Service. If you do not agree, do not use the Service.
1. Who is responsible
Casezy is the controller of personal information collected through the Service, except where a provider acts as an independent controller (for example, Clerk for the account you create with them, or a site you open from a citation).
Privacy requests: privacy@casezy.com
2. Information we collect
Account information
If you create an account, Clerk collects the details needed to register and authenticate you. From Clerk, we store a copy of:
- Your Clerk user identifier
- Email address, if Clerk has one for you
- Display name (from your first and last name, username, or email)
- Profile image URL, if Clerk provides one
- When that profile copy was created and last updated
We do not receive or store your password. Authentication methods (email, password, or any social sign-in Clerk is configured to offer) are handled by Clerk. If you use a third-party sign-in, that provider shares with Clerk the account information you authorize.
Conversations
When you use Ask Casezy, we collect and store:
- The text of your questions and of the model’s replies
- A chat title derived from your first message, plus created and updated timestamps
- Whether a message finished successfully or ended in an error
- Citation metadata we attach to a reply (title, publisher, and link), when citations are present
- The Clerk user id for signed-in chats, or a random guest id for a guest chat
You choose what to type. The Service is built for legal questions, so you may include details about a dispute, housing, a business, or other sensitive facts. We do not require a government ID, payment card, or Social Security number to use the Service, and you should not submit those.
Guest identifiers
If you use the Service without an account, we set a random guest identifier so we can attach your one free conversation to that browser and enforce the guest limit. If you later sign in on the same browser, we may associate that guest conversation with your account.
Device storage
The browser may keep a local copy of a guest conversation in localStorage under the key casezy.guestChat so the chat can reload if the server copy is not available. That copy stays on your device until you clear site data.
Information collected automatically
Our hosting and authentication providers receive standard request data when you load pages or call our APIs. That typically includes IP address, user agent, request URL, timestamps, and diagnostic logs. We do not run a separate advertising or product-analytics SDK (no Google Analytics, PostHog, or similar).
3. Cookies we set
We set first-party cookies that are required to operate the Service. We do not set advertising or cross-site tracking cookies.
casezy_guest_id— a random identifier for guest chats. HttpOnly, SameSite=Lax, Secure in production, 30-day lifetime.casezy_free_chat— records that the complimentary guest conversation has been used. SameSite=Lax, Secure in production, 30-day lifetime.- Clerk session and client cookies — required to keep you signed in and to protect the account. Clerk sets and controls those cookies.
You can block cookies in your browser. If you do, guest chat and sign-in may not work. Clearing cookies can start a new guest id; an older guest conversation may remain in our database but we may no longer be able to show it to you.
4. How we use information
We use the information above to:
- Provide the chat, keep history, and restore a session
- Create and maintain your account profile in our database
- Send your conversation to model and retrieval providers so we can generate a reply
- Enforce the one-conversation guest limit
- Secure the Service, debug failures, and prevent abuse
- Respond to your requests and meet legal obligations
We do not use your conversations to train a Casezy-owned model. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
5. Who processes your information
We use the following processors to run the Service. Each receives only what is needed for the role described.
- Clerk, Inc. — account registration, sign-in, session management, and the hosted sign-in, sign-up, and account widgets. Clerk processes your account credentials and profile.
- MongoDB — database hosting for the user profile copy, chats, and messages described above.
- Vercel, Inc. — application hosting, request logs, and Vercel AI Gateway. The Gateway receives the conversation we send to generate an answer, and library text we send to create embeddings. We also send a user tag (your Clerk id, or “guest”) and internal feature tags so usage can be attributed.
- Google — the current answer model is Google Gemini (Gemini 3.7 Flash), reached through Vercel AI Gateway. Library passages and questions are also embedded with Gemini Embedding 001 through the Gateway. Google processes that text to generate answers and vectors.
- Pinecone — stores Gemini embedding vectors and matching source excerpts. When you ask a question, the Gateway embedding of that question is sent to Pinecone to retrieve citations.
Those providers may process data in the United States or other countries where they operate. Their use of the data they receive is also governed by their own terms and privacy policies.
We may disclose information if required by law, to protect the Service or users, or in connection with a merger, acquisition, or sale of assets, in which case this Policy will still apply to the information unless you are notified otherwise.
6. How long we keep information
Account profile copies and stored chats remain until you ask us to delete them or we delete them in the ordinary course of shutting down or cleaning unused data. There is no automatic expiry on chat records in our database.
Guest cookies expire after 30 days. A guest conversation may still exist in the database after the cookie expires. Hosting and authentication logs are kept for the period those providers retain them.
Deleting your Clerk account through Clerk’s account UI stops sign-in with that account. It does not by itself erase chats stored in our database. Email privacy@casezy.com if you want that history deleted.
7. Your choices and rights
You can decline to create an account and use only the guest conversation, or stop using the Service. You can clear cookies and local storage in your browser. You can manage Clerk profile details in the account menu when you are signed in.
Depending on where you live, you may have the right to request access, correction, deletion, or a copy of personal information we hold, to appeal a denial, and to lodge a complaint with a supervisory authority. We will not discriminate against you for exercising those rights. To make a request, email privacy@casezy.com from the address associated with your account when possible. We may need to verify your identity before acting.
If you are in the European Economic Area, United Kingdom, or a similar jurisdiction, we process information as needed to provide the Service you request (contract), to operate and secure the Service (legitimate interests), and where required by law. Because we do not use non-essential tracking cookies, we do not currently seek cookie consent for analytics or ads.
If you are a California resident, the categories of personal information we collect are identifiers (such as email, Clerk id, guest id, and IP address), internet and electronic activity (pages and API calls, plus conversation content you submit), and information you choose to include in a question. We collect them from you, your device, Clerk, and our hosting logs. We use them for the purposes in Section 4. We do not sell personal information or share it for cross-context behavioral advertising. You may request access, deletion, or correction as described above. You may use an authorized agent if the request includes proof of authorization and we can verify you.
8. Children
The Service is for users 18 and older. We do not knowingly collect personal information from children. If you believe a child has used the Service, contact privacy@casezy.com and we will delete the information we can identify.
9. Security
We use HTTPS, authenticated APIs, and access controls at our providers. No method of transmission or storage is completely secure. You should avoid putting highly sensitive identifiers into a chat.
10. International users
The Service is operated from the United States. If you use it from another country, you understand that your information will be processed in the United States and in other locations where our providers run, which may have different data-protection rules than your home country.
11. Changes
We may update this Policy when the Service or the law changes. The “Effective” date at the top will change when we do. Material changes will be posted on this page. Continued use after an update means you accept the revised Policy.
12. Contact
Privacy: privacy@casezy.com
Terms and other legal: legal@casezy.com