Back to site
Birdlaw
Legal

Privacy Policy

Last updated: July 12, 2026

This policy explains what information Birdlaw collects, how we use it, and the choices you have.

1. Introduction and scope

This Privacy Policy explains how Birdlaw LLC (“Birdlaw,” “we,” “us”) collects, uses, discloses, and protects information when you use the Birdlaw website and application (the “service”). It applies to visitors to our website, to the individual users who access the application, and to the firms and organizations that sign up.

2. The roles of the parties

Customer Data. Much of the information in the service is data your firm enters or connects about its matters (defined in Section 3 as “Customer Data”). For that information, your firm or organization is the controller (or “business”) and Birdlaw acts as a processor (or “service provider”), handling it on your firm’s instructions and only to provide the service. Requests from an individual to access or delete personal information contained in Customer Data are generally directed to, and handled by, the firm that controls it.

Birdlaw as controller. For account, billing, website, and usage information that we determine how and why to process (Section 3), Birdlaw acts as the controller.

3. Information we collect

Account and firm information: your name, email address, firm or organization name, role, and authentication credentials.

Matter and workspace data (“Customer Data”): information you enter or connect about your cases, such as docket numbers, court and judge information, orders and documents you upload, deadlines, calendar entries, contacts, tasks, and time entries.

Billing information: when you subscribe, our payment processor collects your billing details. We receive limited billing records (such as plan, amount, and the last four digits of a card) and do not store full payment card numbers.

Usage, log, and device information: IP address, browser and device type, pages and features used, and diagnostic and error logs, collected to operate, secure, and improve the service.

Cookies and similar technologies: identifiers used to keep you signed in and to understand usage (see Section 11).

AI assistant conversations: if you use the built-in assistant (“Birdie”), your questions, its answers, and the text of any document you attach are stored with your account so you can revisit them, and you can delete a conversation at any time. Assistant questions and related excerpts of Customer Data are processed by the AI provider your firm connects in User settings → AI, under your firm’s own agreement with that provider; the assistant does not use an AI provider of Birdlaw’s.

We do not intentionally collect special categories of personal data or government identifiers, beyond what a firm may choose to place in Customer Data.

4. How we use information

We use information to: provide, maintain, secure, and improve the service; calculate and surface deadlines; authenticate users and prevent fraud and abuse; process payments and manage subscriptions; provide support you request; send service, security, and administrative messages; and comply with law and enforce our Terms.

We do not sell your personal information or Customer Data; we do not “share” it for cross-context behavioral advertising; and we do not use Customer Data to train artificial-intelligence or machine-learning models.

5. Legal bases for processing (EEA/UK)

Where the GDPR or UK GDPR applies, we process personal information on these bases: performance of a contract (to provide the service to you or your firm); our legitimate interests (to secure, support, and improve the service and prevent abuse, balanced against your rights); compliance with a legal obligation; and, where required, your consent (for example, certain communications), which you may withdraw at any time.

6. Automated processing and deadline calculations

Birdlaw’s deadline features apply rules and dates to information you provide to produce proposed deadlines and calculations. These are informational aids that you review; they are not decisions that produce legal or similarly significant effects about an individual within the meaning of data-protection law, and a qualified person (you) remains responsible for verifying and acting on them. We do not use your information for profiling or automated decision-making of that kind.

7. Legal and client data; confidentiality

We understand that Customer Data may include information subject to professional confidentiality obligations. Each firm’s workspace is logically isolated, and access is restricted based on your organization’s permissions. We access Customer Data only as needed to operate the service, provide support you request, or comply with law.

You are responsible for the confidentiality obligations you owe your own clients and for determining whether the service is appropriate for your data.

8. How we share information; subprocessors

Service providers (subprocessors). We use a limited set of trusted vendors to run the service, which may process information only to provide services to us and under contractual confidentiality and security obligations.

Within your firm. Customer Data is visible to users in your workspace according to the roles and permissions your administrators set.

Legal and safety. We may disclose information if required by law or valid legal process, to enforce our Terms, or to protect the rights, safety, and security of Birdlaw, our customers, or others.

Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

9. Data storage and international transfers

Information is stored and processed in the United States and in other locations where we or our service providers operate. If you or your firm are located outside the United States, your information will be transferred to and processed in the United States.

Where required, we rely on appropriate safeguards for international transfers, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), and take steps designed to ensure your information receives an adequate level of protection.

10. Security and breach notification

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, encryption in transit, tenant isolation between firms, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If we become aware of a personal-data breach affecting your information, we will notify affected customers as soon as practicable.

11. Cookies, Do Not Track, and Global Privacy Control

We use cookies and similar technologies that are necessary to operate the service (for example, to keep you signed in) and to understand usage. You can control cookies through your browser settings, though some features may not function without them. We do not use third-party advertising cookies.

Because there is no common standard, we do not respond to browser “Do Not Track” signals; however, where required by law, we treat a recognized Global Privacy Control (GPC) signal as a valid request to opt out of any “sale” or “sharing” of personal information.

12. Data retention

We retain Customer Data for as long as your account is active and as needed to provide the service. After account termination, we make Customer Data available for export for a limited period and then delete or de-identify it, except where retention is required by law or for legitimate business purposes such as security, fraud prevention, and dispute resolution. Account, billing, and log data are retained for the periods needed for those purposes.

13. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict or object to the processing of your personal information, and to withdraw consent where processing is based on consent. You can update much of your account information in the app, and you can contact us to exercise applicable rights. We will respond consistent with applicable law and will not discriminate against you for exercising your rights.

If your personal information is held in a firm’s workspace as Customer Data, we will refer your request to that firm (the controller) or act on its instructions.

14. California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to know the categories and specific pieces of personal information we collect, to access and delete it, to correct inaccuracies, and to opt out of any sale or sharing of personal information. We do not sell or share personal information as those terms are defined under California law.

Categories we collect (as defined by the CPRA) include: identifiers (such as name, email, account ID, and IP address); professional or employment information (firm and role); commercial information (subscription and billing records); internet or network activity (usage and log data); and other information you place in Customer Data. We collect these to provide and secure the service as described above and disclose them only to the subprocessors and recipients listed in Section 8.

You may exercise these rights as described in Section 16, and you may use an authorized agent to submit a request on your behalf with proof of authorization.

15. European and UK privacy rights (GDPR)

If you are in the EEA or UK, in addition to the rights in Section 13 you have the right to lodge a complaint with your local supervisory authority. Our legal bases for processing are described in Section 5, and information about international transfers is in Section 9. For questions about our processing, contact us at support@birdlawapp.com.

16. How to exercise your rights

To make a privacy request, email us at support@birdlawapp.com. We will take reasonable steps to verify your identity before acting, which may require confirming information associated with your account. We will respond within the timeframes required by applicable law.

17. Children’s privacy

The service is intended for legal professionals and is not directed to children under 18. We do not knowingly collect personal information from children, and if we learn that we have, we will delete it.

18. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by email or in-app). The “last updated” date reflects the most recent revision, and prior versions are retained.

19. Contact

Questions about this Policy or your data, or to exercise your rights, contact us at support@birdlawapp.com.