Privacy Policy
Last updated July 25, 2026
This policy explains what AsyncConfer collects, why, and who else touches it. It covers the asyncconfer.com website and the AsyncConfer application.
AsyncConfer is operated by AsyncConfer LLC, a limited liability company based in San Francisco, California, which is the party responsible for the information described here (the "data controller," if you are asking under the GDPR).
The short version: we collect what the Service needs to work, we do not sell it, we do not run ad trackers or analytics, and we do not use your case material to train machine learning models.
1. What we collect
Account information
- Your email address, and the date you verified it.
- A cryptographic hash of your password — never the password itself. We cannot read it or recover it for you, which is why a reset issues a new one.
- Your Square customer and subscription identifiers, and your subscription status, if you pay.
Workspace content
Whatever you and the other participants put into a workspace, which typically includes:
- the case caption, court, docket number, document title, and counsel block;
- the names, roles, and email addresses of the parties you invite, and of any colleagues those parties add to their own side;
- section headings, proposals, counter-proposals, comments, and accept/reject decisions;
- deadlines you set; and
- generated exports, which we store so you can download them again.
Because this is litigation software, workspace content may include information about people who are not our users — parties, witnesses, opposing counsel. You control what goes in.
Activity and technical information
- An audit log for each workspace recording who took which action and when, so the conferral record is defensible.
- Timestamps for when a participant last viewed a workspace.
- Server logs generated by our hosting provider in the ordinary course of running the site.
- A first-party operational log of requests to the site: the page pattern requested (never a link containing your workspace token), the response status, how long it took, your IP address, and a coarse browser label such as “Chrome on macOS” — not your full browser string. We keep these entries for about 30 days and then only daily totals. We use them to run and secure the service — to see errors, capacity problems, and attacks in progress — and for nothing else. There is no profiling, no advertising use, and no third party involved.
Payment information
We never see or store your card number. Card details are captured and tokenized in your browser by Square's payment SDK and sent directly to Square. We store only the identifiers Square gives us so we can tell whether a workspace is paid and whether a subscription is active.
2. Cookies
We use one cookie: a signed session cookie that keeps you logged in. It is HttpOnly, restricted by SameSite, and expires after 30 days. Invited parties get a similar cookie for the workspace they were invited to.
We run no third-party analytics, advertising, or cross-site tracking of any kind. There is no Google Analytics, no advertising pixel, and no session recording on this site, and no third party receives data about your visit.
We do keep our own operational request log, described above. It is first-party, it never leaves our systems, it is not linked to any advertising identity, and it exists to keep the service running and to spot attacks. We would rather describe it plainly than hide it behind a claim to run “no analytics”.
3. How we use information
- To operate the Service: authenticate you, render workspaces, and generate exports.
- To send transactional email — email verification, workspace invitations, password resets, and notices about the Service. We do not send marketing email.
- To take payment and manage subscriptions.
- To keep the audit trail that makes a conferral record credible.
- To secure the Service, investigate abuse, and debug problems.
- To comply with the law.
We do not sell personal information, share it for cross-context behavioral advertising, or use workspace content to train machine learning models.
4. Who else processes your information
We keep the list of vendors short and deliberate:
| Provider | What it handles |
|---|---|
| Render | Application hosting and the PostgreSQL database where all content is stored. |
| Square | Card processing and subscription billing. Square receives your payment details directly. |
| Resend | Delivery of transactional email, which means it processes recipient addresses and message contents. |
| Cloudflare | The bot challenge (Turnstile) on our sign-in, sign-up, and password-reset pages. It sets no tracking cookie and is not loaded anywhere else on the site. |
| Anthropic | The AI features, and only when you use one. It receives the text you submit to that feature: the text of a document you choose to import, the notes you type when you ask it to draft a section, or — when someone asks for a suggested compromise on a section the parties disagree about — the two competing positions and that section's discussion. Anthropic does not train models on content submitted through its API. |
That is the whole list. Our typefaces are served from our own servers rather than a font CDN, so apart from the bot challenge on those three authentication pages, loading a page here announces your visit to no third party. Anthropic is involved only when you invoke an AI feature yourself: the request is made by our server after you act, so simply having a workspace, or reading one, sends nothing anywhere.
When you import a document, the file itself never leaves your browser — it is converted to text on your own machine, and it is that text we send. The model answers with paragraph numbers rather than prose, so the language that ends up in your statement is copied from your own document, and nothing is saved until you review and accept it.
Two features do have the model write language, and that is worth being plain about. When you ask it to draft a section, it writes from the notes you typed for that section and nothing else — the result lands in an editor, and it is your proposed language only once you submit it. A suggested compromise is shown to both parties at once, marked as machine-generated, and belongs to neither of you unless one of you adopts it — and if someone does, the conferral record shows the language came from a suggestion. For that feature the model is not told which position is whose, or whether either party is representing themselves. Neither feature is ever asked to produce legal authority, and a draft that introduces a citation you did not write is discarded before you see it. If you would rather no third party saw the content at all, do not use these features; the rest of the application does not depend on them.
We may also disclose information if legally required — a subpoena, warrant, or court order — or to protect the rights and safety of our users. If a legal demand covers your workspace content and we are permitted to tell you, we will.
5. Who can see your workspace
- The host of a workspace can see and export everything in it.
- Invited parties can see the workspace they were invited to, as can any colleague they add to their own side.
- Anyone holding a valid record link can view that workspace's read-only record. The host controls whether such a link exists and can rotate it at any time, which invalidates the old one.
- Our staff can access data only where necessary to operate the Service or support you — for example, to diagnose a bug you have reported.
6. Retention
We keep account and workspace information for as long as your account is active. If you delete your account, we delete your account record and associated workspace content from our production systems, other than what we must keep for legal, tax, or accounting reasons — payment records in particular. Encrypted backups age out on our provider's ordinary schedule.
The operational request log described in section 1 is kept for about 30 days, after which individual entries are deleted and only daily totals per page pattern remain. Those totals contain no IP addresses and are not linked to any account.
One record survives account deletion by design: when we take an administrative action on an account — signing it out, resetting two-factor, or deleting it — we keep a tamper-evident note that we did so, including the reason. It records our own conduct rather than yours, and keeping it is what allows an unauthorised action by us, or by someone impersonating us, to be detected afterwards. It holds no workspace content.
7. Security
Traffic is encrypted in transit with TLS. Passwords are stored as salted scrypt hashes. Session cookies, invitation links, verification links, and password-reset links all carry expiring, HMAC-signed tokens; a password reset link becomes useless as soon as it is used or the password changes. No system is perfectly secure, and we cannot guarantee absolute security — but we would rather tell you that plainly than imply otherwise.
8. Your rights
Depending on where you live — including under the California Consumer Privacy Act and the GDPR — you may have the right to access, correct, export, or delete your personal information, to object to or restrict processing, and to withdraw consent. Email stan@asyncconfer.com and we will act on your request within the time the applicable law allows. We will not discriminate against you for exercising these rights.
If you are an invited party and want your information removed, contact the host of the workspace first — they control that record. Write to us if that does not resolve it.
9. International users
The Service is operated in the United States, and information is stored and processed there. If you use it from elsewhere, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from your own.
10. Children
The Service is for legal professionals and is not directed to anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.
11. Changes
If we change this policy materially, we will give notice by email or in the app before it takes effect. The "last updated" date above always reflects the current version.
12. Contact
Privacy questions and requests go to stan@asyncconfer.com.
AsyncConfer LLC
San Francisco, California, USA