Data Residency Statement

Where Centralize Legal stores and processes Customer Data. Last updated July 4, 2026.

Declared region

Centralize Legal production infrastructure is deployed in United States — Google Cloud and Railway region us-west1 (Oregon / US West).

Configuration key: DATA_RESIDENCY_REGION=us-west1

What resides in this region

  • Application servers (Railway)
  • PostgreSQL database: encrypted OAuth refresh tokens, non-privileged index metadata, audit logs, billing metadata, account settings
  • Google Cloud KMS keys used for token envelope encryption (us-west1 key ring)

What does not persist in our database

  • Email bodies and subjects
  • Document filenames and titles
  • Matter and client names
  • File contents (files are streamed pass-through from source systems)

Connected source systems

When users connect Clio, Microsoft 365, or Dropbox, data may also be processed in those providers' regions under Customer's existing agreements. Centralize Legal retrieves data using the user's delegated OAuth token and does not replicate full document stores into our database.

Subprocessors & transfers

See Subprocessor List for vendor locations. Primary subprocessors (WorkOS, Google Cloud, Railway, Twilio, SendGrid, Stripe) process data in the United States.

Data removal (delete on disconnect / account closure)

  • Per-source disconnect: OAuth connection and associated index rows for that connection are removed.
  • Firm account closure: after a 14-day grace period, operational data (connections, index items, checklists, SMS opt-in fields) is purged from our database. Audit metadata may be retained for compliance.

Customers may request account closure through firm administrators or by contacting support@centralizelegal.com.

HTTPS

All customer-facing endpoints are served over TLS (HTTPS).

Contact

Residency questions: support@centralizelegal.com

Related: Privacy Policy · Terms of Service · Security Overview · Data Processing Agreement · Subprocessors · Data Residency