Data Residency Statement
Where Centralize Legal stores and processes Customer Data. Last updated July 4, 2026.
Declared region
Centralize Legal production infrastructure is deployed in United States — Google Cloud and Railway region us-west1 (Oregon / US West).
Configuration key: DATA_RESIDENCY_REGION=us-west1
What resides in this region
- Application servers (Railway)
- PostgreSQL database: encrypted OAuth refresh tokens, non-privileged index metadata, audit logs, billing metadata, account settings
- Google Cloud KMS keys used for token envelope encryption (
us-west1key ring)
What does not persist in our database
- Email bodies and subjects
- Document filenames and titles
- Matter and client names
- File contents (files are streamed pass-through from source systems)
Connected source systems
When users connect Clio, Microsoft 365, or Dropbox, data may also be processed in those providers' regions under Customer's existing agreements. Centralize Legal retrieves data using the user's delegated OAuth token and does not replicate full document stores into our database.
Subprocessors & transfers
See Subprocessor List for vendor locations. Primary subprocessors (WorkOS, Google Cloud, Railway, Twilio, SendGrid, Stripe) process data in the United States.
Data removal (delete on disconnect / account closure)
- Per-source disconnect: OAuth connection and associated index rows for that connection are removed.
- Firm account closure: after a 14-day grace period, operational data (connections, index items, checklists, SMS opt-in fields) is purged from our database. Audit metadata may be retained for compliance.
Customers may request account closure through firm administrators or by contacting support@centralizelegal.com.
HTTPS
All customer-facing endpoints are served over TLS (HTTPS).
Contact
Residency questions: support@centralizelegal.com
Related: Privacy Policy · Terms of Service · Security Overview · Data Processing Agreement · Subprocessors · Data Residency