Privacy Policy
Centralize Legal ("we", "us") provides practice-tool integration software for law firms. This policy describes how we handle information when you use https://centralizelegal.com. Last updated July 4, 2026.
Information we collect
- Account data: name, email, and firm affiliation from your identity provider (WorkOS).
- SMS opt-in data: if you opt in to text reminders, we store your mobile phone number and the date/time of your consent.
- Usage metadata: non-privileged audit logs (tool names, timestamps, result counts) — never email bodies, matter names, or document content.
- Billing metadata: if you subscribe, we store Stripe customer and subscription identifiers — not full payment card numbers.
Third-party integrations (Clio, Microsoft 365, Dropbox)
Each user connects their own accounts via OAuth. We never use one user's tokens for another user or mix data between firms.
- Clio Manage: when connected, we use your Clio OAuth token to search matters, contacts, documents, tasks, calendar entries, and communications you can already access in Clio. Results are returned to your AI assistant with links back to Clio. We do not bulk-export or store Clio record content in our database.
- Microsoft 365 (Outlook / OneDrive / SharePoint): when connected with a work or school account, we use delegated permissions (
Mail.Read,Files.Read.All,Sites.Read.All) to search mail and files you can access. Mail and file content is retrieved on demand when you or your AI request it — not copied into our index. - Dropbox: when connected, we use your Dropbox OAuth token to search folders and files (including team folders and folders shared with you), read file content only when you request preview or text extraction, and create shareable links for search-result provenance. File bytes are streamed pass-through — we do not cache or store them on our servers.
What we store at rest: encrypted OAuth refresh tokens; non-privileged structural metadata (IDs, statuses, dates, counts, timestamps) where indexing applies; audit and billing metadata as described above. We do not store email bodies, document contents, filenames, matter titles, or client names in our index.
What flows through our service: when you search or open a file, privileged content may pass through our servers transiently to fulfill your request, then is discarded. We do not use your source data to train models — Centralize Legal does not run an LLM.
You can disconnect any source at any time from onboarding or account settings. Disconnecting removes that OAuth connection; firm account closure follows our offboard process (see Terms).
Subprocessors
We use contracted service providers solely to operate the service. Full list with purposes and locations: Subprocessor List. Primary vendors include WorkOS (authentication), Google Cloud KMS (encryption key management), Railway (hosting), Twilio (SMS), SendGrid (email), and Stripe (billing).
Your AI assistant (BYO-AI)
Centralize Legal connects your practice systems to your AI assistant. We recommend using a business or enterprise-tier AI appropriate for confidential client data. Your firm's relationship with its AI provider is governed by your agreement with that provider. See our Data Processing Agreement.
Content retrieved via the service is transmitted to the AI environment the Customer connects. That AI provider is a Customer-connected system under the Customer's own agreement, not a Subprocessor of Centralize Legal.
Security & compliance documents
SMS messaging
If you opt in to SMS notifications, we use your phone number only to send generic account alerts (for example, reminders to log in and review time-sensitive items). Messages do not include client names, matter titles, or other privileged content.
We do not sell or share your SMS opt-in data or phone number with third parties for their marketing purposes. We share data only with service providers that help us deliver the service (for example, Twilio for SMS delivery), under contract and solely to perform that service.
Message frequency varies. Message and data rates may apply. Reply STOP to opt out or HELP for help. Program details: SMS notification program.
Data retention & security
OAuth tokens are encrypted at rest using envelope encryption (per-record keys wrapped by a cloud KMS). We do not store privileged source content in our index. After firm account closure (following a grace period), operational data such as connections and index rows is purged; audit metadata may be retained for compliance.
Contact
Support: support@centralizelegal.com · Security: security@centralizelegal.com
See also our Terms of Service.