Effective date: March 30, 2026. Last updated: August 17, 2026. This Privacy Policy describes how the operator, Completely Offensively LLC, of Docket Daily ("Operator," "we," "us," or "our") collects, uses, and shares information when you use our websites, applications, and related services (collectively, the "Service"). It is written to reflect common practices under major U.S. state consumer privacy frameworks (for example California, Virginia, and Colorado) and other U.S. laws that may apply to you. Privacy laws and regulations vary by state and change over time. If you need legal advice for your situation, then always consult a qualified attorney. We will update this Policy when we materially change our practices.
1. Scope
This Privacy Policy applies to personal information we process in connection with the Service. It does not apply to information that is de-identified, aggregated, or excluded from "personal data" / "personal information" definitions under applicable law. If you interact with us only as an employee or representative of a business customer, additional terms in your agreement may apply.
2. Personal information we collect
Depending on how you use the Service, we may collect:
- Identifiers — such as name, email address, IP address, device identifiers, and account credentials.
- Commercial information — such as records of services purchased or considered.
- Payment verification data — when you add a payment method to the Service (for example before your trial ends or when starting a paid subscription), we may receive from our payment processor (Stripe) a tokenized card fingerprint associated with your payment method. This fingerprint is a non-reversible identifier that allows us to determine whether a payment card has previously been used to activate a free trial on the Service. We do not receive or store your full card number, CVV, or expiration date.
- Internet or network activity — such as pages viewed on our Service, referring/exit pages, and interaction with our emails or pages. When you use dashboard search, we may record that a search occurred for reliability and abuse prevention, but we do not intentionally retain, log in our application, or associate with your account the text of your search queries. Search terms are transmitted in request bodies rather than URL query strings to reduce exposure in routine server access logs; hosting infrastructure may still briefly process request metadata in transit. See our Attorney confidentiality statement.
- Security-verification signals — when you use signup or other protected flows, we use Cloudflare Turnstile to help distinguish legitimate users from automated abuse. Turnstile may process limited device and browser signals (such as IP address, user agent, and interaction data) strictly necessary to verify that a request is not automated. We do not use Turnstile for advertising or cross-context behavioral profiling.
- Geolocation data — coarse location inferred from IP address.
- Professional or employment-related information — if you provide it (e.g., law firm affiliation).
- Business profile information — such as industry, organization size range, jurisdictions of operation, and categories of data you handle, which you may provide to tailor compliance information to your circumstances.
- Marketing and lead-generation information — if you respond to an advertisement or request information about the Service, we collect the professional email address you provide (a law firm, company, or other organizational address), the professional role you self-select (for example, technology attorney or in-house counsel), the date and time of your submission, your IP address and browser user agent at that time, the advertising campaign, ad, and referral identifiers associated with your visit, and a record of the consent language displayed to you. When you continue past the role-selection step on an advertising landing page, we store those campaign and referral identifiers in a signed, HttpOnly browser cookie rather than in the URL of subsequent pages, so those identifiers do not appear in browser history, routine server access logs, or outbound Referer headers on later steps of the funnel.
- Communications content — messages you send via contact forms or email, including support inquiries and privacy requests.
- Inferences — derived from the above (e.g., product interests), where permitted.
We do not use the Service to knowingly collect sensitive personal information within the meaning of state laws (such as government ID numbers, precise geolocation, or health data) except where you voluntarily submit it in a message. Always avoid sending unnecessary sensitive data.
We may store and display public news headlines and excerpts from third party publishers (for example the AP News) for editorial context. That content is not "your" personal information, but it may be processed on our servers in the ordinary course of operating the Service.
3. Sources
- Directly from you (e.g., forms, account registration, email).
- Automatically through cookies, logs, and similar technologies.
- From service providers that assist us (e.g., hosting, analytics, email delivery).
3.1 Subprocessors
Depending on configuration, we use infrastructure and service providers that process information on our behalf, including for example Supabase (database and authentication infrastructure), Vercel (hosting and serverless functions), Resend (transactional and service email delivery, including contact form messages and account and trial notifications), Stripe (payment processing and trial eligibility verification), ScrapingBee (proxied fetching of public government legal sources), Cloudflare, Inc. (bot and abuse protection via Turnstile on signup and related flows), and Meta Platforms, Inc. (advertising delivery and conversion measurement for campaigns we run on Meta properties, where enabled). Their use of data is governed by our agreements with them and their own privacy notices.
3.2 AI-assisted processing
For internal classification, semantic relevance scoring, summarization, and verification workflows, we send public corpus content — such as state, federal, and municipal instrument text, court opinions, titles, and citations — to external model providers (Anthropic for language-model tasks and OpenAI for embedding-based relevance scoring) and to models we run locally. Section 5 describes this processing in detail. These requests are not intended to include your personal information. Do not paste unnecessary personal data into contact forms or other fields.
4. Purposes of processing
- Provide, maintain, secure, and improve the Service.
- Communicate with you, including support and legal notices.
- Process payments and fulfill subscriptions where applicable.
- Detect, prevent, and address fraud, abuse, or security issues, including by verifying signup and related requests using security-verification services (such as Cloudflare Turnstile) to detect and block automated abuse.
- Verify free trial eligibility and prevent unauthorized circumvention of trial offer limits, including by checking whether a payment card has previously been associated with a free trial on the Service.
- Comply with law and enforce our Terms of Service.
- Analytics to understand how the Service is used (where permitted).
- Operate optional news headline features and other editorial content derived from public sources.
- Send marketing communications about the Service — including product information, feature announcements, and offers — to professional email addresses submitted to us for that purpose, until you unsubscribe.
- Measure, attribute, and optimize our advertising, including by reporting conversion events to advertising platforms, subject to the opt-out choices described in Section 7.
5. Artificial Intelligence Processing
Docket Daily uses artificial intelligence to classify, score, summarize, and verify public legal materials. Some processing uses external model providers; some runs on infrastructure we control.
External processing — language models. We transmit public legal source content — including state, federal, and municipal instrument text, court opinion documents, titles, citations, publication dates, categories, and matched legal terms — to Anthropic, Inc. (Claude) for topic classification (where LLM classification is used), summarization (when enabled), and automated accuracy verification. For compliance-assistance features, the content transmitted to Anthropic also includes the text and metadata of related tracked instruments and of curated foundational reference laws assembled as context for generating compliance summaries and suggested compliance language. Anthropic processes this content under its commercial API terms at anthropic.com. Under those terms, API inputs are not used to train Anthropic's models.
External processing — semantic relevance scoring. We transmit public instrument and opinion text to OpenAI for embedding-based semantic relevance scoring using the text-embedding-3-small model. Each embedding request is capped at 8,000 characters. For long documents, we may send sequential segments until a relevance threshold is met: up to ten segments for court opinions (roughly 80,000 characters total) and up to fourteen segments for discovery title-nexus body confirmation (roughly 112,000 characters total). OpenAI processes this content under its API terms at openai.com. We do not authorize OpenAI to use API inputs to train its models.
Local processing. We may also run language models locally using Ollama on infrastructure we control. When local models are used, that LLM content is not transmitted to Anthropic or any other third-party language-model provider. Local processing does not replace OpenAI embedding calls when those are enabled.
The following subscriber data is NOT transmitted to any AI service, external or local:
- Your name or email address
- Your account credentials
- Your payment or billing information
- Your law firm or organization name
- Your usage history or preferences
- Your dashboard search query text
- Email addresses or role attestations you submit through advertising or lead-capture forms
This also applies to compliance-assistance features: the business-profile information you provide to filter compliance obligations is used only to tailor which obligations are shown to you and is not transmitted to any AI provider.
AI-generated summaries are stored in our database and associated with the relevant legal development record. They are not associated with individual subscriber accounts or identities.
All AI-generated content is labeled as such, is reviewed by an attorney editor before publication, and is intended for informational purposes only.
6. Disclosure of personal information
We may disclose personal information to:
- Service providers and processors bound by contractual obligations (e.g., hosting, email, analytics, security).
- Professional advisors (e.g., lawyers, accountants) under confidentiality duties.
- Authorities when required by law, legal process, or to protect rights and safety.
- Business transfers in connection with a merger, acquisition, or asset sale, with notice where required.
7. “Sale,” “sharing,” and targeted advertising
We do not sell your personal information for monetary consideration.
Some state laws treat certain disclosures of personal information for cross-context behavioral advertising as "sharing" or as a non-monetary "sale." When we run advertising campaigns on third-party platforms (for example, Meta), we may transmit limited identifiers — such as a hashed email address, an advertising click identifier, an IP address, and a record that a conversion event occurred — to that platform so it can measure and optimize delivery of our advertisements. Depending on the law of your state, that transmission may qualify as "sharing" for targeted advertising or as a "sale."
You may opt out. Use the "Your Privacy Choices" link in our site footer. When you are signed in, one click opts your account out on every device. When you are not signed in, the toggle opts out this browser only. We also honor opt-out preference signals transmitted by your browser or device, including Global Privacy Control (GPC); when we detect that signal we treat it as an opt-out of sale, sharing, and targeted advertising for that browser or device. When you have opted out, we do not load advertising measurement technologies or transmit conversion events.
We do not knowingly sell or share the personal information of consumers under 16 without affirmative authorization where required.
8. Retention
We retain personal information only as long as necessary for the purposes above, unless a longer period is required or permitted by law (for example, tax or litigation holds). Criteria include the nature of the data, operational needs, and legal obligations.
Marketing lead information. We retain information submitted through advertising or lead-capture forms for up to twenty-four (24) months from your most recent interaction with us, after which we delete or de-identify it, unless you unsubscribe sooner or a legal obligation requires a longer period. If you unsubscribe, we retain a minimal suppression record (your email address and the date of the request) for as long as necessary to honor that request.
9. Your U.S. privacy rights
Depending on where you live, you may have rights to access, delete, correct, port, or opt out of certain processing, and to appeal our decisions. We will not discriminate against you for exercising these rights, except as permitted by law (e.g., certain loyalty differences tied to reasonably expected value).
9.1 How to submit a request
Email brad@docketdaily.ai with "Privacy Request" in the subject line. We may need to verify your identity (and, for California, authorized agent documentation) before fulfilling requests. We will respond within the timeframes required by applicable law (typically 45 days, with one extension where permitted).
You may also unsubscribe from marketing email at any time using the link in any marketing message. Unsubscribing stops marketing email; it does not delete other information we hold about you, which you may request separately using this Section.
9.2 California residents (CCPA / CPRA)
If you are a California resident, you may have the right to:
- Know what personal information we collect, use, disclose, and retain (right to know).
- Delete personal information we collected from you, subject to exceptions.
- Correct inaccurate personal information.
- Opt out of the "sale" or "sharing" of personal information and of certain uses of sensitive personal information, where applicable.
- Receive a portable copy of certain personal information.
- Limit use of sensitive personal information to permitted purposes, where applicable.
- Not be discriminated against for exercising CPRA rights.
California's "Shine the Light" law (Civil Code § 1798.83) permits California residents to request certain information about disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes as traditionally defined by that statute; you may still contact us with questions.
9.3 Virginia residents (VCDPA)
Virginia consumers may have rights to confirm processing, access, delete, correct, obtain a copy, and opt out of processing for targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. If we deny a request, you may appeal by replying to our decision email within the period specified by law.
9.4 Other U.S. states with comprehensive consumer privacy laws
Many states have enacted or are enacting consumer privacy laws with rights such as access, deletion, correction, portability, and opt-out of certain advertising or sale practices, plus appeal rights. Examples include laws commonly referred to as the Colorado Privacy Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, and similar statutes enacted in other states. The exact scope of rights depends on the law in effect when you make a request and your residency status. Submit requests through Section 9.1. We will respond consistent with applicable law after verification.
9.5 Nevada residents
Nevada residents may submit a verified request directing us not to sell certain covered information we have sold or might sell, as defined by Nevada law (Chapter 603A). We do not currently sell covered information as defined there; you may still contact us to record your preference.
9.6 Other states
Privacy laws continue to evolve. If your state grants rights not listed here, contact us using Section 9.1 and we will respond consistent with applicable law. Nothing in this Policy limits non-waivable rights under your state's consumer protection statutes.
10. Cookies and similar technologies
We use cookies and similar technologies for operation, security, preferences, and analytics. You can control cookies through browser settings. Some features may not function if you disable cookies.
10.1 Bot protection (Cloudflare Turnstile)
We use Cloudflare Turnstile on signup and related flows to help protect the Service against automated abuse. Turnstile is operated by Cloudflare, Inc. and processes limited security-verification signals as described in Section 2. Cloudflare processes those signals as our service provider to detect and block bots; Cloudflare may also process certain signals as a controller to improve Turnstile. For more information, see Cloudflare's Privacy Policy and Turnstile Privacy Addendum.
10.2 Advertising and measurement technologies
On advertising landing pages, we may report conversion events to advertising platforms using server-side measurement (Meta's Conversions API) to determine whether an advertisement led to a visit or an inquiry. We do not load client-side advertising pixels on those pages. These reports may include an identifier such as a hashed email address, a click identifier, IP address, and user agent. We do not use advertising measurement on the subscriber dashboard or on any page that displays your account information. You may opt out as described in Section 7.
11. Security
We implement reasonable administrative, technical, and organizational measures designed to protect personal information. No method of transmission or storage is 100% secure. Thus, we cannot guarantee absolute security.
12. Children’s privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Where state law requires a higher age threshold for the sale or sharing of personal information, we apply the under-16 standard described in Section 7. If you believe we have collected information from a child, contact us and we will take appropriate steps to delete it.
13. International users
If you access the Service from outside the United States, you understand that information may be processed in the United States and other countries where we or our providers operate, which may have different data protection laws. Where required, we implement appropriate safeguards for cross-border transfers.
14. Automated decision-making
We do not use personal information to make solely automated decisions that produce legal or similarly significant effects about consumers, as described in laws like the VCDPA, without human oversight appropriate to the context. Internal tools may assist with content classification or summarization of public legal materials; final publication remains subject to our editorial and technical controls.
15. Financial incentives
We do not offer financial incentives in exchange for personal information at this time.
16. Changes to this Policy
We may update this Privacy Policy by posting a new version and revising the effective date. For material changes, we will provide additional notice as required by law (for example, a banner or email).
Revision history
August 17, 2026 — Dashboard search confidentiality
We clarified how dashboard search is handled after migrating search to POST request bodies:
- Section 2.Replaced vague "search activity" language with precise no-retention disclosure for search query text, including an honest infrastructure caveat and a link to our Attorney confidentiality statement.
- Section 5. Added dashboard search query text to the list of subscriber data not transmitted to AI services.
August 12, 2026 — Municipal corpus disclosure; children's privacy age thresholds
We made two clarifications:
- Section 3.2 and Section 5. Clarified that public legal materials processed include municipal/city instruments.
- Section 12.Aligned children's privacy age-threshold language with Section 7.
August 12, 2026 — Lead-capture attribution and measurement clarifications
We clarified how advertising landing pages handle attribution and conversion measurement:
- Section 2. Described storage of campaign and referral identifiers in a signed, HttpOnly cookie after role selection, rather than in subsequent page URLs.
- Section 3.2. Clarified that AI-assisted processing uses instrument text from the public legal corpus, not bill text alone.
- Section 10.2.Clarified that conversion measurement on advertising landing pages is server-side (Meta's Conversions API) and that we do not load client-side advertising pixels on those pages.
August 9, 2026 — Advertising and marketing disclosures
We added disclosures covering advertising landing pages and marketing email:
- Section 2. Added marketing and lead-generation information to the collection list.
- Section 3.1. Listed Meta Platforms, Inc. as a subprocessor for advertising delivery and conversion measurement.
- Section 4. Added marketing communications and advertising measurement to the purposes of processing.
- Section 5. Confirmed that lead-capture email addresses and role attestations are not transmitted to any AI service.
- Section 7.Replaced in full to disclose that conversion events reported to advertising platforms may constitute "sharing" or a "sale" under some state laws, and to add an opt-out mechanism and Global Privacy Control support.
- Section 8. Added a retention period for marketing lead information.
- Section 9.1. Added unsubscribe as a channel.
- Section 10.2. Added advertising and measurement technologies.
August 2, 2026 — Clarified Resend subprocessor description (Privacy §3.1); specified contact email (Terms §22); administrative cleanup of revision history
July 30, 2026 — Turnstile disclosure, Sections 2, 3.1, 4, 10.1
We updated disclosures for Cloudflare Turnstile bot protection on signup and related flows:
- Section 2. Added security-verification signals collected through Turnstile.
- Section 3.1. Listed Cloudflare, Inc. as a subprocessor for Turnstile.
- Section 4. Extended fraud, abuse, and security purposes to cover Turnstile verification.
- Section 10.1.Added bot protection (Cloudflare Turnstile) with links to Cloudflare's Privacy Policy and Turnstile Privacy Addendum.
July 18, 2026 — Privacy Policy updated
We updated disclosures for compliance-assistance features after verifying the production compliance API and rollup paths:
- Anthropic context for compliance assistance. Section 5 now discloses that compliance-assistance features transmit related tracked instruments and curated foundational reference laws to Anthropic as context for generating compliance summaries and suggested compliance language.
- Business-profile filtering. Clarified that business-profile data used to filter compliance obligations is applied server-side and is not transmitted to any AI provider.
- Collection list. Added business-profile information (industry, organization size range, jurisdictions of operation, and categories of data handled) to Section 2.
July 10, 2026 — Privacy Policy updated
We audited our AI processing against our production code and found that Section 5 described it incompletely. We corrected the following:
- Ollama. It was listed as an external AI provider with a link to its privacy policy. Ollama runs on infrastructure we control. Content processed locally is not transmitted to any third party. It is no longer described as an external processor.
- OpenAI embeddings. Our use of OpenAI for embedding-based semantic relevance scoring was not disclosed. We have added it, including the size limits on transmitted document text.
- Verification and QA. Automated verification and quality-assurance processing were not described. Section 5 now covers classification, relevance scoring, summarization, and verification.
- Provider consistency. Section 3.2 and Section 5 previously listed different AI providers. They now agree.
No subscriber personal information is transmitted to any AI service, external or local, and none was at any point. These changes correct our description of processing that involves only public legal materials.
17. Governing law
This Policy is governed by the laws of the Commonwealth of Pennsylvania, USA, without regard to conflict-of-law principles that would require the application of another jurisdiction's laws, except where preempted by U.S. federal law or mandatory consumer privacy protections in your home state. Subject to applicable law and any non-waivable rights you may have to bring claims in your local courts, you agree that exclusive jurisdiction and venue for disputes arising from this Policy or our processing of personal information in connection with the Service shall be in the state or federal courts located in the Commonwealth of Pennsylvania, and you consent to personal jurisdiction there. If you are a consumer, you may also have rights to sue in your state of residence where required by law.
18. Contact
Privacy inquiries and requests email: brad@docketdaily.ai