We will never sell to insurance carriers. Plaintiff-side only is the trust contract. We will not sell customer data, model outputs, or anonymized aggregates to carriers, defense firms, or any defense-side operation. Ever.
Privacy.
Plain-English summary first; the formal terms follow below. Last updated June 9, 2026.
Plain-English summary
We only collect what we need. Account email + firm name to provision the trial, plus a payment method to start it (processed by Stripe — full card data never touches our systems). Case data you put into Predict to run predictions. Standard web analytics and advertising-conversion tags on the public marketing site, plus a first-party cookie that remembers which campaign or search brought you here — so we know which campaigns drive signups. When you submit a form, the contact details you give us flow to our CRM so a person can follow up.
US data residency by default; EU on request. Customer case data is stored on US infrastructure unless your firm operates under EU residency requirements.
You can export and delete your data. Account cancellation triggers a 90-day grace window followed by deletion. Data export is available at any time in machine-readable formats.
1. What we collect
Predict collects the following categories of information:
- Account information. Email address, firm name, primary jurisdiction, primary case type, and any optional notes you provide at signup.
- Case data. Case facts you enter into Predict to run a prediction (jurisdiction, case type, severity, liability classification, medical specials, property damage). For the full subscription, this also includes any documents you upload (medical records, police reports, demand letters) for processing.
- Usage data. Web analytics (Google Analytics) and advertising-conversion tags (Meta, Google Ads, LinkedIn) on the marketing site, loaded via Google Tag Manager. These set cookies and share event data (pageviews, button clicks, conversions) with the respective platforms for measurement and remarketing. We also set one first-party cookie (named "pl_attr") that records which campaign, ad, or search first brought you to the site and which brought you back most recently — the UTM parameters, ad-click identifiers, referring site, landing-page path, and visit timestamps. It carries marketing source signals only: it never stores case facts, uploaded documents, or anything you type into the product, and it expires after roughly 13 months. In-product event data (login times, prediction counts) is kept internal for billing and quality-of-service monitoring.
- Marketing and contact data. When you submit a form on the public marketing site — a demo request, free-trial signup, newsletter subscription, availability waitlist, or partner application — we collect the contact details that form asks for (some combination of name, work email, phone, firm size, active-case volume, jurisdiction, or agency name) and store them in our customer-relationship-management system, together with the attribution signals above, so a person can follow up and we can see which campaigns work. This is marketing-contact information about you as a prospect, and it is kept separate from the confidential case data and documents you enter into the product.
- Billing data. Payment processor (Stripe) handles billing; we receive the last four digits of the card, the billing country, and the subscription status. Full card data never touches our systems.
2. How we use information
We use the information we collect to provision and operate your account, to produce case-valuation predictions, to bill the subscription, to communicate about the service, and to improve the product. We do not use customer case data to target advertising. We do not share customer information with insurance carriers, defense firms, or any defense-side operation.
3. Sub-processors
Predict uses a limited set of sub-processors to operate the service: Supabase (managed backend, authentication, and database), Stripe (billing), Google (Tag Manager, Analytics, Ads), PostHog (product analytics), Twenty (customer-relationship management for marketing leads and sales follow-up), Meta (advertising), and LinkedIn (advertising), along with other infrastructure sub-processors. None of these are insurance carriers, defense firms, or defense-side operations. A complete current list is available on request to support@predict.law and in our Data Processing Agreement.
4. Retention and deletion
Account and case data are retained for the duration of your subscription plus a 90-day grace window after cancellation. After the grace window, primary-system data is deleted within 30 days, and backup data is purged within the next backup rotation (typically inside 60 days). Marketing-contact data held in our CRM is retained while you are a prospect or customer and for follow-up afterward; you can ask us to delete it at any time (see Section 5), and the attribution cookie expires on its own after about 13 months. Aggregated, anonymized usage statistics may be retained indefinitely for product analytics, but contain no personally identifiable information.
5. Your rights
You have the right to access, export, correct, or delete your account, case, and marketing-contact data at any time. Email support@predict.law with the request, including to delete your CRM contact record. You can clear the attribution cookie yourself at any time by clearing cookies in your browser, or avoid it entirely with a browser or extension that blocks cookies before consent. For EU residents, the GDPR rights to data portability and erasure are honored on the standard timelines. For California residents, the CCPA rights to access, deletion, and "do not sell" are honored — we have nothing to "sell" since we do not sell customer information.
6. Security
Customer data is encrypted in transit and at rest, and access to production case data is limited to the engineers who operate the service. We do not sell customer data to insurance carriers, defense firms, or any defense-side operation. If your firm needs a security review or a Data Processing Agreement before enabling Predict, email support@predict.law and we will walk through your requirements.
7. Children's privacy
Predict is a B2B legaltech product for licensed attorneys. The service is not directed at and does not collect information from children under 13 (US) or 16 (EU).
8. Changes to this policy
If we make a material change to this policy, we will notify customers via email at least 30 days before the change takes effect. The "Last updated" date at the top of this page reflects the most recent change.
9. Contact
Privacy questions: support@predict.law. Security incident reporting: support@predict.law. For general inquiries the trial signup form is the fastest path.