Legal
Trust and Data Handling
Last reviewed: August 24, 2026
LawEngine is built around inspectable legal sources and explicit product boundaries. That same approach applies to data handling: we explain what a feature stores, what it processes, what it deletes, and what remains your responsibility.
Document Search Beta
Document Search lets a signed-in user upload one text-based PDF, DOCX, TXT, or Markdown file and ask a question about it.
- The file is uploaded to private temporary object storage through a time-limited, one-path upload authorization.
- The file is used as private context for the answer. Extracted text is also processed by LawEngine's model provider to generate that answer.
- LawEngine requests deletion from active storage as soon as extraction succeeds or fails. If that deletion is not confirmed, automated cleanup retries it. LawEngine does not persist extracted text as a Document Search history; during the active job, the text is held process-locally and sent to the model provider described above.
- An unused or abandoned upload is also handled by automated cleanup. Our operational target is that no temporary Document Search object remains in active storage beyond twenty-four (24) hours.
- The answer is ephemeral. LawEngine does not provide a saved Document Search library or answer history; copy or download the answer before leaving the page.
- The content-free upload control record excludes the original filename, file contents, extracted text, question, answer, citations, quotations, and source links. After deletion is confirmed and the workflow reaches a terminal state, routine operational metadata is ordinarily retained for thirty (30) days so we can enforce limits and verify cleanup. A record may remain longer while deletion is unresolved or when a limited security, legal, abuse, or disaster-recovery exception applies.
Deletion from active storage does not mean the file was never processed or cannot remain temporarily in a managed provider's restricted backup or disaster-recovery systems. Limited retention may also be required for a security incident, legal hold, valid legal process, or abuse investigation.
Document Search does not currently support OCR, scanned or image-only PDFs, a persistent document library, multi-document review, or saved answers. An uploaded document is context, not verified authority. Review linked legal sources and independently verify the answer before relying on it.
Verify Brief Is a Separate Workflow
Verify Brief has a separate consent and audit-retention contract. If you accept that feature's disclosure, the uploaded file, extracted text, assessment, and audit metadata may be retained privately for audit, dispute verification, product improvement, and service integrity. Document Search's temporary-storage promise does not describe Verify Brief, and Verify Brief's retention does not describe Document Search.
Analytics Boundary
Marketing and acquisition pages may use marketing analytics and attribution tools. Legal-input product routes use content-free product, security, and operational events.
We do not intentionally send legal queries, keystrokes, filenames, uploaded files, extracted document text, answers, citations, quotations, proof or source URLs, signed upload links, or document/job identifiers to third-party marketing analytics. Product events use coarse categories such as access tier, public search scope, normalized file type, size bucket, query-length bucket, duration bucket, result-count bucket, and safe reason code.
Security Posture
LawEngine uses managed encryption in transit and at rest, private storage, authentication and access controls, restricted administrative access, monitoring, and automated deletion for the temporary Document Search workflow. Infrastructure providers operate under a shared-responsibility model; Law Engine Inc. remains responsible for application access control, credential handling, logging, deletion behavior, configuration, and truthful disclosure.
Law Engine Inc. is not currently SOC 2 certified. We do not claim that these controls eliminate all risk, and no internet service can guarantee perfect security.
Your Responsibility
Submit confidential, privileged, personal, health, trade secret, client-identifying, or other sensitive material only if you are authorized to share it with LawEngine and its service providers for the selected workflow. LawEngine is not a law firm, does not provide legal advice, and does not replace your independent professional review.
For the legally binding details, read our Privacy Policy and Terms of Service. Questions may be sent to support@lawengine.ai.
Also see Privacy Policy.