Operated by Truth Computing Incorporated, a Delaware corporation ("Truth Computing", "we", "us"), the maker of Clientlyy.
This policy explains what information Clientlyy collects, why, and what we do with it. Clientlyy is a business-to-business service used by law firms (our "customers"). Most of the personal information in Clientlyy belongs to the firm's own clients and matters; the firm decides what to put into Clientlyy and remains responsible for it. We handle that information on the firm's behalf and under its instructions.
Your data is yours. We process it to run the service you asked for, we do not sell it, we do not use your clients' information or your documents to train external or third-party AI models, and you can export or delete it. The rest of this section is the detail.
1.Information we handle
Depending on how your firm configures Clientlyy, this can include:
- Firm & account data. Names, work email addresses, roles, and login credentials of the attorneys, paralegals, and administrators you invite. Passwords are stored only as salted hashes.
- Client & matter data. Client names, mobile phone numbers, case or matter identifiers, case-file events, cadence preferences, and the consent status of each client.
- Messages & communications. The template-based updates drafted for and sent to clients, inbound replies (including opt-out keywords such as STOP), and the approval decisions your team makes.
- Documents. Legal documents, matter files, and their extracted events that your firm uploads or connects for drafting, review, deadline, and retrieval features.
- Billing data. Your plan, active-case count, and billing contact. Card and bank details are entered directly with our payment processor and are never received or stored by us.
- Operational logs. A tamper-evident, hash-chained audit trail of who drafted, approved, edited, and sent what and when, plus standard security and diagnostic logs. Audit and integration logs are designed not to record message bodies, document contents, full email bodies, or secrets.
2.How we use it
We use the information above only to provide and support the service, specifically to:
- Draft client updates by selecting from your attorney-approved template library, and route anything uncertain to a human for review;
- Capture and honor client consent and opt-outs, and send messages only within permitted local time windows;
- Run the document, deadline, filing-check, review, and fact-retrieval features your firm enables;
- Maintain the audit trail, enforce access controls, secure the service, and prevent abuse;
- Provide support, and bill you for your plan.
Clientlyy does not write free-form, client-facing prose about legal matters. For client messaging, the model's only role is to pick an approved template variant or to escalate to a human — a message a model wrote from scratch is never sent without a person reading it first; that is enforced in code, not a setting your firm can change. We do not use your clients' personal information, your matter data, or your documents to train models that serve anyone other than your firm, and we do not sell or share that information for advertising.
By default, Clientlyy reads your documents using a model that runs locally, so document contents do not leave your environment for that purpose. One optional capability — Document AI, used for reading scanned records such as medical records — instead sends the document to Anthropic's Claude API. That capability is off by default, cannot be turned on until an attorney at your firm attests that a signed Business Associate Agreement covering that flow is in effect, and can be switched off at any time, firm-wide or for a single client. Anthropic processes that document under a 30-day data-retention window required by its BAA terms and does not use it to train its models. See the sub-processor list for the full picture.
3.Our role and legal bases
For client and matter data, your firm is the controller (or "business") and Clientlyy acts as a processor (or "service provider"): we process that data under your instructions and the agreement between us. For your own account and billing data, and for securing the service, we act as controller. Where data-protection law applies, we rely on the performance of our contract with you, our legitimate interest in operating and securing the service, and - for communications to clients - the consent your firm is responsible for obtaining and that Clientlyy records. Where a firm processes protected health information, a Business Associate Agreement (BAA) is required before that data is placed in Clientlyy.
4.Sub-processors
We use a small set of vetted providers to run the service. Each receives only what it needs, and only when your firm enables the relevant feature:
| Provider | Purpose | Data involved |
|---|---|---|
| Stripe | Payment processing | Billing and card data (entered directly with Stripe) |
| Twilio | Delivering and receiving text and WhatsApp messages | Client phone numbers and message content |
| Anthropic | Document AI — reading scanned records, when your firm enables it under a signed BAA | The specific document sent, retained 30 days under Anthropic's BAA terms, never used for training |
| Google (Gmail / Drive) | Optional mailbox drafts and document access, when connected | Emails and documents you authorize |
| Microsoft (Outlook) | Optional mailbox drafts, when connected | Emails you authorize |
| Clio | Optional read-only pilot integration for matter documents | Matter documents are read in memory to prepare a draft and are not stored by Clientlyy |
| Cloud hosting & object storage | Running the service and storing documents (tenant-scoped keys) | All service data, isolated per firm |
The full, current list of sub-processors is always available at /subprocessors. We will provide notice of a new sub-processor at least thirty (30) days before it begins processing Firm Data.
5.Retention & deletion
We keep your data for as long as your account is active or as needed to provide the service. The audit trail is intentionally append-only and tamper-evident, so it is retained for the life of the account as a record of what was sent and approved. You can export your data, including the audit trail, at any time. On request, or after your account closes, we will delete or return customer data within a commercially reasonable period, except where we must retain it to comply with law. Your data isolation to your firm is enforced throughout.
6.Security
- Data is isolated per firm (tenant-scoped), and access is role-enforced and logged.
- Documents pass an egress gate before any storage or model call.
- Passwords are salted and hashed; sessions and cookies are secured in production.
- The hash-chained audit log makes tampering with the record detectable.
- Secrets, document contents, and full message bodies are kept out of integration and audit logs.
No service can promise perfect security, but we work to protect your data and to be honest about how it is handled. Each measure above is documented in full — mechanism, what it means for your firm, and what it does not cover — on the engineering page, alongside where we stand on formal certification.
7.Your rights & choices
Individuals whose data a firm has placed in Clientlyy (for example, a firm's clients) should contact that firm to exercise access, correction, deletion, or opt-out rights, because the firm controls that data; we will assist our customer in responding. Firm users can update their own account details or ask us to do so. Clients can opt out of messages at any time by replying STOP (or CANCEL, END, QUIT, UNSUBSCRIBE), which revokes consent immediately. Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA/CPRA; contact us and we will honor those rights as the law requires.
↑ Back to top of Privacy Policy