Skip to content

Privacy Policy

Effective Date: August 10, 2026

Built for confidential legal and medical-record workflows. BAA available. This policy describes how we handle personal information on the marketing site and in evaluation workflows.

What we do not claim

There is no HHS certification program that makes a vendor "HIPAA certified" or "fully HIPAA compliant" as a marketing badge. EveryCase describes its actual controls, signs a Business Associate Agreement when PHI is in scope, and limits uploads to the authenticated secure portal after agreement acceptance. See Security and the BAA.

Information we collect

  • Contact and qualification data you submit (name, work email, firm, role, state, case type, approximate volume) — do not include client names or medical details in marketing or qualification forms.
  • Case files uploaded only through the authenticated secure portal after agreement acceptance.
  • Technical logs needed for security and reliability (without putting PHI in URLs, analytics, or email subjects).

How we use information

To respond to inquiries, run evaluations, provide deliverables, secure the service, bill for paid cases, and improve reliability. We do not sell personal information. No model training on your cases, ever. Your data is your data.

Sharing

We use subprocessors necessary to operate the service (for example hosting/auth/storage, email delivery, abuse prevention, payments, and case processing). A current list is maintained in our security documentation and available on request.

Retention and deletion

Evaluation files are retained for 30 days by default, then deleted. See What happens to my documents.

Your rights

Contact privacy@everycase.ai for access, correction, or deletion requests where applicable.

Change log

  • August 10, 2026 — Published effective date; removed staging banner; clarified BAA/controls language and that EveryCase does not claim HIPAA certification.