Privacy Policy
Effective Date: August 10, 2026
Built for confidential legal and medical-record workflows. BAA available. This policy describes how we handle personal information on the marketing site and in evaluation workflows.
What we do not claim
There is no HHS certification program that makes a vendor "HIPAA certified" or "fully HIPAA compliant" as a marketing badge. EveryCase describes its actual controls, signs a Business Associate Agreement when PHI is in scope, and limits uploads to the authenticated secure portal after agreement acceptance. See Security and the BAA.
Information we collect
- Contact and qualification data you submit (name, work email, firm, role, state, case type, approximate volume) — do not include client names or medical details in marketing or qualification forms.
- Case files uploaded only through the authenticated secure portal after agreement acceptance.
- Technical logs needed for security and reliability (without putting PHI in URLs, analytics, or email subjects).
How we use information
To respond to inquiries, run evaluations, provide deliverables, secure the service, bill for paid cases, and improve reliability. We do not sell personal information. No model training on your cases, ever. Your data is your data.
Sharing
We use subprocessors necessary to operate the service (for example hosting/auth/storage, email delivery, abuse prevention, payments, and case processing). A current list is maintained in our security documentation and available on request.
Retention and deletion
Evaluation files are retained for 30 days by default, then deleted. See What happens to my documents.
Your rights
Contact privacy@everycase.ai for access, correction, or deletion requests where applicable.
Change log
- August 10, 2026 — Published effective date; removed staging banner; clarified BAA/controls language and that EveryCase does not claim HIPAA certification.