Where your data goes

Last updated September 28, 2026 · facts about other companies as of September 2026

LVAI Pro is a plugin and a connector for Claude. When you use it, your data can pass through four kinds of service: Claude itself, your legal-research service and public statute pages, Legal Velocity's own server, and the companies that bill and email you. This page follows it hop by hop — what each one receives, what it keeps, and what the provider's own published pages say.

Facts about Legal Velocity's server are taken from its code. Facts about other companies are taken only from the pages linked in each row, as they read in September 2026; where we could not confirm a point, we link to the provider's page rather than state it. Providers change their terms — follow the link before you rely on a detail.

The short version

Hop by hop As of September 2026

Where it goesWhat it receivesWhat is kept, and for how longWhat the provider's own pages say
ClaudeHop 1 · Anthropic — your documents and conversations

Your messages and everything Claude reads while it works, including the files in the case folder you connect. Anthropic says Cowork sessions run on its servers, and that local files Claude opens are “processed on Anthropic's servers rather than staying on your computer.”

LVAI Pro's working files — the verification ledger, the re-lookup record and the certificate data — are written to a hidden .lvai folder in your case folder, never sent to us.

Pro and Max (consumer plans): chats stay in your history until you delete them; a deleted chat leaves Anthropic's back-end within 30 days. If you allow model improvement, chats may be kept, de-identified, for up to 5 years in training pipelines.

Team and Enterprise (commercial plans): chats stay in the product until you delete them, and leave the back-end within 30 days of deletion. On Enterprise, an owner can set a retention period — 30 days at the least; without one, data is kept indefinitely.

Every plan: a chat flagged for a usage-policy violation is kept up to 2 years; feedback you send (thumbs up or down) 5 years.

Training. Pro and Max: chats are used to improve Claude only if you allow it in your privacy settings — but the Consumer Terms say feedback you give, and chats flagged for safety review, may be used even if you opt out. Team and Enterprise: the Commercial Terms say “Anthropic may not train models on Customer Content from Services,” and treat that content as your confidential information.

Certifications. Anthropic lists SOC 2 Type I and Type II, ISO 27001:2022, ISO/IEC 42001:2023 and a HIPAA-ready configuration (BAA available).

Sources: Consumer Terms · Commercial Terms · training (Pro, Max) · training (Team, Enterprise) · retention (Pro, Max) · retention (Team, Enterprise) · Enterprise retention controls · certifications · Use Claude Cowork safely
MidpageHop 2 · case-law lookups, under your own Midpage account

What Claude sends for each lookup: a citation, the sentence of your brief that cites it (quotations included), or a short research question built from them — never the whole document unless you say it may be shared.

Midpage says that for plugins and integrations — its Claude integration among them — it does not store submitted queries, uploads or outputs. Those workflows may share submitted queries with AI model providers, which may keep them for up to 60 days.

Midpage does not use customer data to train or fine-tune AI models, and its agreements with AI model providers do not permit them to train on Midpage customer data. Data is encrypted at rest (AES-256) and in transit (TLS 1.2 or higher). Its controls are independently validated through annual SOC 2 Type II and HIPAA audits.

Sources: Security (last updated April 2026) · Trust Center
DescrybeHop 2 · case-law lookups, under your own Descrybe account

The specific request Claude sends — a citation, a quoted passage, a legal question or a jurisdiction — with your account's authorization. Descrybe says connecting it does not give it access to your conversation, documents or files. LVAI Pro sends Descrybe a whole document (for its citation-extraction tool) only if you say the document may be shared.

“Limited request and operational data.” Descrybe says its connector logs record the tool, status, timing and request identifiers, not the complete request text, and that its customer data is stored on DigitalOcean in the New York City region.

Descrybe produces its AI-generated summaries and research outputs with a third-party AI model provider named in its policy. It says that provider does not train on the data (Descrybe has opted out) and may keep abuse-monitoring logs for up to 30 days.

Descrybe does not use customer prompts, files or research history to train its own models. Data is encrypted in transit (HTTPS/TLS) and at rest (DigitalOcean-managed). SOC 2: not yet. Descrybe says it is preparing for an independent SOC 2 examination and does not currently claim a SOC 2 report or ISO 27001 certification.

Sources: Security and data handling (updated September 17, 2026) · Privacy Policy (updated September 16, 2026)
OnecleHop 2 · public statute pages on law.onecle.com — no account

A request for one public page — the statute section being linked or checked (for example law.onecle.com/georgia/title-9/9-3-24.html) — sent from the environment Claude works in, when Midpage is not connected (statute links) or when no connected service carries that state's code (/verify). Nothing from your documents is sent.

Onecle's privacy policy says it records server logs, “such as your Internet Protocol (IP) address, the time day you visited and your browser type,” and may use cookies, including Google's for advertising. It gives no retention period. The statute text /verify reads is kept only in the run's audit folder in your case folder and in the report.

Onecle is a free public website, not a research service: its copies of the codes are old (its pages were last updated between 2006 and 2021), which is why every statute /verify reads there is printed with the page's date and a reminder to confirm the current text.

Sources: Privacy Policy · Terms of Service
Legal VelocityHop 3 · our license and content server — Cloudflare Workers and a D1 database

Only the name of what the plugin asks for — a skill, a reference file, a script or a template — and license-status checks. Its tools have no field for document text; it sends back instructions, scripts and templates. It never receives your documents, your questions or your conversations, and it runs no AI model.

A usage record for each of those requests (and each template download): your license and seat, the tool, the name requested, the time, and whether it was served (with the reason, if it wasn't). A nightly job deletes these records after 90 days.

With your license record we keep when each seat last connected, and for each Claude sign-in the seat, the email address used, when it was made and last used, and the network address it came from. Sign-in codes and the tokens Claude holds are stored only as SHA-256 fingerprints (a legacy connector URL likewise). The server's own log messages (errors and job summaries) go to Cloudflare's Workers Logs, which Cloudflare keeps for at most 7 days; the request logs, which would contain tokens, are switched off. The database was created with Cloudflare's automatic location setting — no EU or FedRAMP jurisdiction.

Cloudflare's SOC 2 Type II report covers security, confidentiality and availability, with Workers and D1 in scope, and Cloudflare is certified to ISO 27001:2022, ISO 27018 and ISO 27701. D1 encrypts everything it stores at rest (AES-256) and in transit (TLS).

Sources: SOC 2 · ISO certifications · D1 data security · D1 data location · Workers Logs
StripeHop 4 · billing

Your name, email address, card and billing details — entered on Stripe's own checkout page, so the card number never reaches us — and your subscription, invoices and payments. For a free trial, the network address the trial was started from is attached to the checkout, for the one-trial check.

Stripe keeps payment records under its own privacy policy. From Stripe we keep the subscription status, invoices and payment events, and the card fingerprint used in the trial check, as our Privacy Policy describes — license and billing records while your account exists and for 7 years afterwards.

Stripe is certified as a PCI Service Provider Level 1 — “the most stringent level of certification available in the payments industry.” Its SOC 1 and SOC 2 Type II reports are produced annually, and card numbers are encrypted at rest with AES-256.

Sources: Security at Stripe · Stripe Privacy Policy
ResendHop 4 · email

Your name and email address, which of our three mailing lists you are on (customers, trial users or former customers), and the emails we send you — including the setup guide, which contains your connector URLs.

Resend says email and log data is kept for 30 days on its Free, Pro and Scale plans, and that stored data is held in the United States. Our own log of emails sent — address, subject and time, not the message — is kept for 90 days.

Resend says it is SOC 2 Type II compliant, encrypts data at rest (AES-256) and in transit (HTTPS/TLS), and that neither Resend nor its subprocessors use customer content to train or fine-tune models.

Source: Resend Security

Also on the list, never with your documents: Attio, our customer-records system (name, email address, firm, license, plan, seats, paid-through date and status); Replit, which hosts this website and counts visits to it; and Google — this site's fonts, and our own mailbox, which holds support email and a copy of each setup guide so that we can resend it if you lose yours. The Privacy Policy covers each of them.

Certifications, plainly

Legal Velocity AI does not currently hold a SOC 2 report. We would rather say so than let another company's badge stand in for ours.

What we can show you is how our server is built: it never receives your documents. Its tools accept only the name of a skill, reference file, script or template; it keeps a record of those names for 90 days; it stores your connector URL only as a fingerprint; and it runs no AI model. Your client documents are handled by Anthropic and — for case-law lookups — by Midpage or Descrybe, under your own accounts. Of the companies in the table above, Anthropic, Midpage, Cloudflare, Stripe and Resend each state that they hold a SOC 2 Type II report; Descrybe says its examination is in preparation.

What we recommend for client work

Only where the provider's own documentation supports it:

  1. On a Pro or Max plan, turn model improvement off before client work: Settings → Privacy → “Help improve our AI models” (Anthropic's instructions). And don't rate client conversations with the thumbs-up or thumbs-down buttons: Anthropic's Consumer Terms say feedback may be used for training even when you have opted out, and Anthropic keeps it for 5 years.
  2. For a firm, consider a Team or Enterprise plan. Their chats fall under Anthropic's Commercial Terms, which say Anthropic may not train models on customer content. An owner can switch off thumbs-up/down feedback for everyone (“Rate chats”, under Organization settings → Data and Privacy), and on Enterprise can set how long chats are kept — 30 days at the least (feedback, retention). Anthropic's deployment guide for legal teams adds that firms working with privileged content typically pair these controls with their own policies on which matters and document types can be processed.
  3. Give each matter its own folder, and connect only that folder. Anthropic's Cowork safety page suggests a dedicated working folder rather than broad access, and asks you to be cautious about granting access to sensitive information such as financial documents, credentials or personal records.

Your duties of confidentiality to your clients — including how you set up your Claude account — remain yours; see section 9 of our Terms.

Sources

Every provider page below was read on September 28, 2026.

Questions

Legal Velocity AI · admin@legalvelocity.ai