§Propound
Pricing Download for Mac
Terms EULA Privacy

Privacy Policy — Propound

Last updated: August 11, 2026 Version: 2026-08-11

This Privacy Policy explains how Data Lab Inc. ("we," "us," or "our") collects, uses, and shares information in connection with the Propound desktop application, the propoundlegal.com website, and related services (together, the "Service"). The website itself sets no cookies, runs no analytics, and serves all assets from our own domain; it collects no personal information unless you email us.

The Service is a professional tool used by legal practitioners to draft and manage discovery objections and responses, with optional AI assistance. We designed it to keep your matter content on your device by default. Please read this Policy carefully, particularly the section on AI Processing, which is the most important part for understanding what leaves your computer.


1. Summary (the short version)

  • Your documents and case data stay on your device by default. Cases, uploaded files, drafts, and chat history are stored in a local database on your computer — we do not upload or store them on our servers.
  • AI processing happens in the cloud. When you use an AI feature, a cloud AI model (Anthropic's Claude) processes the content of your request on Anthropic's servers, reached through our secure proxy. A pattern-based redaction feature (on by default) replaces direct identifiers with placeholders before your request is sent.
  • When you use an AI feature, the substance of your request is transmitted — including the text you are working on and relevant excerpts from your documents. Optional redaction (on by default) replaces direct identifiers with placeholders before sending, but it is pattern-based and the underlying legal and factual text is still sent.
  • We collect limited account and billing data (email, name, subscription status, and usage counts) to operate your account and enforce plan limits. Your AI requests pass through our proxy server in transit, but we do not store their content — the proxy records only token counts and timestamps.
  • We do not sell or share your personal information for cross-context behavioral advertising, and we do not use your matter content to advertise to you.

This summary is for convenience only; the full Policy below controls.


2. Who we are

The Service is provided by Data Lab Inc., located at 8000 Wheatland Ave., Unit H, Sun Valley, CA 91352. For privacy questions or to exercise your rights, contact us at privacy@propoundlegal.com.


3. Information we collect

3.1 Account and profile information

When you create an account or sign in, we collect your email address and, if you sign in with a third-party identity provider (e.g., Google or Apple), the name and basic profile information that provider shares. If you sign up with email, we also collect your law firm's name and, optionally, its business address, which we use to administer your account and communicate with you. We also process authentication tokens to keep you signed in. If you contact support, we receive your email address and the contents of your message.

3.2 Subscription and billing information

If you purchase a paid plan, our payment processor (Stripe) collects and processes your payment details. We do not receive or store full payment card numbers. We retain a Stripe customer identifier, your plan, subscription status, and billing period so we can provide the Service you paid for.

3.3 Usage data

To enforce plan limits and operate the Service, we record counts of AI generations per month and token totals associated with your account, along with timestamps. We do not store the content of your prompts or AI responses on our servers as part of this usage accounting.

3.4 Content you submit to AI features

When you use an AI feature, the app assembles a request that may include case metadata (such as case type and jurisdiction), the specific text you are drafting or responding to, excerpts from your case documents, and prior drafts. See Section 5 (AI Processing) for what happens to this content. We do not log the content of these requests on our servers.

3.5 Information stored only on your device

The following are stored locally on your computer and are not transmitted to us: your cases, uploaded or imported documents, generated drafts and objections, chat history, and redaction settings. Voice dictation audio is processed entirely on your device — temporary audio files are created for transcription, never transmitted, and not retained as part of your case data. All of this lives in application storage in your operating system user profile and remains under your control.

3.6 Diagnostic information (optional crash reporting)

Crash reporting is off by default. If you turn it on in Settings, the app sends crash reports — technical error details such as the error type, stack trace, app version, and operating-system version — to our error-monitoring provider (Sentry) so we can diagnose and fix problems. These reports are scrubbed before sending: they are designed to exclude your case data, documents, prompts, AI responses, account email, and other personal identifiers. You can turn crash reporting off again at any time. When it is off, no diagnostic data is transmitted; basic technical logs may still be written locally on your device for troubleshooting.

3.7 Automatically collected technical information

Like any online service, our infrastructure providers process basic technical information when the app communicates with our servers — such as your IP address, request timestamps, and app version — as a routine part of routing, securing, and operating the Service (including our authentication and proxy infrastructure and the update server). We do not use this information to build profiles or for advertising.


4. How we use information

We use the information described above to:

  • provide, maintain, and secure the Service and your account;
  • authenticate you and keep you signed in;
  • process payments and manage your subscription;
  • enforce plan limits and prevent abuse;
  • respond to your support requests; and
  • comply with legal obligations and enforce our agreements.

We rely on the following legal bases where applicable: performance of our contract with you (providing the Service), our legitimate interests (securing and improving the Service, preventing abuse), your consent (where requested), and compliance with legal obligations.


5. AI Processing — what leaves your device

This section is the most important for understanding the Service's privacy characteristics.

5.1 AI processing (Anthropic Claude via our proxy)

When you use an AI feature, the app sends your request to Anthropic, PBC to generate a response. The request travels over an encrypted connection to our proxy server (hosted on Supabase), which authenticates your account, enforces your plan limits, attaches our API credentials, and forwards the request to Anthropic's API. Our proxy does not store the content of your prompts or Anthropic's responses — it records only token counts and timestamps for usage accounting.

What is sent to Anthropic: the substance of your request, which may include case type and jurisdiction, party and entity names (unless redacted), identifiers such as vehicle/VIN, addresses, case numbers, phone numbers, and emails (unless redacted), the specific interrogatory, request, or text you are working on, relevant excerpts from your case documents, and prior drafts.

Anthropic's handling of this data: Anthropic processes the request to generate a response. Under Anthropic's commercial API terms as of this Policy's date, Anthropic does not use data submitted through its commercial API to train its models. Anthropic's handling of API data is governed by its own terms and privacy commitments, which may change; we encourage you to review them.

5.2 Redaction

The app includes a redaction feature that is enabled by default. When enabled, it attempts to replace direct identifiers — such as names, VINs, addresses, case numbers, phone numbers, email addresses, and (when they match recognizable formats) Social Security numbers, dates of birth, and driver's-license and account numbers — with placeholders before your request is sent. Most masked values are restored in the response shown to you; certain high-sensitivity identifiers (such as Social Security numbers, dates of birth, and license and account numbers) are deliberately not restored automatically, so a surviving placeholder prompts your review. Redaction is pattern- and value-based and not guaranteed to catch every identifier, and even when redaction is enabled, the underlying legal and factual text of your request is still transmitted. You can disable redaction in settings.

5.3 Your responsibility for confidential and privileged material

You are responsible for ensuring that your use of the AI features is consistent with your confidentiality, privilege, and professional-responsibility obligations to your clients and under applicable rules. For highly sensitive matters, keep redaction enabled and consider carefully what you submit. With respect to personal information about other people contained in your matter content (such as clients, parties, and witnesses), you determine what is submitted and why; we and our service providers process that content only to provide the AI feature at your direction, and we do not use it for any other purpose. The Service is not offered for use as a HIPAA business associate, and we do not offer a Business Associate Agreement; the Terms of Service contain the related use restriction. See also the Terms of Service.


6. How we share information

We do not sell your personal information. We share information only as described here:

Recipient Purpose What is shared
Anthropic, PBC Generating AI responses The content of your AI request (see Section 5.1)
Supabase Backend hosting, authentication, database, and the AI proxy Account identifiers, authentication data, subscription and usage records
Stripe Payment processing and subscription billing Email, payment method, and plan information
Google / Apple (if you use them to sign in) Authentication Sign-in request and the profile data you authorize
Sentry (only if you enable crash reporting) Diagnosing crashes Scrubbed technical error details; no case data or identifiers
GitHub (software distribution and updates) Delivering the app and updates A download or version-check request (which, like any web request, includes your IP address); no personal account data

We may also disclose information if required by law, to enforce our agreements, to protect the rights, safety, and security of users or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will provide notice as required).

Except for Google and Apple — which act as independent identity providers under their own privacy policies when you choose to sign in with them — these recipients act as our service providers / processors and are limited in how they may use the information.


7. Data retention

  • Local data (cases, documents, drafts, chat history) remains on your device until you delete it or uninstall the app. Uninstalling may not remove all local data; you can delete the application data folder to remove it.
  • Account and subscription data is retained while your account is active and for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion as described below.
  • Usage records (counts and token totals) are retained for billing, abuse-prevention, and accounting purposes.
  • AI request content sent when you use AI features is retained by Anthropic according to Anthropic's terms; we do not retain it on our proxy.

8. Data security

We use reasonable technical and organizational measures to protect information, including encryption in transit (TLS), encryption of stored authentication tokens on your device using your operating system's secure storage where available, and row-level access controls on our backend that restrict each account to its own records. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.


9. Your privacy rights

9.1 All users

You may access or update your account information, or request that we delete your account and associated server-side data, by contacting privacy@propoundlegal.com. We will respond to verified deletion requests within 45 days (and will notify you if we need a permitted extension). We may retain records we are required or permitted to keep for legal, billing, security, or dispute-resolution purposes. Because your matter content is stored locally, you control it directly on your device.

9.2 California residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to request deletion or correction of your personal information; and to be free from discrimination for exercising your rights.

Categories of personal information we have collected in the last 12 months (as defined under the CCPA/CPRA):

Category Collected Source Purpose Disclosed to
Identifiers (email, name, account ID) Yes You / your sign-in provider Account, authentication, support Supabase, Stripe, sign-in provider
Commercial information (subscription, plan) Yes You / Stripe Billing, plan enforcement Stripe, Supabase
Internet/usage activity (generation counts, token totals, timestamps) Yes Your use of the Service Plan limits, security Supabase
Content you submit to AI features Processed, not stored by us You Generating AI responses Anthropic
Payment information Processed by Stripe; not stored by us You Payment processing Stripe

We do not "sell" personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We do not knowingly process the sensitive personal information of California residents for purposes that would trigger a right to limit its use beyond what is described here.

To exercise these rights, contact privacy@propoundlegal.com. We will verify your request by confirming control of your account email. You may use an authorized agent where permitted by law.

9.3 Other U.S. state privacy laws

Residents of other U.S. states with comprehensive privacy laws may have similar rights to access, correct, delete, and obtain a portable copy of their personal information, and to appeal a denied request. Contact us at privacy@propoundlegal.com to exercise these rights.

9.4 Users outside the United States (GDPR/UK GDPR-aware)

The Service is offered from the United States and is directed to U.S. legal professionals; we do not currently market it in the European Economic Area or the United Kingdom. If you nonetheless use the Service from a region with data-protection laws, be aware that your data is processed in the United States by us and the processors identified in this Policy (including Anthropic, Supabase, and Stripe), and that using AI features involves an international transfer of the data described in Section 5. You may have rights under your local law to access, rectify, erase, restrict, or object to processing of your personal data, and to lodge a complaint with your local supervisory authority; to exercise them, contact privacy@propoundlegal.com.

9.5 Do Not Track

Neither the app nor the propoundlegal.com website tracks you over time or across third-party websites, and we do not respond to browser "Do Not Track" signals — there is no tracking to disable.


10. Children's privacy

The Service is a professional tool intended for use by adults and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact privacy@propoundlegal.com and we will take appropriate steps to delete it.


11. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and the version, post the revised Policy at https://propoundlegal.com, and, where appropriate, present an updated notice within the app. Your continued use of the Service after the effective date constitutes acceptance of the revised Policy.


12. Contact us

Data Lab Inc. 8000 Wheatland Ave., Unit H, Sun Valley, CA 91352 Privacy: privacy@propoundlegal.com Support: support@propoundlegal.com

§Propound
Terms EULA Privacy support@propoundlegal.com

Propound is a drafting tool for licensed attorneys and their staff. It does not provide legal advice, and its output requires attorney review before use.

© 2026 Data Lab Inc. Propound is a product of Data Lab Inc., a California corporation.