← Back to chat Mudbug Legal Assistant · Privacy Policy — Mudbug Legal Assistant

Privacy Policy — Mudbug Legal Assistant

> DRAFT FOR ATTORNEY REVIEW — generated with Mudbug's Privacy Policy / Terms skill from docs/PRIVACY_POSTURE.md. Bracketed [●] items must be completed and every statement confirmed by the operator's counsel before publication.

Parties: [● LEGAL NAME], a Louisiana sole proprietorship doing business as Mudbug Legal Assistant ("Mudbug," "we," "us," or "our"); Subscribing law firms, legal organizations, licensed attorneys, paralegals, law-firm staff, and other authorized users of the Services

1. Introduction and Scope

1.1 Who operates Mudbug. Mudbug Legal Assistant is operated by [● LEGAL NAME], a Louisiana-licensed attorney acting as a sole proprietor. The Services are available through [● SERVICE URL].

1.2 What this Policy covers. This Policy applies to personal information processed through Mudbug's hosted legal-drafting, document-generation, and legal-research services, related account and billing functions, and communications concerning those services (collectively, the "Services"). It does not govern the independent privacy practices of a customer's law firm or other organization.

1.3 Professional users only. The Services are intended for people who are at least 18 years old and who are licensed attorneys or act under the supervision of a licensed attorney. The Services are not intended for consumers seeking legal representation or legal advice.

1.4 No attorney-client relationship. Mudbug provides software, not legal representation. Using the Services, contacting Mudbug about privacy, or receiving a generated output does not create an attorney-client relationship with Mudbug's operator. Every output is a draft that must be reviewed by an attorney. Citation checks and links to public sources are safeguards, not substitutes for professional judgment.

1.5 Customer responsibility for client information. Customers must not upload or otherwise provide personal information, confidential information, or client material unless they have authority to process that information through the Services and through the service providers described in this Policy. Each customer is responsible for assessing its professional duties of competence, confidentiality, communication, and supervision.

1.6 Defined terms. For this Policy, "Personal Information" means information that identifies, relates to, or can reasonably be associated with a person. "Workspace Data" means chats, uploaded documents, extracted text, generated artifacts, and research records within a Mudbug workspace. These plain-language definitions do not replace definitions imposed by applicable law.

2. Information We Collect

2.1 Account Data. We collect a user's name, work email address, password hash, organization, role, and sign-in times. We store a password hash rather than the user's readable password.

2.2 Workspace Data. We collect and store chat messages; uploaded documents and extracted text; generated DOCX, PDF, XLSX, and CSV artifacts; and research records such as citations, URLs, and excerpts from public sources. Workspace Data may contain client confidential information and any other information a customer chooses to include.

2.3 Usage Data. For each service call, we record token counts, the selected skill and model, timestamps, and organization and user identifiers. We use these records for metering, billing, quotas, and abuse prevention. Usage records do not contain prompts or document contents.

2.4 Audit Data. We record audit events such as event type, actor, organization, chat identifier, filenames, and artifact kinds.

2.5 Billing Data. We collect plan, seat, and subscription-status information; Stripe customer and subscription identifiers; and Stripe webhook event payloads. Stripe processes payment-card information. Mudbug does not see or store payment-card numbers.

2.6 Potentially sensitive information. Account authentication information and Workspace Data may include information treated as sensitive under applicable law. Because customers control Workspace Data, Mudbug cannot identify every type of sensitive information that may be uploaded. Customers should provide sensitive information only when they have authority to do so and only when it is reasonably necessary for the requested work.

2.7 Sources of information. We receive information directly from users and organization owners; automatically from sign-ins and use of the Services; from Stripe in connection with subscriptions and payment events; and from public legal sources when the Services conduct research. Generated artifacts and research records are also produced through the user's interaction with the Services.

3. How We Use Information

3.1 Provide requested services. We use Account Data and Workspace Data to authenticate users, maintain workspaces, process prompts and documents, conduct requested research, and generate drafts and other artifacts.

3.2 Operate subscriptions. We use Account, Usage, and Billing Data to administer plans and seats, measure token use, enforce monthly allowances and quotas, support checkout and billing, and manage subscription status.

3.3 Secure and maintain the Services. We use Account, Usage, and Audit Data to maintain tenant isolation, investigate errors or suspected misuse, apply rate limits, verify billing events, maintain backups, and protect users and the Services.

3.4 Communicate with users. We use work email addresses to send sign-in links, invitations, and service-related communications.

3.5 No model training. Under the OpenAI API terms and configuration used for the Services, the inputs Mudbug sends to OpenAI are not used to train OpenAI models.

3.6 No unrelated advertising use. We do not use Personal Information or Workspace Data for targeted advertising, and no analytics software development kits run in the product.

4. How We Disclose Information

4.1 Limited service-provider disclosures. We disclose information only as needed to operate the Services through the providers described below. We do not allow those disclosures for third-party targeted advertising.

4.2 OpenAI. OpenAI is Mudbug's only artificial-intelligence model provider. OpenAI receives the text needed to perform requested work, including user messages, extracted document text, and research results. Under the API terms and configuration used for Mudbug, those inputs are not used to train OpenAI models.

4.3 Public legal and research sources. CourtListener, GovInfo, eCFR, the Federal Register, Justia, the Legal Information Institute, court websites, SEC EDGAR, the United States Patent and Trademark Office, and native web-search services may receive legal questions, citation searches, and similar research queries. Mudbug does not send uploaded documents to those sources. The Services are instructed not to include client names or private facts in search terms.

4.4 Stripe. Stripe receives the subscribing owner's email address, organization identifier, selected plan, and seat count to provide checkout and subscription services. Stripe, rather than Mudbug, receives and processes payment-card information.

4.5 Email transport. Mudbug's configured SMTP provider receives the information needed to deliver sign-in links and invitations. The provider's identity is [● SMTP PROVIDER IDENTITY].

4.6 Hosting, storage, and database providers. Working files are stored on the service volume and mirrored to a configured object-storage bucket for durability and backup. Metadata is stored in Postgres. The applicable infrastructure providers are [● INFRASTRUCTURE PROVIDER IDENTITIES].

4.7 Legally required disclosures and organizational changes. [● REQUIRED DISCLOSURE SCENARIOS — VERIFY: state whether and how Mudbug may disclose information in response to legal process, to protect the Services, or in connection with a sale, reorganization, or transfer of the business.]

4.8 No sale or advertising sharing. Mudbug does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising. Mudbug does not run advertising or analytics SDKs in the product.

5. Cookies and Tracking Technologies

5.1 Service technologies. [● COOKIE DETAILS — VERIFY: identify authentication cookies, session cookies, local storage, security technologies, their duration, and available controls.] Mudbug does not use advertising cookies or third-party analytics SDKs.

6. Your Choices and Privacy Requests

6.1 Workspace controls. Organization owners can delete an individual chat, all chats associated with a user, or the organization's entire workspace from the Account page. Owners can also configure an organization retention window.

6.2 Submitting a request. To ask about, access, correct, obtain a copy of, or request deletion of Personal Information, contact us at [● PRIVACY EMAIL] or use [● REQUEST WEBFORM OR ADDITIONAL METHOD]. Describe the account and information involved and the action requested. Any right is subject to applicable law and relevant exceptions.

6.3 Verification. We may need to authenticate the account or request information reasonably necessary to verify the requester and protect client confidential information. We will use verification information only to process and document the request.

6.4 Organization-managed accounts. If an organization provides or manages an account, Mudbug may need to coordinate a request with the organization owner. Organization owners control workspace membership, retention settings, and workspace deletion.

6.5 Authorized agents. [● AUTHORIZED AGENT PROCESS — VERIFY: add the procedure for requests submitted by an authorized agent, including any required proof of authority or direct confirmation.]

6.6 Appeals. [● APPEAL PROCESS — VERIFY: add any required privacy-request appeal process, submission method, and response procedure.]

6.7 Opt-out signals. Because Mudbug does not sell Personal Information or use it for targeted advertising, there is no sale or targeted-advertising activity to opt out of. [● GPC CONFIRMATION — VERIFY: confirm how the Services detect and honor browser-based opt-out preference signals and whether a policy statement or link is required.]

7. Data Retention and Deletion

7.1 Workspace Data. Chats and related Workspace Data remain until an organization owner deletes them or an organization retention window removes them. By default, there is no automatic retention deadline unless an organization configures one.

7.2 Deletion from active storage. When an organization owner deletes a chat, a user's chats, or an organization workspace, Mudbug immediately removes the associated local files and mirrored object-storage files and records the deletion event.

7.3 Backups. Backups are snapshots of the service volume and age out under a 35-day backup schedule. Information deleted from active file storage may therefore remain in backup snapshots until the applicable snapshot ages out, no later than 35 days after deletion.

7.4 Account deletion. Deleting an account disables the user and removes the user's workspace memberships. The retention or deletion period for remaining Account Data is [● ACCOUNT RETENTION].

7.5 Usage and Audit Data. After account deletion, Mudbug retains Usage and Audit Data under pseudonymous identifiers for billing and security records. The retention period is [● USAGE/AUDIT RETENTION].

7.6 Billing Data. Mudbug's retention period for subscription records, Stripe identifiers, and webhook payloads is [● BILLING RETENTION]. Stripe applies its own retention practices to information it processes.

8. Security and Confidentiality

8.1 Security measures. Mudbug uses first-party accounts, hardened sessions, cross-site request-forgery origin checks, security headers, per-tenant isolation, rate limits, Stripe signature verification, audit logging, and backups.

8.2 Encryption. Infrastructure providers encrypt stored data at rest. Data is transmitted using HTTPS or TLS.

8.3 Tenant and user separation. Each organization's files are stored under an organization-specific prefix, and each request is bound to one organization. Users can access their own chats; organization-wide matter access is not currently available.

8.4 No absolute security guarantee. No storage or transmission system can be guaranteed to be completely secure. Customers should apply their own access controls, supervision, and professional judgment when deciding what to upload.

8.5 Security reports. Report a suspected security issue to [● SECURITY CONTACT].

9. Children's Privacy

9.1 Users must be adults. Mudbug does not permit people under 18 to create or use an account. The Services are designed for attorneys and people acting under an attorney's supervision.

9.2 Information concerning minors in legal matters. Workspace Data may include information about a minor if an authorized legal professional includes that information in a document, chat, or research request. Customers must have authority to process that information and must use appropriate safeguards.

9.3 Children's privacy compliance. [● CHILDREN/COPPA ANALYSIS — VERIFY: confirm whether any children's-privacy notice, parental-consent procedure, or deletion process is required despite the adult professional-user restriction.]

10. International Processing

10.1 United States audience. The Services are offered to licensed attorneys and law-firm personnel in the United States.

10.2 Processing locations and foreign law. [● INTERNATIONAL PROCESSING LOCATIONS — VERIFY: identify the countries in which Mudbug and each provider store or process information.] [● FOREIGN-LAW PLACEHOLDER — VERIFY: if users, clients, or data subjects are located outside the United States, add any required international-transfer terms and foreign-law disclosures, including any applicable European or United Kingdom requirements.]

11. State-Specific Disclosures

11.1 General application. The disclosures in this Article apply only when the relevant state law applies to Mudbug's processing and the requester qualifies for protection under that law. Mudbug does not use this Policy to state or imply that a particular statutory coverage threshold has been met.

11.2 California collection disclosures. For California notice purposes, Mudbug collects the categories described below. [● CALIFORNIA 12-MONTH CONFIRMATION — VERIFY: confirm whether these disclosures accurately describe all collection and disclosure practices during the required reporting period.]

• Account and identifier information: name, work email, password hash, organization, role, and sign-in times. Sources are users, organization owners, and service interactions. Uses include authentication, account administration, communications, security, and subscription management. Recipient categories may include email, infrastructure, and payment providers as applicable. Retention is described in Article 7 and remains subject to [● ACCOUNT RETENTION].

• Workspace and professional-content information: chats, uploaded files, extracted text, generated artifacts, citations, URLs, and public-source excerpts. Sources are users, uploaded materials, generated results, and public research sources. Uses include performing requested drafting and research, storing work product, security, and backup. Recipient categories include OpenAI and infrastructure providers. Public-law services receive only search queries, not uploaded documents. Retention follows Clauses 7.1 through 7.3.

• Usage and activity information: token counts, skill, model, timestamps, organization and user identifiers, sign-in times, and audit events. Sources are interactions with the Services. Uses include metering, billing, quotas, abuse prevention, security, and audit logging. Recipient categories include infrastructure providers. Retention is subject to [● USAGE/AUDIT RETENTION].

• Commercial and billing information: plan, seat count, subscription status, Stripe identifiers, and webhook payloads. Sources are subscribing organizations, Stripe, and service transactions. Uses include checkout, billing, subscription administration, and fraud or webhook verification. Recipient categories include Stripe and infrastructure providers. Retention is subject to [● BILLING RETENTION].

• Potentially sensitive information: account authentication data and any sensitive material a customer includes in Workspace Data. Sources, uses, recipients, and retention follow the corresponding category above. [● SENSITIVE-INFORMATION PRACTICE CONFIRMATION — VERIFY: confirm whether any processing constitutes a use requiring a California limitation mechanism or additional disclosure.]

11.3 California privacy requests. California residents may exercise any rights available under applicable California law by using the methods in Clause 6.2. [● CALIFORNIA RIGHTS TEXT — VERIFY: insert the current, complete descriptions of covered rights, exceptions, verification rules, authorized-agent rules, response timing, and any non-discrimination requirement after confirming the operative law.]

11.4 California sale, sharing, and sensitive-information choices. Mudbug does not sell Personal Information or share it for cross-context behavioral advertising. Mudbug therefore does not currently provide a "Do Not Sell or Share" link. Workspace Data is used to provide the requested Services and related security, billing, storage, and backup functions. Any required sensitive-information limitation or opt-out mechanism remains subject to [● SENSITIVE-INFORMATION PRACTICE CONFIRMATION] and [● GPC CONFIRMATION].

11.5 Texas rights. If applicable Texas law covers Mudbug's processing and the requester qualifies as a consumer, the consumer may submit an authenticated request to: confirm whether Mudbug processes the consumer's Personal Information and obtain access; correct inaccuracies; delete Personal Information provided by or obtained about the consumer; obtain qualifying Personal Information in a portable and readily usable digital format; and opt out of targeted advertising, sale of Personal Information, or profiling that produces legal or similarly significant effects. A parent or guardian may exercise these rights for a known child. Mudbug does not sell Personal Information, use it for targeted advertising, or use it for profiling that produces legal or similarly significant effects.

11.6 Texas requests and appeals. Submit a Texas request using Clause 6.2. The appeal process is [● APPEAL PROCESS]. [● TEXAS PROCEDURE CONFIRMATION — VERIFY: confirm applicable authentication, response, appeal, agent, and timing requirements.]

11.7 Louisiana. [● LOUISIANA 2027 UPDATE — VERIFY BEFORE JANUARY 1, 2027: determine whether the Louisiana Data Privacy Act applies to Mudbug and add its required notice disclosures, consumer rights, request methods, appeal procedures, opt-out mechanisms, and processor or controller disclosures. Final codification and citation form also require confirmation.]

11.8 New York. [● NEW YORK REQUIREMENTS — VERIFY: identify and implement any New York privacy, data-security, breach-notice, or sector-specific disclosure requirements applicable to Mudbug's actual operations. No verified New York privacy-policy authority was supplied for this draft.]

12. Changes to This Policy

12.1 Policy updates. We may update this Policy to reflect changes to the Services, providers, or legal requirements. We will post the updated Policy at [● POLICY URL] and revise the last-updated date. Material-change notice will be provided through [● POLICY CHANGE NOTICE METHOD].

12.2 Review cycle. Mudbug will review the California portions of this Policy at least annually while those requirements apply.

13. Contact Us

13.1 Privacy requests and questions. Email: [● PRIVACY EMAIL]

Mail: [● MAILING ADDRESS]

Online request method: [● REQUEST WEBFORM OR ADDITIONAL METHOD]

13.2 Security reports. Security reports may be sent to [● SECURITY CONTACT]. Please do not include unnecessary confidential information in an initial report.

14. Effective Date

14.1 Dates. Effective date: [● EFFECTIVE DATE]

Last updated: [● LAST UPDATED DATE]

Open items (complete before publication)

Drafting notes


Mudbug Legal Assistant is software for use by licensed attorneys and their staff. Every output is a draft for attorney review, not legal advice, and does not create an attorney-client relationship with the operator of this service. Citations are verified against public sources where possible; anything not verified is flagged and must be checked before use.

Terms of Service · Privacy Policy · Status