Privacy Policy — Mudbug Legal Assistant
> DRAFT FOR ATTORNEY REVIEW — generated with Mudbug's Privacy Policy / Terms skill from docs/PRIVACY_POSTURE.md. Bracketed [●] items must be completed and every statement confirmed by the operator's counsel before publication.
Parties: [● LEGAL NAME], a Louisiana sole proprietorship doing business as Mudbug Legal Assistant ("Mudbug," "we," "us," or "our"); Subscribing law firms, legal organizations, licensed attorneys, paralegals, law-firm staff, and other authorized users of the Services
1. Introduction and Scope
1.1 Who operates Mudbug. Mudbug Legal Assistant is operated by [● LEGAL NAME], a Louisiana-licensed attorney acting as a sole proprietor. The Services are available through [● SERVICE URL].
1.2 What this Policy covers. This Policy applies to personal information processed through Mudbug's hosted legal-drafting, document-generation, and legal-research services, related account and billing functions, and communications concerning those services (collectively, the "Services"). It does not govern the independent privacy practices of a customer's law firm or other organization.
1.3 Professional users only. The Services are intended for people who are at least 18 years old and who are licensed attorneys or act under the supervision of a licensed attorney. The Services are not intended for consumers seeking legal representation or legal advice.
1.4 No attorney-client relationship. Mudbug provides software, not legal representation. Using the Services, contacting Mudbug about privacy, or receiving a generated output does not create an attorney-client relationship with Mudbug's operator. Every output is a draft that must be reviewed by an attorney. Citation checks and links to public sources are safeguards, not substitutes for professional judgment.
1.5 Customer responsibility for client information. Customers must not upload or otherwise provide personal information, confidential information, or client material unless they have authority to process that information through the Services and through the service providers described in this Policy. Each customer is responsible for assessing its professional duties of competence, confidentiality, communication, and supervision.
1.6 Defined terms. For this Policy, "Personal Information" means information that identifies, relates to, or can reasonably be associated with a person. "Workspace Data" means chats, uploaded documents, extracted text, generated artifacts, and research records within a Mudbug workspace. These plain-language definitions do not replace definitions imposed by applicable law.
2. Information We Collect
2.1 Account Data. We collect a user's name, work email address, password hash, organization, role, and sign-in times. We store a password hash rather than the user's readable password.
2.2 Workspace Data. We collect and store chat messages; uploaded documents and extracted text; generated DOCX, PDF, XLSX, and CSV artifacts; and research records such as citations, URLs, and excerpts from public sources. Workspace Data may contain client confidential information and any other information a customer chooses to include.
2.3 Usage Data. For each service call, we record token counts, the selected skill and model, timestamps, and organization and user identifiers. We use these records for metering, billing, quotas, and abuse prevention. Usage records do not contain prompts or document contents.
2.4 Audit Data. We record audit events such as event type, actor, organization, chat identifier, filenames, and artifact kinds.
2.5 Billing Data. We collect plan, seat, and subscription-status information; Stripe customer and subscription identifiers; and Stripe webhook event payloads. Stripe processes payment-card information. Mudbug does not see or store payment-card numbers.
2.6 Potentially sensitive information. Account authentication information and Workspace Data may include information treated as sensitive under applicable law. Because customers control Workspace Data, Mudbug cannot identify every type of sensitive information that may be uploaded. Customers should provide sensitive information only when they have authority to do so and only when it is reasonably necessary for the requested work.
2.7 Sources of information. We receive information directly from users and organization owners; automatically from sign-ins and use of the Services; from Stripe in connection with subscriptions and payment events; and from public legal sources when the Services conduct research. Generated artifacts and research records are also produced through the user's interaction with the Services.
3. How We Use Information
3.1 Provide requested services. We use Account Data and Workspace Data to authenticate users, maintain workspaces, process prompts and documents, conduct requested research, and generate drafts and other artifacts.
3.2 Operate subscriptions. We use Account, Usage, and Billing Data to administer plans and seats, measure token use, enforce monthly allowances and quotas, support checkout and billing, and manage subscription status.
3.3 Secure and maintain the Services. We use Account, Usage, and Audit Data to maintain tenant isolation, investigate errors or suspected misuse, apply rate limits, verify billing events, maintain backups, and protect users and the Services.
3.4 Communicate with users. We use work email addresses to send sign-in links, invitations, and service-related communications.
3.5 No model training. Under the OpenAI API terms and configuration used for the Services, the inputs Mudbug sends to OpenAI are not used to train OpenAI models.
3.6 No unrelated advertising use. We do not use Personal Information or Workspace Data for targeted advertising, and no analytics software development kits run in the product.
4. How We Disclose Information
4.1 Limited service-provider disclosures. We disclose information only as needed to operate the Services through the providers described below. We do not allow those disclosures for third-party targeted advertising.
4.2 OpenAI. OpenAI is Mudbug's only artificial-intelligence model provider. OpenAI receives the text needed to perform requested work, including user messages, extracted document text, and research results. Under the API terms and configuration used for Mudbug, those inputs are not used to train OpenAI models.
4.3 Public legal and research sources. CourtListener, GovInfo, eCFR, the Federal Register, Justia, the Legal Information Institute, court websites, SEC EDGAR, the United States Patent and Trademark Office, and native web-search services may receive legal questions, citation searches, and similar research queries. Mudbug does not send uploaded documents to those sources. The Services are instructed not to include client names or private facts in search terms.
4.4 Stripe. Stripe receives the subscribing owner's email address, organization identifier, selected plan, and seat count to provide checkout and subscription services. Stripe, rather than Mudbug, receives and processes payment-card information.
4.5 Email transport. Mudbug's configured SMTP provider receives the information needed to deliver sign-in links and invitations. The provider's identity is [● SMTP PROVIDER IDENTITY].
4.6 Hosting, storage, and database providers. Working files are stored on the service volume and mirrored to a configured object-storage bucket for durability and backup. Metadata is stored in Postgres. The applicable infrastructure providers are [● INFRASTRUCTURE PROVIDER IDENTITIES].
4.7 Legally required disclosures and organizational changes. [● REQUIRED DISCLOSURE SCENARIOS — VERIFY: state whether and how Mudbug may disclose information in response to legal process, to protect the Services, or in connection with a sale, reorganization, or transfer of the business.]
4.8 No sale or advertising sharing. Mudbug does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising. Mudbug does not run advertising or analytics SDKs in the product.
5. Cookies and Tracking Technologies
5.1 Service technologies. [● COOKIE DETAILS — VERIFY: identify authentication cookies, session cookies, local storage, security technologies, their duration, and available controls.] Mudbug does not use advertising cookies or third-party analytics SDKs.
6. Your Choices and Privacy Requests
6.1 Workspace controls. Organization owners can delete an individual chat, all chats associated with a user, or the organization's entire workspace from the Account page. Owners can also configure an organization retention window.
6.2 Submitting a request. To ask about, access, correct, obtain a copy of, or request deletion of Personal Information, contact us at [● PRIVACY EMAIL] or use [● REQUEST WEBFORM OR ADDITIONAL METHOD]. Describe the account and information involved and the action requested. Any right is subject to applicable law and relevant exceptions.
6.3 Verification. We may need to authenticate the account or request information reasonably necessary to verify the requester and protect client confidential information. We will use verification information only to process and document the request.
6.4 Organization-managed accounts. If an organization provides or manages an account, Mudbug may need to coordinate a request with the organization owner. Organization owners control workspace membership, retention settings, and workspace deletion.
6.5 Authorized agents. [● AUTHORIZED AGENT PROCESS — VERIFY: add the procedure for requests submitted by an authorized agent, including any required proof of authority or direct confirmation.]
6.6 Appeals. [● APPEAL PROCESS — VERIFY: add any required privacy-request appeal process, submission method, and response procedure.]
6.7 Opt-out signals. Because Mudbug does not sell Personal Information or use it for targeted advertising, there is no sale or targeted-advertising activity to opt out of. [● GPC CONFIRMATION — VERIFY: confirm how the Services detect and honor browser-based opt-out preference signals and whether a policy statement or link is required.]
7. Data Retention and Deletion
7.1 Workspace Data. Chats and related Workspace Data remain until an organization owner deletes them or an organization retention window removes them. By default, there is no automatic retention deadline unless an organization configures one.
7.2 Deletion from active storage. When an organization owner deletes a chat, a user's chats, or an organization workspace, Mudbug immediately removes the associated local files and mirrored object-storage files and records the deletion event.
7.3 Backups. Backups are snapshots of the service volume and age out under a 35-day backup schedule. Information deleted from active file storage may therefore remain in backup snapshots until the applicable snapshot ages out, no later than 35 days after deletion.
7.4 Account deletion. Deleting an account disables the user and removes the user's workspace memberships. The retention or deletion period for remaining Account Data is [● ACCOUNT RETENTION].
7.5 Usage and Audit Data. After account deletion, Mudbug retains Usage and Audit Data under pseudonymous identifiers for billing and security records. The retention period is [● USAGE/AUDIT RETENTION].
7.6 Billing Data. Mudbug's retention period for subscription records, Stripe identifiers, and webhook payloads is [● BILLING RETENTION]. Stripe applies its own retention practices to information it processes.
8. Security and Confidentiality
8.1 Security measures. Mudbug uses first-party accounts, hardened sessions, cross-site request-forgery origin checks, security headers, per-tenant isolation, rate limits, Stripe signature verification, audit logging, and backups.
8.2 Encryption. Infrastructure providers encrypt stored data at rest. Data is transmitted using HTTPS or TLS.
8.3 Tenant and user separation. Each organization's files are stored under an organization-specific prefix, and each request is bound to one organization. Users can access their own chats; organization-wide matter access is not currently available.
8.4 No absolute security guarantee. No storage or transmission system can be guaranteed to be completely secure. Customers should apply their own access controls, supervision, and professional judgment when deciding what to upload.
8.5 Security reports. Report a suspected security issue to [● SECURITY CONTACT].
9. Children's Privacy
9.1 Users must be adults. Mudbug does not permit people under 18 to create or use an account. The Services are designed for attorneys and people acting under an attorney's supervision.
9.2 Information concerning minors in legal matters. Workspace Data may include information about a minor if an authorized legal professional includes that information in a document, chat, or research request. Customers must have authority to process that information and must use appropriate safeguards.
9.3 Children's privacy compliance. [● CHILDREN/COPPA ANALYSIS — VERIFY: confirm whether any children's-privacy notice, parental-consent procedure, or deletion process is required despite the adult professional-user restriction.]
10. International Processing
10.1 United States audience. The Services are offered to licensed attorneys and law-firm personnel in the United States.
10.2 Processing locations and foreign law. [● INTERNATIONAL PROCESSING LOCATIONS — VERIFY: identify the countries in which Mudbug and each provider store or process information.] [● FOREIGN-LAW PLACEHOLDER — VERIFY: if users, clients, or data subjects are located outside the United States, add any required international-transfer terms and foreign-law disclosures, including any applicable European or United Kingdom requirements.]
11. State-Specific Disclosures
11.1 General application. The disclosures in this Article apply only when the relevant state law applies to Mudbug's processing and the requester qualifies for protection under that law. Mudbug does not use this Policy to state or imply that a particular statutory coverage threshold has been met.
11.2 California collection disclosures. For California notice purposes, Mudbug collects the categories described below. [● CALIFORNIA 12-MONTH CONFIRMATION — VERIFY: confirm whether these disclosures accurately describe all collection and disclosure practices during the required reporting period.]
• Account and identifier information: name, work email, password hash, organization, role, and sign-in times. Sources are users, organization owners, and service interactions. Uses include authentication, account administration, communications, security, and subscription management. Recipient categories may include email, infrastructure, and payment providers as applicable. Retention is described in Article 7 and remains subject to [● ACCOUNT RETENTION].
• Workspace and professional-content information: chats, uploaded files, extracted text, generated artifacts, citations, URLs, and public-source excerpts. Sources are users, uploaded materials, generated results, and public research sources. Uses include performing requested drafting and research, storing work product, security, and backup. Recipient categories include OpenAI and infrastructure providers. Public-law services receive only search queries, not uploaded documents. Retention follows Clauses 7.1 through 7.3.
• Usage and activity information: token counts, skill, model, timestamps, organization and user identifiers, sign-in times, and audit events. Sources are interactions with the Services. Uses include metering, billing, quotas, abuse prevention, security, and audit logging. Recipient categories include infrastructure providers. Retention is subject to [● USAGE/AUDIT RETENTION].
• Commercial and billing information: plan, seat count, subscription status, Stripe identifiers, and webhook payloads. Sources are subscribing organizations, Stripe, and service transactions. Uses include checkout, billing, subscription administration, and fraud or webhook verification. Recipient categories include Stripe and infrastructure providers. Retention is subject to [● BILLING RETENTION].
• Potentially sensitive information: account authentication data and any sensitive material a customer includes in Workspace Data. Sources, uses, recipients, and retention follow the corresponding category above. [● SENSITIVE-INFORMATION PRACTICE CONFIRMATION — VERIFY: confirm whether any processing constitutes a use requiring a California limitation mechanism or additional disclosure.]
11.3 California privacy requests. California residents may exercise any rights available under applicable California law by using the methods in Clause 6.2. [● CALIFORNIA RIGHTS TEXT — VERIFY: insert the current, complete descriptions of covered rights, exceptions, verification rules, authorized-agent rules, response timing, and any non-discrimination requirement after confirming the operative law.]
11.4 California sale, sharing, and sensitive-information choices. Mudbug does not sell Personal Information or share it for cross-context behavioral advertising. Mudbug therefore does not currently provide a "Do Not Sell or Share" link. Workspace Data is used to provide the requested Services and related security, billing, storage, and backup functions. Any required sensitive-information limitation or opt-out mechanism remains subject to [● SENSITIVE-INFORMATION PRACTICE CONFIRMATION] and [● GPC CONFIRMATION].
11.5 Texas rights. If applicable Texas law covers Mudbug's processing and the requester qualifies as a consumer, the consumer may submit an authenticated request to: confirm whether Mudbug processes the consumer's Personal Information and obtain access; correct inaccuracies; delete Personal Information provided by or obtained about the consumer; obtain qualifying Personal Information in a portable and readily usable digital format; and opt out of targeted advertising, sale of Personal Information, or profiling that produces legal or similarly significant effects. A parent or guardian may exercise these rights for a known child. Mudbug does not sell Personal Information, use it for targeted advertising, or use it for profiling that produces legal or similarly significant effects.
11.6 Texas requests and appeals. Submit a Texas request using Clause 6.2. The appeal process is [● APPEAL PROCESS]. [● TEXAS PROCEDURE CONFIRMATION — VERIFY: confirm applicable authentication, response, appeal, agent, and timing requirements.]
11.7 Louisiana. [● LOUISIANA 2027 UPDATE — VERIFY BEFORE JANUARY 1, 2027: determine whether the Louisiana Data Privacy Act applies to Mudbug and add its required notice disclosures, consumer rights, request methods, appeal procedures, opt-out mechanisms, and processor or controller disclosures. Final codification and citation form also require confirmation.]
11.8 New York. [● NEW YORK REQUIREMENTS — VERIFY: identify and implement any New York privacy, data-security, breach-notice, or sector-specific disclosure requirements applicable to Mudbug's actual operations. No verified New York privacy-policy authority was supplied for this draft.]
12. Changes to This Policy
12.1 Policy updates. We may update this Policy to reflect changes to the Services, providers, or legal requirements. We will post the updated Policy at [● POLICY URL] and revise the last-updated date. Material-change notice will be provided through [● POLICY CHANGE NOTICE METHOD].
12.2 Review cycle. Mudbug will review the California portions of this Policy at least annually while those requirements apply.
13. Contact Us
13.1 Privacy requests and questions. Email: [● PRIVACY EMAIL]
Mail: [● MAILING ADDRESS]
Online request method: [● REQUEST WEBFORM OR ADDITIONAL METHOD]
13.2 Security reports. Security reports may be sent to [● SECURITY CONTACT]. Please do not include unnecessary confidential information in an initial report.
14. Effective Date
14.1 Dates. Effective date: [● EFFECTIVE DATE]
Last updated: [● LAST UPDATED DATE]
Open items (complete before publication)
- [● LEGAL NAME]: Confirm the sole proprietor's full legal name and any registered trade name.
- [● SERVICE URL]: Insert the production service URL.
- [● TERMS URL]: Confirm the Terms of Service URL if the Policy will link to it.
- [● POLICY URL]: Insert the permanent public URL for this Policy.
- [● PRIVACY EMAIL]: Insert the monitored email address for privacy requests.
- [● MAILING ADDRESS]: Insert the operator's privacy-request mailing address.
- [● SECURITY CONTACT]: Insert the monitored security-report address.
- [● EFFECTIVE DATE]: Select the effective date.
- [● LAST UPDATED DATE]: Insert the publication or last-revision date.
- [● GOVERNING-LAW/VENUE CONFIRMATION]: Confirm whether a privacy policy should contain governing-law language and whether East Baton Rouge Parish venue belongs only in the Terms of Service.
- [● SMTP PROVIDER IDENTITY]: Identify the configured production email provider.
- [● INFRASTRUCTURE PROVIDER IDENTITIES]: Identify the production hosting, object-storage, backup, and managed-database providers.
- [● REQUIRED DISCLOSURE SCENARIOS]: Confirm practices for subpoenas, court orders, emergency requests, protection of rights, and any business transfer.
- [● COOKIE DETAILS]: Complete a technical inventory of cookies, local storage, session identifiers, CSRF technologies, providers, purposes, and durations.
- [● REQUEST WEBFORM OR ADDITIONAL METHOD]: Decide whether to provide a webform, toll-free number, or other request channel.
- [● AUTHORIZED AGENT PROCESS]: Establish and document the authorized-agent process.
- [● APPEAL PROCESS]: Establish a privacy-request appeal channel and workflow.
- [● GPC CONFIRMATION]: Test and document treatment of browser-based opt-out preference signals.
- [● ACCOUNT RETENTION]: Set the retention and deletion rule for residual Account Data after account deletion.
- [● USAGE/AUDIT RETENTION]: Set the retention period for pseudonymous Usage and Audit Data.
- [● BILLING RETENTION]: Set the retention period for subscription records, Stripe identifiers, and webhook payloads.
- [● CHILDREN/COPPA ANALYSIS]: Complete a verified children's-privacy analysis.
- [● INTERNATIONAL PROCESSING LOCATIONS]: Confirm every country in which Mudbug and its providers process or store data.
- [● FOREIGN-LAW PLACEHOLDER]: Determine whether foreign privacy laws apply based on users, clients, data subjects, and processing locations.
- [● CALIFORNIA 12-MONTH CONFIRMATION]: Confirm the California reporting period and verify that the disclosed practices cover it accurately.
- [● SENSITIVE-INFORMATION PRACTICE CONFIRMATION]: Determine whether account or workspace processing requires a California sensitive-information limitation notice or mechanism.
- [● CALIFORNIA RIGHTS TEXT]: Verify and insert the complete current California rights and procedural disclosures.
- [● TEXAS PROCEDURE CONFIRMATION]: Verify Texas applicability, authentication, timing, agent, appeal, and response requirements.
- [● LOUISIANA 2027 UPDATE]: Complete a substantive Louisiana Data Privacy Act review before January 1, 2027.
- [● NEW YORK REQUIREMENTS]: Complete a New York privacy, cybersecurity, breach-notice, and sector-specific review.
- [● POLICY CHANGE NOTICE METHOD]: Decide how users will receive notice of material policy changes.
Drafting notes
- The California collection section identifies categories of personal and potentially sensitive information, purposes, sale or sharing practices, and retention periods or criteria. A separate just-in-time notice at or before collection may still be required; a general privacy policy may not be sufficient by itself.
- The policy uses descriptive headings, request instructions, contact fields, and a last-updated field. Confirm accessibility, website placement, mobile presentation, and all detailed content requirements before publication.
- California materials supplied for this draft indicate that an annually updated policy should address consumer rights and request methods, collection sources and purposes, third-party categories, and sale, sharing, and business-purpose disclosures. Applicability, exact wording, lookback period, and procedural details remain for attorney verification.
- The supplied California authority addresses disclosures and mechanisms concerning sale, sharing, sensitive-information use, and opt-out preference signals. Because formal citation form and detailed applicability were not confirmed in the supplied digest, the draft includes operational verification placeholders rather than an unqualified compliance claim.
- The Texas rights listed in Clause 11.5 track the supplied digest: confirmation and access, correction, deletion, qualifying portability, and opt-outs from targeted advertising, sale, and qualifying profiling. The digest also permits a parent or guardian to act for a known child. Applicability, exceptions, timing, appeals, and detailed procedure were not established by the supplied digest.
- The supplied Louisiana authority establishes only that the Louisiana Data Privacy Act was enacted with a stated January 1, 2027 effective date. It does not establish substantive policy requirements, applicability, final codification, or citation form. The Louisiana section therefore remains a conspicuous placeholder.
- No verified federal children's-privacy authority was supplied. Counsel should verify whether the adult-user restriction is sufficient and whether uploaded information about minors creates additional obligations.
- No verified foreign-law authority was supplied. Do not add GDPR, United Kingdom, or other foreign-law rights or transfer mechanisms without confirming actual geographic processing and obtaining verified authority.
- No verified New York authority was supplied. A targeted New York privacy and security review is still required.
Mudbug Legal Assistant is software for use by licensed attorneys and their staff. Every output is a draft for attorney review, not legal advice, and does not create an attorney-client relationship with the operator of this service. Citations are verified against public sources where possible; anything not verified is flagged and must be checked before use.