App Privacy Policy
Last updated: April 1, 2026
1. Data Controller
Wixen Company LLC ("we," "us," or "our") operates the CaseIntel iOS application and the website at caseintel.io. CaseIntel is an AI-powered legal discovery platform that helps small law firms process documents, detect privilege, extract timelines, and manage cases. This policy applies to the CaseIntel iOS app available on the Apple App Store.
For our full website privacy policy, see caseintel.io/privacy.
2. Data We Collect & How We Collect It
Account Information
Collected when you create an account or sign in:
- Name and email address (entered directly, or provided via Sign in with Apple or Google)
- Law firm name (entered during registration)
- Authentication tokens (generated by our server, stored in your device's Keychain)
Case & Document Data
Collected when you use the app's features:
- Documents you upload or scan using the in-app document scanner
- Case information and metadata you enter
- AI-generated classifications, privilege flags, summaries, and timelines
- Messages you send to the AI case chat assistant
Device & Usage Data
Collected automatically when you use the app:
- APNs push notification device token (used to deliver case alerts and deadline reminders)
- Device type and iOS version (for compatibility and debugging)
- App crash reports and performance metrics (aggregated, not personally identifiable)
Data We Do NOT Collect
- We do not access your device's location data, contacts, photos, or other personal files
- We do not collect health or fitness data
- We do not use device tracking or advertising identifiers (no IDFA)
- We do not use cookies or cross-site tracking in the app
3. How We Use Your Data
We use the data we collect solely to provide and improve the CaseIntel service:
- Service delivery: Document classification, privilege detection, timeline extraction, AI chat
- Authentication: Verify your identity and secure your account
- Notifications: Send push notifications for case deadlines and updates you opt into
- Support: Respond to your support requests
- Improvements: Fix bugs and improve app performance using aggregated, anonymized analytics
AI Processing Disclosure
All AI processing uses AWS Bedrock (Anthropic Claude) exclusively. Your documents never leave AWS infrastructure and are never used to train AI models. No data is sent to OpenAI, Google, or any other third-party AI provider.
Purpose Limitation
Data collected for the purposes described above will not be repurposed for unrelated uses (such as advertising, marketing, or data mining) without your explicit consent. We do not use your data for advertising or marketing purposes.
4. Sign in with Apple
When you use Sign in with Apple, we receive only the information you choose to share:
- Email: Your real email address, or Apple's private relay address — your choice
- Name: Provided only on first sign-in; stored for your profile display name
- Apple User ID: An opaque, app-specific identifier used to link your account
We do not receive your Apple ID password. We cannot access any other data from your Apple account (photos, contacts, purchases, etc.).
Revoking access: You can disconnect Sign in with Apple at any time from your device: go to Settings > [Your Name] > Sign-In & Security > Sign in with Apple, select CaseIntel, and tap Stop Using Apple ID. You may also request account deletion as described in Section 8 below.
5. Data Sharing & Third Parties
We do NOT sell, rent, or trade your personal data.
We share data only with the following service providers, each of which is contractually required to protect your data to the same or greater standard as described in this policy:
| Provider | Purpose | Data Shared |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage (S3), database (RDS), AI processing (Bedrock) | All service data (encrypted at rest and in transit) |
| Stripe | Payment processing | Billing info only (PCI DSS Level 1 compliant) |
| SendGrid (Twilio) | Transactional email delivery | Email address and message content for magic links and notifications |
| Apple | Sign in with Apple authentication | Only what you authorize during sign-in |
| Sentry | Error monitoring and crash reporting | Anonymized crash reports and stack traces (no personal data) |
We do not use third-party advertising networks, analytics SDKs that track users across apps, or any data brokers. We do not share data with any parent, subsidiary, or affiliated companies beyond Wixen Company LLC.
We may also disclose data when required by law, subpoena, court order, or to protect the rights and safety of our users.
6. Consent & Permissions
By creating an account and using the CaseIntel app, you consent to the collection and use of your data as described in this policy. You may withdraw consent at any time by:
- Push notifications: Disable in iOS Settings > CaseIntel > Notifications
- Sign in with Apple: Revoke in Settings > [Your Name] > Sign-In & Security > Sign in with Apple
- Camera access: Revoke in iOS Settings > CaseIntel > Camera (used for document scanning only)
- All data: Request complete account deletion (see Section 8)
The app will request permission via iOS system prompts before accessing push notifications or the device camera. You can change these permissions at any time in iOS Settings.
7. Data Security
Encryption
- AES-256 encryption at rest (AWS)
- TLS 1.3 encryption in transit
- iOS Keychain for token storage
- Encrypted database connections
Access Control
- Biometric lock (Face ID / Touch ID)
- JWT token authentication
- Automatic session expiry
- Role-based access control
Infrastructure
- AWS SOC 2 certified infrastructure
- Private VPC networking
- Automated security monitoring
- Regular security audits
On-Device
- No data stored in plain text
- Sensitive data cleared on logout
- App locks on background
- No data written to iCloud
8. Account & Data Deletion
You can delete your account and all associated data using either method:
Option 1: In the App
- Open CaseIntel and go to Settings
- Tap Account
- Tap Delete Account
- Confirm the deletion when prompted
Option 2: By Email
- Email legal@caseintel.io with subject "Account Deletion Request"
- Include the email address associated with your account
- We will confirm deletion within 2 business days
What Gets Deleted
- Your profile, account credentials, and authentication tokens — immediately
- All documents, cases, classifications, and chat history — within 30 days
- Backup copies — within 90 days
- Anonymized, aggregated analytics data may be retained (cannot be linked back to you)
9. Data Retention
We retain your data only for as long as your account is active or as needed to provide the service.
- Active accounts: Data retained while your subscription is active
- Inactive accounts: If your account has no activity for 12 months, we may send a reminder email. Data is not automatically deleted without your request.
- After deletion: All personal data permanently removed per the timeline in Section 8
- Legal holds: If required by law, certain data may be retained beyond the standard period
10. Location Services
CaseIntel does not request, collect, or use location data. The app does not use GPS, Wi-Fi-based location, cell tower triangulation, or any other location-based API. Location Services permission is never requested.
11. Children's Privacy
CaseIntel is a professional legal tool intended for licensed attorneys and legal professionals. The app is not directed at children under 18, and we do not knowingly collect personal information from anyone under 18 years of age.
If we become aware that we have collected personal information from a child under 18, we will promptly delete that information. If you believe a child has provided us with personal data, please contact us at legal@caseintel.io.
12. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Access
Request a copy of your personal data
Rectification
Correct inaccurate or incomplete data
Erasure
Request deletion of your data
Portability
Export your data in a machine-readable format
Restriction
Limit how we process your data
Objection
Object to certain processing activities
To exercise any of these rights, contact legal@caseintel.io. We will respond within 30 days. We will not discriminate against you for exercising any of these rights.
13. International Data Transfers
Your data is processed and stored on servers located in the United States (AWS us-east-1 region). If you are accessing the app from outside the United States, your data will be transferred to and processed in the United States. By using CaseIntel, you consent to this transfer. We ensure appropriate safeguards are in place in accordance with applicable data protection laws.
14. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will notify you through the app or by email before the changes take effect. The "Last updated" date at the top of this page indicates when the policy was last revised. Your continued use of the app after changes constitutes acceptance of the revised policy.
15. Contact Us
For privacy-related questions, data requests, or to exercise your rights:
Related Policies
- Full Privacy Policy — comprehensive website privacy policy
- Terms of Service — terms governing use of the platform