Draft policy
Privacy Notice
This draft notice describes the current public website behavior and the protected product data categories that require approval before production launch.
Last updated: June 20, 2026
Current site behavior
The Legeva website is a public marketing site. It does not include account creation, payment processing, advertising pixels, or an on-site contact form in the current implementation.
The site uses PostHog analytics to understand aggregate page activity. PostHog is configured without session replay, form/input autocapture, advertising pixels, or persistent browser storage.
Demo requests use a mailto link. If you send an email, the information you choose to include is handled by the recipient mailbox and the email systems involved in delivery.
Public contact information
You may choose to provide name, organization, role, email address, practice area, and workflow context when contacting Legeva.
Do not send confidential client materials, privileged documents, regulated personal data, or matter files through the public demo request email unless a separate reviewed intake process has been agreed.
Product account and organization data
When the protected app is activated, Legeva expects to process account and organization data such as user identifiers, organization membership, roles, permissions, invitation metadata, session metadata, workspace settings, and administrative decisions.
Provider-backed auth, organization creation, invites, and member management are not live in the current local foundation. They require approved auth and database providers, reviewed environment handling, and production launch approval.
Product usage and audit metadata
Protected workflows are designed to create minimized product usage and audit metadata for route access, matter access decisions, document workflow states, review dispositions, approval gates, rate-limit checks, and provider-gate decisions.
Protected app analytics and observability are blocked until an event taxonomy, scrub rules, persistence target, privacy review, and provider setup are approved. Sensitive route names, matter content, legal text, prompts, outputs, secrets, headers, and cookies must not be captured in analytics events.
Files, legal content, and AI processing
Future protected workflows may process customer files, extracted text, source packets, review tables, drafts, work packets, prompts, model outputs, and client portal materials as sensitive customer content.
No live customer-content storage, AI provider processing, embeddings, extraction, drafting, agent execution, or high-volume processing is approved in the current local foundation. Those actions require provider approval, DPA/vendor review, model policy approval, audit controls, and customer-data handling approval.
Operational data
Hosting providers may process standard request logs such as IP address, user agent, URL, timestamp, and response metadata for security, reliability, debugging, and abuse prevention.
PostHog may process pageview events, route paths, device/browser metadata, and network-derived technical metadata for analytics. The implementation does not intentionally store PostHog cookies or persistent local analytics identifiers.
Use, retention, and deletion
Contact information is used to respond to inquiries, assess fit, coordinate demo follow-up, and maintain basic business records.
Product records, audit metadata, uploaded files, derived artifacts, and support records need reviewed retention, legal-hold, export, deletion, and backup deletion paths before production customer data is processed. A final retention schedule requires legal review.
Your requests
Privacy requests should be sent to the privacy contact listed below. Requests may include access, correction, export, deletion, objection, or other rights available under applicable law.
Legeva has local planning helpers for privacy request intake, export, deletion, and processor review, but live persistence and fulfillment workflows require approved database, storage, audit, backup, and legal/provider review.
This draft is not legal advice and should not be treated as final privacy documentation until approved by the appropriate reviewer.
Contact
privacy@legeva.com