Privacy notice — Legalix connector
Last updated: October 2026. This notice covers the Legalix connector for Claude, ChatGPT and other AI assistants (https://mcp.legalix.ai). It supplements the Legalix privacy policy; where they differ for the connector, this notice applies.
Who we are
The connector is operated by Legalix.ai ("Legalix", "we"). Contact: privacy@legalix.ai.
What Legalix receives
Legalix receives only what your AI assistant sends to a Legalix tool, and what you upload to Legalix:
- Account data — your name and email address from sign-in (Google or email and password), and your office's details.
- Firm profile — the letterhead details and logo you set for documents.
- Case data you add — clients, cases, and the files you upload to a case, with the text Legalix extracts from them.
- Tool inputs — the arguments of each tool call: a legal question, the details for a document, the figures for a calculation, a search query.
- Usage data — which tool was called, when, its outcome and duration, the assistant used (for example Claude or ChatGPT), and the credits used.
Legalix does not receive the rest of your conversation with the assistant, and files you only attach to a chat are never sent to Legalix. Your assistant's provider (Anthropic or OpenAI) handles your conversation, including the tool results Legalix returns, under its own privacy policy.
How we use it
- To run the tool you asked for: answer the legal question, produce the document on your letterhead, search your case files, compute the result.
- To keep your office's data separate from everyone else's, to bill credits under your plan, to secure the service and to fix errors.
- To understand how the connector is used (tool names and outcomes — never the content of your questions, documents or files).
Legalix does not sell your data and does not use your questions, case files or documents to train AI models.
Where it is stored
- Uploaded case files: Google Cloud Storage, Tel Aviv region, encrypted at rest.
- Extracted text, search index, accounts and firm profiles: Google Cloud SQL, Tel Aviv region.
- The case fact index (parties, facts, timeline): MongoDB Atlas on AWS, Tel Aviv region.
- Connection tokens: Google Firestore, stored as one-way hashes.
Service providers
These providers process data on our behalf, under their business terms. Google's paid Gemini API and OpenAI's API do not use the data we send them to train their models.
| Provider | What for | What they receive |
|---|---|---|
| Google (Gemini API, paid tier) | Reading scanned and image pages (OCR); answering a question about a case image; building the case fact index | Page images and extracted text of the files you upload; the image question |
| OpenAI (API) | Semantic search in your case files | The extracted text of each page, and your search queries, to compute search vectors |
| Legalix legal-research service, using Google Gemini and OpenAI models | Answering Israeli-law questions with sources | The question your assistant sends — no case files |
| CloudConvert | Converting Word and RTF files to PDF | Those files; CloudConvert deletes them within 24 hours |
| Google Firebase Authentication | Sign-in | Name, email, sign-in method |
| Mixpanel (EU data residency) | Product analytics | Name, email, office, tool names, outcomes and timings; how you arrived at the connector page — never content |
| Sentry; LangSmith | Error reports; processing traces | Technical details such as file names, sizes and page numbers — not file content |
Some of these providers process data outside Israel (for example in the United States or the European Union). We rely on their contractual and technical safeguards for those transfers.
How long we keep it
- Case files, extracted text and the fact index: until you delete them, or until your office's account is closed. Deleting a file in Legalix removes the file, its extracted text and its search entries; backup copies of the file and its text are erased within 30 days. Files uploaded before 2 October 2026 also remain in a read-only copy at our previous storage provider (Amazon Web Services, Tel Aviv region) until that copy is deleted in full on 2 November 2026. Facts already extracted from a deleted file stay in the case's fact index until the index is rebuilt — ask privacy@legalix.ai to erase them sooner.
- Documents you produce: available through their download link for 24 hours, then deleted.
- Upload links expire after 7 days. Connection tokens expire after 1 hour (access) and 30 days (refresh).
- Account and billing records: for as long as the account exists and as required by law.
Your choices and rights
- Disconnect Legalix at any time in your assistant's connector or app settings; its access ends immediately.
- Delete files and cases from your case (ask the assistant, or use the case page Legalix links to).
- Ask to access, correct or delete your personal data, or to close your account, at privacy@legalix.ai. We answer within 30 days, as Israeli privacy law requires.
If you upload documents about other people (for example your clients or opposing parties), you are responsible for having a lawful basis to do so; Legalix processes them only on your instructions.
Security
Connections to the connector use HTTPS. Each request is limited to the signed-in office. Files are uploaded straight to encrypted storage through short-lived links, and the connector never hands case data to another office.
Children
The connector is a professional tool for lawyers and legal teams and is not intended for anyone under 18.
Changes
We will update this page when the connector's data handling changes, and change the date at the top.