Security & Trust
Built for attorneys who answer to bar rules. Here is exactly how we handle your data and how we keep AI output on a verifiable leash — stated plainly, with nothing we can't back up.
Your Data
Documents are processed through the OpenAI API. OpenAI's policy states that “data sent to the OpenAI API is not used to train or improve OpenAI models” unless the customer explicitly opts in — and we do not opt in. Under the same policy, OpenAI retains API abuse-monitoring logs for up to 30 days.
All traffic to The Legal Prompts runs over TLS, and your account data and document history are stored in our PostgreSQL database infrastructure with encryption at rest.
Payments run entirely through Stripe-hosted checkout. We see your subscription status — never your card number.
Delete generated documents from your dashboard at any time — deletion removes them from our database. Nothing about your practice is shared with third parties for marketing.
Accuracy by Design
Most legal AI vendors talk about encryption and stop there. For an attorney, a confidently wrong deadline is as dangerous as a leak. This is the part of security we built the product around.
Statutory deadlines for California and New York (including Cal. Gov. Code § 911.2 and N.Y. GML § 50-e presentation deadlines) are injected from a static dataset verified against official sources — the model never generates a statute, deadline, or citation. If your jurisdiction isn't covered yet, you get an explicit “not yet verified” notice, never a guess.
Every plan, every document. Authorities you provide are transcribed as cited — never “corrected” or embellished. Generators are bench-tested against trap fixtures (fake citations, arithmetic inconsistencies) before they ship.
The Strategic plan includes the Reasoning Log — an exportable record of the stated basis for each document, so your independent review is documented, not just performed.
AI drafts. The lawyer signs. Every output of The Legal Prompts is a draft for attorney review — we say it on every page because it is how responsible legal AI works, whatever tool you use.
No. Documents are processed through the OpenAI API, whose policy states that data sent to the API is not used to train or improve OpenAI models unless the customer explicitly opts in — and The Legal Prompts does not opt in. OpenAI retains API abuse-monitoring logs for up to 30 days under its own policy.
Yes. You can delete generated documents from your dashboard at any time, and deletion removes them from our database. Document history retention depends on your plan (30 days on Starter and Professional, unlimited on Strategic) — but deletion is always available.
Three mechanisms. Anti-hallucination rules are applied to every generation on every plan. Jurisdiction Guardrails inject statutory deadlines (for California and New York) from a verified static dataset — the model never generates a statute, deadline, or citation, and an unverified jurisdiction produces an explicit notice instead of a guess. And generators are bench-tested against trap fixtures (fake citations, arithmetic errors) before they ship.
No. Payments are processed entirely by Stripe through Stripe-hosted checkout. Card details go directly to Stripe and never touch our servers.