Privacy Policy
Last updated August 1, 2026.
Decree handles some of the most sensitive data in civil practice — financial records, children's information, and personal identifiers. This policy describes how we collect, use, and protect that data. It is not legal advice.
Who we are and what this policy covers
Decree is operated by DECREE.LEGAL, LLC, a Washington limited liability company doing business as Decree, from Seattle, Washington. This policy covers the decree.legal website, the Decree application, and our support channels. Two kinds of data flow through Decree, and we treat them differently: data about your firm and its users is handled as described in this policy, and data your firm enters about its clients is processed to provide the service on your firm’s instructions.
Our two roles: your firm's data and your clients' data
For account, billing, website, and support data, Decree decides how the data is handled. For information a firm enters about its clients and their children — including parties, children, income, health-related expenses, financial declarations, form contents, intake answers, and uploaded documents — Decree processes the information to provide the service on the firm’s instructions. Your firm controls that data.
If a law firm entered your information into Decree, please direct privacy requests to that firm. We will work with the firm on requests it asks us to support.
Data we store
Account data. Your name, email address, and organization membership, managed through our authentication provider (Clerk).
Matter data. Information you or your clients enter about matters: names, contact details, children, income, deductions, health-related costs, calculations, form contents, and work product. Stored matter data is protected by our database provider’s encryption at rest. Fields designated as sensitive — including Social Security and driver’s license numbers — receive additional application-level encryption with a key held outside the database.
Uploaded documents. A browser upload first goes to a private temporary S3 staging location that relies on storage-level encryption. During finalization, current uploads are encrypted with AES-256-GCM under a fresh document key, that key is wrapped by AWS KMS, and the encrypted file is stored under an organization-prefixed object key. Decree then requests deletion of the staging object; bucket lifecycle rules are intended to expire abandoned staging uploads. Documents stored under an earlier storage version use the application’s prior authenticated-encryption format until migrated.
Client intake. We store the credential hash for newly issued links, draft and submitted answers, timestamps, and status. Sensitive fields identified by the form manifest are application-encrypted before storage; other answers receive database storage-level encryption. Intake links are described further below.
AI extraction records. When a firm requests extraction, Decree stores the run status, document references, summaries, proposed values, source evidence, review decisions, and usage counts. These review records are saved before a user accepts or rejects a proposal.
Contact submissions. If you use our contact form, we store the name (optional), email, type of request, message, and the page you contacted us from. If you are signed in, the request is also linked to your account and organization. A copy may be sent through Zoho Mail so we can respond.
Usage data. We run no third-party product analytics and no ad trackers. Our hosting provider keeps standard server request logs, and Decree keeps an audit log of selected actions involving matters, parties, calculations, documents (including downloads), client intake, AI extraction, and billing. This is an action log, not a record of every page view or database read.
Unexpected application errors may be sent to Sentry as minimized technical events. These events use bounded error classifications, event codes, release and environment identifiers, sanitized route shapes and source locations, and random correlation IDs. Decree’s integration is designed not to send raw exception messages or stacks, request bodies, cookies, headers, query strings, user details, matter identifiers, document contents, form values, or AI inputs and outputs. Browser replay, performance tracing, product analytics, and Sentry logging are disabled.
Client intake links
Client intake uses a long, randomly generated bearer link instead of a client account. Anyone who has the link can open the questionnaire, view the non-masked answers available through it, and save or submit answers while the credential is active. Existing sensitive values are masked when the questionnaire loads. Newly issued links expire 30 days after issue and can be disabled or deleted sooner. Submission is terminal: it immediately revokes the credential, so the same link cannot be reopened, edited, or resubmitted. Firms should send links through an appropriate channel and disable links that are no longer needed.
For newly issued links, the bearer token is placed in the URL fragment rather than the HTTP request path. The intake page removes the fragment from the visible URL, sends the token in a same-origin POST body, and exchanges it for a 30-minute, HttpOnly, SameSite session cookie (marked Secure in production). URL fragments are not sent in ordinary HTTP request URLs or referrer headers, which reduces exposure in hosting request logs. The original link remains a secret: messaging systems, browsers, extensions, or anyone who receives a copy may still see or use it while it is active.
Decree shows a newly issued bearer token only when the link is created and stores only its SHA-256 hash in the database while the link is open. Submitting or disabling the link clears that hash and revokes access. Deleting an intake link also clears its draft and submitted answers and creator reference, then soft-deletes the remaining metadata row. Submitting or disabling retains the answers for the firm’s review and pull workflow.
Cookies and tracking
Decree uses necessary cookies only. Clerk authentication cookies keep firm users signed in, and client intake uses the short-lived session cookie described above after a bearer link is exchanged. Our sign-up flow may use a bot-protection challenge that sets its own necessary cookie. We use no advertising, analytics, or cross-site tracking cookies. Your theme preference is stored in your browser, not on our servers. Subscription checkout happens on Stripe’s site, which sets cookies under Stripe’s policy.
Because we do not sell personal information, share it for advertising, or track you across sites, there is no sale, advertising share, or cross-site tracking for browser signals such as Do Not Track or Global Privacy Control to opt out of.
How we use your data
We use data to operate the product: running calculations, generating forms, storing and returning documents, collecting intake answers, extracting figures when a firm asks us to, billing, security, and support. We do not sell your data, share it for cross-context behavioral advertising, use it for targeted advertising, or use your firm’s client data for a purpose unrelated to providing the service. Decree does not use matter data to train its own AI models.
AI document extraction
Extraction starts only when someone at the firm selects documents and requests it, after the firm has recorded a consent attestation for the matter, and while AI features are enabled for the organization. The selected documents — together with party names, file name, and document category used as context — are sent inline to Decree’s configured AI provider (Anthropic or OpenAI). Decree does not upload them through either provider’s retained Files API.
Decree saves proposed values, source evidence, summaries, and run metadata so a firm user can review them. A proposal does not change the matter’s structured financial or property records until an authorized firm user accepts and applies it. Rejecting a proposal does not erase its review record. Deleting a source document selectively removes that document’s summaries, source references, evidence, review overrides, proposals, reconciliation content, and temporary page-group results while preserving unrelated documents’ extraction records. Decree retains limited non-content call audit data, including cryptographic request hashes, provider/model and response identifiers, timing, status, and token usage, for metering, reliability, and security. Values already accepted into the matter remain part of the matter record.
Under the providers’ standard commercial API terms, inputs and outputs are not used for model training by default; a provider account holder may be able to opt into optional data sharing or model improvement. Provider account settings therefore matter in addition to the API request itself. Standard safety logs may retain inputs and outputs for up to about 30 days, subject to provider settings and trust-and-safety or legal exceptions.
Subprocessors
We rely on a small set of infrastructure providers:
- Vercel — application hosting, request routing, and server request logs
- Clerk — authentication and organization management
- Neon — Postgres database hosting
- Amazon Web Services — document staging, encrypted storage, and key management
- Anthropic or OpenAI — AI document extraction, as described above
- Stripe — billing and hosted payment collection
- Zoho Mail — support and contact-form email
- Sentry — minimized application error monitoring
These providers operate their own networks and infrastructure. Decree does not promise that every request is processed only in the United States; processing location depends on provider networks and the relevant service-account configuration. We update this list as our subprocessors change.
Other circumstances where we may disclose data
We may disclose data when required to comply with law, a subpoena, or other valid legal process; at your firm’s direction or with its consent; to protect the rights, safety, or integrity of users or the service; or as part of a merger, acquisition, or asset sale, subject to the obligations that apply to the successor.
Security
Browser traffic to Decree uses TLS, and our storage providers supply encryption at rest. Designated sensitive identifiers receive additional application-level encryption. Current finalized document uploads receive per-document envelope encryption, with the wrapping key managed by AWS KMS; temporary staging and legacy-format documents follow the storage paths described above.
Access to firm matter data is enforced in the application through organization and matter relationships. Some child records inherit their scope from a parent matter, and public intake intentionally authorizes access through its bearer token rather than firm membership. Tenants share application, database, bucket, and key-management infrastructure; organization checks and object-key prefixes provide the logical boundary. In-product administrative functions are restricted to allowlisted accounts.
We do not currently hold third-party certifications such as SOC 2. No system is perfectly secure; firm users are responsible for safeguarding credentials, intake links, and downloaded files, and we recommend enabling multi-factor authentication.
Retention, deletion, and export
Available downloads. While a firm has access to the application, users can download supported court forms and worksheets as Word documents, export property schedules as CSV or Excel, and download uploaded source files. Decree does not currently provide an automated whole-firm export. Contact support to discuss the available scope and delivery method for a broader request.
Uploaded-document deletion. For a current envelope-encrypted document, deletion marks the metadata row deleted and clears its wrapped document key and IV in the live database transaction. Legacy-format document content is removed from its storage row. This blocks new downloads and prevents new extraction results from being committed from that source. It cannot recall plaintext already delivered, a document already transmitted to an AI provider, or guarantee cancellation of a download that was authorized and began before deletion. Decree then requests deletion of stored ciphertext from S3 on a best-effort basis; ciphertext may remain until that request succeeds, but the application no longer has the live document key needed to decrypt it. Earlier database state may remain in provider backups during the provider’s backup-retention window.
The deleted document’s metadata — including its file name, type, size, fingerprint, and notes — remains for the firm’s history. Decree selectively purges that document’s extraction proposals, source evidence, summaries, reconciliation results, and temporary page-group results without deleting unrelated documents’ extraction records. Limited non-content call identity, request-hash, response-id, status, timing, and token-usage records remain for billing, reliability, and security. Values already applied to a matter remain with a non-content provenance record marked as source deleted.
Matter and intake records.Matters, calculations, financial entries, prepared forms, child entries, and attorney entries generally use soft deletion, so their stored content remains after it is hidden or closed. Intake-link deletion clears its credential and answers as described above while retaining limited metadata and an audit record. Decree does not currently offer self-service restoration. Contact support about a deletion made in error, but recovery is not guaranteed; earlier state may remain in provider backups during their retention windows.
Cancellation and organization-level requests. Cancellation does not automatically delete firm data; it remains stored so the firm can reactivate. Decree does not currently run an automated whole-organization purge or promise a fixed completion period for an export or deletion request. Contact support to discuss a verified request, including its scope, timing, provider backups, and any records that must be retained for security, billing, support, or legal purposes. Audit logs and contact submissions do not currently have a fixed automatic deletion schedule. An authorized internal administrator can redact a contact submission’s original name, email, message, page, and account links from the application database, leaving a placeholder tombstone and audit event. That action does not recall a copy already delivered through our email provider, whose retention also applies.
If there is a breach
If a security incident affects your firm’s data, we will notify you as applicable law requires and provide available information relevant to your own notice obligations. Document wrapping keys are stored separately from document ciphertext, which is designed to reduce the exposure of file contents if storage alone is compromised.
Your rights and how to exercise them
Firm users can view and correct information in the application and use the downloads described above. For access, correction, deletion, or portability questions, email us. We will coordinate requests with the firm that controls the matter data and respond as applicable law requires. If a law firm entered your information, contact that firm first.
We do not sell personal information or share it for cross-context behavioral advertising. Residents of states with comprehensive privacy laws may have rights of access, correction, deletion, and portability, subject to applicable exceptions. You may also direct complaints to your state attorney general.
Washington health data
Matter files and client intake can include health-related information — for example, disability income, insurance premiums, or medical and mental-health expense details. A client may submit that information directly through a Decree-hosted intake questionnaire created by the firm. Decree receives and processes it to provide the service on the firm’s instructions, not for marketing or advertising. Washington residents may have rights under the My Health My Data Act; requests about a firm’s matter data should be directed to that firm. Counsel must confirm the parties’ legal roles and any additional policy requirements before general availability.
Children's privacy
Decree is a professional tool for law firms and is not directed to children. The intake portal is designed for adult clients, but it does not perform age verification; firms should not send intake links to children. Children’s names, birthdates, and other case information may be entered by a firm user or an adult client in the course of legal representation. Children’s Social Security numbers receive application-level encryption; names, birthdates, and other fields receive database storage-level encryption. Decree does not use children’s information for marketing, advertising, or profiling.
Marketing email
If we send marketing email, it will include an unsubscribe link, honored promptly. Transactional messages — billing notices, client-intake links, support replies — are not affected by a marketing opt-out.
Changes to this policy
The last-updated date at the top of this page is kept accurate. We will tell firm customers about material changes by email or in-app notice before they take effect.
Contact
Questions about this policy, or a privacy request? Email support@decree.legal. If a law firm entered your information into Decree, please contact that firm first.