CaseFront (the "Company") has established and publishes this Privacy Policy in accordance with applicable data protection laws, in order to protect the personal information of users and provide a means of swift, smooth resolution of any related concerns.
Data We Collect and How
Categories of Personal Data
At sign-up (required)
- Email address, password
- Firm name, attorney name
At sign-up (optional)
- Phone number, practice areas, firm logo
Collected automatically during service use
- Recording files (audio data), recording date/time, recording duration
- AI speech-to-text (STT) transcriptions
- AI-generated case reports
- App usage logs, IP address, device information (OS, device model)
At payment
Payment method information is processed directly by external payment providers (Stripe / Toss Payments). The Company does not collect or store payment credentials directly.
Collection Methods
- Direct input by the user during sign-up or service use
- Audio data collected via the in-app recording feature
- Automatically generated and collected during service use
How We Use Your Data
The Company uses collected personal data for the following purposes.
- Service delivery — AI speech-to-text transcription and case report generation from recordings
- Account management — Registration, identity verification, service access and restrictions
- Service improvement — Enhancing service quality, error analysis and fixes
- Customer support — Responding to inquiries, delivering notices
- Subscription & billing management — Managing paid subscriptions, tracking usage
Retention Period
In principle, the Company destroys personal data without delay once the purpose of collection and use has been achieved.
| Data | Retention Period | Notes |
|---|---|---|
| Account information | Until account deletion | Deleted immediately upon withdrawal |
| Recording files (mp3) | 1 year | Deletion on request |
| STT transcripts | Until account deletion | Retained even after recording deletion (separate deletion request possible) |
| AI reports | Until account deletion | Retained even after recording deletion (separate deletion request possible) |
| Service usage logs | 3 years | Retained per applicable telecommunications law |
| Payment records | 5 years | Retained per applicable e-commerce law |
Third-Party Disclosure
As a rule, the Company does not provide users' personal data to external parties. Exceptions apply in the following cases.
- Where the user has given prior consent
- Where required by law, or where a law enforcement agency requests data through legally prescribed procedures for investigative purposes
Data Processing Partners
The Company entrusts the following parties with personal data processing tasks in order to provide the service.
| Vendor | Task | Country |
|---|---|---|
| Supabase Inc. | Database and file storage operation | USA |
| OpenAI, Inc. | Speech-to-text (STT) processing | USA |
| Google LLC | AI report generation (Gemini API) | USA |
| Stripe, Inc. / Toss Payments | Payment processing | USA / Korea |
| Vercel Inc. | Web service hosting | USA |
Audio and text data transmitted to partner vendors is used solely for the purpose of providing the service and is not separately stored on vendor servers after API processing.
International Data Transfers
The Company transfers personal data overseas as follows in order to provide the service.
- Data transferred — Recording files, STT transcripts, text used for AI report generation
- Destination country — United States
- Purpose — Provision of AI speech recognition and report generation services
- Method — API transmission over network
- Retention — Deleted immediately upon completion of API processing (not stored separately on vendor servers)
Data Deletion
The Company destroys personal data without delay when it is no longer necessary — for example, when the retention period expires or the processing purpose has been achieved.
- Deletion method — Personal data stored in electronic file format is deleted using technical methods that make recovery impossible.
- Recording file deletion — Users are notified by email and in-app notification 7 days before the retention period expires, after which files are automatically deleted. Users may download the original file before expiry.
Your Rights
Users may exercise the following rights at any time.
- Right to access personal data
- Right to rectification of errors
- Right to erasure
- Right to restriction of processing
Rights can be exercised via the in-app settings menu or by email (privacy@casefront.app), and the Company will act without delay.
Account Deletion
Users may delete their account at any time via Settings > Delete Account in the app. The following data will be deleted.
- Account information (email, name, etc.)
- Recording files
- STT transcripts and AI reports
- Subscription information
Information required to be retained by law (such as payment records) will be destroyed after the applicable period.
Security Measures
The Company takes the following measures to ensure the security of personal data.
- Encryption — Passwords are stored and managed in encrypted form, and SSL/TLS encrypted communication is used for data transmission.
- Access restriction — Access to personal data is limited to the minimum number of personnel required.
- Data isolation — Each law firm's data is logically fully isolated based on firm_id.
- Storage security — Recording files are kept in a private (non-public) storage, accessible only to authenticated users.
Special Notice on Recording Data
Lawfulness of Recording
This service provides a recording tool. Responsibility for the lawfulness of any recording rests with the user. Under applicable law, recording by a party to the conversation is generally lawful, while a third party secretly recording the conversation of others without their consent is unlawful.
AI Processing Notice
Recording files are automatically converted to text via AI speech recognition (STT) technology, and AI generates a case report based on the resulting transcript. AI-generated output is for reference only and does not constitute legal advice.
STT Accuracy
AI speech recognition results may not be 100% accurate and have no legal evidentiary value. Please refer to the original recording for accurate content.
Privacy Officer
For inquiries, complaints, or remedies related to personal data, please contact the person below.
Policy Updates
This Privacy Policy takes effect from the effective date above. If additions, deletions, or corrections are made in accordance with laws and regulations, changes will be announced via the notice board at least 7 days before taking effect.