DraftyAI Logo

Privacy Policy

Last updated: March 2026

We do not use your data or your clients' case data to train AI models. We do not sell or share your personal data with third parties for advertising or any independent commercial purpose. Your case data is yours.

About This Privacy Policy

This Privacy Policy explains what personal data DraftyAI collects about you, how we use it, why we use it, and how you can control how it is processed. We are committed to protecting the confidentiality of attorney-client information and the privacy of the individuals whose data you work with on our platform. Because DraftyAI serves immigration attorneys, we recognize that data processed through our platform may involve sensitive immigration status, national origin, and personal circumstances. We treat all such data with the highest level of care.

1. The Basics

1.1 Who We Are DraftyAI is an AI-powered legal drafting platform built for immigration attorneys. Our platform helps attorneys prepare case documents, respond to Requests for Evidence (RFEs), draft personal statements, affidavits, and declarations, and manage legal workflows more efficiently. DraftyAI is operated by Navarro Immigration LLC and its affiliated entities. Our principal place of business is in the United States. For questions about this Privacy Policy or to exercise your rights, contact us at: - General inquiries: legal@draftyai.com - Privacy requests: info@draftyai.com 1.2 Our Role: Controller and Processor Data protection law distinguishes between a party that determines why and how personal data is processed (a "controller") and a party that processes data solely on the controller's behalf (a "processor"). When you use DraftyAI as an attorney or firm administrator, we are the controller of account and usage data we collect about you. When you upload case materials or client data to our platform to perform drafting services, we act as a processor on your behalf — you remain the controller of that data, and we process it strictly according to your instructions and our Terms of Service. 1.3 Definitions - "Services" means AI-assisted legal drafting, document generation, RFE response tools, and all related features of the DraftyAI platform. - "Personal data" means any information that identifies or could identify a natural person, directly or indirectly. - "Case data" means any documents, notes, client information, or materials you upload or input in connection with a legal matter. - "You" means attorneys, paralegals, firm administrators, and other authorized users of our platform. 1.4 A Note on Legal Bases We only collect and process personal data where we have a valid legal basis. Depending on the type of data and the context, this may include: - Performance of a contract (your use of our platform under our Terms of Service) - Our legitimate business interests (platform security, fraud prevention, service improvement) - Your consent (for marketing communications and optional features) - Legal obligations (where required by applicable law)

2. The AI and Your Data — Our Core Commitment

DraftyAI does not use your personal data, your clients' data, or your case materials to train, fine-tune, or improve any AI model. Ever. This commitment is foundational to our product and our relationship with you. We understand that attorneys have ethical obligations around client confidentiality, and that immigration case data is among the most sensitive data that exists. Our AI operates on your inputs to produce your requested outputs — nothing more. Specifically: - Your uploaded case documents are never used as training data - Generated briefs, letters, and responses remain your work product - We do not share case content with third-party AI providers for any purpose other than generating your requested output - We do not analyze, sell, or monetize patterns from your legal work

3. Personal Data We Collect, How We Use It, and Why

3.1 Account Registration Data When you create a DraftyAI account, we collect your name, email address, firm name, and bar number (if provided). If you register via a third-party authentication service, we receive the data that service shares with us. How we use it: To create and manage your account, verify your identity, communicate with you about the platform, and maintain platform security. Legal basis: Performance of our contract with you (Terms of Service). 3.2 Case Data and Uploaded Materials When you use DraftyAI to draft documents, you may upload or input case materials, client details, facts of record, and supporting documents. This may include: - Client names, contact information, and biographical details - Immigration status, visa category, country of origin, and case history - Supporting documents such as employment letters, declarations, and personal statements - Attorney notes, strategy, and research How we use it: Solely to generate the documents or outputs you request. We process this data on your behalf as a processor. We do not review, analyze, or use this data for any purpose beyond fulfilling your request. Legal basis: Performance of our contract with you and your instructions as the data controller. Your responsibility: When you upload data that includes third-party personal information (such as client data), you represent that you have all necessary rights, authorizations, and consents to do so, including compliance with applicable bar ethics rules and data protection obligations. 3.3 Website and Platform Activity Data When you visit our website or use our platform, we automatically collect certain technical and behavioral data, including: - IP address and device identifiers - Browser type, operating system, and referring URLs - Pages visited, features used, time spent, and clicks - Error logs and performance data How we use it: To maintain and improve the platform, diagnose technical issues, prevent fraud, and understand how users interact with our tools. We may use session recording tools (such as Microsoft Clarity or similar) configured to mask sensitive input fields. We also use this data to optimize our marketing and onboarding experience. Legal basis: Our legitimate interest in maintaining and improving our platform and marketing our services. 3.4 Communications and Support Data When you contact us, submit a support ticket, complete a survey, or communicate with our team, we collect the content of your communications and any personal data you include. How we use it: To respond to your request, improve our support processes, and inform product decisions. We may use your feedback (anonymized) to improve DraftyAI. Legal basis: Performance of a contract and our legitimate interest in improving our services. 3.5 Marketing and Lead Generation Data If you download a resource, register for a webinar, complete a lead magnet form, or subscribe to our communications, we collect your name, email address, firm name, and any other information you provide. How we use it: To send you information about DraftyAI, legal tech developments, product updates, and relevant educational content. We only send marketing communications with your consent. You may withdraw consent at any time. Legal basis: Your consent. You can unsubscribe at any time via any email we send or by emailing info@draftyai.com. 3.6 Data Enrichment We may supplement the information we collect with data from third-party business intelligence providers (such as Apollo or LinkedIn) to better understand our prospective customers and personalize our outreach. This enrichment is limited to professional and business information and is used solely for B2B marketing purposes. Legal basis: Our legitimate interest in marketing our services to relevant legal professionals.

4. How We Use Data for Marketing

4.1 Email Marketing With your consent, we send: - Onboarding and activation sequences to help you get value from DraftyAI quickly - Product updates, new feature announcements, and tips - Educational content on AI in immigration law, ethics compliance, and practice efficiency - Promotional offers and trial conversion communications You may unsubscribe from any marketing email using the unsubscribe link included in every message, or by contacting us at info@draftyai.com. Unsubscribing from marketing does not affect service communications related to your account. 4.2 Retargeting and Web Advertising We may use cookies and pixel technologies to serve advertisements to visitors of our website on third-party platforms including LinkedIn, Meta, and Google. These ads are based on your prior interaction with our website. You may opt out of interest-based advertising by adjusting your browser cookie settings or via your privacy settings on the relevant advertising platform. 4.3 Custom Audiences We may use hashed (anonymized) email addresses to create custom audiences on platforms such as LinkedIn and Meta to serve targeted advertisements to professionals similar to our existing users. No unencrypted personal data is shared with these platforms for this purpose. You may opt out by contacting us at info@draftyai.com.

5. How We Share Your Data

We do not sell your personal data. We do not share your personal data with third parties for their own commercial use. We share data only in the following limited circumstances: Cloud Infrastructure. We use third-party cloud hosting providers to store and operate our platform. All personal data stored on our platform is hosted on these secure servers, encrypted at rest and in transit. AI Processing (e.g., Anthropic). When you request a document to be generated, we transmit the inputs you provide for that specific task to our AI processing provider solely to generate your requested output. No data is retained by the provider for training purposes. Payment Processing (Chargebee). We use Chargebee to manage subscriptions and billing. We share your name, email address, and subscription details. Payment card data is collected directly by Chargebee and is not stored by DraftyAI. Email Marketing Platform. We use a third-party email platform to send onboarding sequences, product updates, and marketing communications. We share your name, email address, and subscription status for this purpose. Customer Relationship Management (CRM). We use a CRM tool to manage customer relationships and support. We share your name, firm name, email address, account status, and support history with this provider. Analytics. We use analytics providers to understand how users interact with our platform. These providers receive anonymized or aggregated usage data and IP addresses. No case data is shared for analytics purposes. Project Management and Issue Tracking. We use internal project management tools to track bugs, feature requests, and development tasks. User identifiers such as email addresses or account IDs may be associated with reported issues in these systems. Legal and Compliance. We may share personal data with legal authorities, courts, or regulators where required by applicable law or valid legal process. All service providers operate under contractual confidentiality obligations and may only use your data as we direct. 5.1 AI Model Providers — Special Notice Where we use third-party AI models (such as Claude by Anthropic) to power our drafting features, inputs you provide for a specific generation are transmitted to that provider solely to generate your requested output. We use providers whose terms prohibit the use of inputs for model training purposes. We do not send personally identifying client information to AI providers unless it is necessary to complete your specific request. 5.2 Business Transfer If DraftyAI undergoes a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will provide notice and ensure continued protection of your data under this Privacy Policy. 5.3 Legal Disclosure We may disclose your data to comply with applicable law, respond to lawful legal process, enforce our Terms of Service, or protect the rights and safety of DraftyAI, our users, or the public.

6. Immigration Data — Special Protections

Immigration data is among the most sensitive personal data. We treat it accordingly. Our platform is designed for immigration attorneys, and we recognize that the data processed through DraftyAI may include highly sensitive information about individuals' immigration status, national origin, citizenship, visa history, and personal circumstances. We apply the following enhanced protections: - Immigration-related case data is processed only to fulfill your specific drafting request - Case data is never reviewed by DraftyAI employees except where explicitly required to resolve a support issue - We do not profile individuals based on immigration status or national origin - We do not cooperate with immigration enforcement agencies or share case data with government immigration authorities except where required by a valid legal order

7. Attorney-Client Privilege and Professional Responsibility

DraftyAI is a tool for attorneys. We do not provide legal advice and do not create an attorney-client relationship with you or your clients. Responsibility for all work product submitted to any government agency or court remains with the attorney of record. We recognize that communications between you and your clients may be privileged. We do not access, review, or disclose case communications or strategy except as described in this Privacy Policy. Attorneys are responsible for ensuring their use of DraftyAI complies with applicable bar rules, ethics opinions, and professional responsibility obligations regarding AI-assisted legal work and client data.

8. Data Security

8.1 Technical Measures We use industry-standard security measures including: - Encryption of all data in transit (TLS) and at rest (AES-256) - Secure cloud infrastructure hosted on Google Cloud Platform (GCP) - Regular security assessments and vulnerability monitoring - Automated threat detection and anomaly alerts 8.2 Access Controls Access to personal data is restricted to authorized DraftyAI personnel with a documented need. Access is role-based, logged, and reviewed regularly. Access is revoked immediately upon termination of employment or contract. 8.3 Incident Response In the event of a data breach that poses a risk to your rights or the rights of individuals whose data was affected, we will notify affected parties as required by applicable law and work promptly to contain and remediate the incident.

9. Data Retention

We retain your data only as long as necessary for the purpose for which it was collected, or as required by law. - Case data and uploaded files: Deleted from active systems within 60 days of the last relevant request, unless stored in your active account - Marketing and lead data: Retained until you unsubscribe or request deletion - Support and communication records: Retained for 3 years to support dispute resolution - Financial records: Retained as required by applicable tax and accounting law You may request deletion of your data at any time subject to legal retention requirements. See Section 11 for how to exercise this right.

10. Cookies and Tracking Technologies

10.1 What Are Cookies Cookies are small text files placed on your device when you visit our website. We use cookies and similar technologies (pixel tags, local storage) to operate our platform, analyze usage, and support our marketing activities. Strictly Necessary Cookies. These cookies are essential for the platform to function. They enable authentication, navigation, and core security features. These cookies cannot be disabled. Preference Cookies. These cookies remember your settings and customizations to personalize your experience. You may disable them via your browser settings, though some platform preferences may not be saved. Analytics Cookies. These cookies collect information about how you interact with our platform — such as which features you use and how long you spend on certain pages — so we can improve the product. You may opt out via your browser settings or our cookie manager. Marketing Cookies. These cookies are used to serve relevant advertisements and measure the effectiveness of our campaigns. You may opt out via your browser settings or through the privacy settings on the relevant advertising platform. You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect platform functionality.

11. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data: 11.1 Right to Access You may request a copy of the personal data we hold about you. We will respond within 30 days. 11.2 Right to Correct You may request correction of inaccurate or incomplete personal data. 11.3 Right to Delete You may request deletion of your personal data. Note that we may retain certain data where required by law or for legitimate operational purposes (e.g., fraud prevention, legal obligations). 11.4 Right to Restrict or Object You may request that we stop processing your data for certain purposes, including direct marketing. We will honor opt-out requests immediately for marketing and within a reasonable time for other processing. 11.5 Right to Data Portability You may request your personal data in a structured, machine-readable format. 11.6 Right to Withdraw Consent Where processing is based on your consent, you may withdraw consent at any time without affecting the lawfulness of prior processing. 11.7 How to Exercise Your Rights Contact us at info@draftyai.com. We may ask you to verify your identity before processing your request. We do not charge a fee for exercising your rights.

12. California Residents — CCPA/CPRA Rights

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with additional rights. 12.1 Your California Rights - Right to Know: You may request disclosure of the categories and specific pieces of personal data we collect about you, the sources, business purposes, and third parties we share it with. - Right to Delete: You may request deletion of your personal data, subject to certain exceptions. - Right to Correct: You may request correction of inaccurate personal data. - Right to Opt-Out of Sale or Sharing: We do not sell your personal data. We do not share your personal data with third parties for cross-context behavioral advertising without your consent. - Right to Limit Use of Sensitive Personal Information: You may limit our use of sensitive personal data (such as immigration status, if applicable) to the purpose of providing the service. - Right to Non-Discrimination: We will not discriminate against you for exercising your California privacy rights. 12.2 Categories of Data Collected (CCPA) We collect the following categories of personal data: - Category A: Identifiers (name, email, IP address, account identifiers) - Category B: Personal information (name, contact details) - Category D: Commercial information (subscription history, billing records) - Category F: Internet activity (platform usage, browsing behavior on our site) - Category I: Professional information (firm name, bar number, professional role) - Category K: Inferences (product usage patterns used to improve onboarding) - Category L: Sensitive personal information (case data you upload, processed only to fulfill your drafting request) 12.3 How to Submit a California Privacy Request Email: info@draftyai.com. You may submit up to two access requests in a 12-month period. We will respond within 45 days, with one 45-day extension if needed.

13. Children

DraftyAI is intended for licensed attorneys and legal professionals. We do not knowingly collect personal data from individuals under 18. If you believe a minor has accessed our platform, please contact us at info@draftyai.com immediately.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have an account) and by updating the "Last Updated" date at the top of this document. Continued use of DraftyAI following notice of changes constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at info@draftyai.com. We take all privacy inquiries seriously and will respond within 10 business days.