Privacy Policy
Last updated: August 12, 2026
1. Who we are
Caseconnective is a client-management company. We build and operate a cloud platform that law firms and legal teams use to manage claimants and matters ("Services"), and we also use that same platform ourselves to run public eligibility checks, community outreach and claimant support for the matters we work on. This Privacy Policy describes how we handle information across both, on the websites and Services operated by Caseconnective ("we," "us," or "our").
Caseconnective is not a law firm, does not provide legal advice, and does not represent clients. Using this site, submitting an eligibility check, or contacting us does not create an attorney–client relationship. Information you submit may be shared with attorneys working on the matter you enquired about; whether they contact you is their decision.
Some information we decide the use of ourselves — for example, what our public intake forms ask. Other information we hold inside a law firm's workspace on that firm's instructions, and the firm decides what happens to it. Where those two differ we say so below.
2. Information we process
Depending on how you reach us, we may process:
- Identity and contact details — name (including any alias, middle name, suffix and salutation), date of birth, date of death, gender identity, preferred language, the last four digits of a Social Security number, email address, home and mobile phone numbers, and your preferred way of being contacted.
- Where you live — mailing address, and for matters involving environmental contamination the specific parcels associated with a household: street address, county, parcel number and map coordinates.
- Health and claim information — what happened and when, the conditions or injuries described, answers to intake and case questionnaires, notes written by staff, and documents that are uploaded on your behalf or by you, which commonly include medical records.
- Environmental test results — where a matter involves sampling, we hold the record of each soil, water or other sample taken in connection with a property: the address and coordinates it was taken at, the kit and barcode, collection and result dates, photographs of the sampling site, and the laboratory's measured concentrations of individual PFAS compounds (including PFOA, PFOS, PFHxS, PFNA, PFBS and GenX) together with their combined total.
- Communications — text messages you exchange with the team and any pictures or files sent with them, emails, portal messages and their attachments, and a record of each phone call: the numbers, direction, time and length, and whether a voicemail was left. See section 11 for what is and is not recorded.
- Information taken automatically from files you upload. When you attach a photograph to an intake form, your browser reads its embedded metadata before the file is sent: the GPS coordinates and the date and time the photo was taken, any barcode or QR code visible in the image, and any text found in it by optical character recognition. Coordinates found this way are sent to our mapping provider to be turned into a street address. All of it is stored with your submission.
- Signing records — if you sign an agreement electronically, we record your typed or drawn signature, your name and email address, the version of the document, the time, and the IP address the signature came from.
- Community outreach records — where our field team visited, when, the business or location name, the address and coordinates of the stop, and notes about follow-up.
- Account, security and usage data — sign-in information for staff and portal accounts, an audit record of who viewed or changed which record, with the IP address and browser used, and a rate-limiting record of sign-in attempts that stores only a hashed IP address. Public pages also collect anonymous usage statistics (section 9).
- Approximate location, worked out from your IP address. Where you have accepted analytics on a public page (section 9), the request carries the IP address your connection presents, and each analytics provider named in section 5 derives an approximate location from it — country, region and, roughly, city. It is calculated by those providers at their end rather than being a field we ask you for or read ourselves, it is an estimate rather than your actual whereabouts, and it applies to public pages only. If you have not accepted, nothing reaches them and no location is derived. This is separate from the addresses in the bullets above, which are the ones you or a firm give us.
Much of the above is information a law firm decides to put into its own workspace. Where a firm uses the Services to hold health, identifying, or otherwise regulated material about the people it works with, that firm chooses what goes in and remains responsible for its own obligations in respect of it — health-privacy law, the professional-conduct rules that bind it, and any business associate or data-processing agreement it is required to put in place. Section 5 of our Terms of Service allocates that responsibility the same way. It is not a responsibility this policy moves onto you or off that firm.
3. How we use information
We use information to:
- Provide, operate, maintain, and secure the Services;
- Authenticate users, enforce permissions, and prevent fraud or abuse;
- Check a submission against the published criteria for the matter it was sent about. That check is a fixed set of rules configured for the matter, run automatically on what you submitted. It is not legal advice, it is not a decision about your situation, and it is not made by a lawyer;
- Contact you about a submission, arrange and record environmental sampling, and pass information to attorneys working on the matter;
- Plot sample results and outreach activity on maps so a matter can be worked geographically;
- Provide support and communicate about the Services;
- Improve features, reliability, and performance, including the AI features described in section 4;
- Comply with law, respond to lawful requests, and enforce our agreements.
4. AI processing
Two features send case information to Anthropic's Claude models to produce text. Each one is started by a signed-in member of staff, one request at a time — no background job, automation rule or scheduled task sends anything to a model, and the client portal has no AI feature at all, so nothing a claimant does starts one. The features are: a suggested document type for an uploaded file, and an internal assistant staff can ask questions about a matter.
What goes with a request depends on the feature and on the firm's settings. It can include a person's name and contact details; the status and history of their claim or lead; staff notes that are not marked privileged; task titles and descriptions; the name and type of a document, and some of the text inside it where a document is being classified or has been attached to a chat; and a log of recent calls, emails and text messages, including message bodies and — for the accounts allowed to read them at all — call transcripts. Notes marked privileged are never sent. Where a document is referenced in the assistant, one marked privileged is given by name and type only, without its contents; that protection is specific to the assistant, and a file put through the document-classification feature, or attached to a chat by a member of staff, has its text read whatever its privilege marking says. A firm can narrow which of these sources the assistant may use, or switch the AI features off for its workspace, in its settings. The assistant is restricted to reading and drafting: it cannot send a message to anyone, delete a record, or change personal or billing data.
Two limits worth stating plainly. First, the eligibility check run on an intake submission is not done by AI — it is a fixed rules evaluation (section 3). Neither that check nor anything either AI feature produces is legal advice or a decision about anyone's situation. Second, whether a given AI feature is available depends on how the installation you are using is configured; where the AI provider is not configured, the request is refused and nothing is sent.
5. Sharing
We do not sell personal information. We share it with the service providers that make the Services work, and with attorneys working on the matter you enquired about.
The providers that receive information are:
- Supabase — the database, file storage and sign-in system. Everything described in section 2 is stored here.
- Vercel — hosting for the website and application.
- Twilio — text messages and phone calls, including any voicemail recording (section 11). When someone calls a firm number and the firm holds no record of them yet, that number is also sent to Twilio to look up the name the phone company bills the line to and whether the line is a mobile, a landline or an internet number, so the record we open starts with a name rather than “Inbound Caller”. That name comes from the carrier and not from the caller — it is often a business, a family member, or years out of date — so it is stored together with a note saying where it came from. This lookup runs only for a number the firm does not already hold, and not at all where a firm has not connected a Twilio account.
- Resend, or SendGrid where a firm configures that instead — email we send you, such as intake receipts, portal invitations and signing links.
- Anthropic — the AI features described in section 4.
- Esri (ArcGIS) — address search, converting coordinates to addresses, and maps. Map components and background imagery load directly in your browser from Esri.
- Sentry — error monitoring. It is configured not to record sessions or screens and to strip personal and health information from reports before they are sent.
- PostHog — anonymous usage statistics on public pages only (section 9).
- Google Analytics — anonymous usage statistics on public pages only (section 9), and never on the pages where a matter's intake questions are answered: it is not loaded on them, and if you reach one of those pages from a page it was loaded on, it is switched off before the page is displayed. Unlike every other provider in this list it is loaded into your browser directly from Google rather than routed through our servers, which is what lets the approximate location in section 2 be worked out from your connection rather than from ours.
- The laboratory that analyses a test kit — where a matter involves sampling, kits are processed by the issuing laboratory and their results are imported into your record.
A law firm using the Services can additionally connect its own accounts with Google (Calendar, Sheets and Drive), Microsoft (Outlook and OneDrive), Slack and DocuSign, and can configure webhooks and API keys that send data to systems of its choosing. Those connections are made by the firm, and what leaves through them is the firm's decision.
We may also disclose information if required by law or to protect rights, safety, and security.
6. Security
We maintain administrative, technical and organisational safeguards designed to protect personal information against loss and against unauthorised access, disclosure, alteration and destruction, and we revisit them as the product changes. The rest of this section says what those safeguards actually are, so that the sentence you just read can be checked rather than taken on trust.
Records are separated by firm in the database itself, so a signed-in user can only reach their own firm's rows. Within a firm, access is restricted by role: dates of birth and death, gender identity, the last four digits of a Social Security number, home addresses and parcel locations, privileged notes, and any call recording or transcript are readable only by attorney and administrator accounts — not by case managers or other staff — and a person who cannot see a value is shown that it exists and is withheld rather than that it is absent. Staff can be required to use a second factor to sign in, and a further check can be required before certain health information is opened. Reads and changes to that information are written to an audit record that cannot be edited or deleted.
Intake answers marked as containing health information are encrypted with AES-256-GCM before they are stored, and the system refuses to save them at all if encryption is unavailable rather than storing them in plain text. Credentials a firm gives us for its own third-party accounts are encrypted the same way. Everything else relies on the encryption in transit and at rest provided by Supabase and Vercel.
Links that work without a password. Three things we send you open without signing in, because the link itself is the key: a link to sign an agreement, a link to check the status of a submission, and a shared report link. Each link is signed so it cannot be altered, and each expires. Until it expires, anyone holding the link can open it — including someone you forward it to. The status page is deliberately built to be harmless if forwarded: it shows only a first name, the matter, and a coarse progress step. Shared report links refuse to open at all if they would show claimant-level rows without being scoped to a single claim.
No method of transmission or storage is completely secure, and nothing here is a claim of certification under any particular security or health-privacy standard.
7. Retention
We do not delete case records automatically. There is no expiry clock and no scheduled job that destroys them. When a document is deleted in the application it is hidden from view; the file itself is kept. Leads and client records behave the same way. Audit records are never deleted at all.
The only files that are ever permanently removed are ones that were never attached to anything — a file picked on an intake form that was then abandoned, or a portal message attachment that was never sent — and even those are skipped if a member of staff has hidden them or placed a legal hold on them. A legal hold blocks destruction outright.
We keep records for as long as the matter, our agreements, and applicable record-keeping rules require. Because matters of this kind can stay open for many years, that period is long.
8. Your rights
Depending on where you live, you may be able to ask for a copy of the personal information we hold about you, ask us to correct it, ask us to delete it, or object to how it is used. To make a request, write to us at the address in section 12. We may need to verify who you are, and where the information sits inside a law firm's workspace we will coordinate with that firm.
Two honest limits. First, deletion is not always available: records connected to an open matter are subject to hold obligations, and audit records cannot be removed. Where we cannot delete something we will tell you why. Second, these requests are handled by a person rather than by a self-service tool, so please allow time for a reply.
If you have a client portal account, you can see and use much of this yourself: your case progress, your property and its test results, documents shared with you, questionnaires assigned to you, and your messages with the team. You can upload documents, answer forms, and message us from there. A portal account can only ever reach your own records.
10. International transfers
Information is stored and processed in the United States, and our providers are located there. We do not currently offer storage in any other region. If you access the Services from outside the United States, your information will be transferred to and processed in the United States.
11. SMS & telephone communications
We process phone numbers, message content and attachments, and call metadata — who called whom, the direction, the time and the length — to deliver and log those communications. Pictures and files sent by text are saved to the record.
Calls placed and answered through the platform are not recorded and not transcribed. No recording is made, no announcement is played because there is nothing to consent to, and no audio is sent to a transcription service. If nobody answers, callers are invited to leave a voicemail; producing that message requires our telephone provider to record it, and we store only the fact that a voicemail was left and how long it was — not the audio and not a transcript. Where a call is instead placed or received through the Twilio mobile app, that app can supply a recording link and a transcript, and those are stored; both are restricted to attorney and administrator accounts, while everyone else can see that the call was recorded without being able to open it.
SMS consent and opt-out status, including STOP, START and HELP messages, is recorded so we honour your preferences and to support TCPA and A2P 10DLC compliance. A STOP applies to every record holding that number. Message frequency varies. Message & data rates may apply. Message and call data is shared only with the telecommunications provider needed to deliver it; we do not sell this information, and mobile information is not shared with third parties for their own marketing purposes.
12. Contact
Questions about this policy, or a request under section 8: info@caseconnective.com. We do not operate a separate privacy mailbox — a privacy request sent to that address reaches the people who handle it.
Formal legal notice — notice of a dispute, a claim, or a demand under our Terms of Service — goes instead to legal@caseconnective.com, the address named in section 13 of those Terms.