✦ Last updated: 28 June 2026 · Effective: 28 June 2026

Privacy Policy

This Privacy Policy explains how Courts & Cases (operated by Ariham) collects, uses, stores, and protects your personal data. It also describes your rights under the Digital Personal Data Protection (DPDP) Act, 2023 and how to exercise them.

DPDP Act compliance: Courts & Cases is committed to operating in accordance with the Digital Personal Data Protection Act, 2023 (India). Where we act as a Data Fiduciary, we process personal data only for the purposes described in this policy, with your consent where required.

Overview

Courts & Cases is an AI-powered legal drafting and research platform built for Indian advocates, law firms, and legal professionals. When you use our platform, we collect limited personal data necessary to provide the service — your identity for authentication, your usage of platform features, and the content you create and save in your Vault.

We do not sell your personal data. We do not use your vault content or legal drafts for advertising. We process data only to deliver and improve the service you signed up for.

Minimal collection

We collect only what is necessary to run the service — no more.

No data selling

Your data is never sold to third parties or used for advertising targeting.

Indian law

We comply with the DPDP Act, 2023 and applicable Indian law.

Your control

You can request access, correction, or deletion of your data at any time.

Who we are

Data Fiduciary: Courts & Cases, operated by Ariham ("we", "our", "us"), is the Data Fiduciary under the DPDP Act, 2023 in respect of the personal data you provide when using this platform.

The platform is accessible at courtsandcases.com.

For any privacy-related questions or to exercise your rights, contact our Grievance Officer — see the Grievance Officer section.

Information we collect

We collect the following categories of personal data:

Account & identity data

  • Google account information: When you sign in with Google OAuth, we receive your name, email address, and profile photograph from Google. We do not receive your Google password.
  • Credits & billing: Credit balance, purchase history, and transaction identifiers associated with your account.

Content you create

  • Drafts and documents: Legal drafts, written arguments, opinions, and other documents you create using the platform and save to your Vault. This content belongs to you.
  • Research sessions: Queries and outputs from the Research feature, saved as sessions you can revisit.
  • Style samples: If you upload reference documents to personalise your drafting style, we extract and store only the text — the original binary file is never stored.
  • Client records: Names and matter details for clients you add to the platform.
  • Reminders: Reminder text, dates, and associated matter details you create.

Usage data

  • Feature usage: Which features you use, when, and how often (e.g., number of drafts generated, judges profiled). This is used solely to improve the platform.
  • Log data: IP address, browser type, operating system, and request timestamps, collected by our servers for security and debugging purposes.

What we do NOT collect

  • We do not collect Sensitive Personal Data such as financial account numbers, biometrics, health data, or Aadhaar numbers.
  • We do not use third-party advertising trackers or analytics pixels.
  • We do not store the original PDF files you upload for style personalisation.

Why we collect it

We process your personal data for the following specific purposes:

  • Service delivery: Authenticating you, running AI drafting and research features on your behalf, and retrieving your saved documents.
  • Credits & billing: Tracking credit usage, processing payments, and maintaining billing records.
  • Team features: Enabling document sharing within teams you create or join.
  • Platform improvement: Aggregated, anonymised usage analytics to identify features to improve. We do not use the content of your legal drafts for AI model training.
  • Security: Detecting and preventing fraud, abuse, and unauthorised access.
  • Legal obligations: Complying with applicable law, including court orders and regulatory requirements.
  • Communication: Sending you service-related emails (account events, reminders if enabled). We do not send marketing emails without your separate consent.

Your rights under the DPDP Act, 2023

As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights in respect of your personal data processed by us:

Right to access

You may request a summary of the personal data we hold about you and the purposes for which it is processed.

Right to correction

You may request correction of inaccurate or incomplete personal data. For most account details (e.g., display name), you can update these directly from your profile settings.

Right to erasure

You may request deletion of your personal data. We will delete your account and associated data within 30 days of a verified erasure request, subject to any legal retention requirements. Vault documents, research sessions, style samples, client records, and reminders will all be permanently deleted.

Right to grievance redressal

If you believe your rights have not been respected, you may file a grievance with our Grievance Officer (see below). If your grievance is not resolved within the period set by law, you may escalate to the Data Protection Board of India.

Right to nominate

You may nominate another individual to exercise your rights in the event of your death or incapacity. Contact our Grievance Officer to register a nomination.

How to exercise your rights: Email our Grievance Officer at [email protected]. We will respond within 30 days. We may ask you to verify your identity before acting on a request.

Grievance Officer

In accordance with Section 13 of the Digital Personal Data Protection Act, 2023, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have appointed a Grievance Officer.

If your grievance is not resolved to your satisfaction within the statutory period, you may approach the Data Protection Board of India once it is constituted and operational, or seek other remedies available under Indian law.

Third-party processors

We engage the following third-party service providers who may process your personal data on our behalf. All processors are bound by data processing agreements that require them to protect your data.

We do not permit our processors to use your personal data for their own purposes.

Data retention

We retain your personal data for as long as your account is active or as needed to provide the service, and thereafter for the periods below:

  • Account & identity data: Retained while your account is active. Deleted within 30 days of a verified erasure request.
  • Vault documents, research sessions, style samples, client records, reminders: Deleted within 30 days of account closure or erasure request.
  • Credits & billing records: Retained for 7 years to comply with tax and accounting requirements, even after account deletion. This is limited to transaction records and does not include the content of your legal documents.
  • Server logs (IP, request timestamps): Retained for 90 days for security and debugging, then automatically purged.
  • Aggregated usage analytics: Anonymised and retained indefinitely for platform improvement. Once anonymised, this data cannot be used to identify you.

Cross-border data transfers

When you use AI features on Courts & Cases (drafting, research, judge profiling, AI summaries), your prompts and document content are sent to Microsoft Azure OpenAI, which processes data in the United States.

Microsoft is bound by appropriate data processing agreements and complies with applicable data protection frameworks. The transfer is necessary to deliver the core AI features of the platform.

All other data — your account, vault documents, research sessions, and billing records — is stored on servers in India (Azure East India region).

Security

We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse:

  • Encryption in transit: All connections to Courts & Cases use HTTPS/TLS. We enforce HTTPS-only access.
  • Encryption at rest: Data stored in our database is encrypted at rest.
  • Access controls: Database access is restricted to the application server; no direct public access is permitted.
  • Minimal exposure: API documentation and admin interfaces are disabled in production. Database ports are not publicly accessible.
  • Audit logging: Significant actions (e.g., document sharing, team management) are audit-logged.
Security incident: If you suspect your account has been compromised, contact us immediately at [email protected].

Cookies & local storage

Courts & Cases uses a minimal set of cookies and browser storage necessary for the service to function:

  • Session cookie: A signed, HTTP-only session cookie that keeps you logged in. It expires after 30 days of inactivity. This cookie is strictly necessary and cannot be disabled while using the service.
  • Local storage preferences: Dark mode preference and other UI settings are stored in your browser's localStorage. This data never leaves your device.

We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies.

Children

Courts & Cases is a professional platform intended for legal practitioners and is not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account, please contact us at [email protected] and we will delete the account promptly.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes affecting your rights, we will notify you by email (to the address associated with your account) at least 14 days before the changes take effect.

Your continued use of the platform after the effective date constitutes acceptance of the updated policy.

Contact us

For any questions about this Privacy Policy, to exercise your rights, or to file a grievance:

You also have the right to approach the Data Protection Board of India (once operational) if your grievance is not resolved within the statutory period under the DPDP Act, 2023.