What we store
Your account. Your email address and subscription. Billing details are held by Stripe; JuraSum does not receive or store card numbers.
Your saved matters and firm profile, encrypted. When you save a matter, the figures, matter name, notes and results are encrypted in your browser before anything is sent. What reaches our servers is unreadable ciphertext, together with a record identifier, its size and the time it was saved.
Figures you have not saved. These are not transmitted. Calculations in every tool are performed in your browser.
We do not log the contents of requests.
Who can read your matters
Only a person who knows your vault passphrase or holds your recovery key. You set the passphrase the first time you save a matter; it never leaves your computer. The recovery key is shown to you once, for you to print and store.
JuraSum, Cloudflare and Stripe cannot read your saved matters. The encryption uses AES-256-GCM through the Web Crypto API built into your browser, with a key derived from your passphrase using PBKDF2-SHA256 at 600,000 iterations.
On a computer where you have unlocked your vault, your matters are also kept in that browser so the workspace opens promptly. Signing out removes them from that computer.
Where it is stored
Encrypted matters are stored in Cloudflare's D1 database service. The site and its sign-in service are also operated on Cloudflare.
Deletion and retention
| When you | What happens | When |
|---|---|---|
| Delete a matter | The stored copy is deleted. A marker containing only its identifier and the time is kept so that your other computers remove it too. | Immediately |
| The deletion marker is removed. | After 30 days | |
| Database backups, which contain only ciphertext, age out. | Within 30 days | |
| Reset your vault | Every stored matter and your vault keys are deleted. | Immediately |
| Let a subscription lapse | Stored matters remain available to read and export. | For 60 days |
| The vault and stored matters are deleted, after notice by email 14 days and 2 days beforehand. | After 60 days | |
| Ask us to delete your account | All of the above, and your billing record at Stripe. | On request |
What we cannot do
- Reset or recover your vault passphrase.
- Open your stored matters if both the passphrase and the recovery key are lost.
- Produce readable matter data in response to a subpoena or other demand, because we do not hold any.
We can, and must, respond to lawful requests for the account information we do hold: your email address and subscription records.
What remains your responsibility
Your duty of confidentiality, and the judgment about whether and how to use any technology service with client information, remain yours. This page is written to make that assessment simpler, not to replace it. We recommend that client names be kept to initials in matter names.
Your passphrase and recovery key protect your matters. Keep the recovery key with your other firm credentials, and do not share the passphrase outside the firm.
Sub-processors
| Provider | Purpose | Receives |
|---|---|---|
| Cloudflare | Hosting and encrypted storage | Ciphertext, email address |
| Stripe | Subscriptions and billing | Email address, billing details |
| Resend | Sign-in email | Email address |
Questions about this page may be sent through the contact page.