Privacy Policy
Effective date: August 26, 2026
1. Scope, Who We Are, and Our Role
Handled Legal Technologies, LLC, a Nevada limited liability company doing business as Handled., is referred to throughout this Privacy Policy as "Handled." Handled. is the provider responsible for this Privacy Policy and provides the services described in this document. Questions and legal notices may be sent to [email protected].
Handled. ("we," "us," or "our") provides litigation case-management software and related services. This Privacy Policy explains how we handle information through the Handled. website, accounts, subscriptions, support, and desktop application (collectively, the "Service"). It describes information practices only; it does not expand any software license or other rights under the Terms of Service or EULA. Transaction-specific checkout and trial disclosures control if they conflict with this Policy, and applicable law controls where it cannot be waived.
The Service is designed for professional and business use by litigation attorneys and their authorized assistants or paralegals in the United States. It is not directed to consumers acting in a personal or household capacity.
Our two roles. We handle two kinds of information in two different roles:
As a business/controller, for the limited account, authentication, license, device, billing, and support information we collect to provide the Service to you, we determine the purposes and means of processing and act as a "business" (California) or "controller" (other states).
As a service provider/processor, for the case information you enter, import, synchronize, back up, or export ("case information"), you (or your firm) are the business/controller, and we process that information solely on your behalf and under your instructions. Our processing of personal information within case information is governed by our Data Processing Addendum (the "DPA"), which is incorporated by reference. For most of that case information on Pro, we hold only a protected copy we cannot read (Section 3).
2. Categories of Information We Handle, and Why
We handle the following categories of personal information, the sources they come from, and the purposes for handling them:
- Case information. Matter names and numbers, clients, parties, counsel, courts, judges, dates, deadlines, notes, and next actions, collected from you and your authorized users, used to provide local case management and, on Pro, protected synchronization and collaboration processed on your behalf under the DPA.
- Account and authentication. Email address, account and user identifiers, authentication and session data, account roles, and login or license-revalidation records, collected from you, used to create and secure accounts and authenticate users.
- License, device, and collaboration. Plan and license status, device identifiers and names, device public keys, invitation addresses and status, owner and assistant roles, and registered-device records, collected from you and your device, used to validate licenses, enforce plan, seat, and device limits, and manage invitations.
- Recovery, protection, and synchronization. Wrapped key material, public keys, key-version numbers, account and matter identifiers, table and row relationships, timestamps, and deletion and synchronization state, collected from your device, used to operate protection, recovery, and synchronization; we do not receive the recovery phrase or raw account key.
- Billing and trial. Subscription, plan, trial, cancellation, expiration, and billing-state information, collected from you and Lemon Squeezy, used to administer trials, subscriptions, and billing.
- Support communications. Email address, message, and attachments you send, collected from you, used to respond to support and privacy requests.
- Website and delivery. Information generated when you visit the site or download the application, collected from you and your browser, used to host the website and deliver the application; if you accept our cookie banner, also used to understand site traffic through Google Analytics (Section 8).
We may collect sensitive information only incidentally, within case information you control; we process it solely on your behalf under the DPA and do not use it to infer characteristics about you.
3. Where Case Information Lives
Free and Solo case information stays in the encrypted local application database on the user's computer. Those plans do not copy case content between users or computers through Handled. Pro also keeps a protected online copy so an account owner and one invited assistant or paralegal can work from authorized computers. Before upload, case content is protected on the device, and we do not hold the key required to read that protected content. We can read and process the operational account, license, device, invitation, key-wrap, and synchronization metadata described in Section 2; that metadata can reveal facts such as which account, device, record, or key version is involved and when an update occurred, though it does not reveal the protected case content itself.
The Service does not independently monitor courts or discover docket information; users supply and verify their own case information.
4. How We Use Information
We use information to: create and authenticate accounts; register devices, validate licenses, and enforce plan, seat, and device limits; provide the local application and, for Pro, store the protected online copy and synchronize authorized updates; administer invitations, trials, subscriptions, plan changes, cancellations, and billing; protect the Service, investigate misuse, prevent fraud, troubleshoot, and maintain security; respond to support and privacy requests; and comply with law and preserve records for billing, tax, security, fraud-prevention, dispute, and legal-compliance purposes.
We do not use case information for advertising, to train machine-learning or artificial-intelligence models, or for unrelated product development. We do not use protected Pro case content for these operational purposes because we cannot read it; storing, transmitting, and synchronizing that protected content is still processing it on your behalf under the DPA.
5. How We Share Information; No Sale or Sharing for Advertising
We disclose information only to the service providers and recipients below, each acting under a written contract that limits their use of the information to providing services to us:
- Supabase, authentication and storage of account, license, seat, device, invitation, login/revalidation, key-wrap, and protected Pro synchronization records.
- Lemon Squeezy, checkout, subscription administration, and cancellation as merchant of record; sends us billing and license events.
- Resend, sends assistant-seat invitation email (processes the recipient address and invitation content).
- Netlify, builds and hosts the website.
- GitHub, hosts application release files reached through the website's download route.
- Google Analytics (Google LLC), provides website traffic analytics, and only receives information if you accept our cookie banner; declining keeps it from receiving any information (Section 8).
- An invited assistant or paralegal, can receive future authorized access to the Pro account's case information after accepting the invitation and completing device approval; the account owner decides whom to authorize.
- Government authorities, courts, or other parties, only as Section 11 permits or requires.
A current list of our subprocessors is set out in Section 8 of the Data Processing Addendum, incorporated by reference. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under applicable state privacy law. We have not sold or shared personal information in the preceding 12 months.
6. How Long We Keep Information
We keep each category of information only as long as reasonably necessary for the purpose for which it was collected, subject to the periods below:
- Local application data. Remains on your computer until you delete or overwrite it, or the storage is lost; we do not control or delete local data.
- Protected Pro copy and obsolete access or recovery records. Protected Pro case information and obsolete access or recovery records are automatically deleted within 30 days after leaving Pro.
- Account, invitation, device, and access records. Kept while the account is active; deleted within 30 days after account deletion, subject to the limited-retention items below.
- Billing, tax, fraud-prevention, security, dispute, and legal-compliance records. Up to seven years when reasonably needed for those purposes or required by law.
- Support communications. Kept as reasonably needed to address the request and maintain a record, and then deleted within 24 months, unless a longer period is required by law or an open dispute.
- Provider logs and backups. Retained per each provider's standard configuration; copies in provider backups expire through the provider's ordinary backup lifecycle, generally within 30-90 days.
- User-created files (.lhbackup, CSV export). Controlled by you; remain wherever you save them until you delete them; they do not inherit the local database's encryption or Pro's online protection.
7. Your Privacy Rights and Choices
Depending on your state of residence and applicable law, you may have the right to: (a) know or access the personal information we hold about you and the categories of sources, purposes, and recipients; (b) obtain a portable copy; (c) correct inaccurate information; (d) delete your information; (e) opt out of any sale or sharing for cross-context behavioral advertising (we do neither); and (f) limit the use of sensitive personal information (we use it only to provide the Service you request). We will not discriminate against you for exercising these rights.
How to submit a request. Email [email protected], or use the in-application account controls. Because we operate online and have a direct relationship with you, email is a designated request method. We will verify your identity and authority over the account and will respond within 45 days, extendable once by an additional 45 days where reasonably necessary, with notice to you. You may use an authorized agent, subject to reasonable proof of authorization. If we deny a request, you may appeal by replying to our decision; we will respond to an appeal within the period required by your state's law.
Requests about case information. Where we hold case information as a service provider/processor on your behalf, we will direct a request we receive from an individual whose data appears in that information to you (or your firm) as the controller, and we will assist you in responding, as described in the DPA. Rights do not extend to personal information about another person that we maintain on your behalf.
You can manage information in the application, create a .lhbackup, and, on Solo or Pro, create a CSV report. A CSV report contains only a subset of application information and is not a complete backup. You are responsible for protecting, retaining, and securely deleting files you export.
A Pro account owner can remove the invited assistant or paralegal and registered devices. Removal blocks future authorized online access after the system processes it, but it does not erase case information already stored on the other person's computer or retrieve information that person already viewed, copied, exported, photographed, or otherwise retained, and it should not be understood as completed key rotation or re-encryption of previously stored content.
8. Cookies and Tracking
Our website uses local storage and session storage strictly necessary to operate the site, for example to remember your cookie choice and to keep you signed in. If you accept our cookie banner, we also use Google Analytics to understand site traffic, such as which pages are visited and for how long. Google Analytics sets cookies and is the only third-party analytics tool we use; we do not use advertising or cross-site tracking tools of any kind, and Google Analytics is not used for advertising.
You can decline Google Analytics at any time from the cookie banner, which keeps it from loading. If you previously accepted, you can withdraw consent by clearing your browser's local storage for this site or by using Google's Analytics opt-out browser add-on. We do not sell or share personal information for advertising.
9. Where Information Is Processed
We and our service providers, Supabase, Lemon Squeezy, Resend, Netlify, and GitHub, are based in the United States. If you accept our cookie banner, Google Analytics also processes limited website-traffic information, as described in Section 8; that processing occurs on Google's infrastructure, which may include locations outside the United States. The Service is directed to users in the United States and is not offered to individuals in the European Economic Area, the United Kingdom, or other jurisdictions whose data-transfer laws would apply.
10. Business Use and Age Requirement
The Service is offered only for professional or business use by people who are at least 18 years old and have authority to create or use the relevant account. It is not directed to children, and users should not provide the Service directly to anyone under 18.
11. Legal Requests
We may preserve, use, or disclose information in response to a subpoena, court order, government demand, or other legal process only when legally required. When legally permitted, we will give the affected account owner advance notice so the owner may seek protection or otherwise respond. We may withhold notice where law prohibits it or where a legally permissible emergency, safety, security, or fraud concern makes advance notice inappropriate.
Because we cannot read protected Pro case content, our ability to produce intelligible case content from the protected online copy is limited. We may still be able or required to preserve or disclose readable account, device, license, invitation, key-wrap, synchronization, billing, support, or other operational records.
12. How We Protect Information; Reasonable Security
We implement and maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of the information we handle, designed to protect it from unauthorized access, use, modification, destruction, or disclosure. The desktop application is designed to store its working database in an encrypted local database using a key held through the computer's operating-system credential store. Pro protects case content on the device before uploading it, and we do not hold the key needed to read the protected online copy. Access to online systems requires an authorized account seat and a current Pro license.
These measures reduce risk but cannot guarantee perfect security. Security also depends on users protecting their computers, operating-system accounts, credentials, recovery information, authorized devices, exported files, and access granted to others. No method of storage, transmission, authentication, or encryption eliminates all risk.
13. Recovery Information and Authorized Devices
Pro's account key and human-readable recovery phrase are generated or derived on an authorized computer. Current setup and recovery flows do not send the recovery phrase or raw account key to us. We store device-specific protected key material and related operational records, but we cannot recreate a lost recovery phrase from those records. Keep recovery information somewhere safe and separate from the computer.
A new assistant device submits a public key and displays a fingerprint that an owner device must confirm before it can synchronize; an owner may use the recovery phrase to authorize an additional owner device.
14. Security-Incident Notices
We maintain an incident-response process. If a security incident affects information for which notice is legally required, we will notify affected individuals and any regulators as required by applicable law, without unreasonable delay and within the timeframes the law requires. Where we process personal information on your behalf as a service provider/processor, we will notify you (or your firm) of a relevant incident without undue delay so that you can meet your own notification obligations, as further described in the DPA.
15. Changes to This Policy
We may update this Policy as the Service, information practices, providers, or legal requirements change. The revised Policy will identify its effective date, and we will provide additional notice or obtain consent where legally required. A change to this Policy does not itself expand rights under the Terms of Service or EULA.
16. Contact Us
For privacy questions, correction or deletion requests, or requests concerning a protected online copy, email [email protected]. For accessibility feedback, see our Accessibility Statement.