This page is Casehand's privacy notice and its data-handling plan. It forms part of the terms of service and is read with the data processing addendum the Customer accepts with the terms. Words with capitals that are not defined here have the meaning the terms give them.
1. Scope and roles
Casehand is operated by Entropic LLC ("Casehand", "we", "us"). Casehand is software for immigration law firms, lawyers and recognized organizations with accredited representatives. It is not a law firm and does not give legal advice.
Customer Data. The firm that holds a Casehand account (the "Customer") decides what client information goes into Casehand and why. For that information the Customer is the controller, or the "business" under California law, and Casehand is its processor and service provider. We process Customer Data only to provide the service to the Customer, on its documented instructions, which are the terms, this page, the data processing addendum and the Customer's use of the product's settings and features.
Account and site data. For the details of the people who use Casehand, their support tickets, and visitors who write to us through the contact page, Casehand decides the purposes and is responsible as controller.
This page does not cover the Customer's own handling of its clients' information. A client of a law firm should ask that firm about it.
2. What we hold
Customer Data, entered or uploaded by the Customer's users:
- Notice files the firm uploads, the text read from each page, and a fingerprint (SHA-256) of each file used to detect duplicates.
- Values read from each notice, with the printed text each value came from: for example notice type, receipt number, A-number, names, date of birth, notice, decision, hearing and appointment dates, court, judge and office.
- Client records: names and aliases, A-number, date of birth, preferred language, email, phone, and a reference to the firm's case management system.
- Matter records: matter number, forms, receipt numbers, court, office, status and assigned attorney.
- Deadlines with their rule, citations and inputs, expected-notice alerts, case status text the firm pastes in, and drafts of client updates.
- The firm's audit log of views, edits, approvals, overrides, exports and sign-ins.
Account data about each user: name, work email, role (clerk, paralegal, attorney or admin), the firm they belong to, and session records. Sign-in is by a six-digit code sent by email. Codes are stored only as one-way hashes, last 15 minutes and work once. Where a password is used instead, only a salted hash of it is stored.
Support data: the tickets a user files on the Support screen and the replies to them. Replies are written by software and a person reads every case it hands up. A copy of each ticket from a firm account, with email addresses, A-numbers, receipt numbers and phone numbers removed, is kept as an issue in our private issue tracker on GitHub, where our staff answer the cases handed up. The Support screen asks users to leave client details out.
Contact page data: the name, email, firm and message you send. Your network address is stored only as a salted one-way hash, to limit abuse.
Technical data: our hosting provider processes network addresses and request details to deliver and protect the service, and we keep operational logs of requests and errors to run and secure it.
We do not buy personal information, and we do not collect information about your clients from any source other than the Customer.
3. Sensitive data and minors
Immigration notices carry sensitive information: A-numbers, dates of birth, addresses, immigration status, and sometimes passport numbers, criminal or removal history, or other details printed on a government document. California treats citizenship and immigration status as sensitive personal information. Casehand processes this information only as the Customer's service provider, only to provide the service, and never to infer characteristics about anyone.
Immigration files often concern children. Casehand is not directed to children, does not collect information from children directly, and requires every user to be an adult acting for the Customer. Information about a minor reaches Casehand only when the Customer uploads it, and is processed only on the Customer's instructions under this page.
The Customer is responsible for having a lawful basis, and any consent it needs, for the information it puts into Casehand.
4. How we use it
We use Customer Data only to:
- provide the service: read notices, match them to clients and matters, compute deadlines, keep the firm's records, and produce the exports and calendar feeds the firm asks for;
- keep the service secure, prevent abuse, and investigate faults the Customer reports;
- comply with law, as described in section 10.
We use account data to run accounts, send sign-in codes and service notices, and bill for paid plans. We use support and contact page data to answer you and to fix what you report.
We do not sell personal information, share it for cross-context behavioral advertising, or use it for marketing to anyone other than the user it belongs to. We do not use Customer Data to train AI models, and we do not combine it with data from other customers or other sources. Casehand does not send messages to the Customer's clients: client updates are drafts that the firm reviews and sends itself.
We may use operational measurements that contain no Customer Data content, such as counts, timings, error rates and how often independent reads agree, to run and improve the service.
Where the law of a place outside the United States applies to our own processing of account or contact page data, we rely on performance of our contract with the Customer and on our legitimate interest in running and securing the service.
5. AI reading of notices
AI models read uploaded notices and propose values. They never set a deadline. Deadlines come from a deterministic rules engine that shows its citation, and nothing reaches the firm's docket until a user approves it.
Today notices are read on Cloudflare Workers AI. Cloudflare states that it does not use customer inputs to Workers AI to train models. Anthropic, PBC is listed on the subprocessors page as planned. It receives no Customer Data until that page lists it as active. When it is active, the text read from a notice is sent to Anthropic through Cloudflare AI Gateway with request logging switched off on every request, and scanned pages are still transcribed on Workers AI first. Anthropic's commercial terms state that it does not train its models on customer content sent through its API, and permit it to keep inputs and outputs for a limited period as those terms describe.
We use a model provider only under terms that do not allow it to train on Customer Data.
6. Where data is held
Casehand runs on Cloudflare. Records are held in a Cloudflare D1 database and notice files in Cloudflare R2 object storage, both created with Cloudflare's location hint for eastern North America. A location hint places the primary copy; it is not a legal restriction. Requests are handled at the Cloudflare data center nearest the user, and AI inference runs where Cloudflare places it, which may be outside the United States. We do not move Customer Data out of the United States ourselves, but we do not promise that every processing step happens inside it.
7. Subprocessors
The subprocessors page lists every company that processes Customer Data for us, what it does and which data it handles. Cloudflare, Inc. is the only active subprocessor today.
We list a new subprocessor on that page at least 30 days before it receives Customer Data. If a Customer objects on reasonable data protection grounds within that period, we will discuss the objection in good faith. If we cannot resolve it, the Customer may end the affected subscription by notice before the change takes effect and receive a refund of fees prepaid for the period after termination. That is the Customer's only remedy for the objection.
Each subprocessor is bound by written terms that protect Customer Data at least as well as this page in substance, and we are responsible for its performance of them.
8. Security
- All traffic to Casehand uses TLS. Records and files are encrypted at rest by our hosting provider.
- Every query is scoped to the Customer's own firm, and the data layer refuses one that is not.
- Access inside a firm is set by role. Only attorneys confirm deadlines, and two-person docketing is on by default.
- Sessions end after 12 hours. Deactivating a user ends their sessions at once.
- The audit log is append-only: the database refuses any edit or deletion of an entry.
- Sign-in codes and password guesses are rate limited per address.
- Calendar feeds show matter numbers and client initials only, never a name, A-number or receipt number. Feed links are secret and can be rotated.
The security page describes our controls and how to report a vulnerability.
The Customer is responsible for its own side: who it invites, the roles it gives them, keeping their email accounts and devices secure, keeping calendar feed links private, and removing people who leave.
9. Security incidents
A security incident means a confirmed breach of our security that leads to unauthorized access to, or accidental or unlawful loss, alteration or disclosure of, Customer Data. Unsuccessful attempts, such as blocked sign-in attempts, scans and denial of service attempts, are not security incidents.
We will notify the Customer's admins without undue delay, and in any case within 72 hours after we confirm a security incident affecting its Customer Data. The notice will say what we know at the time and will be updated as we learn more. We will take reasonable steps to contain the incident and will give reasonable help so the Customer can meet its own notification duties to clients and regulators. The Customer decides whether to notify its clients. Our notice of an incident is not an admission of fault or liability.
10. Government and law enforcement requests
Many of our Customers' clients are in removal proceedings. We do not give Customer Data to any government agency voluntarily, including the Department of Homeland Security, Immigration and Customs Enforcement, and Customs and Border Protection.
- We disclose Customer Data only when compelled by a valid, binding legal order, such as a subpoena, court order or warrant, that is properly served on us.
- We first ask the requester to seek the data from the Customer directly.
- We review each demand, and we object to or seek to narrow one that is overbroad, unclear or not properly issued, where we have a reasonable basis to do so.
- We tell the Customer promptly and before disclosure, so it can seek a protective order, unless the law or a court order prohibits it. If we are prohibited, we tell the Customer once the prohibition ends.
- We disclose only the minimum the demand requires.
The same applies to demands from private parties in litigation.
11. Retention and deletion
This schedule is the retention policy for Casehand.
| Data | How long we keep it |
|---|---|
| Customer Data, including notice files, records and drafts | For the life of the subscription. Deleted from live systems within 30 days after the subscription ends. |
| Audit log | For the life of the subscription, unchangeable by any user. Deleted with the rest of the Customer Data. |
| Backup and recovery copies | Age out within 30 days after the live copy is deleted. They are not restored except to recover the service. |
| User accounts | For the life of the subscription. A deactivated user stays on record so the audit log can name who did what. |
| Sessions | 12 hours. Expired sessions are removed daily. |
| Sign-in codes | Stored as a hash only, valid for 15 minutes, cleared once used. |
| Invitations | Valid for 7 days; kept as a record for the life of the subscription. |
| Sample firms opened from the site | Deleted, with their files, 3 days after they are opened. They hold synthetic data only. |
| Operational logs | No longer than 30 days. |
| Contact page messages | 24 months after the last exchange. |
| Billing records and the record of which terms version a firm accepted | For as long as tax, accounting and legal duties require, and no longer than 7 years after the account ends. |
Export. While the subscription runs, attorneys and admins can export clients, matters, deadlines and the full audit log as CSV, and can download each notice file. During the 30 days after the subscription ends, the Customer may ask through the contact page for an export of its Customer Data, including its notice files, and we will provide it. Firms that must keep records for longer than this schedule, for example under their own file retention rules, are responsible for exporting them.
Deletion on request. An admin may ask us to delete the firm's account and Customer Data at any time. We do so within 30 days of the request, and backup copies age out as above.
Legal holds. We keep data longer only where the law requires it or a valid legal order directs it, and then only the data concerned and only for as long as required. We tell the Customer unless we are prohibited.
12. Cookies and browser storage
Casehand sets one cookie, ch_session, when you sign in. It keeps you signed in, cannot be read by page scripts, is sent only over encrypted connections, and expires after 12 hours. The app also stores your table density choice and whether you have closed a banner in your own browser's storage. Nothing stored this way leaves your browser.
There is no analytics, advertising or tracking code on this site or in the app, and we do not sell or share data for advertising. Casehand sets no cookie when you only read the public pages.
13. California and other state privacy laws
For Customer Data, Casehand acts as a service provider or processor under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and under comparable state laws. We:
- process Customer Data only for the business purposes set out in the terms and this page;
- do not sell or share it, or retain, use or disclose it outside our direct business relationship with the Customer;
- do not combine it with personal information we receive from anyone else, except as those laws permit;
- give it the level of protection those laws require, and tell the Customer if we can no longer meet our duties under them;
- allow the Customer, on written request, to take reasonable and appropriate steps to stop and remedy unauthorized use;
- help the Customer respond to requests from its clients, as section 14 describes.
14. Requests about your data
If you are a client of a law firm that uses Casehand, your firm controls your information. Contact the firm. If you contact us, we will send your request to the firm and will not act on it ourselves except on the firm's instruction or where the law requires.
If you are a user or wrote to us, you may ask to know, correct or delete what we hold about you as controller. Use the contact page and choose "Privacy request". We verify the request against the email address on record and answer within 45 days. We will not treat you differently for making a request. Where a user's details sit in a firm's audit log, deleting them is the firm's decision.
15. Changes
We will post any change to this page here with a new version line. If a change materially reduces the protection of Customer Data, we will tell Customer admins by email at least 30 days before it takes effect. Changes that the law requires, or that add protection, may take effect at once.
16. Contact
Entropic LLC, 1309 Coffeen Avenue, Ste 1200, Sheridan, WY 82801. Email hi@casehand.ai. Privacy requests and questions can also go through the contact page, topic "Privacy request". Please do not include client information in a message.