Last updated: July 4, 2026
Sidebar is a legal AI workspace built for attorneys, which means we are held to the standard our customers are: confidentiality by default, and no surprises. This policy says what we collect, what we do with it, and what we never do with it — in plain language.
Draft — pending attorney review. This document describes how Sidebar actually operates today and is published for transparency while formal legal review is completed. It will be finalized before general availability.
Account information. Your name, email address, and firm/organization details, managed through our authentication provider (Clerk). We never see or store your password.
Workspace content you create.Conversations with the AI, documents you upload, research memos, generated drafts, and matter memory. This is your data; we store it so your workspace persists between sessions — see “How we protect it” below.
Usage metadata. Which model handled a request, token counts, estimated cost, and timestamps — used for billing and rate limiting. Usage records do not contain your message content.
Billing information. Handled by Stripe. Stripe sees your payment details and billing identity; it never sees any workspace content.
Error reports. If an error occurs, a scrubbed report (no request bodies, no personally identifying content) may be sent to our error-monitoring service (Sentry).
We use your information to operate Sidebar: run your AI requests, persist your workspace, bill your subscription, enforce rate limits, and fix errors. That is the complete list of purposes.
What we never do: we do not sell your data; we do not use your content for advertising; we do not use your content to train AI models; and no AI provider we route to retains your content or trains on it (see Section 4).
All traffic is encrypted in transit (TLS 1.2+). Your workspace lives in a database partition isolated per firm, enforced on every request with row-level security as a backstop. Conversation content, extracted document text, research memos, and matter memory are additionally encrypted at rest with application-layer AES-256-GCM under Sidebar's own key, on top of our infrastructure's disk encryption. Uploaded original files and generated documents are stored in private, access-controlled storage. Workspace labels (conversation titles, matter names) are stored unencrypted so lists and search work; if you prefer, use matter numbers rather than client names in titles.
All content-bearing infrastructure runs in the United States. We do not currently offer other data-residency options.
Your prompts and documents are sent to the AI model you select, and every model we offer is reachable only because a zero-retention agreement is already in place with that provider — it is never a bolt-on setting. Claude (the default) runs in an isolated, contractually zero-retention cloud environment; OpenAI requests are sent with storage disabled on every call, enforced in code; Google's Gemini runs under a signed zero-retention agreement. No provider stores your content after processing or uses it for training.
Research queries.When you use case-law or web research, search queries are composed by the model from your conversation and sent to CourtListener (public case-law database) and Brave (web search). We attach no account or firm identifiers to these queries, but the query text itself derives from your conversation — an inherent property of any web-grounded research. If a matter is too sensitive for external research, don't enable research for it.
Your workspace is retained until you delete it. Deleting a conversation or matter is a hard delete: the messages, extracted document text, and uploaded original files are removed from our systems, not soft-hidden. Certain internal records (such as encrypted tool-audit content) are automatically purged after 30 days.
Full account erasure — everything, across all matters — is self-serve: closing your account hard-deletes every record and stored file in your workspace. If you prefer, you can also request erasure by email at privacy@sidebar-ai.com and we will honor it completely.
Our position is that demands for your content belong with you, the account holder. Unless we are legally prohibited from doing so, we will notify you of any subpoena or legal demand for your data before responding and give you the opportunity to object. The full policy is in our Legal Process Policy.
We use a limited set of vendors to operate the service — including the AI providers, case-law and web-search services, error monitoring, and billing. Each sees only what it needs to perform its function, and we will notify you before adding or changing any subprocessor that handles workspace content.
We use only the cookies required to keep you signed in and to operate the service (set by our authentication provider). We do not run third-party advertising trackers, third-party analytics, or session-recording/“session replay” tools on your workspace, and we do not sell or share your information for targeted advertising.
Your workspace is backed up by our database provider for reliability and disaster recovery, within the same United States region and inside the same isolation and encryption boundary as your live data. When you delete content or close your account, the deletion propagates to these copies as they cycle out; we do not maintain a separate long-term archive of deleted content.
If you contact us for support, a limited number of authorized personnel may access what is necessary to resolve your issue, and only for that purpose. Access to production systems is restricted, and our internal diagnostic tooling records its use in an access log.
Sidebar is operated from and stores all workspace content in the United States. We do not offer other data-residency regions today. If you access the service from outside the United States, you understand your information is processed in the United States.
You can access your data in the product, export conversations, delete conversations and matters yourself, and request full account erasure (Section 5). Depending on your state of residence, you may have additional statutory rights — such as the right to access, correct, delete, or obtain a copy of your personal information, and to be free from sale of it (we do not sell it). To exercise any of these, contact us and we will honor them; we do not discriminate against you for doing so.
Sidebar is a professional tool and is not directed to, or for use by, anyone under 18. We do not knowingly collect information from minors.
Sidebar is operated by Sidebar AI LLC, an Illinois limited liability company. How we protect your data is described in Section 3 and on our Security page. To report a security concern or vulnerability, email security@sidebar-ai.com. For any other privacy question, or to exercise your rights, contact privacy@sidebar-ai.com.
If we make material changes to this policy, we will notify account holders by email before the changes take effect, and update the “last updated” date above.