Legal draft
AI Data Policy
This page should become the client-facing explanation of when AI tools are used, what data may be processed, what stays human-reviewed, what consent is required, and which providers are involved.
AI use
AI may be used for document summaries, AI Systems Audit analysis, drafts, triage, internal assistance, workflow review, and other support tasks only when appropriate for the project.
Consent
Sensitive client documents should not be sent to an AI provider unless the client has consented to that use and the purpose has been recorded.
Human review
AI can draft, summarize, classify, and organize. Important customer-facing outputs, pricing decisions, legal interpretation, sensitive communications, and business-critical decisions should be reviewed by a person.
Server-side processing
AI calls should run through backend functions. API keys should never be exposed in frontend code or shared with client browsers.
Records
The app should record AIRun entries showing provider, purpose, related project, consent state, timestamp, and responsible user.