Privacy Policy

Last updated:

This page describes how UT Chart works. It is not legal advice.

OptionWhere it goesWhat is sentWhose account
OffNoneNothing leaves the platform—
AI assistance we operateGoogle (Gemini)Question and answer text of individual chart itemsTempusLexIT Inc.
Your own provider keyOpenRouter, Google, OpenAI, or Anthropic — whichever your firm selects, and a model you specify if you set oneQuestion and answer text of individual chart itemsYour firm

AI wording assistance is optional. Your firm can turn it off, in which case no transcript text is sent to an AI provider.

Your firm can supply its own provider key for OpenRouter, Google, OpenAI, or Anthropic. When you do, we send excerpts to that provider using your key, and to a model you choose if you specify one. Your agreement with that provider governs what happens to them, and we make no representation about it.

Whether excerpts sent for wording drafts may be used to improve the provider’s models depends on the service tier in use. We will state our position here once that is settled.

Subprocessors
NamePurposeData reachedLocation
Amazon Web ServicesHosting and object storageTranscripts, account dataRegion set in the deployment configuration
GoogleAI wording drafts (Gemini), on the AI assistance we operate; and sign-in with a Google accountQuestion and answer text of individual chart items. For sign-in, the email address, the name on the Google account and an account identifier. Never the full transcript or the PDF.Outside Canada
ResendTransactional email deliveryEmail address and name of the recipient, and the contents of the message sent to them. No transcripts.Outside Canada
StripeBillingAccount and payment data. No transcripts.Outside Canada

Signing in with a Google account is offered, and Google is told that the account holder is signing in to UT Chart. Google returns the address, the name on the account and an account identifier, which are stored.

Deleting a case moves it to a deleted-cases area, where your firm can restore it for the period stated above. We will state here what happens to the underlying transcript file at the end of that period once we have verified that behaviour in the production environment.

The application does not terminate TLS itself; what protects a connection to it depends on how a deployment is fronted. We will state the transport protections that apply here once the production deployment is verified.

Encryption of stored files is a property of the storage service a deployment points at, not something we set on each object we write. We will state what applies here once the production storage configuration is verified.

Transcripts and account data are stored in Amazon Web Services object storage. The storage region for a given deployment is set in that deployment’s configuration.