PRIVACY & DATA SECURITY
Your clients' documents are confidential. We treat them that way.
myDiscovery is built for plaintiff attorneys handling sensitive discovery productions. Here is exactly how we handle your data — no vague promises, no fine print.
Your documents stay in your storage
Every PDF, spreadsheet, and native file you upload is stored in a dedicated DigitalOcean Spaces bucket — a private cloud storage container assigned exclusively to your account. Your files are not stored on shared infrastructure, not co-mingled with other firms' data, and not accessible to anyone except your authorized users.
Raw files are never sent to any AI service. Only the extracted text — the same text you'd see if you opened the PDF — is passed for analysis.
Which AI we use and why it matters
myDiscovery uses Anthropic's Claude — not OpenAI, not Google, not an open-source model running on shared infrastructure. Anthropic is an AI safety company whose API terms for business customers explicitly prohibit using submitted data to train future models.
This is different from consumer AI products. When you use the Claude API through myDiscovery, your data is processed and returned — it is not retained, indexed, or used to improve any model.
Anthropic's API Data Usage Policy: "We do not train our models on your inputs or outputs unless you explicitly opt in." Read Anthropic's full policy →
What leaves your infrastructure and what doesn't
Raw PDF files
Stored in your private Spaces bucket only
Spreadsheets and native files
Stored in your private Spaces bucket only
OCR text extracted from documents
Sent to Anthropic API for analysis, not retained
AI summaries and tags
Stored in your private database only
Your case notes and annotations
Stored in your private database only
Client names and account numbers
May appear in OCR text sent for analysis
Encryption and access controls
- → All data is encrypted in transit via TLS/HTTPS
- → Storage is encrypted at rest in DigitalOcean Spaces
- → Authentication uses 2FA email codes — no passwords stored
- → Each case is isolated — users only see cases their firm is assigned to
- → Access logs are maintained for all logins and activity
The honest limitation
If your requirement is that absolutely zero case text ever leaves your own servers — no cloud AI product meets that bar, including myDiscovery. The OCR text of your documents passes through Anthropic's servers for processing.
If your requirement is that your client's documents are not retained by any AI company, not used to train public models, and not accessible to anyone outside your firm — myDiscovery meets that bar.
Plaintiff-side only
myDiscovery does not work with defense firms. Every firm is reviewed before access is granted. This is not just a business decision — it means your production will never be analyzed by a system that also serves the opposing side in any case.
Questions about privacy or data handling?
We are happy to discuss specific concerns before you commit to using myDiscovery on a case.
