Skip to main content

Legal

Subprocessors

Last updated: September 28, 2026

Why this page exists. CourtFlow AI uses a small number of specialized vendors to deliver the Service. This page lists every entity (a "Subprocessor") that may process customer data on our behalf, what each one does, and the categories of data we share with it. It is the authoritative list referenced by our Data Processing Addendum and Privacy Policy.

1. Service Subprocessors

The following Subprocessors process customer data in the ordinary course of operating CourtFlow AI. All are bound by written agreements that impose data-protection obligations no less protective than those in our agreement with you.

SubprocessorPurposeData CategoriesRegion
Google LLCOAuth identity, Gmail (court e-service ingest, label, send), Google Drive (document filing), Google Calendar (deadline events), Google Tasks (deadline tasks). Google Analytics 4 measures page views on courtflow.ai’s public marketing pages only; it does not load in the signed-in application. CourtFlow also uses its own Google Workspace mailbox to send sales email to prospective customers.Account profile, email metadata + body for messages identified as court e-service, OAuth refresh and access tokens (encrypted at rest). Google Analytics receives page-view and device data, not names or email addresses.United States
Microsoft CorporationOAuth identity (Azure AD), Outlook (court e-service ingest, label, send), OneDrive (document filing), Microsoft Calendar, Microsoft To Do.Account profile, email metadata + body for messages identified as court e-service, OAuth refresh and access tokens (encrypted at rest).United States
Google Cloud / Gemini APIAI document analysis, deadline extraction, case briefing, draft generation, probate drafting, the free filing analyzer at /try, and the rules chat.PDF/DOCX/EML court documents, case metadata, prompts. Most documents are sent inline with the request; larger PDFs are uploaded through the Gemini Files API, where Google keeps them for up to 48 hours and then deletes them automatically. Not used to train Gemini models.Google-managed (the Gemini Developer API does not let us pin a region)
Anthropic, PBCClaude API for the courtflow.ai sales chat widget, the in-app support chat, and internal content automation.Sales chat: the visitor’s messages. In-app support chat: the user’s messages plus account diagnostics (firm name, plan, state, user name or email and role, connection and processing status, the configured court e-service sender address, and the subject lines and error messages of up to three recently failed court emails, which can include case names and numbers). Internal automation: CourtFlow-authored prompts; public court opinions for the case law digest; information about prospective customers (names, firms, practice areas, locations and research notes) for drafting sales emails; counts of activity types and screened code-change summaries, with no case, client or firm details, for drafting product changelog entries that a person reviews before they are published; and case-study answers a firm chooses to submit, with the firm and attorney name. No court documents or email bodies.United States
CourtListener (Free Law Project, Inc.)Verification of AI-generated case law citations; sourcing of weekly Florida court opinion digest.Citation strings, and for related-case search a short topic (document type and practice area) and jurisdiction. No client names, party names, or document content.United States
Supabase Inc.Managed PostgreSQL database hosting (case metadata, deadlines, analysis summaries, audit logs).All persisted application data except documents (which live in Customer Drive/OneDrive). Encrypted at rest with AES-256.United States (us-east region)
Vercel Inc.Application hosting, edge network, serverless functions, scheduled cron triggers.Request payloads in transit; no persistent storage of customer data on Vercel infrastructure.United States
Upstash, Inc.Managed Redis (rate-limit counters, short-lived caches) and QStash (scheduled-job queue).Opaque identifiers, request metadata, and access tokens cached for ~1 hour. No client documents or case content.United States
Stripe, Inc.Subscription billing, payment method handling, invoice + receipt delivery, billing portal.Billing email, firm name, payment method (handled directly by Stripe; CourtFlow never receives card numbers). PCI DSS Level 1.United States
Resend (Resend Inc.)Transactional email delivery (welcome, briefings, alerts), CourtFlow’s own sales email to prospective customers, and inbound email receiving for federal CM/ECF NEF processing.Recipient address, message body. Inbound NEF emails routed via dedicated subdomain.United States
Cloudflare, Inc.Turnstile bot-challenge verification on public, unauthenticated surfaces (the free filing analyzer at /try).Visitor IP address and an opaque challenge token, sent to Cloudflare’s siteverify endpoint. The challenge widget is loaded in the visitor’s browser from challenges.cloudflare.com. No customer case data, court documents, or email content.United States
Functional Software, Inc. (Sentry)Error monitoring and performance tracking.Stack traces and request metadata, with PII actively scrubbed via lib/sentry-scrub.ts before transmission. No client documents, email content, or OAuth tokens.United States
LinkedIn CorporationComposing and publishing posts to the CourtFlow company page (admin-only outbound marketing).Posts authored by CourtFlow staff. No customer or case data.United States
GitHub, Inc.Source code hosting, automated testing, and storage of daily database backups.A full backup of the CourtFlow database (all persisted application data; OAuth tokens remain encrypted), taken daily, encrypted before it leaves the backup job so GitHub stores only encrypted files, and kept for 90 days as a private workflow artifact.GitHub-managed
Hunter.io and Clearbit (optional)Contact enrichment for CourtFlow’s own sales outreach, used only when enabled.Email addresses of prospective customers. No customer case data.Provider-managed
Slack Technologies (optional)Internal operational alerts to CourtFlow staff, used only when a webhook is configured.Alert messages about CourtFlow’s own systems (job names, error summaries).Provider-managed

2. Customer-Controlled Storage (Not Subprocessors of CourtFlow)

Court documents, case files, and client materials processed through the Service are filed directly to your own Google Drive or Microsoft OneDrive account using the OAuth grant you provide at sign-up. Those storage providers are not Subprocessors of CourtFlow; you are the customer and the data controller of your own Drive/OneDrive tenant, and you can revoke our access at any time from your provider's account settings. CourtFlow does not retain copies of these documents on its own infrastructure.

The same applies to practice-management systems you choose to connect, such as Clio Manage. When a firm enables that integration, CourtFlow sends deadlines, hearings, filing PDFs and AI summaries to the firm's own account, under the firm's authorization.

3. Public Data Sources (Not Subprocessors)

The following systems are read-only data sources that CourtFlow downloads from on your behalf. They do not receive customer data from CourtFlow and are not Subprocessors as defined in our DPA:

  • PACER (Administrative Office of the U.S. Courts): For firms that enable federal court processing, CourtFlow downloads filing PDFs via the one-time free-look URL contained in each Notice of Electronic Filing (NEF) email. CourtFlow does not maintain a PACER account on your behalf, sends no customer data to PACER, and only retrieves documents that the federal court has already sent to you via NEF.

4. Notification of New Subprocessors

Before we engage a new Subprocessor that will process customer data, we will update this page and post the change to the changelog. We aim to provide at least 30 days' notice in advance of any new Subprocessor going live, except where a faster engagement is required to maintain Service availability or to address a security risk; in those cases we will notify customers as soon as practicable.

To receive proactive notification, contact us at privacy@courtflow.ai and ask to be added to the Subprocessor change list.

5. Right to Object

If you have a reasonable, documented basis to object to a new Subprocessor (for example, a regulatory restriction in your jurisdiction or a legal-ethics constraint on the storage of client data), you may notify us at privacy@courtflow.ai within 30 days of our notice. We will work in good faith to find a workable resolution. If no commercially reasonable resolution can be reached, you may terminate the affected Service for cause and receive a pro-rata refund of any prepaid fees covering the period after termination.

6. Removed or Replaced Subprocessors

When a Subprocessor is removed or replaced, we will note the change in the changelog and, where applicable, describe how data previously handled by that Subprocessor has been migrated, returned, or deleted.

Questions?

For questions about a specific Subprocessor or to request a change-notification subscription, contact privacy@courtflow.ai.