Privacy
What we collect, which is less than you would expect.
binding.law is a product of Jubal, Inc. This page describes what the service actually stores, who processes it, and what you can ask us to do about it. It is written from the code rather than from a template, and it is kept in the same commit as the code it describes.
Last updated 20 September 2026
The short version
- We do not sell your data, and we do not share it for advertising.
- We do not store the citations you look up or the text you search for — only a one-way hash of the query.
- We never see your password and we never see your card number.
- We cannot read your API key back to you, because we only hold its hash.
- The law itself is public. Nothing you query is secret to us because we do not keep what you queried.
What we collect, and why
Your email address, and a name if you give one
To create the account, to send the verification email, and to reach you about the service.
Held by WorkOS, our identity provider. Your password is set with WorkOS and we never receive or store it.
Your API key, stored only as a SHA-256 hash
To authenticate your requests. The hash is what the API compares against.
We cannot recover your key and neither can anyone who obtains our database. This is why a lost key is rolled rather than re-sent.
Request metadata: which endpoint, the method, the status code, how long it took, and how many units it billed
To meter usage against your plan, to bill correctly, and to find faults.
Held in our own database. This is how the number on your dashboard is calculated.
A hash of the query, not the query
To recognise a repeated request for caching and rate-limit purposes without retaining what you searched for.
We do not store the citations you look up or the text you search for. The record holds a one-way hash of it and nothing more.
Billing details, if you buy a paid plan
To take payment.
Handled entirely by Stripe. Card numbers never reach our servers; we hold Stripe's customer and subscription identifiers so we know what you bought.
Who else processes it
These are the only third parties that touch personal data. Each is a processor acting on our instructions.
We have no analytics tracker, no advertising pixel and no session recorder on this site. If that changes, this list changes with it.
If you are an attorney in our data
Attorney and firm records are built from public bar directories and other public sources. They are professional information — the licence, the firm, the admission date — not personal information you gave us.
You can review your own record, correct it, and have your correction become the authoritative value. That is free and always will be; we do not charge attorneys or firms for anything, and reviewing your own record is not a product we sell.
Your choices
Get a copy, correct it, or delete it
Email us and we will send you what we hold, correct what is wrong, or close the account and delete it. We do not require a particular form of words and we do not charge for it.
How long we keep it
Account details for as long as the account exists. Usage records while they are needed for billing and for the statements that follow it. Delete the account and the account data goes; billing records we are required to retain are kept for that period and no longer.
Write to hello@binding.law. A person reads it. If you are an enterprise customer and need a data processing agreement, ask and we will send one.
When this changes
This page is versioned with the code it describes, so a change to what we collect and a change to this page are the same commit. If we ever begin collecting something materially different, we will say so here and tell account holders by email rather than changing the date quietly.
Jubal, Inc. is a Delaware corporation. Terms of service.