DeedScribe

Draft for attorney review — not yet in effect.

Privacy Policy

Privacy Policy

What DeedScribe collects, why, who processes it, and how long it is kept. Every statement here describes how the product is built today and agrees with the Security page.

Last updated: September 2026

1.Who we are

DeedScribe is operated by [LEGAL ENTITY NAME] (“DeedScribe,” “we,” “us”), a company owned by a New York attorney. DeedScribe is document-preparation software that law firms use to draft deeds and transfer-tax forms for New York property transfers. This policy explains what information the service handles, why, who else touches it, and how long it is kept.

Because our customers are law firms, most of the personal information in DeedScribe is about the firms’ clients and the parties to their transactions, not about our users. Section 8 explains how that changes who you should contact.

2.What we collect

Account information. Your name, your email address, your role (owner or member), the firm you belong to, and sign-in records such as when you were invited, when you confirmed your account, and when you last signed in. Passwords are handled by our sign-in provider and stored only as hashes. For the firm itself we keep its name, its email domain (used to route colleagues with a matching firm address into the right firm on first sign-in), its AI allowance, and when it was created.

Prior deeds you upload. When you upload a prior deed, the PDF is read in memory on our server to extract its text. The file itself is not written to storage and is discarded when the request finishes. If the PDF is a scan or key fields are missing, the document is sent to our AI provider for interpretation (see section 4).

Deed records. The fields you accept or enter — grantor and grantee names and addresses, trust or entity details, the property address, county, tax-map numbers, the legal description (Schedule A), the prior deed reference, consideration, assessment data, and the details needed for the TP-584 and RP-5217 forms — are stored as a deed record that belongs to your firm. Where a form requires it, this can include a Social Security or employer identification number that you enter. Each deed record also carries when it was created and last updated, its status in the workflow, and, if it was started from Clio, the Clio matter identifier. Generated deeds and forms are returned to your browser as downloads; we do not keep copies of the generated files.

Parcel data. When you use Parcel Search or tax lookup, our servers query the New York State assessment roll and tax-parcel layer published on data.ny.gov. What comes back — owner names, addresses, tax-map numbers, assessed values, and similar public-record fields — is shown to you and, if you start a deed from it, saved to that deed.

AI usage records. For every AI call we record the route and operation, the model used, the number of input and output tokens, an estimated cost, the duration, and the firm and deed the call belongs to. We do not store the prompts sent to the model or the responses it returned.

Support messages. If you use the form on the Support page or email us, we receive what you send — your name, email address, firm, topic, and message — plus the page you were on and your connection’s IP address, and, if you are signed in, your account email, firm, and role. Please do not paste Social Security or EIN numbers into support messages.

Clio data, when connected. If a firm owner connects Clio, DeedScribe reads only what is needed to start a deed: matter names and identifiers, the client’s and spouse’s names and contact details, and property details held on the matter. We store the tokens Clio issues to your firm and the identifiers of the Clio account and user who connected. Raw records from Clio are not stored and are never sent to your browser; only the fields you choose to import become part of a deed.

Server logs. Our hosting providers keep request logs with metadata such as the path requested, timing, status codes, page counts, and the IP address of the request. Our own log lines never contain deed text, Schedule A, or party names.

3.How we use it

We use the information above to:

  • sign you in, keep your session, and enforce which firm you belong to;
  • extract, store, and generate the deeds and forms your firm prepares;
  • look up public parcel and assessment data at your request;
  • measure each firm’s AI usage against its monthly allowance, show that usage to firm owners, and email owners at 80% and 100% of the allowance;
  • send invitation, password-reset, and other account emails;
  • answer support requests and investigate problems you report;
  • keep the service secure, detect abuse, and meet our legal obligations; and
  • understand how the service is used in aggregate, without identifying a firm, a user, or a client.

The only email we send is transactional: invitations, password resets, allowance notices, and replies to messages you send us. We do not send marketing email to users [CONFIRM, or describe any opt-in newsletter for firm owners].

We do not sell personal information, use it for advertising, share it across firms, or use it to train AI models.

4.AI processing

Three steps use Anthropic’s Claude models through Anthropic’s API: reading a prior deed when the PDF is a scan or text extraction misses critical fields, cleaning up Schedule A spacing and formatting (followed by a second check that no legal content was dropped), and a pre-generation review of the deed data. For those calls the relevant material — the uploaded PDF, the Schedule A text, or the deed’s party and property fields — is sent to Anthropic and the result is returned to you for review.

Anthropic processes that material under its commercial terms, under which API inputs and outputs are not used to train Anthropic’s models. We may change models or providers; if we do, the replacement will be bound by an equivalent commitment. We keep the usage records described in section 2 for each call, not the content.

5.Who we share it with

We share information only with the providers that run parts of the service on our behalf, each of which receives only what its part requires:

  • Vercel — hosts the application; all requests and responses pass through it.
  • Supabase — hosts the database (deed records, accounts, firm membership, AI usage records, Clio tokens) and the sign-in system, in a project used only by DeedScribe.
  • Anthropic — AI processing, as described in section 4.
  • Resend — delivers support messages and AI allowance notices by email.
  • Render — runs a small companion service of ours that fills the RP-5217 form; it receives the field values for that form, returns the completed PDF, and deletes its working copy before the request finishes.
  • Clio — only when a firm owner connects it, and only the reads and note or document uploads your firm initiates.

Queries to the New York State assessment roll and tax-parcel layer are sent to data.ny.gov and the State’s GIS service; those queries contain the search terms you enter (an owner name, address, or tax-map number) and nothing else about the deed. Data in transit to every provider is encrypted with TLS. We may also disclose information where the law requires it, or to protect the security of the service, and we may transfer it to a successor if DeedScribe’s business is sold, in which case this policy continues to apply. We do not sell information and we do not share it with advertisers. Our providers store data in [REGION — CONFIRM, e.g., the United States].

6.Firm isolation and security

Each firm is a separate tenant in the database, and every deed record carries its firm’s id. Every query that lists, reads, saves, or deletes a deed is filtered by the signed-in user’s firm, so another firm’s data does not exist from your account’s point of view. Row-level security is enabled on every table, your browser never talks to the database directly, and every page and endpoint that touches firm data requires a signed-in session. Data at rest is encrypted by our hosting providers under their standard controls. We have not undergone a third-party security audit. The full description, including what we do not do yet, is on the Security page.

7.Retention

  • Deed records are kept while your firm’s subscription is active and for [PERIOD] after it ends, so the firm can retrieve them; then they are deleted. A firm owner can download the firm’s deed records at any time (a ZIP of CSV and JSON files) from the Billing page. Users can delete individual deeds from within the application at any time.
  • Uploaded PDFs are not stored; they are discarded when the extraction request finishes.
  • Account records are kept while you are a member of a firm on DeedScribe. When an owner removes you, your membership ends and your login is disabled; we delete the disabled login on request (write to us at the address below). When a firm is deleted, the logins of all of its current members are permanently deleted with it.
  • Clio tokens are deleted when an owner clicks Disconnect or when DeedScribe is removed inside Clio.
  • AI usage records (counts and costs, not content) are kept for [PERIOD] for billing and allowance purposes.
  • Support correspondence lives in our email and is kept for [PERIOD].
  • Server logs are kept according to each hosting provider’s standard retention, typically days to weeks, and are not archived by us.

A firm owner can delete the firm sooner from the Users page by typing the firm’s name. The deletion is scheduled seven days out, every owner is emailed, and any owner can cancel it from the Users page during those seven days. When it runs, the firm’s deeds, AI usage records, Clio tokens, memberships, and every member’s login are permanently deleted, and we email the owners to confirm, keeping only billing records and correspondence we are required to keep. Questions about deletion can go to support@deedscribe.com.

8.Your rights and the firm’s role

For its clients’ information, your firm is the controller: it decides what to upload, what to enter, and when to delete it, and DeedScribe processes that information only on the firm’s instructions, as its service provider. If you are a party to a transaction, or a client of a firm that uses DeedScribe, and you have a question about your information, please contact your attorney; we will help the firm respond, but we do not act on instructions from a firm’s clients directly.

If you are a user at a firm, you can see and correct your own name in the application and can ask us for a copy of the account information we hold about you, for its correction, or for its deletion (subject to your firm’s decisions about its membership) by writing to support@deedscribe.com. We will respond within [30] days. Where state privacy laws give you additional rights, we will honor them.

If we learn of a security incident that affects your firm’s data, we will notify the firm’s owners without undue delay [and in any case within X hours/days — FOR REVIEW], tell them what we know about what was affected, and keep them informed as we learn more, so that the firm can meet its own notification obligations to its clients.

9.Cookies

DeedScribe uses only the cookies needed to keep you signed in and to complete the Clio connection handshake (a short-lived, HTTP-only state cookie set while an owner connects Clio). There are no analytics, tracking, or advertising cookies, and no third-party scripts that track you across sites. If you block cookies, you will not be able to sign in.

10.Children

DeedScribe is a professional tool for law firms and is not directed at anyone under 18. We do not knowingly collect information from children as users of the service. Deed records may name minors as parties or beneficiaries where a transaction requires it; that information is entered and controlled by the firm.

11.Changes to this policy

We will update this policy when the product changes in a way that affects what we collect or who processes it, and we will update the “Last updated” date above. For material changes we will email firm owners at least 30 days before they take effect.

Privacy Policy — DeedScribe