Privacy Policy
Last updated: June 28, 2026
1. Introduction
LitiCare, LLC ("LitiCare, LLC," "we," "us," or "our") operates the CaseFlow platform (the "Service"). We respect your privacy and are committed to protecting personal information entrusted to us. This Privacy Policy explains what we collect, how we use it, and the choices you have.
2. Information We Collect
- Account information: name, email, password (hashed), firm name, role, bar number (if provided).
- Firm and client data: matters, contacts, documents, time entries, trust ledger entries, calendar events, communications, and other content that firms enter into the Service.
- Usage data: log data, device and browser info, IP address, pages viewed, and feature interactions.
- Payment information: processed by Paddle, our merchant of record. We do not store full payment card numbers.
- Support communications: messages and attachments you send us.
3. Our Role as a Data Processor
For data that law firms enter about their own clients, LitiCare, LLC acts as a data processor on behalf of the firm, which is the data controller. The firm is responsible for the lawful basis of that processing, for obtaining any necessary consents, and for responding to data-subject requests from its clients. LitiCare, LLC will support firms in meeting those obligations to the extent reasonably practicable.
4. How We Use Information
- To provide, maintain, and improve the Service;
- To process subscriptions, billing, and payments through Paddle;
- To provide customer support and respond to your requests;
- To send service-related notices, security alerts, and product updates;
- To detect, prevent, and address fraud, abuse, and security issues;
- To comply with legal obligations.
5. Confidentiality of Legal Data
We understand that firms store privileged, confidential, and sensitive client information in the Service. We implement administrative, technical, and physical safeguards designed to protect this data, including:
- Encryption in transit (TLS) and at rest;
- Row-level tenant isolation enforced at the database layer;
- Role-based access controls and audit logging;
- Signed, short-lived URLs for document downloads.
You remain responsible for your own confidentiality, privilege, and ethical obligations, including who within your firm has access to client information.
6. How We Share Information
We do not sell your data. We share information only:
- With subprocessors that help us operate the Service (see below), under appropriate confidentiality and data-protection agreements;
- With your authorized users and people you choose to share data with through the Service;
- If required by law, subpoena, court order, or to protect rights, safety, or property;
- In connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality.
7. Subprocessors
- Supabase — application hosting, database, authentication, and file storage.
- Paddle — payment processing and merchant of record.
- Resend — transactional email delivery (e.g., invoices, notifications).
We may add or change subprocessors over time. Material changes will be reflected in this policy.
8. Data Security
We implement industry-standard security measures including encryption, tenant isolation, access controls, and monitoring. However, no system is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for promptly reporting any suspected unauthorized access.
9. Data Retention
We retain Firm Data while your account is active and for a reasonable period afterward to allow for export, backup integrity, dispute resolution, and legal compliance. You can request deletion of your data at any time by emailing the address below; certain records may be retained where required by law.
10. Your Rights
Depending on your jurisdiction (including under GDPR and CCPA), you may have the right to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing. To exercise these rights, contact us using the details below. Where LitiCare, LLC acts as a processor for a firm's client data, please direct requests to the firm; we will assist as required.
11. Data Location
The Service is hosted on cloud infrastructure operated by our subprocessors, primarily in data centers located in the United States. By using the Service, you understand that your data may be transferred to and processed in jurisdictions other than your own.
12. Children's Privacy
The Service is intended for use by legal professionals and is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn we have collected such information, we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance.
14. Contact Us
For privacy questions or to exercise your rights, contact:
admin@myliticare.com
myliticare.com