Legal

Privacy Policy

How Lauyer collects, uses, shares, retains, and protects account, payment, search, legal-source, and AI usage information.

Last updated: 30 August 2026

1. Controller and scope

Pedro Martins operates Lauyer and is the controller for personal data processed to provide the website, accounts, OAuth and MCP authorization, subscriptions, legal-source tools, AI summaries, support, and security. Privacy requests may be sent to privacy@lauyer.org.

This Policy applies to Lauyer’s processing. Your MCP client, Google, Stripe, Cloudflare, OpenRouter, model providers, DGSI, and Diário da República process information under their own roles and policies.

2. Account and authentication information

  • Name, email address, profile image when supplied by Google, email-verification status, account identifiers, and account timestamps.
  • Google provider identifiers and OAuth tokens when Google sign-in is used.
  • A securely hashed password when email/password sign-in is used. Lauyer does not store plain-text passwords.
  • Session records, cookies, authorization codes, MCP/OAuth client registrations, access and refresh tokens, consent records, requested scopes, signing keys, and revocation or expiry information.
  • IP address, user agent, request time, security events, rate-limit state, and other ordinary infrastructure or abuse-prevention logs.

3. Legal research and tool data

When a client calls a Lauyer tool, Lauyer processes the search query, filters, court or publication selection, dates, identifiers, requested language, source URL, and tool options needed to perform the request. Search and retrieval requests are sent live to DGSI or Diário da República.

Lauyer does not maintain a stored copy of the DGSI or Diário da República legal corpus and does not intentionally store ordinary search-result bodies. Upstream sources receive the request needed to return results and may create their own logs.

Court decisions and official publications can contain names and other personal data. Public availability does not remove all data-protection, professional, confidentiality, or lawful-use obligations. Users are responsible for a lawful purpose and appropriate handling of results.

4. AI summary processing

When you request an AI summary, Lauyer sends the relevant decision, headnote, legislation, or official-publication text, together with summary instructions and language, to OpenRouter and an underlying model provider currently using a Google Gemini model.

OpenRouter states that it does not use API inputs or outputs to train its own models, but underlying model providers may have different logging, retention, and training practices. Lauyer does not promise zero retention by every downstream provider unless a specific contractual or technical configuration says so.

Lauyer records an AI usage ledger containing your account identifier, tool or entity type, source entity identifier such as a URL or act ID, model identifier, token counts, estimated provider cost, and time. The ledger does not intentionally store the full legal text or generated summary.

5. Subscription, credit, and payment information

Lauyer processes plan, subscription status, renewal date, usage allowance, credit purchases, credit balance and expiry, invoices, refund state, payment status, Stripe customer and transaction identifiers, currency, amount, and tax-related records.

Stripe collects payment-method, billing, fraud-prevention, device, and transaction information needed to process payment. Lauyer does not receive or store full card numbers or card security codes. Stripe may act as processor and, for some fraud, compliance, and payment functions, as an independent controller.

6. Email, support, device, and preference data

  • Cloudflare Email Service processes the recipient, sender, subject, message content, delivery identifiers, and delivery or suppression events for verification and password-reset messages.
  • If you contact us, we process your address, message, attachments, and the records needed to investigate and respond.
  • The website may store theme preference locally. Locale routing and strictly necessary authentication or OAuth state may use cookies or browser storage.
  • Cloudflare may process IP address, network, security, performance, request, and diagnostic information while hosting and protecting the Service.

7. Purposes and legal bases

  • Contract: create and secure your account, provide MCP access, run searches, retrieve documents, generate requested summaries, manage usage, deliver paid plans and credits, and provide support.
  • Legitimate interests: prevent abuse and fraud, secure accounts and sources, diagnose failures, maintain reliable service, enforce terms, defend legal claims, and understand aggregate operating costs.
  • Legal obligations: maintain payment, tax, consumer, accounting, security, and compliance records and respond to valid legal requests.
  • Consent: optional provider authorization and any future non-essential cookies or communications that require consent. You may withdraw consent without affecting earlier lawful processing.

8. Providers and recipients

  • Cloudflare for Workers hosting, D1 database, KV storage, network security, logs, and transactional email.
  • Google for OAuth sign-in and, through the selected OpenRouter route, Gemini model inference.
  • OpenRouter and the underlying model provider for AI summary requests.
  • Stripe, banks, card networks, payment methods, and fraud-prevention partners for billing and refunds.
  • DGSI and Diário da República as the requested live legal-information sources.
  • The MCP client you choose, which receives tool results and may store prompts, authorizations, and outputs.
  • Professional advisers, authorities, courts, acquirers, or successors where necessary for legal advice, compliance, claims, security, or a business transaction.

9. International transfers

Some providers may process information outside Portugal or the European Economic Area, including in the United States. Depending on the provider and transfer, safeguards may include an adequacy decision, the EU-US Data Privacy Framework, Standard Contractual Clauses, supplementary measures, or another lawful mechanism.

Provider locations and mechanisms can change. Contact privacy@lauyer.org for current information relevant to a specific processing activity.

10. Retention

  • Account and core authorization records are kept while the account is active and then deleted or anonymized when no longer needed, subject to security, dispute, payment, and legal retention.
  • Sessions, authorization codes, verification values, and access tokens expire or are revoked according to their security periods; limited records may remain in logs or backups.
  • AI usage and cost records are kept for account administration, quota enforcement, fraud prevention, reconciliation, and dispute handling. They may remain for the account lifetime and a reasonable period afterwards unless a shorter period is legally required.
  • Payment, invoice, tax, refund, and anti-fraud records are retained for statutory and legitimate business periods, including after account closure.
  • Support correspondence, security logs, provider logs, and backups are kept only as long as reasonably needed for their purpose, then deleted, aggregated, or de-identified.

11. Security

Lauyer uses HTTPS, password hashing, verified email, OAuth, scoped consent, signed tokens, server-side validation, restricted infrastructure bindings, rate and usage limits, provider access controls, and limited-access Cloudflare infrastructure.

No service is perfectly secure. Protect your email, Google account, password, device, and MCP client. Do not put confidential or sensitive third-party information into a query unless external processing is authorized and appropriately protected.

12. Your rights and choices

Send requests to privacy@lauyer.org. We may request proportionate information to verify identity. We generally respond within one month, subject to lawful extensions, exceptions, and the rights of others.

  • Request access to, correction of, or a copy of personal data about you.
  • Request deletion, restriction, portability, or objection where the GDPR or another applicable law provides that right.
  • Withdraw consent and revoke Google or MCP authorizations without affecting prior lawful processing.
  • Cancel a subscription separately from an account deletion request.
  • Complain to the Portuguese Data Protection Authority, CNPD, or another competent supervisory authority.

13. Account deletion

Self-service deletion is not currently available. You may request account closure and deletion at privacy@lauyer.org. We will remove or anonymize account, authentication, consent, and usage information where required and technically supported.

Deletion does not automatically cancel Stripe billing, reverse completed payments, remove information held independently by your MCP client or providers, or erase records that must be retained for tax, accounting, fraud, security, dispute, or legal reasons.

14. Children, marketing, and automated decisions

Lauyer is intended for adults and is not directed to children. We do not knowingly create accounts for anyone under 18.

Lauyer does not currently sell personal data, run behavioral advertising, or use first-party marketing analytics. We do not use account data to make solely automated decisions that produce legal or similarly significant effects about you. AI summaries are generated at your request and are not decisions by Lauyer about a person.

15. Changes and contact

We may update this Policy to reflect legal, provider, security, or product changes. Material changes will receive reasonable notice by email or through the Service when practical, and the last-updated date will change.

Controller and privacy contact: Pedro Martins, privacy@lauyer.org.