Privacy Policy

Last Updated: 27 September 2026

1. Introduction

LupaSoft Ltd, trading as CourtPilot ("Company," "we," "us," or "our") operates the CourtPilot service ("Service") at www.courtpilot.co.uk. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our application.

We are committed to protecting your privacy and ensuring you have a positive experience on our platform. If you have questions about this Privacy Policy, please contact us at privacy@courtpilot.co.uk.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Information: Name, email address, password, and profile details
  • Case Information: Details about your legal claim, including parties, amounts, dates, and case description
  • Documents: PDFs, images, and other files you upload for analysis
  • Communication: Messages, feedback, and support requests you send us
  • Payment Information: Processed securely through third-party payment providers (we do not store credit card details)

2.2 Information Collected Automatically

  • Usage Data: Pages visited, time spent, clicks, searches, and features used
  • Device Information: Browser type, operating system, device model, IP address, and unique device identifiers
  • Location Data: Approximate geographic location (city/country level) based on IP address
  • Cookies & Tracking: Through cookies, pixels, and similar technologies (see Cookie Policy)

2.3 Third-Party Data Collection

We work with a small number of carefully selected sub-processors to deliver the service. Section 6 lists each sub-processor in full. The categories of data collected through them are summarised here:

  • Anthropic (Claude API): Receives the text we send for AI processing — case descriptions, extracted text from uploaded documents, conversation messages, and the prompts our system constructs around them
  • Vercel: Hosts the CourtPilot website and APIs; receives all traffic and request metadata in the course of normal use
  • Railway: Runs our background workers, which scan, extract text from (OCR) and index the documents you upload
  • Vercel AI Gateway (embeddings): Receives short passages of text extracted from your uploaded documents so that they can be turned into search vectors for document search within your case
  • Neon (database): Stores account data, case records, document metadata, extracted text, and audit logs
  • Cloudflare R2: Stores your uploaded documents in encrypted form
  • Redis Cloud: Caches non-sensitive application state and rate-limit counters
  • Stripe: Collects transaction data for payment processing
  • Resend: Sends transactional email (verification emails, receipts, case notifications)
  • Sentry: Collects error logs and crash reports to improve platform stability, with PII filtering applied
  • Google Analytics 4 & Google Tag Manager: Collect aggregate usage, device, and approximate location data to measure platform performance (only with your consent)
  • Google Ads: Receives the ad click identifier, purchase value and your cookie consent choice when a purchase follows a click on one of our ads; your hashed email only with marketing consent (see section 6.13)
  • Homedata and the energy performance certificate register: Receive the postcode and address you look up in the council tax band checker
  • Telegram: Carries internal notifications to our staff about checks and purchases (see section 6.15)

2.4 Free Checkers and Calculators

You can use our free tools without an account. What happens to your answers depends on the tool:

  • Free case assessment (small claims): the type of dispute, the amount, your description of what happened, and your answers about evidence and pre-action steps. We store these with the result, your IP address and an approximate location (town, region and country) derived from it. Your description is sent to Anthropic to produce the assessment.
  • Employment Tribunal assessment: the type of claim, your description, employment start, end and dismissal dates, salary, age, and your answers about ACAS early conciliation, grievances and evidence (including an ACAS certificate number if you give one). We store these with the result, your IP address and an approximate location. Your answers are sent to Anthropic to produce the assessment.
  • Council tax band checker: the postcode and the address you select, the property details you confirm, and the result (current and suggested band, estimated saving). We store these with your IP address. To look up the property, we send the postcode and address to Homedata, a property data provider, and to the government's energy performance certificate register.
  • Private parking charge checker: the dates on your ticket and notices, the charge and the amount now demanded, how and where the charge was issued, and your answers about signs, permits and payment. The checker does not ask for your vehicle registration, name or address, and we do not store your IP address with it. It works by fixed rules and does not send your answers to an AI provider.
  • Calculators and other checkers (Employment Tribunal deadline checker, employment compensation calculator, court fee calculator, interest calculator, Section 8 notice checker): these run in your browser and your answers are not sent to us. The enforcement method comparison reads the result of a free case assessment you have already completed.
  • Email: if you choose to give an email address to receive your results, we store it with the check and record whether you agreed to marketing emails.

2.5 Visitor ID and Attribution

On your first visit we set a first-party cookie called cp_vid, containing a random visitor ID, which lasts 180 days. When you arrive from a link or advert, we record the campaign details in the address (such as utm_source, utm_campaign and the Google Ads click identifier gclid), the referring page and the page you landed on, against that visitor ID, together with a hashed form of your IP address, your browser's user agent and your country. The results of free checks are stored with the same visitor ID and campaign details, even if you do not create an account.

If you later create an account or make a purchase, we link your earlier free checks and the first campaign that brought you to us to your account, by matching the visitor ID from the same browser or the email address you gave. We use this to understand which pages and adverts lead to people getting help, and to report purchases to Google Ads as described in section 6.13. This cookie is set whether or not you accept analytics or marketing cookies, because we treat it as necessary to run and measure the service; it is not read by any other website.

3. How We Use Your Information

  • Service Delivery: Creating and managing your account, processing cases, generating documents
  • AI Analysis: Analysing documents and cases to provide legal insights and recommendations
  • Communication: Sending transactional emails (confirmations, password resets) and product updates
  • Platform Improvement: Understanding user behaviour to enhance features, fix bugs, and optimise performance
  • Compliance & Security: Detecting fraud, enforcing terms, preventing abuse, and maintaining audit trails
  • Legal Obligations: Responding to court orders, law enforcement requests, or regulatory requirements
  • Marketing (with consent): Sending newsletters or promotional content only if you've opted in
  • Attribution and advertising measurement: Linking free checks and the campaign that brought you to us with a later account or purchase, and telling Google Ads when a purchase followed an ad click (sections 2.5 and 6.13)

4. Data Security & Encryption

We design CourtPilot around privacy-by-design and security-by-default principles, and operate the service to support compliance with the UK General Data Protection Regulation and the Data Protection Act 2018:

  • AES-256-GCM Encryption at Rest: Uploaded documents are encrypted before being stored
  • TLS 1.3 in Transit: All data transferred to and from CourtPilot is encrypted with modern cryptographic protocols
  • Encryption Key Management: Encryption keys are managed via cloud-platform secret storage with restricted access
  • PII Tokenisation in Conversational Case-Building: Identifying details that you type into our conversational case-builder (such as names, email addresses, phone numbers, and addresses) are substituted with placeholders before the message is sent to our AI provider. Tokenisation does not currently apply to documents you upload or to letter generation, where the original details are needed for the AI to produce a useful output. We may extend tokenisation to other parts of the service in future
  • Role-Based Access Control (RBAC): Staff and application access limited to the information necessary for the task at hand
  • Audit Logging: Document and case access is tracked and logged for security and compliance purposes
  • Malware Scanning: Uploaded documents are scanned with ClamAV in our document-processing pipeline before they are made available for analysis
  • Encrypted Document Storage: Documents are stored in Cloudflare R2 (UK/EU regions) in encrypted form

While we maintain strong security practices, no system is 100% secure. Please use unique, strong passwords and enable two-factor authentication if available.

5. Legal Data & Case Information

Your case information is treated with the highest level of confidentiality:

  • Chain of Custody: All document uploads and modifications are tracked with timestamps and user attribution
  • No Unsecured Logging: Case details and sensitive information are never logged in plain text
  • Legal Professional Privilege: Case information is treated as confidential and is not shared with third parties except as required by law
  • Data Retention: Case data is retained as long as your account is active. What happens when you delete a case or your account is set out in section 8
  • No AI Training: Your case data is not used to train AI models — Anthropic is contractually prohibited from training on customer content submitted via the API, and we do not maintain a separate training corpus

6. Third-Party Tools & Services

6.1 Google Analytics 4 & Google Tag Manager

We use Google Analytics 4 to measure website traffic and user behaviour (page views, time on site, conversions). Google Tag Manager manages the deployment of these tracking pixels.

  • Data Collected: Usage patterns, device type, browser, location
  • Privacy: Google Analytics data is anonymized and cannot be linked to individuals
  • GDPR Compliance: Data processing agreements are in place with Google
  • Consent: Google Tag Manager, and the Google Analytics tags it loads, run only after you accept analytics cookies in our cookie banner. Google Ads conversion and remarketing tags additionally require you to accept marketing cookies. Your choice is stored in your browser and you can change it at any time
  • Opt-Out: You can disable Google Analytics with the Google Analytics Opt-Out Browser Extension
  • Privacy Policy: See Google's Privacy Policy at https://policies.google.com/privacy

6.2 Payment Processing (Stripe)

Payment information is processed securely by Stripe. We do not store or have access to your full credit card details.

  • PCI DSS Compliance: Stripe is fully PCI-DSS Level 1 certified
  • Data Sharing: We receive only a transaction ID and confirmation of payment

6.3 Error Monitoring (Sentry)

We use Sentry to track errors and crashes. This helps us identify and fix issues quickly.

  • Data Collected: Error messages, stack traces, device/browser information
  • PII Redaction: We filter out case details and sensitive information from error reports

6.4 Email Service (Resend)

Transactional emails (verification emails, receipts, case notifications) are sent via Resend, Inc., based in the United States. Resend acts as our sub-processor under its data processing terms, which include EU Standard Contractual Clauses and the UK ICO Approved Addendum.

6.5 AI Processing (Anthropic)

Our AI features rely on Anthropic, PBC and the Claude API. When you use an AI feature, we send the relevant text — your case description, the extracted text content of documents you have uploaded, your conversation messages, and the prompts our system constructs around them — to Anthropic for processing. We do not send your password, payment details, or the encrypted document files themselves.

This covers the case chat and assistant, document analysis, drafting of letters and court documents in your case workspace, and the free small claims and Employment Tribunal assessments (section 2.4). Anthropic's Claude models generate the drafts and answers; the text of your case is sent to Anthropic for that purpose. Text extraction (OCR) from your uploaded documents and the search index over them run on our own infrastructure: our background workers on Railway and our database on Neon, which stores the search vectors using the pgvector extension.

  • Contractual safeguards: Anthropic acts as our sub-processor under Anthropic's Commercial Terms of Service and Data Processing Addendum, which include EU Standard Contractual Clauses and the UK Information Commissioner's Approved Addendum for international transfers
  • No model training: Anthropic is contractually prohibited from training its models on customer content submitted via the API
  • Limited retention by Anthropic: Anthropic retains submitted content only for the limited period needed to operate the service and to respond to abuse and trust-and-safety concerns; details are set out in Anthropic's published policies
  • Sub-processor list: Anthropic's own list of sub-processors is published at anthropic.com/subprocessors

We do not use AI to make solely automated decisions producing legal effects within the meaning of Article 22 UK GDPR. AI outputs are guidance and drafts that you review, accept, modify, or reject before any decision is acted upon, filed with a court, or sent to a third party.

6.6 Hosting (Vercel)

The CourtPilot website and APIs are hosted on Vercel Inc., based in the United States with edge infrastructure in the UK and EU. All data transmitted to and from the service in the course of normal use passes through Vercel's infrastructure. Vercel acts as our sub-processor under its data processing terms, which include EU Standard Contractual Clauses and the UK ICO Approved Addendum.

6.7 Database (Neon)

Our primary application database is provided by Neon Inc., with data hosted in the United Kingdom (eu-west-2). Neon acts as our sub-processor under its data processing terms.

6.8 Document Storage and CDN (Cloudflare)

Encrypted documents are stored in Cloudflare R2. Cloudflare also provides DNS and content-delivery services for the website. Cloudflare, Inc. acts as our sub-processor under its data processing terms, which include EU Standard Contractual Clauses and the UK ICO Approved Addendum.

6.9 Caching (Redis Cloud)

Redis Ltd. (Redis Cloud) provides caching and rate-limit tracking, with data hosted in the United Kingdom (eu-west-2). Redis Cloud acts as our sub-processor under its data processing terms.

6.10 Background Processing (Railway)

Our background workers run on Railway Corp. When you upload a document, a worker retrieves the encrypted file, decrypts it, scans it for malware, extracts its text (OCR) and indexes it for search, then stores the results in our database. Railway acts as our sub-processor under its data processing terms.

6.11 Document Search Embeddings (Vercel AI Gateway)

To let you and the case assistant search your documents by meaning, the text extracted from each uploaded document is split into short passages and sent through the Vercel AI Gateway to an embedding model (currently OpenAI's text-embedding-3-small), which returns a list of numbers for each passage. We store those numbers alongside the passages in our database. Only document text is sent, not the files themselves or your account details.

6.12 Transactional Email and Payments

Stripe processes all payments through Stripe Checkout; we never see or store your card number. Resend sends our transactional emails, such as sign-in links, receipts, results you ask us to email you and case notifications (see sections 6.2 and 6.4).

6.13 Google Ads Purchase Reporting

If you arrived by clicking one of our Google adverts and later make a purchase, our server tells Google Ads that a purchase followed that click, using the stored click identifier (the gclid), the purchase value and time, an order reference and, only if you accepted marketing cookies, a one-way hashed (SHA-256) form of your email address. The report is sent from our server, not from your browser, together with your cookie banner choice at checkout: if you declined marketing cookies, or made no choice, no email hash is sent and Google is told there is no consent, so it can use the report only for aggregate measurement and not to build a profile. It lets us see which adverts lead to purchases. If you object, email privacy@courtpilot.co.uk.

6.14 Property Data (Council Tax Band Checker)

To look up a property's current band and details, the council tax band checker sends the postcode and selected address to Homedata, a UK property data provider, and to the government's energy performance certificate register. The results are cached by postcode. CourtPilot is not affiliated with the Valuation Office Agency.

6.15 Internal Notifications (Telegram)

We use a private Telegram group to tell our staff when a free check is completed, an account is created or a purchase is made. These messages contain the minimum needed: the product, the amount, the type of dispute and the verdict of a check, and a masked email address (for example, j***@example.com). They never contain your case description, documents, address or payment details.

6.16 Sub-processor Changes

We will update this list at least 14 days before a new sub-processor begins processing your personal data. If you object to a new sub-processor, please contact privacy@courtpilot.co.uk before the change takes effect.

7. Your GDPR Rights (EU/UK Users)

If you are located in the EU, UK, or other jurisdictions with similar laws, you have the following rights:

  • Right to Access: Request a copy of all personal data we hold about you
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your data, subject to legal obligations
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to specific uses of your data (e.g., marketing)
  • Right to Lodge a Complaint: Contact your local data protection authority (e.g., ICO in the UK)

To exercise any of these rights, contact us at privacy@courtpilot.co.uk with "GDPR Request" in the subject line. We will respond within 30 days.

8. Data Retention and Deletion

  • Account Data: Retained as long as your account is active.
  • Deleting a case: When you delete a case from your dashboard, the documents you uploaded to it are deleted from our file storage straight away. The case record itself is marked as deleted and removed from your account, but is not immediately erased from our database; a note that the case was deleted is kept in its history. If you want the case record erased as well, email us (see below).
  • Deleting your account: You can delete your account from your profile page after confirming your password. This deletes your account record and the cases linked to it from our database. Free check results you completed before or after signing up are kept without the link to your account. If you want those erased, or want us to confirm that uploaded files have been removed from storage, email us.
  • Free check results: Kept with their visitor ID and campaign details (section 2.5) until you ask us to delete them.
  • Erasure requests: You can ask us to erase any of your data at privacy@courtpilot.co.uk. We may keep limited records where the law requires it, such as payment records for tax purposes.
  • Analytics Data: Google Analytics data retained for 26 months by default
  • Audit Logs: Kept for 12 months for security and compliance purposes

9. Children's Privacy

Our Service is not intended for individuals under 18 years old. We do not knowingly collect data from children. If we learn that a child has provided personal information, we will delete it immediately.

10. International Data Transfers

Our servers are located in the US. By using our Service, you consent to the transfer of your information to the United States, which may have different data protection laws than your home country. We implement Standard Contractual Clauses and other safeguards to ensure adequate protection.

Several of the services listed in section 6 (including Anthropic, Stripe, Resend, Google, Telegram, and the embedding model reached through the Vercel AI Gateway) may process data outside the UK.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a prominent notice on our website. Your continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

LupaSoft Ltd (trading as CourtPilot)

Website: www.courtpilot.co.uk

Registered office: 62 The Dolls House, Chipstead Lane, Sevenoaks, Kent TN13 2AG. Registered in England & Wales, company number 16943875.

Email: privacy@courtpilot.co.uk

Subject: "Privacy Policy Inquiry"