Privacy Policy
What Docket holds, who else touches it, and how to get it back or get rid of it.
Version 2026-09-15
1.The short version
Docket holds your matters, your dates, and the scheduling orders you send it. Four vendors touch that data to make the service work, and they are all named in section 4. We do not sell it, do not use it for advertising, and do not use it to train models. You can export everything at any time, and deleting your account deletes it for good.
Most of what is in here is your clients’ confidential information, not yours. We have written this policy so that you can do your own evaluation under Rule 1.6 and Business & Professions Code § 6068(e)(1) without having to ask us follow-up questions. If something you need is missing, write to privacy@airdeskhq.com and we will answer it.
2.What we collect
Account information. Firm name, each user’s name and email address, role, and a hashed password. We never see your password in readable form.
Matter data. Everything you enter or upload: case captions, case numbers, forums, party names, deadlines, hearing dates, panel information, tasks and free-text notes.
Uploaded and forwarded documents. Scheduling orders and related documents you upload, and the full contents of any email forwarded to your intake address — including its body, headers and attachments. If you forward a message with an unrelated attachment or a privileged thread below the signature, we receive that too.
Acceptance records. Who accepted the signup acknowledgement, when, and the exact wording shown to them.
Operational logs. Sign-in events, IP addresses, request logs, error reports, and a record of support access to your matters.
We do not use advertising cookies, analytics trackers or third-party pixels. The only cookies Docket sets are the ones that keep you signed in.
3.What we do with it
We use it to run the service: to extract dates from your documents, to show you your docket, to send the morning brief, to serve your calendar feed, to respond when you contact support, and to keep the system secure and working.
We do not do anything else with it. No profiling, no resale, no sharing with anyone not named in section 4, no model training.
4.Who else touches it
These are every vendor that processes your data. Each is bound by contract to process it only on our instructions, and we are responsible to you for what they do with it.
Anthropic, PBC
Reads uploaded scheduling orders to extract dates
Receives: The full text of scheduling orders you upload or forward, including captions, case numbers and party names
Processed through the commercial API. Anthropic does not train its models on data submitted through that API.
Supabase, Inc.
Database, authentication and file storage
Receives: Everything in your account: matters, dates, notes, uploaded order PDFs, sign-in credentials
Data is held in the United States.
Resend (Plus Five Five, Inc.)
Sends the morning brief and receives forwarded mail
Receives: Recipient addresses, brief contents (case captions and dates), and the full contents of anything forwarded to your intake address
Vercel Inc.
Application hosting
Receives: Request logs, IP addresses, and all data in transit through the application
We will update this list before adding a vendor, and will email the account owner at least 30 days beforehand where the change is material. If you object, you may terminate and receive a refund of any prepaid fees for the unused period.
5.Automated extraction, specifically
Worth calling out on its own, because it is the part most firms will want to put in front of their own risk committee.
When you upload or forward a scheduling order, the text of that document is transmitted to Anthropic’s commercial API so that a language model can read the dates out of it. Your clients’ case captions and party names go with it. Anthropic does not train its models on data submitted through that API, and does not retain it for its own purposes.
If your engagement with a client, or a protective order in a matter, prohibits sending that matter’s documents to a third-party processor, do not put that matter into Docket.
6.Where it lives, and for how long
Data is stored in the United States. We keep it for as long as your account is open.
When you delete your account, your matters, dates, notes, uploaded documents and sign-ins are deleted immediately and permanently. There is no soft-delete, no trash folder, and no backup we can restore from. Operational logs containing no matter data may persist for up to 90 days in our hosting providers’ systems, and backups those providers take on their own schedule roll off within 30 days.
7.Security
Every row in the database carries the identifier of the firm it belongs to, and the database itself enforces that a signed-in user can only reach rows belonging to their own firm — the isolation is in the storage layer, not only in the application. Uploaded documents are held in a private bucket under the same rule. Traffic is encrypted in transit and data is encrypted at rest.
Your calendar feed URL is an exception you should know about: it carries a long random token and grants read access to your confirmed dates without signing in, because that is what allows a calendar application to fetch it. Treat it as a password. You can rotate it from the Calendar page at any time.
No system is perfectly secure. If we become aware of unauthorized access to your data we will notify the account owner without undue delay and in any event within 72 hours of confirming it, describing what we know about what was affected and what we are doing.
8.Our access to your matters
We look at the contents of your matters only when you ask us to, when it is necessary to resolve a support issue you have raised, or when we are legally compelled. Support access through the application writes a record identifying the operator, the reason and the related request, and you may ask us for that history at any time.
As section 6 of the Terms of Service says plainly, that record covers access through the application and not direct database administration, which is restricted to operating personnel and logged separately by our hosting provider.
9.Legal demands
If we receive a subpoena, warrant or other compulsory demand for your data, we will notify you before responding unless we are legally prohibited from doing so, so that you can object or seek protection. We will not volunteer your data to anyone.
Remember that information in Docket is not privileged as against us. We cannot assert your clients’ privilege on their behalf.
10.Your rights, and California law
You can export everything in your account as a single file at any time from Settings, including the source passage and calculation behind every date. You can correct anything directly in the application, and you can delete everything by closing the account.
For data about your clients, your firm is the business and we act as a service provider under the California Consumer Privacy Act: we process that data only to provide the service to you, and we do not sell it or share it for cross-context behavioral advertising. For data about the people on your own account, you may request access, correction or deletion by writing to privacy@airdeskhq.com.
11.Children
Docket is sold to law firms and is not directed to anyone under 18. We do not knowingly collect information from children.
12.Changes, and how to reach us
We will email the account owner at least 30 days before a material change to this policy takes effect. Minor clarifications take effect when posted, and the version is shown at the top of this page.
Privacy questions: privacy@airdeskhq.com. Everything else: support@airdeskhq.com. By post: [ENTITY NAME TO BE INSERTED], [BUSINESS ADDRESS FOR NOTICES].