Legal

Privacy Policy

Last updated: April 13, 2026

Who we are

Locus is operated by Waypoint Clinical & Forensic Psychology. We provide plain-language analysis of psychological and forensic evaluations for individuals navigating legal proceedings. Our contact email is hello@locuslegal.app.

The most important thing: your documents

Before any AI analysis begins, your uploaded document is automatically de-identified by Elider, our de-identification pipeline. Names, dates, addresses, case numbers, and other identifying information are removed. The de-identified version is what gets analyzed. Your original document is never stored on our servers.

The de-identification process runs entirely in memory and is discarded after your session. We retain only the analysis output (the three-panel result), not the source document or the de-identified intermediate text.

What we collect and store

Account information: When you create an account, we store your email address and the date your account was created. We use Supabase for authentication and database storage.

Analysis results: We store the three-panel output of each analysis (plain-language summary, methodology review, questions to raise) in your account so you can access it from your dashboard. We also store the document type you selected and any legal context you provided.

Payment information: Payments are processed by Stripe. We do not store your credit card number or payment details. We store your Stripe customer ID and subscription status.

Usage data: We collect anonymized usage analytics via Google Analytics 4 to understand how people use the product. This includes page views, analysis completion rates, and general usage patterns. IP addresses are anonymized.

Third-party services

Locus uses the following third-party services to operate:

  • Elider (elider.ai): document de-identification pipeline. Your document passes through Elider's API for PII removal before analysis. Elider processes documents in memory and does not store them.
  • Anthropic: AI analysis via the Claude API. The de-identified document text is sent to Anthropic's API to generate the plain-language analysis. Anthropic's data use policies apply to API interactions.
  • Supabase: authentication and database.
  • Stripe: payment processing.
  • Vercel: hosting and deployment.
  • Google Analytics 4: anonymized usage analytics.

How we use your information

We use your information only to provide the Locus service: to authenticate you, to run analyses, to show you your analysis history, and to process payments. We do not sell your data. We do not use your documents or analysis content to train AI models.

Your rights

You can request deletion of your account and all associated data at any time by emailing hello@locuslegal.app. We will delete your account, analysis history, and all associated data within 30 days.

Security

All data is transmitted over HTTPS. Database access is protected by row-level security. You can only access your own data. Payment data is handled entirely by Stripe and never touches our servers.

Changes to this policy

If we make material changes to this policy, we will notify users by email. The date at the top of this page reflects when the policy was last updated.

Contact

Questions about this policy: hello@locuslegal.app