Last updated: October 3, 2026
Aver is a litigation-intelligence service for law firms, provided by ECA360 LLC d/b/a Litigation Labs ("Litigation Labs", "we" or "us"). This policy explains what personal information Aver handles, why, who receives it and how long it is kept. Terms such as Customer, Customer Data, Workspace, Matter and Output have the meanings in the Terms of Service.
1. Who this covers
- People who use Aver ("users"): the attorneys, staff and others a firm gives access to.
- People named in a firm's material: parties, witnesses, counsel and others who appear in the documents a firm puts into Aver.
- Visitors to the public Citation Check page on aver.legal (section 12).
2. Our role
- Customer Data. For Customer Data, including the personal information in a firm's documents, the firm decides how it is used and Litigation Labs processes it on the firm's behalf. The Data Processing Agreement governs that processing. Questions about it are best sent to the firm first.
- Our own records. For account details and the records described below, Litigation Labs decides how they are used.
3. What we collect
| Category | What it includes |
|---|---|
| Account details | Name, work email, role, Workspace and two-factor settings. Passwords are stored only as bcrypt hashes. |
| Sign-in and security records | IP address and browser type at sign-in, session times, sign-in attempts (the email address is stored as a hash), and an audit log of actions taken in Aver. |
| Customer Data | The documents and other material a firm puts into Aver and everything Aver produces from it. It can contain any kind of personal information about the people named in it. |
| Usage and billing records | The input and output units each AI request used, with its Workspace and Matter; storage volume; invoices. |
| Support requests | What a user writes to us, including an Aver Helper conversation they choose to send with a request. |
| Error reports | When Aver's web app hits an error, it sends Aver's own servers the error message, its stack trace (and, for a display error, the component stack), the page address and the browser's user agent. |
We do not sell personal information, use it for advertising or track people across other websites.
4. How we use it
- To provide, secure and support Aver for each firm.
- To bill each firm for its use.
- To send service email, such as password resets and the notices a firm's users turn on.
- To improve Aver, using account, usage and error records. We do not use Customer Data to train AI models (section 5).
- To meet legal obligations and enforce our agreements.
5. AI processing
- Where the AI runs. Aver's AI features run on models at Fireworks AI.
- What is sent. For each task, Aver sends Fireworks AI the text of the documents and other Customer Data the task needs, over an encrypted connection. A task can include Matter, client and party names and the questions users type. Fireworks AI receives page images for three tasks only: reading the printed page numbers on a deposition transcript's first pages, finding the page a citation points to when the text does not show it, and reading the layout of the first 4 pages of a PDF style exemplar a user uploads.
- Scanned pages. Where a page has no readable text, Aver sends an image of it to OCR servers Litigation Labs operates, reached through Cloudflare's network, which return the page's text. Scanned pages are not sent to Fireworks AI to be OCR'd.
- Fireworks' commitments. Fireworks AI's terms say it will not use that content to train its models. They also say it will not retain the content beyond the time needed to produce the response, subject to exceptions its terms describe.
- Batch files are kept. Large batch runs leave stored files at Fireworks, as the Subprocessor List explains.
- What stays on Aver's servers. The vectors Aver uses for meaning-based search are computed on its own servers and are not sent to an AI provider. If that ever changes, we will give firms notice under section 6 of the DPA first.
- No training by us. We do not use Customer Data to train AI models unless a firm agrees in a separate signed writing.
- Self-hosted Aver. A firm can run Aver's software on its own network under a separate agreement. Then AI processing and document storage can be kept inside that network. This policy describes the hosted Aver at aver.legal.
6. Who receives information
- Subprocessors. The third parties that process Customer Data for Aver are listed, with what each receives, in the Subprocessor List: Fireworks AI (AI models), Railway (hosting), Cloudflare (document storage, backups, uploads and the network path to our OCR servers), Resend (email delivery, including support requests), Google Workspace (our own email) and Vercel (an alternate web address).
- CourtListener. This public legal-research service receives case citations and search terms. When an attorney runs a case-law search, the terms are written from the issues and facts the attorney enters and can contain words from them. It has no data-processing terms with us.
- Our partner platforms. PageLineIQ and First Legal are Litigation Labs' own litigation platforms. If a firm's Workspace is connected to one, it can sign users in, create their accounts and add them to linked Matters, and Ask Aver exchanges search queries and excerpts with it, as the Subprocessor List describes.
- Services a firm connects. If a firm connects Box or its own AI agents, data flows to them at the firm's direction.
- Legal requests. We disclose information when the law requires it. For Customer Data we first refer the requester to the firm and tell the firm unless the law forbids it.
- Business transfers. If Litigation Labs is merged or sold, information may pass to the successor, which must honor this policy.
7. How long we keep it
| Record | How long |
|---|---|
| Customer Data | For the term of the firm's agreement and a 60-day export period. Litigation Labs then deletes the Workspace within 30 days, as section 15 of the Terms describes. |
| A deleted Matter | Hidden from users and restorable by the firm's administrator. Its data stays until the Workspace is deleted. Aver cannot yet permanently erase a single Matter on request. |
| A deleted document's file | Kept in storage trash, and in the Replica (the second, encrypted copy of document files), for 30 days, then deleted. |
| Documents set aside after a clawback | Kept out of use until the production they came from, or the Workspace, is deleted. |
| History of changes to extracted facts | Kept without an end date, including after the Workspace is deleted. It records each change to a fact, with the fact's text. |
| Audit log | One year in Aver's database, then deleted. Before this version of the policy took effect the period was 180 days, so older entries have already been deleted. An append-only copy kept to detect tampering has no fixed end date. |
| Access-control log | Kept without an end date, including after the Workspace is deleted. |
| Sign-in attempts | 90 days. |
| Sessions | A session ends after 2 hours without activity or 24 hours in total. |
| Account details | Until the firm's administrator deletes the user, or we do on request. Deleting a Workspace does not delete its users' accounts: an account whose home Workspace is deleted is detached and signed out, and we delete it on request. A record that a user was deleted, with their name, email and role, is kept. |
| Records tied to a person rather than a Matter | Conversations not tied to a Matter and their messages, learned preferences and saved prompt templates are kept until the person deletes them. Deleting the person's account does not delete them; we do on request. Deleting the Workspace deletes the preferences Aver inferred while working in one of its Matters, and keeps the rest. |
| The record of a deleted Workspace | Kept as the record that the deletion happened. It lists the stored files' paths, which contain the files' names. |
| The record of a deleted document or production | Kept without an end date, including after the Workspace is deleted, as the record that the deletion happened. It names the document or production, its Matter, and what was removed with it. |
| Background job and error records | Completed jobs 14 days, failed jobs 30 days, error and operational events 30 days. |
| Database backups | A backup is made every 24 hours, encrypted, and stored with Cloudflare. Database backups are deleted after 90 days, except that the seven most recent are always kept. A backup made before something was deleted still contains it. |
| Batch files at Fireworks AI | Kept in Litigation Labs' Fireworks account until deleted; Aver does not yet delete them automatically. |
| Usage and billing records | As long as needed for billing, tax and accounting. |
| Support requests | As long as needed to resolve them and keep a record of support. |
8. Cookies and browser storage
Aver sets two cookies. session keeps a user signed in; it cannot be read by page scripts and lasts up to 24 hours. csrf_token protects against cross-site request forgery. Aver also keeps preferences in the browser's own storage, such as Day or Night theme, unsent drafts and filters. Aver uses no advertising or analytics cookies and loads no scripts or fonts from other websites.
9. Security
Annex B of the Data Processing Agreement describes Aver's security measures. In short:
- Each firm's data is kept in its own Workspace, and access to a Matter is checked when someone signed in asks for it. A briefing share link is the exception: anyone holding one can read that briefing until it expires or is revoked.
- Connections are encrypted, except for the last leg to our OCR servers, which we have not yet confirmed.
- Aver's own copies in Cloudflare R2, including the append-only copy of the audit log, its database and its backups are encrypted by Aver. Working copies on Railway's servers, such as documents being processed, rely on Railway's storage encryption.
- Passwords are hashed, and two-factor authentication is available.
If a breach affects a firm's data, we tell the firm within 48 hours of becoming aware of it.
10. Your choices and rights
- Users can ask their firm's administrator, or us, to see, correct or delete their account details, or for a copy of them.
- People named in a firm's material should contact that firm, which decides about Customer Data. We help the firm respond.
- California residents. For Customer Data, Litigation Labs is a service provider under the California Consumer Privacy Act. We do not sell or share personal information.
- People in the EEA, the UK and Switzerland have rights under their data-protection laws; the DPA explains how we help firms honor them.
Send requests to andrew@litigationlabs.ai. We will not treat anyone differently for exercising these rights.
11. Where information is processed
Aver is run from the United States, and our Subprocessors may process information in the United States and other countries where they operate. Section 11 of the DPA covers transfers of personal data from the EEA, the UK and Switzerland.
12. The public Citation Check
Anyone can paste a brief, or upload one, into the Citation Check page on aver.legal to check its case citations. Aver sends the text to CourtListener to look up the citations. An uploaded file is read in memory and not stored, and Aver does not store or log the text. If a visitor enters an email address to see the full report, we keep the address with the report's counts, may pass both to the customer-relationship service we use (Attio), and may use the address to contact them about Aver.
13. Children
Aver is a professional service for law firms and is not intended for children.
14. Changes to this policy
We post updates on the Legal page in Aver and tell firms' administrators by email. The date at the top shows the latest version.
15. Contact
andrew@litigationlabs.ai · 312-796-9040
ECA360 LLC d/b/a Litigation Labs, Attn: Privacy, 192 N Wells #3078, Chicago, IL 60606