Data We Process
Lightfield processes data submitted to or connected with the legal intake platform, including:
- Account and team profile information.
- Legal intake requests, comments, attachments, operational metadata, and audit events.
- Connected mailbox or integration metadata needed to ingest and route legal requests.
- Product analytics and diagnostic events used to operate and improve the service.
Lightfield may process legally privileged, confidential, personal, or commercially sensitive information when customers submit it through intake requests, emails, attachments, or integrations.
How We Use Data
We use data to:
- Provide legal intake, triage, assignment, status tracking, and related workflow features.
- Authenticate users and enforce tenant isolation.
- Maintain audit logs, security logs, and operational reliability.
- Detect abuse, investigate incidents, and comply with legal obligations.
- Improve product quality using aggregated or minimized analytics.
We do not sell customer data.
Google API Limited Use
If a customer connects Gmail or another Google API integration, Lightfield's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When a customer connects Google Workspace, Lightfield receives the Gmail messages, headers, attachments, and mailbox identifiers needed to create legal-intake matters and apply Lightfield mailbox labels. If the user grants the separate read-only permissions, Lightfield also searches files across the Google Drives the user can access, downloads or exports selected file content for bounded text extraction, and reads Google Calendar event details to add relevant context to the user's intake workflow. Lightfield does not request Google Contacts access and cannot edit, move, share, or delete Drive files.
Lightfield shares, transfers, or discloses Google user data only as needed to provide this functionality:
- To Render, which hosts the Lightfield API and workers that process the connected data.
- To Supabase, which hosts Lightfield's tenant-isolated application database and stores the resulting intake records, source references, and encrypted integration-token records.
- To the OpenAI API, which processes the minimum relevant content needed for classification, summarization, routing, and connected-context features. Lightfield configures supported model requests with response storage disabled (
store=false), does not opt Google user data into model-training data sharing, and does not permit Google user data to be used to train generalized or foundational AI models.store=falseis not represented as zero data retention; limited provider security or abuse-monitoring retention may still apply under the provider's API terms. - To the customer's authorized Lightfield users, when the data or derived intake output is displayed as part of the service.
Lightfield does not transfer Google user data to advertising platforms, data brokers, or model gateways, and does not sell Google user data. Human access is limited to security, support, legal, or compliance purposes with customer authorization, when required to operate the requested feature, or as required by law.
AI Processing
Lightfield uses the OpenAI API directly for enabled AI classification, summarization, routing, and enrichment features. Lightfield does not route customer or Google user data through an AI gateway or model hub. AI processing is limited to providing Lightfield functionality, and Lightfield does not use customer-identifiable content to train generalized, public, or third-party AI models.
Security
Lightfield uses access controls, audit logging, encryption in transit, encryption at rest, tenant-scoped authorization, session revocation, and secure development controls to protect customer data. Security incidents are handled under the incident response plan.
Retention and Deletion
Customer data is retained according to the Data Classification and Retention Policy. Authorized administrators can request or initiate organization export and deletion. Some records may be retained as required for security, legal, audit, backup, or compliance purposes.
Subprocessors
Lightfield's core service providers include Render for backend hosting, Supabase for database services, Vercel for frontend hosting, OpenAI for enabled AI processing, Stripe for billing, GitHub for engineering operations, and Axiom and Better Stack for redacted operational telemetry. Optional Google, Microsoft, Slack, Salesforce, Atlassian, Zendesk, ServiceNow, and similar integrations process data only when enabled by the customer. Lightfield's logging controls are designed to exclude Google user content, prompts, documents, tokens, and message bodies from operational telemetry.
Contact
Privacy requests and security reports can be sent to security@trylightfield.ai.