Privacy Policy
Last Updated: July 26, 2026
1. Scope and Our Role
This Privacy Policy explains how FirmLink Legal, LLC ("FirmLink," "we," "our," or "us") collects, uses, discloses, and protects personal information when you use our websites, legal practice management platform, client and intake portals, AI and automation features, communications tools, virtual receptionist and voice services, connected integrations, video services, payment features, and FirmLink Legal Chrome extension (collectively, the "Services").
Law firms and other organizations that subscribe to FirmLink generally determine why and how information about their personnel, leads, clients, cases, and communications is processed. For that Customer Data, the subscribing organization is generally the controller or business, and FirmLink acts as its service provider or processor under our agreement with that organization. If you are a law firm's client, lead, contact, or employee, that firm's privacy notice and instructions may also apply. We process information for our own purposes when we manage accounts, billing, security, public websites, product analytics, and our business relationship with you.
FirmLink is a technology provider, not a law firm, and use of the Services does not create an attorney-client relationship with FirmLink.
2. Information We Collect
2.1 Account, Firm, and Contact Information
- Name, email address, phone number, username, authentication identifiers, and profile details.
- Law firm name, address, branding, practice areas, staff roles, permissions, and professional information.
- Sales inquiries, demonstrations, referrals, onboarding information, support requests, and feedback.
2.2 Leads, Clients, Cases, and Legal Work
Customers and authorized users may enter, upload, import, generate, or receive information relating to legal matters. Depending on the matter, this can include:
- Names, contact details, identity information, relationships, and demographic information.
- Intake answers, incident facts, timelines, claims, legal research, court information, and case strategy.
- Medical, treatment, disability, injury, health insurance, and other health-related information.
- Immigration, criminal, employment, family, financial, insurance, lien, settlement, and payment information.
- Case status, tasks, notes, activities, appointments, deadlines, offers, expenses, and outcomes.
2.3 Communications, Calls, and Meetings
- Team messages, client portal messages, emails and email drafts, text messages, and attachments.
- Phone numbers, call routing and status data, voicemail, call audio, transcripts, summaries, and intake answers.
- Video-meeting invitations, participants, chat, meeting metadata, recordings, and transcripts when those features are enabled.
- Communication preferences, consent records, delivery status, opt-out requests, and related audit records.
2.4 Documents and Electronic Work Product
We process documents, templates, correspondence, forms, signatures, records requests, photographs, evidence, exports, and other files or work product submitted to or created through the Services, together with file names, metadata, access history, and signature audit information.
2.5 Connected Accounts and Integrations
If an authorized user connects another service, we receive the authorization tokens, account identifiers, and data needed for the selected integration. Depending on the connection and permissions approved by the user, this may include:
- Google Calendar event information and, when enabled, information needed to create Gmail drafts.
- Microsoft profile, Outlook mail and drafts, calendars, contacts and people, Teams meetings, OneDrive files, and SharePoint sites.
- Calendar events, meeting links, attendees, email recipients, subjects, message bodies, attachments, contact details, and related metadata.
The exact data depends on the integration, the scopes shown during authorization, the features the user activates, and the actions the user requests.
2.6 AI Inputs, Outputs, and Actions
When users interact with Wynn or another AI-enabled feature, we process prompts, messages, conversation history, selected matter context, documents, audio, transcripts, generated responses, feedback, tool calls, and actions requested or approved by the user. We also process limited technical metadata such as model, token, latency, success, and error information. Our application telemetry is designed not to include prompts, responses, document names, or tenant identifiers where the feature is configured for metrics-only logging.
2.7 Payments and Billing
We collect subscription, invoice, payment-request, transaction, payout, settlement, bank-account status, and billing contact information. Payment processors such as Stripe and Confido Legal collect and process payment-card or bank-account information needed to complete a transaction. FirmLink receives transaction identifiers, status, amounts, and related records, but payment credentials submitted directly to a processor are handled under that processor's privacy policy and terms.
2.8 Device, Usage, Cookie, and Security Information
- IP address, browser and device type, operating system, language, and approximate region derived from an IP address.
- Pages or screens viewed, links and controls used, referral information, session times, and feature interactions.
- Authentication events, audit trails, API requests, diagnostic logs, error reports, performance data, and security signals.
- Cookies, session identifiers, and similar technologies used for authentication, preferences, analytics, fraud prevention, and service reliability.
2.9 Public and Third-Party Sources
At a user's request, the Services may retrieve or link to information from public legal and government sources, such as court opinions, dockets, statutes, regulations, agency materials, and other publicly available websites. We may also receive data from Customers, their authorized users, clients, leads, referral sources, service providers, and integration partners.
3. How We Use Information
We use information to:
- Provide, operate, personalize, maintain, and support the Services.
- Authenticate users; administer organizations, roles, permissions, and client portals; and keep accounts secure.
- Manage leads, matters, documents, deadlines, treatments, liens, negotiations, settlements, tasks, and firm operations.
- Send, receive, draft, route, record, transcribe, summarize, and organize communications requested by users.
- Schedule appointments, create meetings, synchronize connected calendars, and manage reminders.
- Generate drafts, analyze authorized content, answer questions, recommend workflows, and carry out user-approved AI actions.
- Process subscriptions and facilitate Customer-requested client payments.
- Provide support, investigate incidents, troubleshoot, monitor reliability, prevent abuse, and protect the Services.
- Measure and improve features, develop new functionality, and understand use of our public websites and platform.
- Communicate about accounts, security, product updates, transactions, and, where permitted, FirmLink services.
- Comply with law, enforce agreements, establish or defend legal claims, and protect users, FirmLink, and others.
Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests such as operating and securing the Services, consent, and compliance with legal obligations. When FirmLink acts as a processor, the Customer determines the applicable legal basis and instructs our processing.
4. Wynn, AI, Automation, and Research
FirmLink uses artificial intelligence to support user-facing features such as intake, drafting, summarization, document analysis, research assistance, workflow suggestions, voice interactions, transcription, and requested actions. Depending on the feature and configuration, relevant content may be processed by Amazon Web Services, including Amazon Bedrock, or by providers such as OpenAI, Vapi, Deepgram, and Cartesia.
AI output can be incomplete, inaccurate, or inappropriate for a particular matter. It is provided as a draft or operational aid and is not a substitute for an attorney's professional judgment. Authorized users are responsible for reviewing output, confirming sources and deadlines, and deciding whether to approve or use an AI-recommended action. FirmLink does not independently make legal decisions for a client.
We use AI content and derived data only as described in this Policy, our agreements, and applicable in-product notices. Provider handling of data is also subject to the applicable service configuration and contractual terms.
5. Calls, Recording, Transcription, Email, and SMS
FirmLink may support AI or human receptionist calls, inbound and outbound calls, voicemail, appointment reminders, intake, SMS, email, and video meetings. When recording or transcription is enabled, the Services may capture the participants' voices, statements, telephone numbers, timestamps, recordings, transcripts, and summaries. A notice or consent prompt may be presented through the call, meeting, form, or Customer.
Recording, monitoring, and automated-call laws vary by location. Customers and users are responsible for configuring these features lawfully, giving required notices, obtaining required consents, honoring communication preferences, and avoiding unlawful or unsolicited communications.
5.1 SMS Consent and Choices
By providing a mobile number and opting in, a recipient may receive messages requested by the recipient or the applicable law firm, including intake follow-up, case updates, appointment reminders, document or portal notifications, security codes, and other service communications. Message frequency varies. Message and data rates may apply.
Reply STOP to opt out and HELP for help. A recipient may also contact the sending law firm or support@firmlinklegal.com. An opt-out may limit the ability to receive timely updates but does not prevent non-SMS communications that are otherwise permitted.
Mobile information, including phone numbers and SMS opt-in or consent records, is not sold or shared with third parties or affiliates for their own marketing or promotional purposes. We may share it with communications providers and vendors only as needed to deliver messages, maintain the service, prevent fraud or abuse, comply with law, or as otherwise directed or consented to by the user or Customer.
6. Connected Google and Microsoft Services
Connected-account features are optional and require authorization. FirmLink requests permissions shown on the provider's consent screen so users can enable functions such as calendar synchronization, event creation, Gmail drafts, Outlook mail and drafts, contacts and people, Teams meetings, OneDrive files, and SharePoint access. FirmLink uses, stores, and transfers connected-account data only to provide or improve the user-facing features the user enables, secure those features, comply with law, or as otherwise permitted by the provider's policies.
Users may disconnect an integration in FirmLink where that control is available and may revoke access through their Google or Microsoft account settings. Disconnecting stops new access, but does not automatically delete information previously imported into Customer records or retained for security, legal, or contractual reasons. Users may request deletion as described below.
Google API Services Limited Use Disclosure: FirmLink Legal's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data for personalized or interest-based advertising, sell it to data brokers or information resellers, or use it to determine creditworthiness or for lending. Human access is limited to cases allowed by Google's policy, such as when a user affirmatively agrees to access specific data for support, when necessary for security or legal compliance, or when data is aggregated for lawful internal operations.
7. FirmLink Legal Chrome Extension
The Chrome extension gives an authenticated FirmLink user access to Wynn, FirmLink team communications, and client communications in a browser side panel. Its single purpose is to let FirmLink users access these FirmLink productivity and communication features while they work in Chrome.
7.1 Chrome Permissions
- Side panel: displays the FirmLink extension interface beside the active browser tab.
- Identity: completes FirmLink authentication through Amazon Cognito using an authorization-code and PKCE flow.
- Storage: keeps the authentication token in Chrome's session storage so the signed-in session can operate. The token is not placed in persistent local extension storage.
- Tabs: reads the current active tab's title and web address only when the user turns on Page Context.
- FirmLink host access: communicates with authorized FirmLink web and authentication domains to sign in and provide extension features.
7.2 Page Context
Page Context is off unless the user turns it on. When it is on, the extension includes the active tab's title and web address with a Wynn request so Wynn can answer in relation to that page. The extension does not automatically send this information merely because a page is open. Page Context resets when the active tab changes and when the user leaves the Wynn view.
The extension does not read or transmit page text, images, form fields, passwords, email content, drafts, files, downloads, the contents of other tabs, or a list of browsing history. Google may categorize the current active tab title and web address as web-history or browsing-activity data even though FirmLink does not read the browser's history database.
7.3 Extension Messages and History
Messages a user sends to Wynn, team members, or clients; selected case, lead, or client context; responses; and saved Wynn conversation history are processed by FirmLink's servers as part of the user's FirmLink account. They are not stored as a persistent copy in Chrome local storage. Starting a new Wynn chat saves or closes the current conversation according to the applicable FirmLink history and retention settings.
Chrome Web Store Limited Use Disclosure: The use of information received from Chrome APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Chrome API data is used only to provide or improve the extension's disclosed user-facing purpose and related security, reliability, and support. We do not use or transfer it for personalized advertising, sell it to data brokers or information resellers, or use it for creditworthiness or lending. We permit human access only with the user's explicit consent to access specific data, when necessary for security or legal compliance, or for lawful internal operations using aggregated and anonymized data.
8. How We Disclose Information
We do not sell Customer legal-matter content, Chrome API data, Google user data, or mobile opt-in data. We may disclose personal information in the following circumstances:
- Customers and authorized users: to the subscribing firm, its personnel, its clients or leads, and other participants according to configured permissions and user-directed workflows.
- Service providers and integration partners: to operate features a Customer or user requests, as described in Section 9.
- At your direction or with consent: when a user connects an account, sends a communication, shares a record, invites a participant, requests a payment, or otherwise directs a disclosure.
- Security and protection: to detect, prevent, and respond to fraud, abuse, malware, security incidents, or threats to rights, safety, or property.
- Legal process: when we reasonably believe disclosure is required by law, subpoena, court order, or other valid legal process, or is needed to establish or defend legal claims.
- Business transaction: in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to applicable notice, consent, and provider-policy requirements.
- Aggregated or de-identified information: where the information cannot reasonably identify an individual, for lawful analytics, reliability, and business operations.
We do not use Chrome API data or Google user data for personalized, retargeted, interest-based, or cross-context behavioral advertising.
9. Service Providers and Integration Partners
Depending on the Customer's configuration and features used, information may be processed by the following categories and providers:
- Cloud, authentication, storage, email, SMS, voice, and AI infrastructure: Amazon Web Services, including ECS, ECR, S3, Cognito, SES, Pinpoint, Polly, and Bedrock.
- Database infrastructure: Neon.
- AI, voice, and transcription: Amazon Bedrock, OpenAI, Vapi, Deepgram, and Cartesia.
- Telephony and messaging: Twilio, AWS communications services, and Postmark.
- Video meetings and transcription: Daily.co.
- Subscription billing and legal payments: Stripe and Confido Legal.
- Connected productivity services: Google and Microsoft.
- Monitoring and analytics: Sentry and Google Analytics.
- Spam, bot, and abuse prevention: Google reCAPTCHA and Cloudflare Turnstile where enabled.
- Legal and public research sources: CourtListener and other public court, government, and legal-information websites requested through the Services.
These parties receive only the information reasonably needed for the relevant function or user-directed integration. Their processing may also be governed by their privacy notices and the Customer's direct agreement with them. The provider list may change as we improve the Services; material changes will be addressed as described in Section 18.
10. Cookies, Analytics, and Session Replay
We use cookies and similar technologies to authenticate users, maintain sessions, remember preferences, secure forms, prevent fraud, measure usage, diagnose errors, and improve performance. With your permission, Google Analytics measures visits and button interactions on our public marketing pages. We do not send Google Analytics events from the authenticated FirmLink workspace, client portals, intake forms, document links, or signing flows. Sentry may receive limited diagnostic and performance information. Session replay is disabled in the authenticated FirmLink workspace.
You can allow, decline, or change optional analytics at any time through Cookie Settings in the public-site footer. Browser controls may also allow you to block or delete cookies. Blocking essential cookies can prevent authentication or other Services from functioning.
11. Security and Access
We use administrative, technical, and physical safeguards designed to protect information, including encrypted network connections, managed cloud infrastructure, authentication and authorization controls, role-based permissions, tenant-scoping controls, encrypted storage for certain credentials and integration tokens, audit records, monitoring, and backup and recovery practices.
FirmLink personnel and contractors are expected to access Customer Data only when needed to provide support requested by an authorized user, maintain or secure the Services, investigate abuse, comply with law, or perform other permitted operations subject to confidentiality and access controls. Support access may be restricted by role, purpose, and time where supported by the feature.
No security measure is perfect. Customers are responsible for managing authorized users, permissions, connected accounts, devices, passwords, exports, and appropriate safeguards after information leaves the Services. Please notify support@firmlinklegal.com promptly if you believe an account or record has been accessed without authorization.
12. Confidential and Privileged Information
Customer Data may include confidential, privileged, health-related, or other sensitive information. FirmLink processes that information to provide the Services under the Customer's instructions and applicable agreements. The Customer and its attorneys remain responsible for professional obligations, legal privilege, confidentiality, conflicts, supervision, client consent, records management, and determining whether a particular feature, provider, or disclosure is appropriate for a matter.
This Policy does not itself create an attorney-client relationship, guarantee that a communication is privileged, or replace a Customer's professional or regulatory analysis.
13. Retention and Deletion
We retain information for as long as reasonably necessary to provide the Services, follow Customer instructions, maintain security and audit records, complete transactions, comply with legal and professional-retention obligations, resolve disputes, and enforce agreements. Retention varies by data type, feature, Customer configuration and contract, account status, legal hold, and backup schedule.
Customers may delete certain records or request account deletion, subject to permissions, product functionality, contractual terms, and applicable law. Deleted information may remain temporarily in backups, logs, fraud-prevention records, or legal archives until those records are securely overwritten or no longer required. Disconnecting an integration or uninstalling the Chrome extension stops future access through that interface but does not by itself delete data already stored in the FirmLink account.
14. Your Choices and Privacy Rights
Depending on your location and our role, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or an appeal of a privacy-request decision. You may also opt out of marketing email using its unsubscribe link, opt out of SMS as described above, manage browser cookies, disconnect integrations, revoke Google or Microsoft authorization, or uninstall the Chrome extension.
If your information was submitted to FirmLink by a law firm or other Customer, please direct your request to that organization first. Because the Customer controls its records, we may refer the request to the Customer or assist it in responding. For information FirmLink controls directly, contact privacy@firmlinklegal.com. We may verify your identity and authority before completing a request, and legal exceptions may apply.
We will not discriminate against you for exercising an applicable privacy right. Authorized agents may submit requests where permitted by law, subject to verification of their authority.
15. United States State Privacy Disclosures
State privacy laws may provide additional rights concerning categories of personal information collected, sources, purposes, recipients, deletion, correction, portability, and opt-outs. The categories described in Sections 2, 3, 8, and 9 are intended to provide that notice.
FirmLink does not sell Customer legal-matter content, Chrome API data, Google user data, or mobile opt-in information. We do not use those categories for targeted or cross-context behavioral advertising. Public-site analytics technologies may involve disclosures of device and usage information to analytics providers. You may contact privacy@firmlinklegal.com to ask about available opt-out rights or other state-specific choices.
Sensitive personal information is used to provide and secure the Services, comply with law, and perform other purposes permitted by applicable privacy law. We do not use sensitive personal information to infer characteristics for advertising.
16. International Processing
FirmLink is based in the United States. Information may be processed in the United States and other countries where our providers operate. Privacy laws in those locations may differ from those in your jurisdiction. Where required, we use contractual or other appropriate transfer safeguards.
17. Children's Privacy
The Services are designed for law firms, legal professionals, and adults interacting with them; they are not directed to children under 13. Legal matters may concern minors, and an authorized adult, legal professional, or Customer may submit information about a minor when lawful and necessary for the matter. If you believe a child submitted personal information directly to FirmLink without appropriate authorization, contact privacy@firmlinklegal.com.
18. Changes to This Policy
We may update this Policy to reflect changes in the Services, providers, law, or our data practices. We will post the updated version and revise the "Last Updated" date. When required, we will provide additional notice in the Services or by email and request consent before using information for a materially new purpose. Changes to Chrome extension or connected-account data practices will also be disclosed in the relevant product interface where required.
19. Contact Us
For questions, concerns, or privacy requests, contact:
FirmLink Legal, LLC
Privacy: privacy@firmlinklegal.com
Support: support@firmlinklegal.com
Website: https://firmlinklegal.com