1. Introduction
DivorceParty ("DivorceParty," "we," "us," or "our") operates a secure, AI-enhanced legal technology platform designed to assist individuals going through divorce and the legal professionals who represent them. We are committed to protecting the privacy, confidentiality, and security of the personal information entrusted to us.
This Privacy Policy describes how we collect, use, disclose, retain, and protect your personal information when you use our website at divorceparty.com (the "Website"), our platform and applications (the "Platform"), and any related services (collectively, the "Services").
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation in Canada, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), the Gramm-Leach-Bliley Act (GLBA) where applicable, the Health Insurance Portability and Accountability Act (HIPAA) where applicable, and other applicable federal and state or provincial privacy laws in Canada and the United States.
2. Definitions
- •"Client" means an individual going through a divorce who uses the Platform to organize their case, upload evidence, communicate with their lawyer, or access AI-assisted guidance.
- •"Professional User" means a lawyer, paralegal, mediator, or other legal professional who uses the Platform to manage divorce cases on behalf of Clients.
- •"Firm" means the law firm or legal practice that subscribes to the Platform for its Professional Users.
- •"Case Data" means all information, documents, communications, and evidence related to a specific divorce case on the Platform.
- •"Connected Data" means information imported into the Platform from third-party sources such as Google Calendar, Gmail, or text message exports.
- •"AI Services" means the artificial intelligence features of the Platform, including but not limited to the AI assistant, evidence intelligence, sentiment analysis, pattern detection, credibility scoring, and document drafting capabilities.
3. Information we collect
3.1 Information you provide directly
Account Information: When you create an account, we collect your full legal name, email address, phone number, and role (Client or Professional User). Professional Users also provide their firm name, bar association number (if applicable), and business address.
Intake Information: Clients who complete the intake wizard provide detailed personal, financial, and family information across 13 sections including personal details, marriage details, information about children, income and employment, real property, financial assets, debts and liabilities, business interests, insurance, monthly expenses, spousal support details, domestic issues, and personal goals and priorities. This information is highly sensitive and is treated with the highest level of protection.
Case Documents and Evidence: Users upload documents to the Platform including financial statements, tax returns, bank statements, legal documents, court filings, correspondence, photographs, and other evidence relevant to their divorce proceedings.
Communications: Messages exchanged between Clients and Professional Users through the Platform's secure messaging system.
Billing Information: Professional Users and Firms provide payment information including credit card details, billing address, and tax identification numbers. Payment processing is handled by Stripe, Inc. and we do not store complete credit card numbers on our servers.
3.2 Information collected through data connections
With your explicit consent, we import information from third-party services to support your case:
Calendar Data: When you connect your Google Calendar, Apple Calendar, or Outlook Calendar, we import calendar events including event titles, dates, times, locations, descriptions, and attendee information for the date range you specify. We access your calendar in read-only mode and cannot modify, create, or delete your calendar events.
Email Data: When you connect your Gmail or Outlook account, we import emails relevant to your divorce case. We use smart filters based on the contacts and keywords you provide during setup to identify relevant messages. We import email metadata (sender, recipient, date, subject), email body content, and attachments. We access your email in read-only mode and cannot send, modify, or delete your emails.
Text Message Data: When you upload text message exports from our extraction tool, WhatsApp, or other sources, we import message content, timestamps, sender and recipient information, and any included attachments.
3.3 Information collected automatically
Usage Data: We collect information about how you interact with the Platform including pages visited, features used, time spent on pages, clicks, and navigation paths.
Device and Technical Data: We collect your IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
Cookies and Similar Technologies: We use essential cookies for authentication and session management, functional cookies to remember your preferences, and analytics cookies to understand Platform usage. We do not use advertising or tracking cookies. See Section 12 for more details.
Log Data: Our servers automatically record information including access times, API requests, error logs, and performance metrics. These logs are used for security monitoring, debugging, and performance optimization.
3.4 Information generated by AI Services
Our AI Services generate additional information based on your Case Data and Connected Data:
- •Sentiment Analysis: Emotional tone classification (positive, negative, neutral, aggressive, conciliatory) applied to imported communications.
- •Topic Detection: Automatic identification of discussion topics in communications (children, finances, property, scheduling, legal matters).
- •Pattern Recognition: Detection of communication patterns, frequency changes, behavioral anomalies, and timeline correlations across data sources.
- •Insights and Reports: AI-generated summaries, case strength assessments, credibility scores, contradiction reports, and strategic recommendations.
- •Document Drafts: AI-generated draft documents, affidavit sections, and evidence summaries created at the request of a Professional User.
All AI-generated information is clearly marked as such and requires human review before being used in any legal proceeding.
4. How we use your information
4.1 Providing and operating the Services
- •Creating and managing your account
- •Processing and organizing case information through the intake wizard
- •Storing, encrypting, and managing documents and evidence
- •Facilitating secure communication between Clients and Professional Users
- •Processing data connections (calendar, email, text messages) to build your evidence profile
- •Running AI analysis on your case data to generate insights, detect patterns, and support case preparation
- •Generating documents, summaries, and reports at your request
- •Processing payments and managing subscriptions for Professional Users and Firms
4.2 Improving and developing the Services
- •Analyzing aggregate, de-identified usage patterns to improve Platform features
- •Testing new features and functionality
- •Monitoring Platform performance, reliability, and security
- •Training and improving our AI models using de-identified, aggregated data only (never individual case data — see Section 5.3)
4.3 Security and compliance
- •Detecting and preventing unauthorized access, fraud, and security threats
- •Maintaining comprehensive audit logs as required by applicable regulations
- •Complying with legal obligations, court orders, and regulatory requirements
- •Enforcing our Terms of Service
4.4 Communication
- •Sending transactional notifications (task reminders, deadline alerts, document updates, message notifications)
- •Responding to your support requests and inquiries
- •Sending service announcements and security notices
- •With your consent, sending product updates and educational content
5. How we protect your information
AES-256-GCM encryption
All data encrypted at rest
Per-tenant isolation
Each firm's data is containerized
Zero cross-tenant access
No data sharing between firms
TLS 1.3 in transit
Secure data transmission
5.1 Encryption
All data is encrypted in transit using TLS 1.3. All data is encrypted at rest using AES-256-GCM encryption. Each case uses its own unique encryption keys. Encryption keys are managed through HashiCorp Vault with automated key rotation.
5.2 Tenant isolation
Each law firm's data is isolated in separate containerized environments. There is zero cross-tenant data access by design. Per-tenant encryption keys ensure that even in the event of a system-level breach, data from one firm cannot be used to access data from another.
5.3 AI data handling
Your individual case data is never used to train our AI models. AI processing occurs within your isolated tenant environment. AI-generated content is logged in full (prompts and responses) for auditability and transparency. All AI outputs are clearly labeled and require human review before use in legal proceedings. We may use aggregate, de-identified, and anonymized usage patterns to improve our AI capabilities. Such data cannot be re-identified to any individual, case, or firm.
5.4 Access controls
Role-based access controls ensure that only authorized individuals can access case data. Professional Users can only access cases they are assigned to. Clients can only access their own case. Firm administrators can manage their firm's users and settings but cannot override case-level access controls without being assigned to the case. All access is logged in immutable audit trails.
5.5 Infrastructure security
Our infrastructure is hosted on enterprise-grade cloud providers with SOC 2 Type II and ISO 27001 certifications. We conduct regular penetration testing and vulnerability assessments. We maintain an incident response plan and will notify affected users within 72 hours of discovering a confirmed data breach. We pursue our own SOC 2 Type II and ISO 27001 certifications and will update this policy when they are obtained.
7. Data retention
7.1 Active accounts
We retain your personal information and Case Data for as long as your account is active and the associated case is open.
7.2 Closed cases
When a case is closed, we retain the Case Data for a minimum period determined by the applicable jurisdiction's legal record-keeping requirements, generally not less than 7 years from the date of case closure, unless you request earlier deletion and no legal hold applies.
7.3 Post-divorce retention
Clients and Firms may opt into our post-divorce data retention service to maintain access to case data after closure. This is a paid add-on service and is entirely optional.
7.4 Account deletion
You may request deletion of your account and associated data at any time (see Section 9). Upon receiving a verified deletion request, we will delete your personal information within 30 days, except where retention is required by law, necessary to complete an ongoing transaction, or subject to a legal hold.
7.5 Audit logs
Audit logs are retained for a minimum of 7 years from the date of creation for compliance purposes. Audit logs may contain references to your actions on the Platform but do not contain the substantive content of your case data.
7.6 Backups
Encrypted backups are maintained for disaster recovery purposes and are purged on a rolling 90-day cycle. Deleted data is removed from backups within 90 days of the deletion request.
8. Your privacy rights
If you are a Canadian resident, you have the right to:
- •Access: Request access to the personal information we hold about you.
- •Correction: Request correction of inaccurate or incomplete personal information.
- •Withdrawal of Consent: Withdraw your consent to the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions.
- •Complaint: File a complaint with the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated.
8.3 Rights under other jurisdictions
Depending on your location, you may have additional rights under applicable privacy legislation. We endeavor to respect the privacy rights of all users regardless of jurisdiction.
8.4 Exercising your rights
To exercise any of your privacy rights, you may:
- •Use the Privacy Dashboard within the Platform (Settings → Privacy & Data)
- •Email our Privacy Officer at privacy@divorceparty.com
- •Write to us at: DivorceParty Privacy Officer, [Mailing Address]
We will verify your identity before processing any request. We will respond to verified requests within 30 days (or sooner if required by applicable law). If we need additional time, we will notify you of the reason and expected timeline.
9. Data deletion and portability
9.1 Data export
You may export a complete copy of your data at any time through the Platform's data export feature (Settings → Privacy & Data → Export My Data). The export includes your account information, case data, documents, messages, imported data, and AI-generated insights in machine-readable formats (JSON, CSV, and original file formats for documents).
9.2 Data deletion
You may request deletion of your data through the Platform or by contacting our Privacy Officer. The deletion process is as follows:
- You submit a deletion request through the Platform or via email.
- We confirm receipt and verify your identity.
- If you are a Client with an active case managed by a Professional User, we notify the Professional User of the pending deletion and allow a 14-day window for them to export any data they are legally required or entitled to retain.
- After the 14-day window (or immediately if there is no active Professional User), we delete your personal information and Case Data from our active systems within 30 days.
- Backup copies are purged within 90 days.
- Audit log entries referencing your actions are retained for the mandatory 7-year period but are anonymized so they can no longer be linked to your identity.
9.3 Limitations on deletion
We may retain certain information after a deletion request where required by applicable law or regulation, necessary to complete an ongoing legal proceeding, subject to a litigation hold, part of our audit logs (anonymized), or necessary to enforce our Terms of Service or protect against fraud.
10. Children's privacy
Our Services are not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately and we will take steps to delete it.
Information about children may be entered by their parents as part of the intake wizard (Section 3 — Children). This information is provided by the parent, is part of the parent's case, and is protected under the same security and privacy measures as all other Case Data.
11. International data transfers
DivorceParty stores and processes data in Canada and the United States. If you are located outside of these countries, your information may be transferred to and processed in Canada and/or the United States.
For Canadian users, we store data in Canadian data centers by default to comply with PIPEDA data residency preferences. For U.S. users, we store data in U.S. data centers.
We ensure that any international transfer of personal information is protected by appropriate safeguards, including contractual clauses and organizational measures that provide a level of protection equivalent to the protection offered in your home jurisdiction.
13. Third-party links and services
Our Platform may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you interact with.
When you connect a third-party service (Google Calendar, Gmail, etc.) to the Platform, you are also subject to that service's terms and privacy policies. We only access the minimum data necessary and do so in read-only mode where applicable.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- •Notify you by email at least 30 days before the changes take effect
- •Display a prominent notice within the Platform
- •Update the "Last Updated" date at the top of this policy
We encourage you to review this Privacy Policy periodically. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated policy.
15. How to contact us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
DivorceParty Privacy Officer
Email: privacy@divorceparty.com
Mailing Address: [To be provided at launch]
Phone: [To be provided at launch]
For complaints regarding our handling of your personal information:
- •Canada: You may file a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca
- •California: You may contact the California Attorney General's office at oag.ca.gov
We take all privacy complaints seriously and will respond within 30 days.
16. Solicitor-client privilege
DivorceParty is designed to support, not replace, the solicitor-client (attorney-client) relationship. Communications between Clients and Professional Users through the Platform may be protected by solicitor-client privilege. DivorceParty does not waive, and is not intended to waive, any privilege that may attach to communications or information shared through the Platform.
DivorceParty personnel do not access the content of communications between Clients and Professional Users except as necessary for technical support at the express request of the user, to comply with a valid legal order, or to investigate a credible security incident.
See also: Terms of Service
