Privacy Policy

Last updated: 1 September 2026

1. Overview

Barrister AI ("the Service") is operated by Barrister AI Pty Ltd (ACN 695 722 699) ("we", "us", or "our"). We are committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Privacy Policy explains how we collect, use, disclose, and store your personal information.

2. Information We Collect

We collect the following personal information when you register for and use the Service:

Account Information

  • Full name
  • Email address
  • Password (stored in hashed form only)
  • Jurisdiction (e.g. state or territory of practice)
  • Role (e.g. Judge, Barrister, Solicitor)

Usage Information

  • Search queries and case viewing history
  • Feature usage and interaction data
  • First-party website page views and successful Junior installer redirects, including the requested platform and release, referring page, and whether the request was a download or an automated availability check. A redirect does not tell us whether the file transfer completed.
  • For a successful Junior installer redirect: IP address, browser and device details, and approximate country or region
  • Daily digest email preferences

Payment Information

If you purchase a paid feature, your payment details are collected and processed by a secure third-party payment processor. We do not store your full card number. We receive limited transaction and billing information for account, support, reconciliation, and compliance purposes.

3. How We Use Your Information

We use your personal information for the following purposes:

  • Providing the Service: To operate your account, authenticate your sessions, process your requests, and deliver legal research content and related features.
  • Personalisation: To tailor case recommendations and search results based on your jurisdiction and role.
  • Communications: To send daily digest emails with recent cases relevant to your preferences. You can unsubscribe from digest emails at any time.
  • Payment processing: To manage your purchases, subscription, billing, and transaction records.
  • Service improvement: To understand usage patterns and improve the Service.
  • Account-deletion review: To conduct the limited, five-day review described in Section 8 when you request account deletion.
  • Security and legal purposes: To investigate a specific security incident, suspected fraud, unlawful activity or serious misconduct; resolve disputes; enforce our Terms of Service; establish, exercise or defend legal claims; and comply with law or a court or tribunal order.

4. Pseudonymous Usage and Restricted Access

Our routine operations are designed to limit access to directly identifying information. Where practical, Service activity is handled without displaying your name or email address to personnel reviewing product usage or performance.

Authorised personnel may link account information to Service activity only where you grant support access, or where doing so is reasonably necessary for a specific security, suspected-abuse, dispute, or legal purpose described in this Policy. Access is restricted and limited to the information reasonably necessary for that purpose.

A request to delete an account does not, by itself, indicate wrongdoing and is not, by itself, a reason to identify the user or inspect their private legal content.

5. Cookies and Authentication

The Service uses first-party cookies and similar technologies to authenticate users, maintain secure sessions, remember preferences, and operate the Service. These technologies are required for authenticated features.

We also use a persistent, randomly generated visitor cookie with a signed companion to link first-party page views and successful Junior installer redirects over time. If you are signed in, the hand-off may also be associated with your account. We do not use advertising or third-party tracking cookies.

6. Service Providers and Disclosures

We use third-party service providers to operate and support the Service. They may process personal information only to the extent reasonably necessary to provide services to us, comply with law, or protect their systems and rights. The categories of providers we use include:

Provider categoryPurposeInformation processed
Cloud hosting and storageOperate and secure the ServiceAccount, usage, and content data
Payment processingProcess purchases and billingAccount, transaction, billing, and payment details
CommunicationsSend service and requested emailsName, email address, and communication preferences
Service functionality and processingProvide requested Service featuresInformation you submit and relevant source material, where required for the requested feature

We do not sell or rent your personal information. We may also disclose information where required or authorised by law, to protect users or the Service, to obtain professional advice, or in connection with a genuine corporate transaction, subject to appropriate safeguards.

7. Data Storage and Overseas Disclosure

Some service providers process or store personal information outside Australia, including in the United States. Where APP 8 applies, we take reasonable steps to ensure that overseas recipients handle personal information consistently with the Australian Privacy Principles.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. When you request account deletion, we disable access immediately and retain your account data for five days before deleting it.

During that five-day hold, authorised staff may inspect pseudonymous account metadata, feature usage, case-access history, operational and security logs, and any voluntary exit feedback to understand why users leave, identify service failures, improve the Service and protect it from abuse. Routine account-deletion review does not show your name or email address and does not include opening your research questions or answers, briefs, uploaded documents, notebook content or other private legal content.

We inspect identity or private legal content during the hold only where you have granted support access, or where access is reasonably necessary for a specific security incident, suspected fraud, unlawful activity or serious misconduct, a dispute or legal claim, or compliance with law or a court or tribunal order. Any review is limited to information reasonably necessary for that purpose.

At the end of the hold we delete your personal information and account content, except for a particular record that we are required by law to retain or still reasonably need for a permitted security, fraud-prevention, dispute or legal purpose. Access to any such record remains restricted, and it is deleted or de-identified when it is no longer needed.

Raw IP addresses and full browser or device user-agent details recorded for Junior installer redirect and availability-probe events are access-restricted and cleared after 30 days. We retain the remaining pseudonymous interaction metadata only for as long as reasonably needed to understand product usage, diagnose delivery issues, and protect the Service.

One such record is kept in every case. When an account is deleted we retain a one-way cryptographic code derived from the email address, together with whether that address has already used a free trial or an introductory research credit. The code cannot be reversed back into an email address, is not used to contact you and is not used for marketing. We keep it for the single purpose of ensuring free trials and introductory credits are available once per person, and it is retained for as long as we offer them.

9. Your Rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you may exercise the following rights and choices:

  • Access: Request access to the personal information we hold about you.
  • Correction: Request correction of inaccurate or out-of-date personal information.
  • Deletion: Australian privacy law does not provide a general right to erasure, but it requires personal information to be destroyed or de-identified when it is no longer needed for a permitted purpose. We also allow you to request account deletion through your account settings or by contacting us below, subject to the process in Section 8.
  • Complaint: Lodge a complaint with us if you believe we have breached the APPs. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner.

10. Security

We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. We use administrative, technical, and organisational safeguards appropriate to the nature of the information we handle. However, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.

11. Children

The Service is designed for adults — legal professionals and, through Junior, individuals dealing with their own legal matters — and is not directed at individuals under the age of 18. We do not knowingly collect personal information from children.

12. Junior for Individuals

Junior is our desktop app. It can be used by legal practitioners and, in its individual mode, by people who are dealing with a legal problem of their own. This section explains what is different about how we handle your information when you use Junior as an individual. Everything else in this Policy still applies.

Your documents stay on your device

The documents you add to Junior are stored on your own computer, not on our servers. When you ask Junior to do something with them (for example, assess how ready your case file is, or prepare a pack to hand to a lawyer), the content is sent to us only for as long as it takes to produce the result. Our servers keep a record that a run happened, when, and what it cost, but that record contains none of your content. The result is sealed so that only your copy of Junior can open it, and the working copy we hold while the run is in progress is held in temporary storage that expires automatically and is then physically deleted.

Litigation funding submissions

We are building a feature that lets you submit your case for consideration by litigation funders. That feature is not yet available. When it is, it will be the one exception to the rule above: if you choose to submit, and only after you have signed a specific waiver that explains what will be shared and with whom, we will store the material you submit for that purpose. Nothing is stored under this exception unless you have signed that waiver.

AI providers

Junior uses third-party AI models to do its work. For the free guide built into Junior, we route requests under zero-data-retention terms: the model operator does not retain your prompts or the responses. For paid runs sent directly to our primary model provider, that provider may retain inputs and outputs for up to 30 days for abuse and safety monitoring, after which they are deleted. No provider is permitted to use your content to train its models.

Records of what you agreed to

When you accept the terms shown to individual users of Junior (and, in future, any funding waiver), we keep a record of that acceptance: which version of the wording you were shown, a digital fingerprint of that wording, the time, your IP address and your browser or device details. We keep this so that we can show what you agreed to and when. We do not store the wording itself in that record, and the record is never edited or deleted.

Health information

If your matter involves a personal injury, the documents you work with in Junior may include health information about you, which is sensitive information under the Privacy Act. The same rules apply: it stays on your device, it is sent to us only for the run you request, and it is not kept afterwards. By using Junior for such a matter you consent to it being handled in that way for that purpose.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the Service. We encourage you to review this page periodically.

14. Contact

If you have any questions about this Privacy Policy or wish to exercise your rights, please use our contact form.

See also our Terms of Service.

Privacy Policy - Barrister AI