Legal
Privacy Policy
Last updated: May 2, 2026
Effective date: May 2, 2026
1.Introduction and Scope
This Privacy Policy explains how Footmark AI ("Footmark," "we," "us," or "our") collects, uses, and protects personal data in connection with our website at footmark.legal and our legal-technology platform (together, the "Service"). Footmark AI is a legal-technology platform that analyzes fetal heart rate, cardiotocography (CTG), and other medical evidence to produce court-defensible medical-legal analysis for attorneys handling birth-injury and medical-malpractice litigation. Footmark AI is in the process of forming a legal entity; this policy will be updated with the entity's details upon formation. This Privacy Policy is incorporated by reference into our Terms of Service.
2.Information We Collect
We collect the following categories of information:
- Account information from Google Sign-In. When you create an account, we receive your name, email address, and basic Google profile information from Google. We use this information to create and authenticate your account.
- Case materials you upload ("Customer Content"). This includes medical records, fetal heart rate tracings, and case files that you or your firm submit to the Service for analysis.
- Information you provide directly. This includes demo requests, support inquiries, and, when available, billing details.
- Automatically collected data. We collect usage data, device information, and cookie and analytics data when you interact with our website.
3.How We Use the Records You Upload, and How We Improve the Service
This section describes how we handle Customer Content. It is important, and we want to be direct about it.
- We use Customer Content only to generate the analysis and reports you request through the Service.
- We do not use identifiable Customer Content to train or improve our artificial-intelligence models, and we do not share it with other customers.
- We may create de-identified information derived from Customer Content — with direct identifiers removed, including patient names, medical record numbers, dates, and facility or provider information — and use that de-identified information to measure, evaluate, and improve the accuracy and performance of the Service. De-identified information cannot reasonably be used to identify any individual, and we do not attempt to re-identify it.
- Our AI processing provider processes Customer Content solely to generate your analysis and does not use it to train its own models.
4.Other Uses of Information
In addition to the uses described above, we use information to operate and secure the platform, authenticate accounts, provide customer support, comply with legal obligations, prevent fraud and abuse, and communicate with you about the Service, including service announcements and responses to your inquiries.
5.Google User Data
When you sign in with Google, we receive your email address and basic profile information. We use this information solely for authentication and account management. Footmark's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6.How We Share Information
We share information only in the following circumstances:
- With service providers and subprocessors that host and operate the Service, only as needed to provide the Service on our behalf.
- When required by law, subpoena, court order, or other valid legal process.
- In connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
- As de-identified or aggregated data.
We do not sell personal data. Our current subprocessors are Railway (cloud hosting), Supabase (database and authentication), Google (sign-in), and Anthropic (Claude, AI processing). This list may be updated from time to time as our providers change.
7.Customer Content — Ownership and Responsibility
The customer (typically the law firm) owns and controls the Customer Content it uploads to the Service. Footmark processes Customer Content as a service provider on the customer's behalf and on the customer's instructions. The customer is responsible for having the legal right to upload the materials it submits, including compliance with any applicable protective orders, court orders, and client authorizations.
8.Data Retention
We retain Customer Content for the duration of your account and delete or return it within thirty (30) days after account termination or upon your written request, except where longer retention is required by law or is reasonably necessary to resolve a dispute. We retain account and usage data while your account is active and afterward only as needed for legal and operational purposes.
9.Security
We maintain reasonable administrative, technical, and organizational safeguards designed to protect the information we process. These safeguards include encryption in transit and at rest, access controls on a least-privilege basis, and US-based cloud hosting. No system is perfectly secure, and we cannot guarantee the absolute security of any information.
10.Your Privacy Rights
Depending on where you live, you may have rights to access, correct, or delete personal data we hold about you. You may exercise these rights by emailing us at privacy@footmark.legal.
California residents (CCPA/CPRA). If you are a California resident, you have the right to know what personal information we collect about you, to request deletion or correction of that information, to opt out of the sale or sharing of personal information (we do not sell or share personal information as those terms are defined under California law), and to be free from discrimination for exercising your rights. Residents of other US states may have similar rights under their state privacy laws.
11.Processing on Behalf of Customers
Where we process personal data contained in Customer Content on behalf of a customer, we act as a service provider or processor. Individuals whose information appears in Customer Content should direct rights requests to the customer (the law firm) that submitted the data. We will assist customers in responding to such requests as required by our agreement with them and by applicable law.
12.Children's Privacy
The Service is intended for legal professionals and is not directed to individuals under 18 years of age. Any personal data about individuals (including minors) contained in Customer Content is controlled by the customer under the service agreement and is not collected by Footmark directly from those individuals.
13.Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated policy on this page with a new effective date. Material changes will be highlighted where appropriate.
14.Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at privacy@footmark.legal.