Last updated: July 5, 2026
The plain-English version of how Sidebar handles your clients' information — written the way we'd want a vendor to explain it to us. If anything here is unclear, ask us and we'll answer in writing.
Draft — pending attorney review. This document describes how Sidebar actually operates today and is published for transparency while formal legal review is completed. It will be finalized before general availability.
Layer one — the AI providers keep nothing.Every model we offer — Claude (the default), OpenAI, and Google's Gemini — is reachable in Sidebar only because a signed zero-retention agreement with that provider is already in place; it is never an opt-in setting you have to find and enable. Claude runs in an isolated, contractually zero-retention cloud environment; OpenAI requests carry storage disabled on every call, enforced in code; Gemini runs under Google's signed zero-retention terms. Nothing you type is stored by an AI company or used to train a model.
Layer two — Sidebar stores your workspace, like your other practice tools do. Saved conversations, uploaded documents, research memos, and matter memory live in a database partition isolated to your firm, so your work persists between sessions. You control what is saved and you can hard-delete it at any time. The rest of this page is about layer two.
| Question | Answer |
|---|---|
| Does the AI provider train on my content? | No. Every model runs under terms that prohibit training on your content. |
| Does the AI provider retain it? | No. Every model is reachable only under a signed zero-retention agreement — nothing is kept after processing. |
| Does Sidebar store it? | Yes — your saved workspace, encrypted and isolated to your firm, so your work persists. You can hard-delete any of it at any time. |
| Can Sidebar personnel access it? | Only as needed to operate the service or at your direction. Content is encrypted at rest; internal diagnostic tooling is gated and records its use in an access log. |
| How do I delete it? | Delete a conversation or matter (hard delete, including uploaded files), or close your account for full self-serve erasure. |
| What happens after account closure? | Every row and stored file in your workspace is hard-deleted, and the deletion propagates to backups as they cycle out. |
| What happens after legal process? | We notify you where permitted, give you a chance to respond, and produce the minimum required. Deleted content can't be produced — it no longer exists. |
| Data | Protection |
|---|---|
| Conversation messages | App-layer AES-256-GCM encryption under Sidebar's own key + disk encryption + tenant isolation |
| Extracted document text, chunks, summaries | App-layer AES-256-GCM + disk encryption + tenant isolation |
| Research memos & matter memory | App-layer AES-256-GCM + disk encryption + tenant isolation |
| Uploaded original files & generated documents | Private, access-controlled storage + disk encryption + tenant isolation |
| Client names & drafting-request descriptions | App-layer AES-256-GCM + disk encryption + tenant isolation |
| Conversation titles, matter titles & file names | Disk encryption + tenant isolation (navigation labels stay readable so lists and search work) |
| Usage records (model, tokens, cost, timestamps) | Contains no message content |
The substance of your work — everything a client would consider confidential — is encrypted under Sidebar's own key. Short navigation labels stay readable so your workspace remains searchable, the same trade-off your practice-management software makes. If you'd rather keep client names out of labels entirely, use matter numbers in your titles.
| Action | What actually happens |
|---|---|
| Delete a conversation | Hard delete: messages, extracted text, summaries, and the uploaded original files are removed — not soft-hidden |
| Delete a matter | Hard delete of the matter's workspace records |
| Do nothing | Your workspace is retained until you delete it; internal tool-audit content is auto-purged after 30 days on a daily schedule |
| Close your account | Self-serve full erasure: every row and stored file in your workspace is hard-deleted and your account is closed. Also honored by email at privacy@sidebar-ai.com if you prefer |
Because deletion is real, it is also your shield: content you have deleted no longer exists on our systems and cannot be produced to anyone — see Section 6.
Your workspace is isolated to your firm's partition, re-checked on every request. The substance of your work is encrypted at rest under Sidebar's own key, so it is not readable from storage alone. Access to production systems is limited to what is needed to operate the service, and our internal support and diagnostic tooling is gated behind an explicit control, never writes decrypted content to disk, and records every use in an access log.
Our commitment, in our Terms of Service and Legal Process Policy: civil demands for your content belong with you, the account holder, not with us. Unless legally prohibited, we notify you of any subpoena or demand before responding and give you time to object or move to quash — you assert your own privilege; our job is to make sure you are standing in front of your own data. And deleted content cannot be produced by anyone, because it no longer exists.
ABA Formal Opinion 512 asks you to understand a vendor's practices before trusting it, and we'd rather make that easy than make you dig. A data processing agreement (DPA) is available on request and countersigned per firm, and we're happy to walk your team through our architecture or complete a security questionnaire. If a question isn't answered here, ask us and we'll answer in writing.