Skip to main content
← Back to home

Legal — Public Document

Privacy Policy

Entity
OneAuris, Inc., a Delaware corporation
Platform
Auris · oneauris.com
Effective
July 29, 2026
Last Updated
July 29, 2026
Contact
contactus@oneauris.com

1. Who We Are

OneAuris, Inc. (“OneAuris,” “we,” “us,” or “our”) is a Delaware corporation with its principal place of business at 27 Irving Avenue, Floral Park, New York 11001. We develop and operate Auris, a software platform that assists law firms in conducting first-pass review of litigation discovery documents, including classification for relevance and for attorney-client privilege.

This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with the Auris platform, our websites at oneauris.com and app.oneauris.com, and related services (collectively, the “Services”).

Privacy inquiries may be directed to contactus@oneauris.com or to the mailing address in Section 16.

2. Scope

This Policy distinguishes between two categories of information, which we treat very differently.

Client Data. Documents, metadata, and related materials that a subscribing law firm (“Firm”) uploads to or generates within Auris in the course of a legal matter. This may include information belonging to the Firm’s own clients, to opposing parties, and to third parties. We process Client Data solely as a service provider and processor, acting on the Firm’s documented instructions. The Firm determines what is uploaded, for what purpose, and for how long it is retained. We do not determine the purposes or means of processing Client Data beyond the technical operation of the Services.

Account and Site Data. Information about the Firm as our customer and about individuals who visit our websites or administer a Firm account. We act as a controller, and under California law as a “business,” with respect to this category.

Where this Policy conflicts with a written agreement between OneAuris and a Firm, including any Data Processing Addendum or Business Associate Agreement, that agreement controls as to Client Data.

3. Information We Collect

3.1 Client Data

The Firm controls what enters the platform. Client Data typically includes:

  • Document files uploaded for review, in native, image, or extracted-text form
  • Document metadata, including filenames, Bates numbers, custodian identifiers, dates, file hashes, and page counts
  • Matter-level information, including matter name, caption, jurisdiction, review parameters, and privilege criteria
  • Review outputs, including relevance and privilege classifications, confidence scores, model rationale, attorney overrides, and the associated audit trail
  • Any personal information contained within uploaded documents. In workers’ compensation, personal injury, and insurance defense matters this routinely includes medical records, treatment histories, billing records, employment records, and government identifiers.

We do not select, curate, or limit what a Firm uploads.

3.2 Account Data

  • Firm name, billing address, and tax identifiers
  • Names, business email addresses, job titles, and telephone numbers of authorized users
  • Authentication credentials, stored as salted cryptographic hashes; we do not store passwords in plaintext
  • Subscription tier, order form terms, invoices, and payment history
  • Support correspondence and the contents of support tickets

3.3 Technical and Usage Data

  • IP address, browser type and version, operating system, and device type
  • Authentication events, session timestamps, and access logs
  • Feature usage, page views, and error and diagnostic logs

3.4 Payment Information

Payments are processed by Stripe, Inc. We do not collect, transmit, or store full payment card numbers, security codes, or bank account numbers. Stripe furnishes us with a payment token, the last four digits of the instrument, its brand, and its expiration date.

3.5 Information We Do Not Collect

We do not collect biometric identifiers or precise geolocation. We do not purchase personal information from data brokers. We do not operate, participate in, or share information with advertising networks. We do not build consumer profiles or draw inferences about individuals for any purpose.

4. How We Use Information

4.1 Client Data

We use Client Data for one purpose only: to provide the Services to the Firm that submitted it. Specifically:

  • Ingesting, extracting text from, indexing, and storing documents
  • Submitting document text to our classification pipeline for relevance and privilege analysis
  • Generating classifications, confidence scores, and rationale for attorney review
  • Maintaining the audit trail of classifications, escalations, and attorney overrides
  • Producing exports, privilege logs, and review reports at the Firm’s direction
  • Providing technical support at the Firm’s request

We do not use Client Data to develop, train, fine-tune, or evaluate machine learning models. See Section 6.4.

4.2 Account, Technical, and Usage Data

  • Creating and administering accounts and authenticating users
  • Billing, invoicing, collections, and tax compliance
  • Providing support and communicating about the Services
  • Monitoring availability, diagnosing errors, and improving performance and security
  • Detecting and preventing fraud, abuse, and unauthorized access
  • Complying with legal obligations and enforcing our agreements
  • Sending administrative notices, and sending marketing communications where permitted, subject to opt-out at any time

5. Legal Basis and Territorial Scope

The Services are offered to law firms located in the United States. We do not target, market to, or solicit customers in the European Economic Area, the United Kingdom, or Switzerland, and we do not offer the Services to individuals resident in those jurisdictions.

We process information on the following grounds:

  • Performance of our contract with the Firm, and steps taken at the Firm’s request before entering into it
  • Compliance with our legal obligations
  • Our legitimate interests in operating, securing, and improving the Services, balanced against the rights of affected individuals
  • Consent, where required, for marketing communications

If we begin offering the Services in a jurisdiction imposing additional requirements, we will update this Policy before doing so.

6. Client Data, Privilege, and Protected Health Information

6.1 Attorney-client privilege and work product

Client Data frequently contains privileged attorney-client communications and attorney work product. We handle it on that assumption at all times.

  • Client Data is logically segregated by Firm and by matter. Access controls prevent any Firm from accessing another Firm’s data.
  • OneAuris personnel do not access Client Data except (i) at the Firm’s express request in connection with a support issue, (ii) where strictly necessary to investigate a security incident, or (iii) where compelled by law. Access is limited to personnel with a need to know, is logged, and is auditable by the Firm.
  • Our processing of Client Data at the direction of counsel is intended to fall within the agent-of-counsel doctrine and is not intended to waive any privilege or protection. Preservation of privilege remains the responsibility of the Firm and its attorneys.
  • If we receive a subpoena, court order, or governmental demand for Client Data, we will, unless legally prohibited from doing so, notify the Firm promptly and before responding, provide reasonable cooperation in any challenge the Firm elects to bring, and produce nothing beyond what is legally required.

6.2 Professional responsibility

Auris produces classification suggestions. It does not practice law and does not render legal advice. Every relevance and privilege determination remains the sole professional responsibility of the licensed attorney supervising the review. The attorney override function exists for that reason and is a required part of the workflow. Nothing in the Services relieves an attorney of any duty of competence, supervision, or confidentiality under the applicable rules of professional conduct.

6.3 Protected health information

Client Data in workers’ compensation, personal injury, and insurance defense matters routinely contains protected health information (“PHI”) as defined at 45 C.F.R. § 160.103. We handle PHI as follows:

  • Where a Firm acts as a business associate of a covered entity, or otherwise handles PHI subject to HIPAA, OneAuris acts as a subcontractor business associate and will execute a Business Associate Agreement (“BAA”) with the Firm. The BAA governs our handling of PHI and, to the extent it conflicts with this Policy, controls.
  • We maintain a Business Associate Agreement with each subprocessor that creates, receives, maintains, or transmits PHI on our behalf.
  • We apply identical administrative, physical, and technical safeguards to all Client Data regardless of whether PHI has been identified within it, on the assumption that PHI may be present in any matter.
  • We do not use or disclose PHI other than as permitted by the applicable BAA, as required by law, or as necessary for the proper management and administration of our operations.

To request a Business Associate Agreement, contact contactus@oneauris.com.

6.4 No model training on Client Data

We do not use Client Data to train, fine-tune, or improve any machine learning model, whether our own or a third party’s. Document text submitted to our classification pipeline is processed through Amazon Bedrock under a zero-data-retention configuration. Under that configuration the model provider does not retain, log, or use submitted content for any purpose once the inference request has been served. This commitment is contractual, applies to all Client Data without exception, and is not subject to opt-in or opt-out because no such use occurs.

7. Data Sharing and Subprocessors

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not disclose Client Data to any party except as set out in this Section.

7.1 Subprocessors

We engage the following subprocessors to deliver the Services. Each is bound by written data protection terms, and each that handles PHI is bound by a Business Associate Agreement.

SubprocessorFunctionData CategoriesLocationPHI
Amazon Web Services, Inc.Application hosting, compute, and relational databaseClient Data, Account Data, Technical DataUnited StatesBAA in place
Amazon Bedrock (AWS)Model inference for classification, zero data retentionClient Data (document text)United StatesBAA in place
Amazon SES (AWS)Transactional account and notification emailAccount Data (name, email address)United StatesNot applicable
Cloudflare, Inc. (R2)Encrypted document object storageClient DataUnited StatesBAA in place
Stripe, Inc.Payment processingAccount Data, billing contactUnited StatesNot applicable

Amazon Web Services, Inc. is engaged in four distinct functions above. Each is governed by a single written agreement with AWS, including a Business Associate Agreement covering the AWS services that create, receive, maintain, or transmit protected health information on our behalf. We maintain a current and complete list of subprocessors and will furnish it on request to contactus@oneauris.com. We give Firms advance notice of any new subprocessor that will process Client Data, together with a reasonable opportunity to object.

7.2 Other disclosures

Professional advisers. Legal counsel, accountants, and auditors, each under a duty of confidentiality.

Legal compulsion. Where required by subpoena, court order, or applicable law, subject to the notice commitments in Section 6.1.

Protection of rights. Where reasonably necessary to investigate suspected fraud or a security incident, or to establish, exercise, or defend legal claims.

Business transfer. In connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality obligations. Client Data will not become subject to a different privacy policy without advance notice to the affected Firm.

At the Firm’s direction. To co-counsel, experts, vendors, or any other recipient the Firm designates.

We do not disclose Client Data to advertisers, data brokers, or analytics providers under any circumstances.

8. Retention and Deletion

We retain information for the periods below, or for a shorter period where the Firm instructs deletion.

CategoryRetentionBasis
Client DataTerm plus 30 daysThirty-day export window following termination, then deletion. A Firm may request earlier deletion of a matter or of specific documents at any time; we action such requests within 30 days.
Audit trail recordsTerm plus 30 daysRetained with, and deleted alongside, the associated matter. Longer retention for litigation hold is arranged in writing.
Account DataTerm plus 7 yearsTax, accounting, and limitation-of-actions requirements.
Billing records7 yearsTax and accounting requirements.
Technical and access logs12 monthsSecurity monitoring, extended only for an active investigation.
Support correspondence3 yearsService history and dispute resolution.
Marketing contactsUntil opt-outA suppression record is retained indefinitely for the sole purpose of honoring the opt-out.

Deletion is executed against live systems within the stated period. Encrypted backups are purged on their own rotation and in no event later than ninety (90) days after deletion from live systems. Backup data is not restored to production except in a disaster recovery event, and any restored data that was subject to a deletion request is re-deleted immediately.

9. Cookies and Tracking

We use strictly necessary cookies only. Specifically:

  • Session and authentication cookies, which keep a signed-in user signed in and protect against cross-site request forgery
  • Load balancing and security cookies set by our hosting and network providers

We do not use analytics cookies, advertising cookies, tracking pixels, session-replay tools, fingerprinting, or third-party trackers on oneauris.com or app.oneauris.com. Because we set only strictly necessary cookies, no consent banner is presented; none is required.

We do not respond to browser Do Not Track signals, as no uniform standard for them exists. We honor Global Privacy Control signals as opt-out requests under California law where such a signal is received. Because we neither sell nor share personal information, honoring the signal produces no change in our processing.

10. Security

Encryption. TLS 1.2 or higher for data in transit. AES-256 for documents and databases at rest.

Access control. Role-based access enforced on the principle of least privilege. Multi-factor authentication is required for all OneAuris personnel with production access.

Tenant isolation. Client Data is logically segregated by Firm and by matter, with authorization enforced at both the application and data layers.

Audit logging. Access to production systems and to Client Data is logged and subject to review.

Personnel. Background-checked where permitted by law, bound by written confidentiality obligations, and trained on confidentiality and privilege handling before receiving any access.

Vendor diligence. Subprocessors are assessed before engagement and bound by written data protection terms.

Incident response. Documented procedures for detection, containment, investigation, and notification.

We have built the platform to align with SOC 2 control criteria. We do not currently hold a SOC 2 attestation and we make no representation that we do. Independent audit is on our roadmap.

No system is perfectly secure. We do not warrant that the Services will be free from unauthorized access.

10.1 Breach notification

If we become aware of a breach of security leading to unauthorized access to or disclosure of Client Data, we will notify the affected Firm without undue delay and in any event within seventy-two (72) hours of confirmation, providing the information reasonably available at that time and supplementing as the investigation progresses. Where a Business Associate Agreement applies, its notification terms govern. Notification to affected individuals, regulators, courts, or opposing parties is the responsibility of the Firm as controller; we will provide reasonable assistance.

11. Your Rights

11.1 Individuals whose information appears in Client Data

Individuals whose personal information appears within documents uploaded by a Firm are not our customers, and we have no direct relationship with them. We act solely on the Firm’s instructions. If you believe your personal information appears in documents processed through Auris and you wish to exercise rights over it, contact the law firm that holds those documents. If you contact us, we will refer you to the relevant Firm where we are able to identify it, and we will assist that Firm in responding. We will not search Client Data to locate an individual absent instruction from the Firm or legal compulsion.

11.2 Account and Site Data

Depending on your state of residence, you may have the right to:

  • Know what personal information we have collected, its sources, the purposes of collection, and the categories of recipients
  • Access a copy in a portable, readily usable format
  • Correct inaccurate personal information
  • Delete personal information, subject to our legal retention obligations
  • Opt out of the sale or sharing of personal information, neither of which we do
  • Limit the use of sensitive personal information, which we do not use for any purpose triggering this right
  • Be free from discrimination or retaliation for exercising any of these rights

11.3 How to submit a request

Submit requests to contactus@oneauris.com with “Privacy Request” in the subject line, or to the mailing address in Section 16. We verify identity by matching the information in the request against our records; for account holders, confirmation from the registered email address is generally sufficient. We respond within forty-five (45) days, extendable once by a further forty-five (45) days with notice to you. There is no charge unless a request is manifestly unfounded or excessive.

An authorized agent may submit a request on your behalf with written permission signed by you. We may require you to verify your own identity and to confirm the agent’s authority directly.

If we decline a request in whole or in part, our response will state the reason and explain how to appeal. Appeals should be sent to contactus@oneauris.com with “Privacy Appeal” in the subject line and will be answered within forty-five (45) days.

12. California Privacy Rights

This Section supplements Section 11 and applies to California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act.

12.1 Our roles

With respect to Client Data, OneAuris is a “service provider” within the meaning of Cal. Civ. Code § 1798.140(ag). We process Client Data only to perform the Services specified in our written contract with the Firm. We do not retain, use, or disclose it for any other purpose, including any commercial purpose of our own; we do not sell or share it; and we do not combine it with personal information received from any other source except as permitted by § 1798.140(ag)(1). With respect to Account and Site Data, OneAuris is a “business.”

12.2 Categories collected in the preceding twelve months

The following applies to Account and Site Data. It does not describe Client Data, which we process only as a service provider.

Category § 1798.140(v)SourceBusiness PurposeDisclosed To
Identifiers — name, business email, IP addressDirectly from you; automaticallyAccount administration, authentication, supportAWS (hosting and email)
Customer records — billing contact, payment tokenDirectly from you; from StripeBilling, invoicing, and collectionsStripe, AWS
Commercial information — subscription and transaction historyDirectly from youContract administrationStripe, AWS
Internet activity — access logs, feature usage, diagnosticsAutomaticallySecurity, availability, and diagnosticsAWS
Professional information — job title, firm roleDirectly from youAccount provisioning and permissionsAWS
Sensitive personal information — account credentialsDirectly from youAuthentication onlyAWS

We do not collect biometric information, precise geolocation, education records, or inferences drawn to create a profile reflecting preferences or characteristics.

12.3 Sale and sharing

We have not sold personal information, and have not shared personal information for cross-context behavioral advertising, in the preceding twelve months, and we do not do so now. We do not knowingly sell or share the personal information of consumers under sixteen (16) years of age.

12.4 Sensitive personal information

The only sensitive personal information we collect is account credentials, used solely to authenticate users. We do not use or disclose it for any purpose that would trigger the right to limit under § 1798.121.

12.5 Retention and Shine the Light

Retention periods are set out in Section 8. We do not disclose personal information to third parties for those parties’ own direct marketing purposes, and therefore make no disclosure under Cal. Civ. Code § 1798.83.

13. International Transfers

We store and process all data in the United States. The subprocessor facilities used to deliver the Services are located in the United States. We do not transfer Client Data outside the United States.

If you access the Services from outside the United States, you are transmitting information to the United States, where privacy laws may differ from those of your jurisdiction. We do not offer the Services in the European Economic Area, the United Kingdom, or Switzerland; see Section 5.

14. Children’s Privacy

The Services are business software licensed to law firms. They are not directed to children. We do not knowingly collect personal information directly from any person under eighteen (18) as a user of the Services, and if we learn that we have done so we will delete it.

Client Data may contain personal information about minors, for example the medical, educational, or employment records of a minor plaintiff in a personal injury matter. Such information is contained within documents supplied by a Firm, is not collected by us from the individual, and is handled solely under the Firm’s instructions and the terms of this Policy and any applicable Business Associate Agreement.

15. Changes to This Policy

We may update this Policy from time to time. The “Last updated” date on the first page reflects the most recent revision. For material changes affecting Client Data or the rights of Firms, we will give at least thirty (30) days’ advance notice by email to the Firm’s account administrator and by notice within the application. Continued use of the Services after the effective date of a change constitutes acceptance of it. Prior versions are available on request.

16. Contact

Direct all privacy inquiries, rights requests, appeals, subprocessor list requests, and Business Associate Agreement requests to:

OneAuris, Inc.
27 Irving Avenue
Floral Park, New York 11001
United States
contactus@oneauris.com

For requests concerning documents held by a law firm using Auris, contact that firm directly. See Section 11.1.

OneAuris, Inc. is a technology provider. It does not practice law, does not provide legal advice, and forms no attorney-client relationship with any Firm, any Firm’s client, or any other person.