Privacy

Privacy policy

Version 1.0 · Last updated: 9 October 2026 · עברית

This policy explains how Volares, Inc. (“Volares”, “we”) collects and uses personal data when you visit volares.com, ask us for a demo, or use the Volares platform.

1. Two roles

When a law firm or legal department uses Volares, it controls the data it puts in. Documents, matters, messages, prompts and AI outputs in a customer’s account (“Customer Data”) belong to that customer. We process Customer Data only on the customer’s behalf and instructions, as its processor (in Israeli terms, a holder; under the CCPA, a service provider). If you are a client of one of our customers, or someone named in a matter, the customer’s own privacy notice applies, and requests about that data go to the customer. We will pass on any request we receive.

For everything else in this policy, we are the controller: data about visitors to our website, people who contact us, and the accounts, users and billing of our customers.

2. What we collect

CategoryWhatWhere it comes from
Account and user dataName, work email, firm, role, language, profile photo if you add one, phone number if you add one for verification codes, password (stored only as a one-way hash), and the sign-in provider you use (Google, Microsoft or Apple) with its identifierYou, your firm’s admin, or the sign-in provider you choose
Security and usage dataSign-in times, failed sign-in attempts with IP address, active sessions with browser type, actions recorded in your firm’s audit log, and system logs of requests, which include IP address and email addressOur systems, automatically
Demo and contact requestsName, work email, firm, role, phone if given, your message, the page you came from and, if you accepted, the campaign tags in the link that brought you (UTM parameters, a click identifier), and browser typeYou, and your browser when you submit the form
Billing dataFirm name, billing contact, billing address, subscription and invoices. Card details go directly to our payment processor, Stripe; we never see the full card numberYou, through Stripe
Support correspondenceWhat you write to us and our repliesYou
Website analyticsOnly if you accept analytics: pages viewed, two events (a button click and a form submission), approximate location derived from IP address, device and browser, through Google AnalyticsYour browser, only after you accept

We do not ask for special categories of personal data about you. We do not knowingly collect data from anyone under 18.

3. Why we use it, and our legal basis

Where the EU or UK GDPR applies, we rely on the legal bases shown.

PurposeDataLegal basis (GDPR)
Provide the platform: create accounts, sign you in, run the features your firm usesAccount, usagePerformance of our contract with your firm, and our legitimate interest in serving its users
Keep the platform secure: detect abuse, investigate incidents, keep audit recordsSecurity and usageLegitimate interests (security), and legal obligations
Bill and keep financial recordsBillingContract; legal obligation (bookkeeping)
Answer demo requests and supportContact, supportSteps at your request before a contract; legitimate interest in answering business enquiries
Send service messages (sign-in codes, invitations, notices about the service or these policies)AccountContract; legitimate interests
Send occasional business updates to people who asked for a demo or are customersContactLegitimate interests, with an unsubscribe link in every message; consent where the law requires it
Understand how our website is usedAnalyticsConsent

We do not use personal data to make decisions that have legal or similarly significant effects on you by automated means alone.

4. AI and your data

  • Every AI model call is made through Amazon Bedrock in our own AWS account, on servers in the United States. The models are made by Anthropic (Claude) and Cohere, and are run by AWS.
  • We do not use Customer Data, or your personal data, to train AI models.
  • We do not use Customer Data for any law firm or legal-services business we own or operate.

5. Who we share it with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share personal data only with:

  • The service providers below, which process it for us under contract.
  • Your firm. Your firm’s admins can see your account, your activity in the firm’s audit log, and the content you create in the firm’s account.
  • Authorities or others where the law requires it, or to protect our rights, users or the public, after giving notice where we lawfully can.
  • A buyer or successor in a merger, acquisition or sale of assets, under this policy.

The service providers we use today:

ProviderWhat it does for usWhat it receives
Amazon Web Services, Inc.Hosting, database, file storage, logs and email sending, in its us-east-1 region (N. Virginia, United States); AI inference through Amazon Bedrock, in US regionsAll the data described in this policy that lives in the platform, including Customer Data
Brave Software, Inc.Web search, only when a user’s session uses web searchThe search query, which the AI writes from the conversation
Stripe, LLCPayments and subscriptions, for a firm that pays by cardBilling data
Google LLCOur own email (Google Workspace); sign-in, if you choose Google; website analytics, if you accept. The platform also loads its typefaces and Google’s sign-in script from GoogleSupport correspondence; your Google identity if you sign in with it; analytics data if you accept; your IP address and browser details whenever the platform loads
Microsoft Corporation, Apple Inc.Sign-in, if you choose themYour identity with that provider

6. Where it is processed

We store data in the United States, in AWS’s us-east-1 region (N. Virginia), and AI inference runs in AWS regions in the United States. Our service providers may process data in other countries as their own terms describe.

If you are in the EEA, the UK or Switzerland, your personal data is transferred to the United States. Where the law requires a safeguard for that transfer, we put one in place, such as the European Commission’s Standard Contractual Clauses. We do not participate in the EU-US Data Privacy Framework.

7. How long we keep it

DataKept
Account and user dataWhile your firm’s account is active. A user your firm removes is deactivated and stays in the firm’s records until the firm’s account is deleted
Customer DataFor the term of the customer’s agreement. When a firm closes its account there is a 7-day period in which the closure can be cancelled; after it, we delete the firm’s data. Deleted file versions expire from storage within 30 days, and encrypted database backups within 7 days
Audit logWhile the firm’s account is active
Application logs, which can include email and IP addresses and contain no prompts or outputs of AI runs90 days
The workflow history of each AI run, including its input and output, held by AWS Step Functions90 days after the run ends
Sign-in attempt records and session recordsNo fixed period has been set yet. You can ask us to delete yours (section 10)
Billing recordsFor the subscription, and afterwards as long as bookkeeping and tax law require
Demo and contact requestsNo fixed period has been set yet. You can ask us to delete yours at any time (section 10)
Website cookies and storageAs section 9 describes

8. Security

We protect personal data with encryption in transit (TLS 1.2 or higher) and at rest, separation of each customer’s data, role-based access, an audit log, and monitoring of our cloud account. Our staff open a customer’s content only when the customer grants time-limited support access. No system is perfectly secure; we will notify affected customers and individuals of a breach as the law requires.

9. Cookies and browser storage

Our website uses Google Analytics only if you accept in our cookie notice. Until you choose, the Google Analytics script is not loaded and no analytics cookie is set. Declining is as easy as accepting, and you can change your choice at any time through Cookie choices at the foot of every page. The platform uses only what it needs to sign you in and protect your session. We use no advertising cookies and no social-media pixels.

NameWherePurposeDuration
vl_consent (cookie, with a copy in local storage)WebsiteRemembers whether you accepted or declined. Strictly necessaryAbout 6 months
_ga, _ga_<id>WebsiteGoogle Analytics: tells visitors apart and keeps session state. Only after you accept. Advertising storage, ad personalisation and Google signals stay off2 years (Google’s default)
volares_attribution (local storage)WebsiteThe campaign tags in the link that brought you, the referring page and the page you landed on, sent with a demo request if you submit one. Only after you accept; declining later deletes itUntil you clear your browser or decline
volares_sessionPlatform; also sent to volares.comKeeps you signed in. Not readable by scripts on the page, and sent only over HTTPS. Strictly necessary30 days, renewed daily while you use the platform
volares_csrfPlatformProtects your session against cross-site request forgery. Strictly necessary7 days
Local and session storage for sign-in and settings (volares-auth, volares-last-account, interface and accessibility preferences, the Microsoft sign-in library’s cache)Platform and websiteRemembers who is signed in on this device and your settings, and completes sign-in. Strictly necessaryUntil you sign out or clear your browser

If you decline, or later withdraw consent, Google Analytics stays off and we delete its cookies from our domain. You can also delete or block cookies in your browser’s settings; blocking the platform’s strictly necessary cookies will stop you from signing in.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to receive it in a portable format, to withdraw consent at any time, and not to be discriminated against for exercising these rights. Where we process your data as a processor for a customer, we will refer your request to that customer.

To make a request, write to yakir@volares.com. We will confirm receipt, may need to verify your identity, and will reply within the period the law sets. An authorised agent may make a request for you with your signed permission.

You may complain to your data protection authority: in the EU, the authority where you live or work; in the UK, the Information Commissioner’s Office; in Israel, the Privacy Protection Authority.

11. California

This section applies to California residents to the extent the CCPA applies to us. In the past 12 months we collected the categories in section 2: identifiers (name, email, IP address), professional information, commercial information (billing), internet activity (website analytics with consent, security logs) and approximate geolocation derived from IP address. We collected them from the sources and for the purposes in sections 2 and 3, and disclosed them to the service providers in section 5 for business purposes. We have not sold or shared personal information, and we do not use or disclose sensitive personal information except to provide the services. You have the rights in section 10, including to know, delete and correct, and to opt out of sale or sharing, which we do not do.

12. Israel

If you are in Israel: you are not legally required to give us personal data, but without your account data we cannot provide the platform, and without contact details we cannot answer your request. The data is used for the purposes in section 3, by Volares and the recipients in section 5. You have the right to inspect your data and to ask for it to be corrected or deleted (sections 13 and 14 of the Protection of Privacy Law). We will not send you marketing messages without the consent the law requires, and you may ask at any time to be removed from any mailing list. A Hebrew version of this policy is at volares.com/he/privacy.

13. Changes

We will notify customers’ account holders of material changes by email and in the product, before they take effect, and post the new version here with its date.

14. Contact

Company
Volares, Inc., a Delaware corporation
Email
yakir@volares.com

We have not appointed a data protection officer; the email address above is our privacy contact.