This English version is an informational translation. In case of discrepancy, the Russian-language legal document governs.
← Home
CasusLegal

Privacy Policy
(personal data processing policy)

v. 1.1 dated 27.09.2026
In brief: we process only the data needed to operate the service — account access, payment, support and anonymized statistics. We do not sell personal data or disclose it to third parties, except where necessary to provide the services (payment processor, hosting, delivery of emails and messages). Consent may be withdrawn at any time through support channels.

1. General Provisions

1.1. This Privacy Policy (the “Policy”) establishes the procedure for processing the personal data of users of the CasusLegal information service for searching case law (the “Service”) and is issued in compliance with the requirements of Federal Law No. 152-ФЗ dated 27.07.2006 “On Personal Data” (the “152-ФЗ”), including Part 2 of Article 18.1.

1.2. The personal-data operator is an individual applying the special tax regime “Tax on Professional Income” (the “Operator”) and providing services under public offers published on the Service website. The Operator’s details (taxpayer identification number and contact details) are stated in invoices or provided upon request through feedback channels (Clause 10.1).

1.3. The Policy applies to all Service products: the website www.casus.legal, web chat and personal account (lk.casus.legal), Telegram bot, MCP connectors (mcp/sip/kas/kud.casus.legal and the cassation district addresses), including the unified address mcp.casus.legal/one/mcp and the CasusLegal One app for ChatGPT, corporate account (lk.casus.legal/corp) and API.

1.4. By using the Service, registering with it or submitting an inquiry, the user confirms consent to this Policy. Where the law requires separate consent to the processing of personal data, it is requested expressly (by checking a box in a form).

2. What data is processed

2.1. Account data: email address, name (how to address you), password (stored only as a cryptographic hash).

2.2. Telegram data — when signing in or linking an account through Telegram: account identifier, name, username, link to avatar; when using the Telegram bot — also the content of the dialogue with the bot.

2.3. Corporate-client data: organization name, taxpayer identification number, KPP, OGRN, registered address, bank details, email address, and the surnames and first names of employees — recipients of access codes, if the Customer specifies them in the account.

2.4. Support inquiries: inquiry text, attached files, contact details for the reply.

2.5. Technical data: IP address, browser and device data (User-Agent), cookies necessary for session operation, log of requests to the Service (time, tool called, volume), anonymized page-visit counters.

2.6. Payment data (card number, etc.) The Operator does not collect or store: payments are processed by the payment provider YooKassa (NCO “YooMoney” LLC). Only the fact and amount of the payment are transmitted to the Operator.

2.6.1. Data processed when working through an AI assistant (connectors, CasusLegal One in ChatGPT). The Service receives only what the assistant sends in a tool call: the search query or phrase, filters (court, year, article, act type), act numbers and, for exports, the collection heading. The Service does not receive or request the conversation history with the assistant. The query text is not written to the database or to request logs; derived data (a numerical representation of the query and a list of its paraphrases, which includes the query itself) is kept in the Service cache for up to 30 days. For each request the Service records the time, the tool called, the duration, the account or access-code identifier, the client IP address and User-Agent. When connected through ChatGPT and other cloud assistants, requests to the Service are made by the assistant developer’s servers, so the IP address of those servers is recorded, not that of the user’s device.

2.6.2. Connector authorization data: at sign-in to the connector the password is checked and not stored; the access token issued to the assistant is stored only as a hash. The connection registry keeps the assistant client identifier, User-Agent, dates of the first and last sign-in and the number of sign-ins.

2.7. The Operator does not request or intentionally process special categories of personal data or biometric data. Users should not include excessive personal data of third parties in requests to the Service or support inquiries; the user is responsible for including such data.

3. Purposes of processing

3.1. Data is processed for: (a) user registration and authentication and operation of the personal account; (b) performance of the contract — providing access to the Service, crediting payments, issuing invoices and closing documents; (c) technical support and responses to inquiries; (d) service notifications (email confirmation, subscription expiry, documents); (e) ensuring security and preventing abuse and technical failures; (f) maintaining anonymized statistics on use of the Service.

3.2. No advertising emails or messenger messages are sent without the user's consent.

4. Legal bases

4.1. Processing is carried out on the following bases: performance of a contract to which the personal data subject is a party (the Service's offer); the personal data subject's consent; the Operator's legitimate interests in protecting the Service against abuse; and performance of obligations imposed on the Operator by law (tax and accounting).

5. Cookies and analytics

5.1. The Service uses cookies necessary for session operation (sign-in to the account) and its own anonymized page-visit counter. Third-party advertising trackers are not used.

5.2. Cookies can be disabled in the browser, but this will make it impossible to sign in to the account.

6. Disclosure of data to third parties

6.1. Personal data is not sold or disclosed to third parties for their own purposes. Disclosure is possible only to the extent necessary for the operation of the Service:

6.2. User requests to the Service are processed using artificial intelligence models of third-party providers; the text of the request is transferred to the model provider to the extent necessary to generate a response, without the user's associated account credentials.

6.3. When searching through the connectors and CasusLegal One, the search query text (without the user’s account credentials) is transferred to: Voyage AI, to build a numerical representation of the query (semantic search); OpenRouter and the provider of the model used through it, to generate paraphrases of the query; TypeSafe, to determine which database the query relates to. These providers are foreign companies, and processing by them may take place outside the Russian Federation.

6.4. Service infrastructure: application hosting (Railway), database (Supabase), storage of encrypted backups (Cloudflare R2), website hosting. These providers process data only to the extent necessary to operate the Service.

7. Storage and retention periods

7.1. Data is processed until the purposes of processing have been achieved: account data — while the account exists; payment data and documents — for the periods established by tax legislation; request logs and analytics — for the period necessary for the purposes set out in Clause 3.1(d)–(e); request logs are currently not deleted automatically and do not contain query texts.

7.1.1. Specific periods for connectors: derived query data in the cache — up to 30 days; act collections exported by link and links to the full text of an act — 30 days; authorization code — 2 minutes; the access token issued to the assistant remains valid until revoked (account deletion, access disabled) and is checked on every request; service authorization records — up to 30 days, refresh token — up to 60 days; the connection registry — while the account exists. Database backups are stored encrypted.

7.2. At the user's request, the account and data associated with it are deleted or anonymized, except for data whose retention is required by law.

7.3. The user may delete the account independently: account (lk.casus.legal) → “Profile” section → “Delete account.” Upon deletion, the email address, name, avatar, and Telegram link are anonymized; access to connectors, the Telegram bot, and the web chat is terminated; correspondence in the web chat is deleted; and auto-renewal and the saved payment method are removed. Payment information is retained in anonymized form for the periods established by tax legislation (Clause 7.1). A paid but unused period is not automatically refunded upon independent deletion; the issue of a refund is resolved in accordance with the procedure provided for in the offer, through support channels (Clause 10.1).

7.3.1. When an account is deleted, request log entries remain linked to the anonymized account. Their deletion can be requested through the support channels (Clause 10.1).

7.3.2. A connector or the CasusLegal One app can be disconnected in the AI assistant’s settings; after the account is deleted or access is revoked, the tokens issued to the assistant stop working.

7.4. Telegram can be unlinked from the account while retaining the account itself in the same place: “Profile” → “Telegram bot” card → “Unlink Telegram.”

8. Rights of the personal data subject

8.1. The user has the right to: obtain information about the processing of their data; request its rectification, blocking, or destruction; withdraw consent to processing; and challenge the Operator's actions before the authorized personal data protection authority (Roskomnadzor) or a court.

8.2. Consent withdrawals and other requests are submitted through support channels (Clause 10.1). Withdrawal of consent may make it impossible to continue providing services that require data processing.

9. Data protection

9.1. The Operator takes the necessary legal, organizational, and technical measures to protect personal data: access to the Service is available only through a secure connection (TLS), passwords are stored as hashes, access to data is restricted, and measures are applied to protect against unauthorized access and automated data collection.

10. Feedback and amendments to the Policy

10.1. Feedback channels: the “Contact support” form in the personal account (lk.casus.legal), the Service’s Telegram bot, and, for corporate customers, also the corporate account (lk.casus.legal/corp). How to contact us is described on the support page.

10.2. The Operator may amend this Policy. A new version is published on this page with the version number and date and applies from the time of publication.

RU