☁️Data on Google Cloud India region|🗣️हिंदी · मराठी · தமிழ் · తెలుగు · বাংলা · ಕನ್ನಡ · + more|⚖️BNS · BNSS · BSA 2023 Ready|🏛️eCourts.gov.in Integration|🔒DPDP Compliant · 256-bit Encrypted|☁️Data on Google Cloud India region|🗣️हिंदी · मराठी · தமிழ் · తెలుగు · বাংলা · ಕನ್ನಡ · + more|⚖️BNS · BNSS · BSA 2023 Ready|🏛️eCourts.gov.in Integration|🔒DPDP Compliant · 256-bit Encrypted|

Privacy notice

Privacy Policy

This notice explains what personal data MyAdvoMate collects, why it is processed, which service providers assist us, how long data is retained, and how you can exercise your privacy rights.

Notice v2026-03-17 • Terms v2026-03-17EN
We rely on explicit actions such as sign-up consent checkboxes, intake-form consent, authenticated account activity, and user-triggered workflows to process personal data. We do not treat passive browsing alone as consent for account or matter processing.

Google API Services Usage Disclosure

MyAdvoMate’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Data Accessed

If you choose to integrate Google Drive or Google Auth, our application accesses your identity (email/name) strictly for authentication, and accesses specific files (e.g., PDFs, Word documents) only after you explicitly select them via the Google Picker interface.

Data Usage

We use this data strictly to authenticate your account and to attach the explicitly selected files to your respective legal matter within MyAdvoMate. This assists you in reviewing, drafting, or archiving case documents directly from your Google Drive.

Data Sharing

Google user data obtained through APIs is not shared with third-party data brokers. It is used strictly for application functionality and is only accessible to you and authorized firm members who have permission to view your matters.

Data Storage & Protection

Selected files are securely transferred and stored in encrypted cloud storage environments (Firebase). Strict access-control rules enforce that retrieved data remains isolated and only visible to authorized system members.

Data Retention & Deletion

Imported files are retained within the system solely for the active duration of the matter. Users can manually delete any imported file from the matter dashboard. If an account is deleted, all retained Google data associated with the account is permanently destroyed.

Data we collect, why we use it, and how long we keep it

Account and identity data

Name, email address, phone number, role, firm details, bar council number, city, state, country, and account credentials handled by Firebase Authentication.

Purpose: Account creation, sign-in, profile setup, subscription management, and security.

Retention: Active account period and up to 3 years after closure unless a longer period is legally required.

Matter and client data

Client names, phone numbers, emails, matter descriptions, court details, CNR numbers, case notes, hearing metadata, timesheets, invoices, and uploaded records.

Purpose: Legal practice management, collaboration, reminders, client communication, invoicing, and portal access.

Retention: Until deleted by the account owner or account deletion is completed, subject to legal retention obligations.

Documents, recordings, and transcripts

Uploaded files, audio recordings, transcripts, extracted text, and document analysis outputs.

Purpose: Document storage, review, drafting, transcription, AI summaries, and matter history.

Retention: Until deleted by the user, matter owner, or account deletion workflow.

Billing and payment data

Plan selections, subscription status, invoice settings, invoice records, payment metadata, and payment processor identifiers.

Purpose: Subscription billing, tax invoicing, and payment reconciliation.

Retention: Generally up to 7 years where financial and tax records must be preserved.

Security, audit, and usage data

IP addresses, client portal sessions, audit logs, token usage logs, device/browser metadata, and support records.

Purpose: Fraud prevention, abuse monitoring, service diagnostics, security investigations, and dispute handling.

Retention: Short-lived sessions are removed automatically where possible; audit and usage logs are retained only as needed for security, support, billing, and compliance.

Data processors and infrastructure

We use selected processors to operate the service. These processors handle data only to provide the contracted service to MyAdvoMate.

Google Firebase

Authentication, database, hosting, and file storage

Account data, case records, uploads, and application telemetry

Google Generative AI / Vertex AI

AI analysis, summaries, and drafting assistance

Matter context, transcripts, prompts, and uploaded documents when a user requests AI features

Amazon Web Services (SES)

Transactional emails and reminders

Email addresses and notification payload metadata

Razorpay

Subscription billing and payment processing

Billing identifiers, plan metadata, and payment status information

MeiliSearch

Search indexing for user content

Searchable matter and document metadata

Some processors may use infrastructure outside India depending on service configuration, support operations, or global cloud delivery. We disclose these processors here and evaluate transfer controls as the applicable regulatory position evolves.

Your rights

Access a summary of your personal data and processing activity.
Request correction of inaccurate or incomplete data.
Download a machine-readable export of your account data.
Request deletion of your account and associated records.
Raise a grievance regarding privacy, consent, or retention handling.

Contact and grievance

Privacy & Grievance Officer

admin@myadvomate.com

MyAdvoMate Technologies Pvt. Ltd., Dehradun, Uttarakhand, India

If you have a privacy complaint, access request, correction request, or deletion request, please sign in to your dashboard to use the Privacy & Data Rights center, or contact us using the details above.

Security and retention controls

Security

We use authenticated access controls, encrypted transport, cloud storage protections, audit logging, and rules-based access restrictions to protect matter and account data.

Retention

We retain data only while it is needed for the stated purpose, user support, billing, legal obligations, and security investigations. Account deletion initiates a cascading deletion workflow for owned records.