← Back to home

Legal

Privacy Policy

Consilena is a legal-information tool. We are built so your confidential material stays confidential: your stored chats and memory are end-to-end encrypted on your device, and every AI provider we use operates under a zero-retention agreement. Last updated 5 July 2026.

Who we are

Consilena is operated by CONSILENA LIMITED, a company registered in England and Wales (company number 17297594), at 518 Maurer Court, John Harrison Way, London SE10 0SX, United Kingdom (“we”, “us”). We provide an AI legal-research and document-analysis service at consilena.com and in our iOS/Android apps, and we are the controller of your personal data. Contact: [email protected].

What we collect

  • Account data — your email, and (if you sign in with Google or Apple) the basic profile those providers return. Used to authenticate you and run your account.
  • Documents & queries — files you upload and questions you ask, so we can analyse them and return answers with citations.
  • Billing — handled by Stripe. We store a credit ledger and Stripe customer reference; we never see or store your full card number.
  • Operational logs — minimal request/error logs to keep the service running and secure. We do not build advertising profiles.

End-to-end encryption

When you enable encryption, your chat history and saved memory are encrypted in your browser/app with a key derived from your passphrase (and a one-time recovery code). The server only ever stores ciphertext — we cannot read that content, and we cannot recover it if you lose both your passphrase and recovery code. Your account key material is stored wrapped; the unwrapped key exists only in memory on your device.

Uploaded documents

Documents you upload (contracts, ID documents, and similar) are stored encrypted at rest: object storage is encrypted with a customer-managed key (AWS KMS), and the most sensitive extracted fields — passport / ID numbers, dates of birth, names and addresses — are additionally encrypted at the database-field level. Every upload is malware-scanned before it is accepted. Unlike your chat history, these documents are not end-to-end encrypted: the server must read them to extract fields, run searches, and generate documents on your behalf. They are never used to train models and are only ever processed under our zero-data-retention arrangements.

How AI processing works

To answer a question we send the relevant text to AI providers (Anthropic, OpenAI, Google, and open-weight models via DeepInfra). We only use providers under a zero-data-retention arrangement: they process the request in memory and do not retain it or train on it. Legal text is retrieved from official public sources; answers are grounded in those sources with verifiable citations.

How we use your data

To provide and improve the service, authenticate you, process payments, prevent abuse, and meet legal obligations. We do not sell your personal data and do not use your documents or queries to train models.

Sharing

We share data only with the processors that run the service — our AI providers (zero-retention, above), Stripe (payments), our email sender, and our hosting/ infrastructure — each only as needed. We may disclose data if required by law.

International operation & data transfers

We are a UK company and operate globally — serving users in the United Kingdom, the EU/EEA and the United States. We act as controller under the UK GDPR, and under the EU GDPR for EU/EEA users. Some of the processors that run the service — in particular our AI providers (Anthropic, OpenAI, Google, and open-weight models via DeepInfra) — are based in the United States, so providing the service involves transferring the necessary data internationally.

We rely on appropriate safeguards for those transfers, including Standard Contractual Clauses and data-processing agreements, and we only use AI providers under a zero-data-retention arrangement (they process the request in memory and do not retain or train on it). Your data is encrypted in transit and at rest throughout. We do not currently claim EU-only data residency; if that changes we will say so here.

Retention

We keep account and billing records while your account is active and as required by law (the credit ledger is append-only for audit integrity). You can delete your documents and chats at any time; encrypted content is unreadable to us regardless. Ask us to close your account and we will delete personal data we are not legally required to keep.

Your rights

Depending on where you live (e.g. GDPR/UK GDPR, CCPA), you can access, correct, export, or delete your personal data, and object to certain processing. Email [email protected] and we will respond within the statutory window.

Children

Consilena is not intended for anyone under 16, and we do not knowingly collect their data.

Changes

We will post any changes here and update the date above; material changes will be notified in-app or by email.

Consilena provides legal information, not legal advice. Consult a licensed lawyer for advice on your situation.