Data safety
How RecourseLink protects account, readiness, evidence, and attorney-sharing data.
RecourseLink separates public source-backed information from private account records. Account records, readiness drafts, contact intake, purchases, evidence, and attorney disclosures are handled through authenticated, consent-scoped workflows.
Data minimization
RecourseLink asks for the minimum information needed for the selected workflow. Public situation checks are designed to avoid names, contact details, account numbers, SSNs, medical record numbers, documents, and other unnecessary sensitive details.
Private workflows may request more information only when the page explains the purpose and the user chooses to continue. Users should not submit information about someone else unless they have authority to do so.
Account and access protection
- Protected account areas require sign-in.
- Private records are scoped to the user account and workflow that created them.
- Attorney access to private information requires separate consent, scope limits, conflict certification, and access logging.
- Administrative and support access is limited to operational, security, billing, privacy, or legal-compliance needs.
- Abuse prevention, rate limits, validation, and monitoring may be used to protect users and the platform.
Consent and access history
Consent is separated by purpose. A user can agree to one workflow without agreeing to unrelated storage, attorney sharing, evidence handling, AI processing, or communications. Consent records may include the text shown, version, timestamp, account, source page, and selected scope.
Access and disclosure events for sensitive workflows are logged so RecourseLink can review who accessed what category of information, under which workflow, and when.
Evidence and document safety
Users should keep original records. RecourseLink may provide upload, organization, integrity-reference, or access-history tools, but those tools do not prove authenticity, admissibility, chain of custody, or legal sufficiency. A court, agency, settlement administrator, or attorney controls those determinations.
Before uploading evidence, users should redact or avoid unnecessary SSNs, account numbers, IDs, minors' information, medical details, passwords, and unrelated private information.
AI and third-party processing
AI features must stay informational, source-grounded, and limited to the purpose shown to the user. The Claim Clarity Report requires separate checkout choices for research involving the confirmed business, similar businesses and issues, published court decisions, and OpenAI processing. OpenAI receives only the authorized non-sensitive intake fields and relevant public-record information; it does not receive database access.
That request excludes uploaded documents, contact or payment data, medical details, privileged communications, account or claim numbers, and full court filings; provider storage is disabled. RecourseLink does not use private user facts to train public AI models. RecourseLink keeps limited private processing and safety records needed to audit the report.
User rights and retention
Users may use the privacy request workflow to ask for access, deletion, correction, export, opt-out where applicable, communication opt-out, and consent revocation. Some records may be retained when needed for security, fraud prevention, billing, legal compliance, consent history, dispute handling, or audit requirements.
