This page supplements the Jurisio Privacy Policy. It lists the third parties that may receive personal information when you use Jurisio, so you can see exactly who is involved. Firm workspaces provided under a written agreement may use a different set of providers described in that agreement.
1. Hosting, storage, and email
Amazon Web Services (AWS) runs the computers and databases that store your account, your documents, and your conversations.
- Amazon Web Services — hosting, databases, file storage, document text recognition, and backups; Amazon Simple Email Service (SES) sends sign-in, account, and billing emails. Receives: all information described in our Privacy Policy that Jurisio stores, and the email address and content of each email we send. Where: United States (AWS US regions).
- Amazon Bedrock (part of AWS) — runs some AI steps directly under our AWS agreement: OpenAI models for supporting steps such as naming conversations, suggesting follow-up questions, and describing progress (when Bedrock is available; otherwise these steps go through OpenRouter under the same routing rules as the rest of the request); Amazon Titan for search representations of text; and Cohere Rerank for ordering search results. Firm workspaces also use Anthropic Claude models on Bedrock. Receives: the text each step needs, such as your question and parts of an answer or of your documents. Where: United States.
2. AI processing for signed-in accounts
For signed-in accounts on every plan, most AI requests go through OpenRouter, a routing service, which forwards each request to one of the hosts below. We instruct OpenRouter to use only hosts that have committed to zero data retention and not to train on your content, and we limit each model to the hosts listed here. Several of these hosts run openly published models (from developers such as DeepSeek, Z.ai, Alibaba’s Qwen team, and Moonshot AI) on their own computers; the model developers themselves do not receive your requests from those hosts.
- OpenRouter — routes AI requests to the model hosts below and to TypeSafe. Receives: the full AI request: your question, earlier messages in the conversation, and document text or images the request uses. Where: United States.
- Microsoft Azure — serves OpenAI models (GPT-6 Luna and GPT-5.6 Luna). Receives: AI requests routed to it. Where: United States (
azure/us), or the European Union (azure/eu) as a second choice when the US host is unavailable, so some requests may be processed in the EU. - Parasail — serves DeepSeek, Z.ai GLM, Qwen, and Moonshot Kimi models. Receives: AI requests routed to it. Where: Set by the host; not fixed by our routing.
- DeepInfra — serves DeepSeek, Moonshot Kimi, and OpenAI gpt-oss models. Receives: AI requests routed to it. Where: Set by the host; not fixed by our routing.
- Fireworks AI — serves DeepSeek, Z.ai GLM, and Moonshot Kimi models. Receives: AI requests routed to it. Where: United States for Kimi (
fireworks/us); otherwise set by the host. - Baseten — serves DeepSeek and Z.ai GLM models. Receives: AI requests routed to it. Where: Set by the host; not fixed by our routing.
- DigitalOcean — serves a DeepSeek model. Receives: AI requests routed to it. Where: Set by the host; not fixed by our routing.
- Phala — serves a Qwen model. Receives: AI requests routed to it. Where: Set by the host; not fixed by our routing.
- Groq and Cerebras — serve OpenAI gpt-oss models. Receives: AI requests routed to them. Where: Set by the host; not fixed by our routing.
- xAI — serves xAI Grok models, with Amazon Bedrock (US West region) as a second host reached through OpenRouter. Receives: AI requests routed to it. Where: United States for the Amazon Bedrock host; otherwise set by the host.
3. AI processing for guests
If you use Jurisio without signing in, your requests take a cost-optimized route that is not limited to zero-retention or no-training hosts. Section 4 of our Privacy Policy explains what this means; please read it before submitting anything sensitive as a guest.
- Meta — serves Meta contributor-tier models that write guest answers. Meta states that prompts and outputs sent to these models may be used to improve its products. Receives: guest questions, earlier messages in the guest conversation, and text the request uses. Where: Set by Meta.
- Z.ai GLM hosts selected by OpenRouter — serve a Z.ai model when the Meta models are unavailable, chosen mainly by price. Receives: the same information as above. Where: Set by the host OpenRouter selects; may be outside the United States.
- Amazon Bedrock, or OpenAI-model hosts selected by OpenRouter — serve OpenAI models for supporting steps such as naming a conversation, suggesting follow-up questions, and describing progress. Amazon Bedrock is used when available; otherwise OpenRouter selects the host. Receives: the text each step needs. Where: United States for Amazon Bedrock; otherwise set by the host OpenRouter selects.
- Other models routed through OpenRouter — for some features, guest requests may also use other models, served by hosts OpenRouter selects on the same cost-optimized route. Receives: the text the feature needs. Where: Set by the host.
4. Web search and legal research
When Ella, Jurisio’s AI assistant, looks something up, the search providers below receive search queries that Jurisio writes from your request, and the addresses of web pages to read. Before a search leaves Jurisio, our own rules and, when it is available, TypeSafe check it to help keep names, addresses, and other private details from your conversation from being sent to search providers.
- TypeSafe — helps check outgoing web searches and page addresses for names, addresses, and other private details, through OpenRouter. If it is unavailable, the search is checked by our own rules alone. Receives: your own messages and uploads in the conversation, and the proposed search query or page address. It does not retain this information. Where: Reached through OpenRouter.
- Exa — our main web search and page-reading provider. Receives: search queries and page addresses. Where: United States.
- Tavily — backup web search and page-reading provider. Receives: search queries and page addresses. Where: Set by the provider.
- Parallel, Brave Search, Context.dev, and You.com — additional search providers we may turn on to spread or back up web searches. Brave is used only for search, not for reading pages. Receives: search queries and, except for Brave, page addresses. Where: Set by each provider.
- Browserbase — an additional page-reading provider we may turn on; it is not used for search. Receives: page addresses only, not search queries. Where: Set by the provider.
- Free Law Project (CourtListener) — a nonprofit legal research database used to look up court cases. If you connect your own CourtListener account, requests use that connection. Receives: case names, citations, and search terms. Where: United States.
- Court and government websites — when Ella reads an official page or document directly, the site receives an ordinary request from Jurisio’s servers. Receives: the address of the page and technical request information; not your account details. Where: Set by each website.
5. Payments and analytics
- Stripe — processes subscription payments and runs the billing portal where you can change or cancel a subscription. Receives: your name, email address, payment details you enter with Stripe, and subscription records. Where: Stripe’s global infrastructure; see Stripe’s Privacy Policy.
- PostHog — product and website analytics. It is not loaded when your browser sends a Global Privacy Control signal. Receives: usage events and technical information such as IP address and device type; never what you type, the contents of your documents, or file names. Where: United States.
6. Services you choose to connect
These companies receive requests from Jurisio only if you sign in with them or connect their service.
- Google — sign in with Google; importing files you pick from Google Drive; adding dates to a calendar Jurisio creates in Google Calendar. Receives: requests for your basic profile (only your email address for a Google Calendar connection), the files you choose, and the calendar events you ask Jurisio to add or remove. Where: Google’s infrastructure.
- Microsoft — importing files from OneDrive; adding dates to a calendar Jurisio creates in Outlook. Receives: requests to read the files you import, to look up your calendar names, to add or remove the events you ask for, and to check the events Jurisio added. Where: Microsoft’s infrastructure.
- Free Law Project (CourtListener account) — if you connect your own CourtListener account, case-law lookups are made through that connection. Receives: case names, citations, and search terms, sent under your account. Where: United States.
- Dropbox and Box — importing files you choose. Receives: requests to read the files you import. Where: Each provider’s infrastructure.
7. Other services we contact
These services receive a small amount of information for a single purpose.
- Federal Communications Commission (FCC) Area API — turns a device location you choose to share into a state and county. Receives: the latitude and longitude you shared, rounded to two decimal places. Where: United States.
- Have I Been Pwned (Pwned Passwords) — checks whether a new password has appeared in a known data breach. Receives: only the first five characters of a scrambled (hashed) form of the password, never the password itself. Where: Set by the provider.
8. Changes and contact
We update this page when we add, remove, or change a provider, and change the date at the top. Questions may be sent to support@jurisio.ai.