®Docs

Data retention & AI privacy

Your clients trust you with privileged information. This page explains exactly what happens to your firm's data when Superpractice's AI features process it, what we store, and for how long.

How AI processing works

Superpractice uses AI models for features like the assistant, meeting and contact summaries, outreach drafts, recommendations, and content generation. Central enforcement controls determine which processing paths are eligible for every request.

Those controls require zero data retention for requests that process workspace content. Only processing partners covered by the required contractual and technical safeguards are eligible to handle those requests.

The requirement is fail-closed: if no eligible zero-data-retention path is available, the request is refused. Superpractice will not silently fall back to a path that retains workspace content.

A limited SEO research workflow processes only public search terms and firm configuration such as the website domain and practice areas. It never receives client, contact, matter, or communication content.

What zero data retention means

  • Not stored by model providers. Prompts and responses are deleted by the model provider once the response is returned. There is no lingering provider copy of your client communications, transcripts, or matter details. Superpractice may separately store workspace copies, such as AI assistant conversations, as explained below.
  • Never used to train model providers' models. The AI model providers serving Superpractice requests are contractually prohibited from training their models on your content.
  • Applies to every AI feature that touches your data. The assistant, meeting summaries, contact summaries, call summaries and outcomes, email and SMS drafts, recommendations, reports, and content tools are subject to the same zero-data-retention policy. Automated controls prevent ineligible processing paths.
  • Pseudonymized telemetry. Request metadata used for routing and billing uses hashed identifiers, never raw user or record IDs, and never message content.
  • Continuously verified. Automated checks verify that workspace-content requests use an eligible zero-data-retention path and are rejected when one is unavailable.

What lives in your workspace

Zero data retention governs processing by third-party AI model providers; it does not mean Superpractice discards the data in your workspace. Superpractice stores the data that makes the product your firm's system of record: contacts, matters, communications you sync, recordings and transcripts you choose to capture, AI assistant conversations, and AI outputs you keep (like a saved meeting summary or an approved draft).

The AI assistant can use its conversation history and access other data within your organization's workspace to answer your requests. That workspace copy remains securely stored by Superpractice and scoped to your organization. When workspace content is sent to an AI model provider, the provider processes it transiently under zero data retention and does not keep its own copy.

That workspace data is encrypted in transit and at rest, scoped to your organization, and under your control — records you delete are removed from the active database, and you can request deletion of your workspace data at any time, processed within 30 days.

Application logs are content-free by policy: prompts, message bodies, and transcripts are excluded from runtime logging.

Retention schedule

DataHow it is handledRetention
Requests sent to AI model providersProcessed transiently by AI model providers; not stored thereProvider copies are deleted once the response is returned, and model providers never use the content to train their models.
AI assistant conversationsStored securely in your organization's Superpractice workspaceStored while your account is active so the assistant can use conversation history and other workspace data to answer your requests. Included in workspace deletion requests.
AI usage recordsStored by Superpractice as metadata onlyFeature, model, token counts, and cost are retained without prompt or response content.
AI outputs you keepStored in your workspaceSummaries, drafts, and recommendations saved into your workspace live with the records they belong to — deleting the underlying record removes them.
Synced email bodiesStored in your workspaceEmail message content is automatically removed 60 days after syncing. Metadata (sender, recipient, subject, timestamps) is kept for activity history, and opening an older email loads its content live from your connected mailbox — the original always stays in your own email account.
Call and meeting recordings & transcriptsStored in your workspace; processed temporarily by the meeting capture partner and, for transcription, by the transcription partnerStored while your account is active; deletion is available on request. Meeting recording and transcription are optional and controlled by your team's settings. The meeting capture partner holds its working copy for at most 48 hours — typically it is deleted within the hour, as soon as the recording is verified and archived into your workspace. Phone call transcription (tracked numbers and calls placed or received in Superpractice) is on by default and can be turned off under Settings → Calling & Messaging → Transcribe Calls. Full call transcripts are stored field-level encrypted (the key is held outside the database) and are automatically deleted 60 days after the call, along with the call recording captured in Superpractice; the short call summary and logged outcome are kept as the record of the call and are written to omit sensitive specifics.
Contacts, matters, and attributionStored in your workspaceKept for the life of your account as your firm's system of record. Full workspace deletion is available on request, processed within 30 days.

Backups exist for disaster recovery and expire on a rolling window, so deleted records can persist in encrypted backups briefly before aging out.

Limits and exceptions

Honesty matters more than marketing here, so three limits worth knowing:

  • Safety and legal retention. Model providers may retain content flagged by their automated trust-and-safety systems or where retention is required by law, even under a zero-data-retention agreement. This is an industry-wide condition of every provider's ZDR terms.
  • Voice and meeting capture. Live call handling and meeting recording are performed by specialized processing partners before any AI summarization happens. Those partners operate under their own data-processing agreements, and recordings are stored in your Superpractice workspace — but the capture step itself is a separate processing lane from the zero-data-retention AI pipeline. For meetings, that lane is time-boxed: the capture partner retains its copy of a recording for at most 48 hours, and in the normal flow it is deleted within about an hour of the recording being verified and archived into your workspace. Transcription of call and meeting audio is processed in-flight by the transcription partner and is not stored there: every transcription request is sent with the partner's model-improvement opt-out, so the audio is never retained by the partner and never used to train its models. The resulting transcript and summary live only in your workspace, and the summary step itself runs through the zero-data-retention AI pipeline described above. Transcription of phone calls (tracked numbers and calls placed or received in Superpractice, inbound and outbound) is optional and controlled by the Transcribe Calls setting; when it is off, recordings are kept in your workspace and never sent for transcription.
  • Legal process. No retention policy prevents a valid subpoena or court order. Our approach is to minimize what exists to produce: content that was never retained cannot be disclosed.

This page describes our technical controls. The binding commitments are in your customer agreement and data processing addendum.

Questions

Ask us directly

Questions about data handling for your firm — including deletion requests — can be sent through Contact support.

Security reviews

Running a vendor security review? We can provide our subprocessor list and documentation of the controls described on this page — use Contact support to start.

On this page