Data retention & AI privacy
Your clients trust you with privileged information. This page explains exactly what happens to your firm's data when Superpractice's AI features process it, what we store, and for how long.
How AI processing works
Superpractice uses AI models for features like the assistant, meeting and contact summaries, outreach drafts, recommendations, and content generation. Every one of those requests is routed through a single governed pipeline — the Vercel AI Gateway — rather than being sent to AI providers directly.
That gateway enforces a zero data retention requirement on every request. Only model providers with contractual zero-data-retention agreements in place (including Anthropic, OpenAI, and Google) are eligible to serve Superpractice requests.
The requirement is fail-closed: if no zero-data-retention route is available for a request, the request is refused. Superpractice will not silently fall back to a provider that retains data.
One registered exception exists: a single SEO keyword-clustering task connects to the model provider directly because it requires an extended context window the gateway does not support. It processes search keywords, your website domain, and your practice areas — never client, contact, matter, or communication content.
What zero data retention means
- Not stored. Prompts and responses are deleted by the model provider once the response is returned. There is no lingering copy of your client communications, transcripts, or matter details sitting on a model provider's servers.
- Never used to train model providers' models. The AI model providers serving Superpractice requests are contractually prohibited from training their models on your content.
- Applies to every AI feature that touches your data. The assistant, meeting summaries, contact summaries, email and SMS drafts, recommendations, reports, and content tools all run through the same governed pipeline. Enforcement is automated — checks run on every code change and reject any code path that would bypass the pipeline.
- Pseudonymized telemetry. Request metadata sent to the gateway for routing and billing uses hashed identifiers, never raw user or record IDs, and never message content.
- Verified against the live gateway. An automated test suite exercises zero-data-retention routing against the live gateway — including a proof that requests to models without a zero-data-retention route are rejected rather than served.
What lives in your workspace
Zero data retention governs AI processing. Separately, Superpractice stores the data that makes it your firm's system of record: contacts, matters, communications you sync, recordings and transcripts you choose to capture, and AI outputs you keep (like a saved meeting summary or an approved draft).
That workspace data is encrypted in transit and at rest, scoped to your organization, and under your control — records you delete are removed from the active database, and you can request deletion of your workspace data at any time, processed within 30 days.
Application logs are content-free by policy: prompts, message bodies, and transcripts are excluded from runtime logging.
Retention schedule
| Data | Where it lives | Retention |
|---|---|---|
| AI prompts and responses | AI model providers | Not retained. Every AI request runs under zero data retention — content is deleted once the response is returned, and model providers never use it to train their models. |
| AI usage records | Superpractice | Metadata only — feature, model, token counts, and cost. No prompt or response content is ever stored in usage logs. |
| AI outputs you keep | Your workspace | Summaries, drafts, and recommendations saved into your workspace live with the records they belong to — deleting the underlying record removes them. |
| Synced email bodies | Your workspace | Email message content is automatically removed 60 days after syncing. Metadata (sender, recipient, subject, timestamps) is kept for activity history, and opening an older email loads its content live from your connected mailbox — the original always stays in your own email account. |
| Call and meeting recordings & transcripts | Your workspace | Stored while your account is active; deletion is available on request. Meeting recording and transcription are optional and controlled by your team's settings. The meeting capture partner holds its working copy for at most 48 hours — typically it is deleted within the hour, as soon as the recording is verified and archived into your workspace. |
| Contacts, matters, and attribution | Your workspace | Kept for the life of your account as your firm's system of record. Full workspace deletion is available on request, processed within 30 days. |
Backups exist for disaster recovery and expire on a rolling window, so deleted records can persist in encrypted backups briefly before aging out.
Limits and exceptions
Honesty matters more than marketing here, so three limits worth knowing:
- Safety and legal retention. Model providers may retain content flagged by their automated trust-and-safety systems or where retention is required by law, even under a zero-data-retention agreement. This is an industry-wide condition of every provider's ZDR terms.
- Voice and meeting capture. Live call handling and meeting recording are performed by specialized processing partners before any AI summarization happens. Those partners operate under their own data-processing agreements, and recordings are stored in your Superpractice workspace — but the capture step itself is a separate processing lane from the zero-data-retention AI pipeline. For meetings, that lane is time-boxed: the capture partner retains its copy of a recording for at most 48 hours, and in the normal flow it is deleted within about an hour of the recording being verified and archived into your workspace. Fallback transcription of meeting audio is processed in-flight and is not stored by the transcription provider.
- Legal process. No retention policy prevents a valid subpoena or court order. Our approach is to minimize what exists to produce: content that was never retained cannot be disclosed.
This page describes our technical controls. The binding commitments are in your customer agreement and data processing addendum.
Questions
Ask us directly
Questions about data handling for your firm — including deletion requests — can be sent through Contact support.
Security reviews
Running a vendor security review? We can provide our subprocessor list and documentation of the controls described on this page — use Contact support to start.