Privacy
loupe.legal · last changed 25 September 2026
A filing is a client's confidence before it is a document, so the short version matters more than the long one.
We do not keep the documents you check. A document is checked and the report is returned to you. Larger multipart uploads may be buffered briefly on ephemeral disk while the request is processed; that temporary data is discarded with the request. Our application does not write document bodies to its database or logs. Cloudflare may retain operational request metadata under its platform settings. The one exception is yours to make: on a paid plan you can keep a check in your account, and then its record is kept until you delete it.
What happens to a document you check
It is parsed, the citations in it are found, and each is checked against the sources named below. Then the report goes back to you and the request buffers are discarded. We keep no application copy of the document, its text, its filename, or the report, unless you press “Keep in account” on the report (see below).
What leaves our service, and what does not
Checking a citation means asking somebody who publishes the law. What we send is the citation, not the document.
| Sent | To whom | Why |
|---|---|---|
| Citations; when citation lookup fails, party names, docket, court and year | CourtListener, run by the non-profit Free Law Project | Whether a case exists, and what it is called |
| Statute, regulation and rule numbers | eCFR, govinfo, Congress.gov, Cornell LII, and two state legislatures | Whether the provision exists and is still in force |
| DOIs | Crossref, DataCite and the DOI resolver | Whether the work exists |
| URLs written in your document | the sites themselves, and the Internet Archive | Whether the link still reaches what was cited. The target site receives its full URL; the archive receives the URL without userinfo, query or fragment. |
Most case-law checks are answered from our own copy of American case law and reach nobody at all.
One check is different, and it is optional. Whether a case actually supports the sentence it is cited for is assessed by a language model, and that check sends the sentence from your document, the citation, and the text of the cited opinion to Anthropic. It runs only on the Firm tier and only when it has been configured and we have separately confirmed Zero Data Retention for that account. Anthropic states that commercial API data is not used for training by default; its standard API retention can otherwise be up to 30 days and its safety, legal and feedback exceptions still apply. Loupe therefore leaves this check off unless that separate retention condition is confirmed. Everything else works without it.
What we keep
| What | Why | For how long |
|---|---|---|
| A count of documents checked, per day | To apply the free tier's daily limit, and to apply the limit a paid licence was sold with | 48 hours |
| A keyed one-way digest of each IP address a licence has been used from, per day | A licence is sold with a number of seats. Counting the addresses it is used from is how we notice one being shared far beyond them. | 48 hours |
| A keyed one-way digest of the IP address an assistant registers itself from, per hour | Any assistant may register itself with us without an account, and this is what limits how often | 1 hour |
An IP address is personal data, so we say plainly where we use one and why. Usage and registration counters store a keyed digest rather than the address itself and expire within two days. None is joined to a document. One raw address is joined to something else: a sign-in link records the address that asked for it beside the email address it went to, described below.
Your account
An account is optional. Checking a filing on this site needs none. Connecting an assistant does, because somebody has to be able to say yes to it. You sign in with a short code or one-use link sent to your email address; there is no password.
| What | Why | For how long |
|---|---|---|
| Your email address, when the account was made and last signed in to, and your licence if you hold one | So that you can sign in, and so that a paid tier goes with you | Until you delete the account on your account page, or ask us to |
| Each sign-in code and link we send, held only as one-way hashes, with the email address they went to, failed code-attempt count and IP address that asked | So that each proof works once, a guessed code stops after five tries, and nobody can use us to flood an inbox | About a day |
| Your signed-in session, held only as a one-way hash | To keep you signed in | 30 days, or until you sign out |
| Which assistants you have allowed, and their access tokens, held only as one-way hashes | So that an assistant can check citations as you, and so that you can see it and take it back | About 30 days after it was last used, or until you remove it on your account page. A removed one's tokens are deleted a week later. |
| Metadata an assistant supplies when it registers: its claimed name, software identifier and redirect addresses | To complete the authorization flow and show where it will return you | 30 days unless it remains connected to an account |
| If you join the waitlist or request a demo: email, request, role, note, seats and source page | To answer the request you made | 12 months, or sooner if you ask us to delete it or delete your account |
| A check you chose to keep: its record (the result, the passage around each citation, your own checks and the seal on them), the document's name and the matter you filed it under | So that you can come back to a check by matter, and show it was done | Until you delete it on your account page, or delete the account |
A one-way hash is a fingerprint: enough to recognise a link or a token when it is presented, and not enough to use one. A copy of our records would not let anybody sign in as you or act as an assistant you allowed. The one credential kept whole is a licence, because the service has to read it; the account page deliberately does not reveal that reusable credential to a 30-day browser session. All of it is held by Cloudflare, which runs this service, and the sign-in message is sent through Cloudflare's mail service. No one else receives it.
We never see your card. When paid tiers open, the merchant of record named at checkout will be the seller for the transaction and will hold the billing details; we will receive the fact that a payment succeeded and for which plan.
Counting visits
We count visits in two ways. Cloudflare Web Analytics runs on the public pages. It sets
no cookie and does not identify you; it gives us totals, such as page views and the
countries they came from. Google Analytics runs only if you allow it, when the front
page asks. It sets cookies whose names begin with _ga, and sends Google the
pages you open, your approximate location, your device and your browser, under Google's
terms; its advertising features are switched off, and Google keeps this for two months.
What you paste or upload is never sent to either.
You can change your answer at any time with "Cookie settings" at the foot of the front page, and saying no removes Google's cookies. Neither counter runs on your account page or on the sign-in pages.
If you check through an assistant
Claude, ChatGPT or another assistant you have allowed sends us the text it wants checked, and that text is treated exactly like a document: checked in memory, answered, and not kept. What you write to the assistant, and what it does with our answer, is held by the company that runs it, under its terms rather than ours.
What we will not do
- Sell what we hold, or share it beyond the services named on this page. There is no advertising here and nothing to advertise with.
- Train anything on your filings.
- Use your documents for anything beyond the check you requested. No copy is kept, except a check you keep in your account, which is used for nothing but showing it back to you.
Your rights
Ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted, at privacy@loupe.legal. Because the answer is usually "an email address", these requests are quick. Most of it you can do yourself. Your account page downloads a copy of what we hold under your account, signs you out of every browser, takes back any assistant you allowed, and deletes the account with everything held under it. An account holding a paid licence is closed with us instead, because it has billing records to settle. If you are in the EU or the UK you have these rights under the GDPR. Our legal basis for the counters above is our legitimate interest in enforcing the terms a licence was sold on; for your account, it is providing the service you signed in to use; for Cloudflare's count of visits, our legitimate interest in knowing how the site is used; and for Google Analytics, your consent, which you can withdraw as easily as you gave it.