Security
loupe.legal · last changed 29 September 2026
A filing is a client’s confidence. Here is where one goes when you check it, who else receives anything, and what we keep. The privacy page has the whole of it.
What happens to a filing you check
It travels over an encrypted connection to Loupe’s edge on Cloudflare, and from there to our checking server, run by Amazon Web Services in Oregon, USA. There it is read in memory, checked and answered. It is not logged, and nothing of it stays on the checking server once the answer has gone back: a large upload may be held briefly on the server’s temporary disk while it is read, and is discarded with the request.
What we keep, and only if you ask
Nothing of a check is kept unless you press “Keep in account”, or ask an assistant for a signed record, which keeps it in your account. Then we keep:
- the record of the check: each citation, what was found, and the seal that shows the record has not changed;
- the document’s text, only if you tick “Keep the document’s full text too”.
It stays in your account until you delete it. Your account and what it keeps are stored in Cloudflare’s database in the United States.
Deleting
A check you delete, or a matter you close, goes to Recently deleted on your account page, where you can bring it back for 30 days; then it is removed. Only the person who deleted something can bring it back. Deleting your account removes everything it holds at once, Recently deleted included; an account holding a paid licence is closed with us instead, because it has billing records to settle.
Our database provider keeps a history of the whole database for 30 days, from which it could be restored after a failure, so a removed item can remain in that history for up to 30 days.
What reads your document
The check does not generate anything. Each citation is looked up in our own index and in public sources, and compared with what they say. A scanned PDF is read by a character-recognition model that runs on our own server. We send neither your document nor anything from it to an outside AI service, and nothing you send is used to train any model.
Who else receives anything
| Who | What they receive | Why |
|---|---|---|
| Cloudflare, Inc. | The document in transit; accounts and kept checks, stored in the United States; the e-mail we send, and e-mail sent to a checking address | Our edge, database and mail |
| Amazon Web Services, Inc. | The document in transit, and in memory while it is checked | Our checking server, in Oregon, USA |
| Paddle.com Market Ltd | If you buy a plan: your name, e-mail address and payment details | It sells the licence, as merchant of record, and takes the payment |
| Google LLC | Visits to the front page and the students’ page, only if you agree to it | Counting visits. Never on the check page or inside your account |
Cloudflare also counts visits to our other public pages. It sets no cookie, and what it sends is the page’s address and how fast it loaded, not what is on it. Nothing counts visits to the page where you check a filing.
Public sources are asked about an authority, and never receive your document:
- Harvard’s Caselaw Access Project, GovInfo, the eCFR, the Federal Register, Congress.gov, the House’s Office of the Law Revision Counsel and two state legislatures, for cases, statutes, regulations and executive orders;
- Crossref, DataCite and the DOI resolver, for DOIs;
- the websites your document links to, and the Internet Archive, for links.
Each is asked for the authority you cite: a case by its volume and page, a statute by its number, a link by its address. A linked site receives the address as your document gives it; the Internet Archive receives it without any user name, query or fragment.
If you check through an assistant, such as the ChatGPT app or Claude through our connector, your text reaches that assistant’s company before it reaches us, under your own agreement with it. Our part begins when the text arrives here.
Inside a firm
- A firm’s matters are seen by its colleagues. A matter can be walled off to named people.
- Someone from outside the firm sees only a matter they were invited to, in the role they were given: works on it, or reads it.
- Each matter keeps a history of who did what.
Signing in and keeping accounts safe
- There is no password to steal. You sign in with a one-time code or link sent to your address, or with a passkey.
- A browser’s request to change anything in an account must come from our own pages; one sent from another site is refused. An assistant acts in an account only with the access you gave it, which you can take back on your account page.
- Our pages run only the scripts we list.
- The checking server accepts no connection from the internet. It is reached only through Cloudflare’s authenticated tunnel.
- When we fetch a link in your document, we refuse any address inside a private network.
A record you can show
A check made on a paid plan is sealed with Loupe’s digital signature, and the key that verifies it is published. Anyone given the record can confirm at loupe.legal/verify that it is the one we made, unchanged since. Whether it satisfies a court or a client is yours to judge.
Questions
Write to privacy@loupe.legal.