Pundora Legaltech Private Limited
Privacy Policy
Pundora is built for advocates. The product exists so that you can use modern AI on client matters without compromising them. This policy says, in plain language, what we collect, where it lives, who can touch it, how long it stays, and what we will never do with it. If anything here is unclear, write to us and a person answers.
Who we are
Pundora is operated by Pundora Legaltech Private Limited, a company incorporated in India (CIN: [CIN — to be added]), with its registered office at [registered office address — to be added]. In this policy, “we” and “Pundora” mean that company; “you” means the advocate, chamber or firm using Pundora, and the people they invite into their workspace. Contact: support@pundora.in.
What we collect, and what we deliberately do not
- Account details. Your name and email address as provided by the Google account you sign in with, your chamber or firm name, and your city. Pundora has no passwords of its own. Sign-up is open: anyone may create a workspace by signing in with a Google account.
- Your work. The case files, documents, scanned pages and photographs you upload; the chronologies, calendar entries, deadlines, research answers, drafts, citation checks, exports and notes Pundora produces from them; the questions you ask about a matter; and anything you add by hand. This is your professional work product and your clients’ confidential information, and everything in this policy is written around that fact.
- WhatsApp, if you connect it. Your WhatsApp number; the messages we send you (the evening digest, the evening check-in, reminders and confirmations); and the messages, photographs and documents you send to Pundora’s number.
- Technical records. Sign-in events, requests to our servers, errors, and the operational records needed to run the service safely and to meet Indian law (see “How long we keep things”). We keep no advertising trackers and no third-party analytics on client content.
We do not collect your date of birth, home address, identity documents, payment details (there are none during free early access), or anything else we do not need.
Where your data lives
Your workspace — documents, matters, calendars, drafts, research, WhatsApp messages — is stored on servers in India (Mumbai region), in your own encrypted, isolated workspace. Isolation means one chamber’s data is walled off from every other chamber’s by controls enforced in the database itself. Uploaded files are encrypted with a key that belongs to your workspace before they are written to storage. Scanned pages and photographs are read (turned into text) on a machine we operate ourselves in Mumbai, never by a cloud reading service. Backups are encrypted and held separately from the live system.
Two things leave India in the course of the service, and we say so plainly. First, when an AI feature runs, the relevant text is sent to our AI provider to produce the result (see the next section). Second, WhatsApp messages pass through Meta’s systems; the number is registered so that message content and media persist only in Meta’s India data centres (see “WhatsApp, honestly”).
How the AI part works — please read this section
When you use an AI feature — reading a case file into a chronology, asking a research question, drafting or reviewing a document — the relevant text is sent to our AI provider, Anthropic, to produce the result, and the result comes back to your workspace. Everything else Pundora does (the calendar, the digest, exports, searches of the judgment corpus, the deterministic verification of citations) runs on our own systems without any AI provider.
Anthropic does not use content sent through its API to train its models. Under Anthropic’s standard terms, inputs and outputs are deleted from its systems within 30 days. We have applied for Anthropic’s zero-data-retention terms for Pundora’s account, under which nothing is retained after the result is produced; until that is approved for our account, the 30-day standard applies, and this policy will be updated on the day it changes.
One exception, stated because you deserve to see it: if content is flagged by the provider’s automated trust-and-safety systems (for example, suspected abuse of the service), the provider may retain the flagged material for up to two years under its published policy. That is the only circumstance in which the provider retains anything beyond the periods above, and it is not an ordinary part of processing a legal matter.
Pundora does not train any model on your content. Your files improve your own workspace (your formats, your vetted drafts), never another chamber’s, and never a shared model. Where Pundora suggests a draft based on your earlier drafts, only the form of those drafts is reused across your matters, never the facts of one matter in another.
WhatsApp, honestly
If you connect WhatsApp, Pundora sends you an evening digest of tomorrow’s hearings and deadlines, an evening check-in asking whether anything happened in a matter, and short confirmations; you can send Pundora photographs of orders, documents and typed updates, which are filed under the right matter for your confirmation.
Messages between you and Pundora on WhatsApp pass through Meta’s WhatsApp Business Platform. That is how every business on WhatsApp works: Meta decrypts and forwards messages on the business’s behalf, and WhatsApp tells you inside the chat that the business uses Meta’s hosting. For that reason we do not describe this channel as end-to-end encrypted. We use Meta directly, with no intermediary provider, so no third company sees your messages. Under Meta’s terms Meta acts as our processor, uses messages only on our instructions, keeps them for a maximum of 30 days, and does not use them for advertising.
Our own handling rules for this channel: the number is registered with India as its storage region; every photograph or document you send is fetched once, encrypted into your workspace, and a deletion request is sent to Meta the same minute, with Meta’s answer recorded in your workspace’s audit trail; nothing is ever sent back out over WhatsApp as a document or as extracted content. The digest names your matters; if you prefer, a discreet setting lets you choose the labels that appear. Your own WhatsApp backups (Apple or Google) are outside everyone’s control unless you switch on encrypted backups in WhatsApp.
The judgment and statute corpus
Pundora’s research answers come from a corpus we assemble from public sources: judgments of the Supreme Court of India and the High Courts published as open data, and bare acts published by the Government of India, with additional legislation datasets published under open licences and credited on the relevant pages. These are public documents; they are not your data. We make no promise that the corpus is complete, and every answer says so when nothing is found.
Who else can touch your data
Only what the service needs to run, each bound by contract to use your data only to provide the service to us:
- Supabase — the database and encrypted file storage, in the Mumbai region.
- Vercel — hosting of the application and this website; the application runs in the Mumbai region.
- Anthropic — the AI provider, as described above.
- Meta Platforms — the WhatsApp Business Platform, if you connect WhatsApp, as described above.
- Amazon Web Services — the machines we operate ourselves in Mumbai for reading scanned pages and for assembling the public corpus. No client content is stored on them.
- Google — sign-in with your Google account; our company email; and the fonts loaded by this website (which means Google’s servers see the address of a visitor’s device when the site loads).
Our source code is kept on GitHub; no client content is stored there. We will keep this list current on this page and update it before any change. Client content never enters third-party analytics or error-tracking tools.
Pundora’s own staff do not read your documents. Our operational view shows counts, spend and system health, not content. We access content only with your express permission to resolve a support request, or where Indian law requires it.
How long we keep things, and how deletion works
Your data stays as long as your workspace does; that is the point of a workspace. When you delete a document, a matter or your account, it is removed from active systems promptly and purged from backups within [30] days. Before account deletion we offer you a full export of your files and records in usable formats, free. Records you remove from a chronology or a calendar stay visible to you as removed, so nothing silently disappears; they are deleted with the matter.
We keep security and access logs for 180 days, as the Indian Computer Emergency Response Team (CERT-In) directions require, and the basic records the law requires a company to keep. WhatsApp message records are kept in your workspace as part of your matters; media is deleted from Meta as described above.
Your rights
You can access, correct, export and delete your data. Export is free, forever, and deletion is real. India’s Digital Personal Data Protection Act, 2023 gives you rights to notice, to access and correction, to erasure, to grievance redressal and to nominate a person to exercise your rights; we honour them regardless of the Act’s enforcement timeline. To exercise any of these, write to support@pundora.in. Our grievance officer is ${GO}, reachable at support@pundora.in and at our registered office; we acknowledge and resolve grievances within the timelines Indian law prescribes.
Your clients’ data
You bring your clients’ information to Pundora in your professional capacity. We process it only on your instructions and only to provide the service to you; we never mine it, profile it, sell it, or use it for advertising or for anything else. Your professional and confidentiality obligations to your clients remain yours; our job is to be infrastructure worthy of them. You are responsible for having the right to upload what you upload.
Children
Pundora is a professional tool for adults. We do not knowingly collect data from anyone under 18.
If something goes wrong
If a security incident affecting your data ever occurs, we will notify the authorities as Indian law requires and tell you plainly and promptly what happened, what was affected, and what we are doing about it.
Changes
If we change this policy, we will say so on this page with a new date, and for material changes we will tell you directly before they take effect.
Contact
support@pundora.in · Pundora Legaltech Private Limited, [registered office address — to be added].