Privacy Policy
- Version
- 2026-07-23.1
- Effective
This Privacy Policy is written to the standard of PIPEDA (the federal Personal Information Protection and Electronic Documents Act) and its ten fair-information principles. It must be live before the eligibility quiz collects anything from you, even on your own device, because the quiz interstitial links to it.
1. Who we are and who answers for your privacy
primarylaw.ai Ltd, operating as Pardoned, is responsible for the personal information under its control. Our designated Privacy Officer — the individual accountable under PIPEDA principle 4.1 — is the founder of Pardoned, identified here by role rather than by name, consistent with our anonymous-founder architecture. The Privacy Officer can be reached at info@pardoned.ai and answers access requests, correction requests, deletion requests, and complaints personally.
Flag for Nick: Quebec's Law 25 (Quebec users are not blocked, per the soft-defer) expects a titled privacy officer and imposes its own incident and policy rules. Confirm the role-title-without-name approach satisfies both regimes, or record the Quebec exposure explicitly — see ops/legal/flag-register.md item 7. No Quebec-specific sections are drafted pending that decision.
2. The short version
Plain-language summary. We know criminal-record information is sensitive, and that finding this page probably means a hard chapter of your life. The short version: your free quiz answers never touch our servers unless you choose to buy — they stay on your device. When you buy, we collect only what the government forms actually require. We encrypt your sensitive answers field-by-field with a key unique to your case. We never email your documents — you always sign in to get them, through links that expire in five minutes. We never use your information for advertising and never use it to train AI models. And you can delete everything: after a 7-day change-of-mind window, we destroy your case's encryption key, which makes your data permanently unreadable — even to us. The details are below; none of them contradict this summary.
3. What we collect, and the consent basis for each category
We collect personal information only with your knowledge and consent, and only what each purpose requires (PIPEDA principles 4.3 and 4.4). By category:
Category What, and when Consent basis Quiz answers (before purchase) Nothing on our servers. Your answers stay in your browser's local storage, on your device. Close the tab and they are yours alone. None needed — we do not collect them. Eligibility-date reminder (optional) If you ask for a reminder, we store the email address you give us and your reminder date — nothing else from your quiz. Your express opt-in, recorded with the exact consent text and version you saw. Purchase Your email address, and your payment details — handled by Stripe; we never see your card number. Your quiz answers move from your device into your case at this moment, with your checkout consent. Necessary to perform the contract you are entering; your checkout acceptance is recorded against the exact Terms and Policy versions shown. Application intake The information the government forms require: identity details, addresses, employment history, and information about your criminal record, charges, and court outcomes. Express consent, given in the intake flow, for the specific purpose of preparing your application. This is sensitive information and we treat consent for it as revocable at any time (see §8). Uploaded documents Supporting documents you choose to upload (for example, court records) to help you assemble your filing package. Express consent, per upload; purged on the schedule in §7. Keep-on-file for renewals (optional) After your case closes, your encrypted intake is retained only if you switch on "keep my case on file for renewals." Express opt-in, revocable any time in your portal settings; each grant and revocation is recorded. Automatic Limited, privacy-hardened product analytics (first-party, pseudonymous, no session recording on forms, inputs masked) and error logs scrubbed of personal information. Implied consent for limited, non-sensitive operational data; see §10 for exactly how it is constrained. We collect nothing else. We never collect information about you from third parties, never buy data, and never look up your record anywhere — everything about your case comes from you.
4. Criminal-record data is sensitive — how we safeguard it
Information about a person's criminal record is among the most sensitive personal information there is (PIPEDA principle 4.3.4: the more sensitive the information, the stronger the consent and safeguards must be). We treat all of it accordingly:
- It is encrypted at the field level, before storage, with a key unique to your case (AES-256-GCM, per-case keys under a versioned master key).
- Access is logged in an append-only audit log that records that events happened — never your form content.
- It is never included in emails. Documents are available only by signing in to your portal, via links that expire in five minutes; we never attach files to email.
- Our payment descriptor, email sender, and subject lines never reveal what our service is about — envelope discretion is a designed feature, enforced by an automated check.
- It is never used for advertising, profiling, sale, or model training (see the negative list in §5).
- Support staff answer from published information only; your case content is not browsed for support purposes beyond what resolving your request requires, and every access is audit-logged.
5. Why we use your information — and why we never will
Identified purposes (PIPEDA principles 4.2 and 4.5 — we use personal information only for these, and new purposes would require your fresh consent):
- Providing the Service you purchased and generating your Documents.
- Supporting you within our published-information support policy.
- Sending transactional and case-milestone emails about your Case.
- Sending reminder and renewal emails you have opted into.
- Complying with legal obligations (for example, tax record-keeping).
- Preventing fraud and abuse of the Service.
We do not, and will not: use your information for advertising; sell or rent it; share it for anyone else's marketing; build retargeting or lookalike audiences from it; or use it to train AI models.
6. Where your data lives and who processes it
Your case data is stored at rest in Canada (AWS ca-central-1, Montréal, via Supabase). To operate the service, the providers below process limited data, in some cases transiently outside Canada — chiefly in the United States, where it is subject to U.S. law while being processed. We will not tell you your data "never leaves Canada" — no honest web service can — but here is exactly who touches what:
| Provider | What it does | What it processes | Location of processing |
|---|---|---|---|
| Supabase (on AWS) | Database, authentication, file storage | Account data; encrypted intake; uploaded documents | Canada (ca-central-1, Montréal) |
| Vercel | Web hosting and delivery | Transient request data (pages you load, form submissions in transit) | United States / global edge network |
| Stripe | Payment processing | Name, email, payment card, purchase amount — never your offence details | United States / global |
| Anthropic | AI-assisted document drafting | Intake facts needed to draft your documents, during generation only; not used to train models | United States |
| Resend | Transactional email | Your email address and neutrally-worded messages | United States |
| PostHog | Product analytics (privacy-hardened) | Pseudonymous usage events; never intake content | United States [confirm US vs EU cloud at setup and state the real one — see flag register item 6] |
| Sentry | Error monitoring | Error reports scrubbed of personal information | United States |
Each provider processes your information only to provide its service to us, under contractual confidentiality and data-protection terms (PIPEDA principle 4.1.3 — we remain accountable for information transferred for processing). This table is data-driven from a single subprocessors content source, so adding or removing a provider is a one-line edit plus a version bump and re-notification under §13.
Flag for Nick: the Anthropic "not used to train models" statement must be verified against the commercial terms/DPA in force at launch, and cited — see ops/legal/flag-register.md item 5. Flag for Nick: PostHog's cloud region (US vs. EU) must be confirmed at setup and stated factually here — see ops/legal/flag-register.md item 6.
This residency/subprocessor disclosure is a PIPEDA transparency requirement, not a marketing claim. Per founder amendment 6 and 00-BUILD_PLAN.md non-negotiables, no data-residency language appears anywhere in marketing copy — it lives only here, factually.
7. How long we keep things
We keep personal information only as long as its purpose requires (PIPEDA principle 4.5), then destroy it on the schedule below:
| Data | Kept for | Why |
|---|---|---|
| Quiz answers (no purchase) | Never on our servers (your device only) | — |
| Reminder email + date | Until reminder sent + [30] days, or until you unsubscribe | You asked for it |
| Uploaded documents | Purged [90] days after your case closes | Filing support only |
| Encrypted intake data | Life of case; after close, only with your "keep my case on file for renewals" opt-in, revocable any time | Renewal prefill |
| Payment records | 7 years | Canadian tax law |
| Audit log | [7] years | Security accountability (records events, never your form content) |
| Analytics events | [12] months | Product improvement |
| Support emails | [24] months | Service history |
| Email suppression list | Indefinitely | To honour your do-not-contact request |
Deleting your account overrides this schedule for everything the law lets us delete — see §8. Flag for Nick: bracketed figures are placeholders pending final sign-off — see ops/legal/flag-register.md item 9.
8. Your rights: access, correction, withdrawal of consent, deletion
These are the actual mechanisms, not aspirations:
Access. You can ask for a copy of everything we hold about you. Email
info@pardoned.aifrom your account email; we verify it is you and respond, normally within 30 days. (Self-serve export is planned; until it ships, export is handled personally by the Privacy Officer.)Correction. You can correct your information yourself in the intake and portal at any time before filing, or ask us at
info@pardoned.aito correct anything you cannot edit.Withdrawal of consent. Consent is yours to take back. You can revoke the "keep my case on file for renewals" opt-in in your portal settings at any time (your encrypted intake is then destroyed on the §7 schedule as if you had never opted in); unsubscribe from reminders and any non-transactional email via the link in every such email; or withdraw consent to processing entirely by deleting your account. Withdrawing consent for processing we genuinely need to deliver a Service you have purchased means we can no longer deliver it — the Refund Policy governs what you get back.
Deletion (crypto-shred, honestly described). You request deletion from your portal, or by email — we verify it is you via your login email. Nothing is deleted for 7 days, a grace period in case you change your mind; you can cancel with one click any time in that window, and all scheduled emails stop immediately when you request deletion. After 7 days, we destroy the encryption keys for your case. Your encrypted case data becomes permanently unreadable — to you, to us, to anyone; there is no undo — and we delete your documents and account.
What survives deletion, and why: basic payment records (amount, date, receipt — required by tax law; these live with our payment processor and contain nothing about your case); a minimal security audit trail with content stripped out (it records that events happened, not what your forms said); and your email address on our suppression list, so we never contact you again. If you had opted into keep-on-file for renewals, deletion cancels that too — everything goes, and any future case would start from scratch. Data you have already delivered to a government yourself is outside our reach and is governed by that government's rules.
9. Email practices
Our email practices under Canada's Anti-Spam Legislation (CASL):
- Transactional and case emails (receipts, sign-in links, documents-ready notices, case milestones) follow from your purchase.
- The eligibility-date reminder is sent only on your express opt-in, and we record the exact consent text and version you agreed to.
- Every non-transactional email includes a working unsubscribe link, honoured immediately.
- We never email people who abandoned the quiz without opting in — full stop. There is deliberately no mechanism in our systems for doing so.
- Envelope discretion is a feature: a neutral sender name ("Pardoned," from
no-reply@mail.pardoned.ai, reply-toinfo@pardoned.ai), neutral subject lines, and nothing in a subject or preview that reveals what our service is about.
10. Cookies and analytics
Our analytics are minimal, first-party, and privacy-hardened: PostHog with autocapture off on quiz and application routes, form inputs masked, no session replay on wizard screens, and a strict code-enforced allowlist of events that never includes personal information. We use no third-party advertising cookies, no ad pixels, and no cross-site tracking of any kind. Essential cookies are limited to what sign-in and security require.
11. Breach notification commitment
If a breach of our safeguards creates a real risk of significant harm to you, we will notify you directly and report to the Privacy Commissioner of Canada as soon as feasible, and we will tell you plainly what happened, what was exposed, when, what we did about it, and what you can do. We maintain a register of all breaches, as the law requires, whether or not they meet the notification threshold. Because your case data is encrypted with per-case keys, our breach analysis distinguishes — and our register records — whether exposed data was readable or ciphertext-only.
Our full internal procedure is ops/legal/breach-runbook.md.
12. Complaints and escalation
Raise any privacy concern with our Privacy Officer first at info@pardoned.ai — you will get a substantive response, normally within 30 days. If you are not satisfied, you may complain to the Office of the Privacy Commissioner of Canada (30 Victoria Street, Gatineau, Quebec K1A 1H3; priv.gc.ca). Quebec residents may also contact the Commission d'accès à l'information du Québec. Using these rights never affects the Service you receive.
13. Changes to this policy
This policy is versioned; the version and effective date appear at the top, every version's text is hash-recorded, and a history is published. Material changes are re-notified to you (by email or portal notice) before they take effect, and no change retroactively expands what we may do with information collected under an earlier version without your fresh consent.