Privacy and query retention
For founders' beta. This is not a signable contract and not a data processing agreement (DPA). A registered legal entity is not published yet: tracked separately.
Privacy: privacy@avokata.com · Security: security@avokata.com
What this is
Avokata is provided by Kiznis Studio (trading name). Avokata gives a lawyer's assistant tools to search Lithuanian statutes and court practice, read provisions with pinpoints, follow citations, and run playbooks. The corpus is public record. About you we store only what an account needs and the text you choose to put in matter profiles and workflows.
We offer no person-search tools, we do not sell personal data, and we do not use your data to train models.
Query text: what we do not keep
Search and tool question text is not stored. We record that a tool ran, when, how long it took, how many results came back, which quota it used, and a one-way digest of the arguments (arg_digest). The digest cannot be turned back into your words: it exists only to recognise repeated calls.
That is deliberate: a lawyer's question can reveal client strategy. Keeping query text would turn the usage ledger into a log of what every user is researching.
Keyless trial before you connect
You can call search_law and search_practice a few times per day with no account. For that path:
- Search question text is still not stored; the same rule as above applies.
- No account is created; matter profiles, workflows and document reads need
connect. - Rate limiting uses a one-way hash of your network address, held in server memory only for the day's allowance. We never store the address itself; the hash cannot be reversed into an IP.
- The counter resets at midnight UTC and also resets when we deploy new server software.
What we store and why
- Email, optional firm name, working language: account and sign-in. Until you delete the account.
- API keys (hashed): authentication. Until revoked or the account is deleted.
- Sessions: bind an MCP connection to your account. Until expiry.
- Usage metadata: tool, time, quota, digest, latency. While the account exists; the owner id is nulled after deletion, with no text kept.
- Matter profiles: the question, provisions and notes you enter. Until you delete the matter or account. This is the deliberate exception to "we do not keep query text."
- Workflows you wrote: your playbooks. Until you delete them or the account.
- Watches: provisions or questions you asked to follow. Until removed or the account is deleted.
- Feedback: if you send it. Until account deletion.
- Newsletter: if you subscribe. Until you unsubscribe.
We keep no copy of statute or ruling text under your name: only pointers into the public corpus.
Where data lives
Servers and nightly backups run on Hetzner in Germany (EU). The network edge, DNS and email routing run on Cloudflare. Connections use HTTPS; data at rest is encrypted on disk and in backups.
Who on our side can read matter data
There is no admin console. Profiles and workflows are reachable only through your connection. In normal operation we do not read customer matter text. If you contact support, we open only what your question needs.
Server and application logs
Containers write server and application logs (startup lines, errors, health checks) to the host. Docker rotates them (about 30 MB per service).
Search and tool question text is not written to server logs. The same rule as the usage ledger applies: we record that a tool ran, not what you asked.
Log access is limited to people who operate the infrastructure, on a need-to-know basis (outages, a report to security@avokata.com, abuse). There is no console where staff browse customer research in logs, and we do not routinely read raw logs to inspect matters. If you contact us about a specific incident, we may inspect relevant log lines for that incident only.
Deletion
Ask your assistant for request_deletion, or write to privacy@avokata.com. We email a confirmation link; confirming erases the account and every attached record in one step. There is no undo. Usage rows survive with the account id nulled: counts with no text.
Per matter: delete_matter. Export: export_account_data.
Incidents
If we become aware of a personal-data breach that may affect your account, we notify the email on your account without undue delay. Reports: security@avokata.com.
Your rights
You can ask for access, correction, deletion, restriction, portability, or object to processing. Write to privacy@avokata.com; we answer within one month. You may complain to your supervisory authority.
Purposes
We process personal data to operate Avokata: accounts, API keys, quotas, matter profiles and workflows you deliberately save, support and security reports. The Lithuanian law corpus is public record and is not your personal data.
Legal bases
Under the GDPR we rely on contract performance (Art 6(1)(b)) for account operation; legitimate interests (Art 6(1)(f)) for security, abuse prevention and keyless trial metering; consent (Art 6(1)(a)) where we ask explicitly, such as newsletter signup.
Recipients and processors
Infrastructure providers listed on our Subprocessors page process data on our behalf. We do not sell personal data or use it to train third-party models.
International transfers
Primary hosting and backups run on Hetzner in Germany (EU). Cloudflare operates a global edge; where data leaves the EEA we rely on appropriate safeguards such as Standard Contractual Clauses.
Retention
Account data is kept while the account exists. Usage metadata survives deletion with the account identifier nulled and no query text retained. Matter profiles and workflows remain until you delete them or the account.
Cookies
See our Cookie policy for strictly necessary cookies and cookieless Cloudflare Web Analytics. We do not use Google Analytics.
Business customers
Enterprise terms, a signable DPA and registered-entity details are not yet available during beta (P1-114).
What this draft is not
This is a draft privacy notice for beta users. Terms: /legal/terms. Formal notice: /legal/privacy. Subprocessors: /legal/subprocessors. Cookies: /legal/cookies. Acceptable use: /legal/acceptable-use. A DPA and signable enterprise documents wait on legal entity registration.
Last updated: 2026-09-04.