Privacy Policy

Last updated: 6 August 2026

This policy explains what Recourse processes, why, and your rights. It is written for three audiences at once: account holders (platforms and professionals who use the venue), disputants (people whose disputes are adjudicated — often without an account), and visitors.

1. Who is responsible

Recourse ("we") is the controller for account, billing, and website data. For the contents of dispute bundles submitted by a platform client, the platform is the controller of its users' data and Recourse processes it as the platform's processor to deliver adjudication; for the email witness, the corresponding parties submit their own thread to the venue. Contact for all privacy matters: the privacy contact form.

2. What we process, and why

DataPurposeLegal basis
Account data — email, organisation, password hash or Google identityProvide the account, dashboard, and API keysContract
Dispute bundles — terms, interaction logs, deliverables, claims; these routinely contain personal data of disputants and third partiesAdjudication: producing the ruling, escalation review, quality assuranceContract (with the submitting client); the client warrants a lawful basis for the disputants' data it submits
Witnessed email threads — addresses, message contents, attachments metadataThe email-witness service: lifecycle tracking, bundle assembly, ruling deliveryContract (the venue agreement formed in-thread)
Usage and billing records — rulings metered, tier, price, invoices, payment statusBilling, rate limits, fraud preventionContract; legal obligation (accounting)
Technical logs — IP, timestamps, request metadataSecurity, abuse and rate-limit enforcement, debuggingLegitimate interest

3. Cookies

We set essential cookies only: a session cookie when you sign in and a short-lived security token during Google sign-in. No analytics, advertising, or cross-site tracking cookies — which is why there is no cookie banner.

4. Subprocessors

We use a small number of providers to run the Service, each bound by data-processing terms:

ProviderWhat forWhat they see
Anthropic (Claude API)The adjudication engine's model inferenceDispute bundle contents, as submitted for adjudication
StripeCard payments for invoicesPayment details (we never see card numbers); invoice metadata
GoogleOptional "Continue with Google" sign-inYour verified email and name, when you choose it
Email delivery providerEmail-witness inbound/outbound transportWitnessed thread contents in transit

5. Retention and the precedent corpus

Account and billing records are kept for the life of the account plus statutory accounting periods. Dispute bundles and rulings are retained while relevant to the parties' dispute lifecycle (including escalation and any liability-backed warranty period). Anonymised rulings — with names, contact details, addresses, and commercially identifying content removed — are retained indefinitely as the venue's precedent corpus; anonymisation is irreversible and the corpus is not used to profile any person.

6. International transfers

The Service is operated from infrastructure that may process data in the United States and the European Union; where personal data of EEA/UK persons is transferred internationally, we rely on adequacy decisions or standard contractual clauses with each subprocessor.

7. Your rights

Depending on where you live (GDPR, UK GDPR, CCPA), you may have rights to access, correct, delete, export, or object to processing of your personal data. Disputants whose data arrived in a platform's bundle should direct requests to the platform (the controller); we support our clients in fulfilling them and honour requests directly where we act as controller. Use the privacy contact form; you may also complain to your supervisory authority.

One thing we will never do: sell personal data, or use dispute contents for advertising. The venue's only business is judgment.