Privacy Policy
Effective October 2, 2026
This Policy explains how Joule Studios, LLC, a Florida limited liability company, collects, uses, shares, and retains information through MatterLynx. It applies to the MatterLynx website, accounts, beta program, and connected tools.
Information we process
- Account and firm information, such as names, work emails, firm identity, roles, and workspace membership.
- Beta, marketing, and support information, including signup answers, campaign data, and messages you send us.
- Connection information, including encrypted OAuth tokens, scopes, connection status, and provider identifiers.
- Operational information, such as tool name, action type, success or failure, timing, rate-limit data, and security events.
- Billing information handled by Stripe, such as customer and subscription identifiers. MatterLynx does not store full payment-card numbers.
- Practice data processed on demand when an authorized user asks MatterLynx to read or change information in Clio or Lawmatics. Depending on the request, this may include contacts, matters, intake records, notes, tasks, calendar entries, emails and attachments, documents and drafts, financial records, and reports.
- File-transfer and retry records, such as filenames, destinations, provider record identifiers, file hashes, and operation status.
How we use information
We use information to provide and secure MatterLynx, authenticate users, connect approved services, carry out user instructions, enforce access and billing controls, maintain audit records, troubleshoot problems, communicate with users, prevent abuse, and comply with law.
MatterLynx does not use client or matter data to train AI models. When you make a request, relevant data may pass through MatterLynx to the AI assistant you selected. That provider may process or retain it under its own terms, privacy policy, plan, and settings.
Practice data and access
MatterLynx processes practice data to complete authorized requests and limited support, security, and reconciliation work. Clio and Lawmatics remain the firm's systems of record. Each user connects their own account for each provider they use. Clio's permissions continue to limit what that user can access. The current Lawmatics beta requires administrator access in both MatterLynx and Lawmatics; ordinary staff access is not available.
Requested information passes through MatterLynx to your selected assistant. Email and file workflows may also use content supplied by you or by a mailbox or file service you connect to your assistant. MatterLynx may temporarily store review results and files as described below. Copies saved in Clio, Lawmatics, or your assistant are subject to those services' retention and deletion practices.
MatterLynx's operator and infrastructure providers may have technical access where needed to operate, secure, support, or comply with law. The routine operator dashboard is designed to show account, connection, and operational status rather than client or matter content.
When information is shared
We share information with service providers that help operate MatterLynx, including hosting, storage, database, authentication, payment, email, monitoring, operations, practice-management, and user-selected AI assistant providers. We may also disclose information when required by law, to protect rights or safety, to investigate misuse, or as part of a financing, reorganization, sale, or transfer of the service.
See the Subprocessors page for the current service categories and providers.
Cookies and security
MatterLynx and Clerk use essential cookies to sign users in and maintain sessions. A separate first-party cookie remembers your marketing measurement choice for up to 180 days. When measurement is allowed, browser storage holds a random visitor identifier, a session identifier, and campaign attribution. Browser attribution is treated as expired after 90 days and removed when next read; this does not delete earlier server-side measurement records. The former founding-offer cookie is no longer used to select offers or access.
MatterLynx uses OAuth, tenant-scoped access controls, encrypted token storage, assistant write-permission controls, and audit records. Your AI assistant settings determine whether it asks before each write or allows writes automatically. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or disclosure will never occur.
Website and marketing measurement
MatterLynx uses first-party funnel measurement to understand website visits, calls to action, setup-form progress, and successful setup-instruction requests. This measurement stores random visitor and session identifiers, landing path, referring site, and campaign parameters. It does not store IP addresses, browser user agents, form answers, client data, or case data.
For visitors in the United States, MatterLynx also uses Meta Pixel and Meta's Conversions API. For a successful setup-instruction request, we may send Meta the page URL, event time, a one-way hashed version of the work email address, IP address, browser user agent, and Meta browser or click identifiers. We do not send signup-form answers, practice area, firm size, client data, matter data, or privileged text to Meta.
The browser and server events use the same event ID to prevent double counting. These marketing measurement tools are enabled by default, but MatterLynx honors Global Privacy Control and any choice to turn marketing measurement off. You can change your choice at any time using the "Your Privacy Choices" control in the site footer.
Vercel also provides website analytics and performance measurement. These run separately from first-party marketing measurement and Meta and are not disabled by this control or MatterLynx's handling of Global Privacy Control. This control does not change email subscriptions.
The product walkthrough loads YouTube's embedded player and player API only after you click to play it. Playback connects your browser to Google/YouTube under their privacy practices. The marketing measurement control does not disable video playback or the data processing needed by that player.
MatterLynx does not sell client or matter data. Some privacy laws may define the use of Meta measurement as "sharing" or targeted advertising. The privacy control and Global Privacy Control signal let you opt out of that measurement.
Setup emails and product updates
We use signup and account information to send setup instructions, service messages, and permitted MatterLynx product updates. Resend stores contact details and audience memberships. We organize audiences using signup information, account status, and whether your own Clio or Lawmatics connection is recorded as connected. These groups do not include client or matter content or OAuth token values.
You can unsubscribe from product updates through the email's unsubscribe link or by contacting us. We preserve existing opt-outs when updating audiences. Necessary account, security, and service messages are separate from product updates. Disconnecting a provider or deleting an account does not automatically unsubscribe a historical signup; you can request removal of that signup as well. Updating this Policy does not itself create marketing consent or override an earlier preference.
Retention and deletion
- Most practice content is processed on demand rather than kept as a long-term MatterLynx record.
- Matter Review jobs temporarily store request, progress, and result data so a long review can resume after a timeout. Pending, completed, and failed jobs are eligible for scheduled deletion after one day without an update. Running jobs are handled separately and may remain longer; continued activity can extend retention.
- Private Clio document-upload sessions normally expire after two hours. Staged file contents are deleted after Clio confirms the result. If the result is uncertain, staged data may remain for up to seven additional days for reconciliation. Active transfers and failed deletion attempts may take longer to resolve.
- Deleting staged file contents does not delete the associated upload or retry records. Filenames, destination labels, provider record identifiers, hashes, and operation status may remain to support reconciliation and prevent duplicate actions. These records have no routine deletion schedule and are considered in verified deletion requests.
- Detailed operational usage events are scheduled for deletion after 90 days once aggregate reporting is complete. Legal preservation or delayed processing may extend that period.
- Aggregate usage reports may be kept indefinitely. Some remain associated with a firm or user identifier; aggregation does not make them anonymous. They are designed to exclude client names, matter names, notes, documents, amounts, and other case content.
- Security and audit records have no routine deletion schedule. They are designed to retain identifiers, action types, timing, results, and other structured metadata while excluding names, contact details, notes, documents, amounts, free text, and secrets.
- A revoked AI assistant connection may leave a limited security record so the same client cannot silently reconnect. Users can restore that connection from Settings.
- Account, support, billing, transaction, and legal records are kept for as long as reasonably needed for the service, security, accounting, disputes, and legal obligations.
- Signup and first-party marketing-event records have no routine automatic deletion schedule. Audience memberships change with account and connection status, but contact and opt-out records may remain. We consider these records when handling verified deletion requests and retain opt-out records where needed to honor your choices.
Scheduled cleanup runs daily, so eligibility for deletion is not a promise of deletion at that exact time. These schedules describe MatterLynx's active application data; infrastructure backups and copies held by connected services have separate retention processes.
Your choices and requests
You or an authorized firm administrator may request access, correction, export, or deletion of MatterLynx account data and may disconnect providers. Requests are handled through a verified manual process. We may need to confirm identity and authority, and may retain records where required or reasonably necessary for security, accounting, disputes, or law. Rights and exceptions vary by location.
Send privacy requests to Joule Studios, LLC at julian@joulestudios.com.
Business use and changes
MatterLynx is intended for business use by adults, not for children. We may update this Policy as the service changes. The effective date above identifies the current version, and material changes may require renewed acceptance or notice.