Privacy Policy
CaseGuardian is operated by CaseGuardian L.L.C., a wholly owned subsidiary of Quantum Companies Global Inc. This policy explains what we collect, why, and how we protect it.
Information we collect
- Account data: name, email, phone number, and authentication credentials.
- Evidence content you choose to upload (photos, video, audio, documents) and associated metadata (timestamps, device, hash).
- Recipient contact information you enter when creating a secure share link (phone number and email of the named recipient).
- Diagnostic and security logs (IP address, device identifiers, access events).
- Kid Calendar entries you choose to record (custody schedule type, verbal-agreement percentages, attempted-pickup log notes).
- Product usage signals, never content: the calendar date the app was opened (date only, nothing about what you did, which mode you used, or what you viewed); whether the upgrade screen was shown and which plan you selected; an optional one-tap reason if you cancel; and, for new accounts, the page, campaign, or on-screen statistic that brought you to sign up.
How we use information
- To operate the app and deliver the features you request.
- To send transactional SMS and email you have opted into (verification codes, share-link access codes, security alerts).
- To send promotional SMS and email only to users who give a separate, explicit marketing opt-in, never on the basis of the transactional opt-in alone. You can withdraw marketing consent at any time by replying STOP, without affecting transactional security messages. We do not run in-app advertising or show third-party ads.
- To verify recipient identity using both phone and email before sealed materials decrypt.
- To meet legal, tax, and regulatory obligations.
AI parsing is opt-in (per-capture and per-document)
CaseGuardian does not send your captures, documents, or Kid Calendar entries to any AI service unless you explicitly turn on the "Parse with AI" toggle for that specific item. The toggle is off by default on every capture and every document. You can change your mind at any time before sealing.
Correction, published deliberately. This page previously stated that an on-device redaction pass removed your name and other identifiers from the document before it left the device. That was not accurate, and the accurate description follows. We have left this note here rather than quietly editing the sentence.
When the toggle is on, the item itself - the photograph or document resized but otherwise intact, or the voice recording in full - is sent over an encrypted connection to the AI sub-processor for that feature. Photographs and documents go to Anthropic. Voice notes go to ElevenLabs for transcription, routed through our infrastructure provider's AI gateway. Each receives the item only for the limited purpose of extracting the data you asked for. The image is not redacted before it is sent. If a document is on screen and you turn the toggle on, assume the model sees all of it.
Redaction runs on the way back, not on the way out. Before the extracted text is saved to your account or displayed to you, CaseGuardian runs a pattern-based pass on your device that replaces email addresses, phone numbers, Social Security numbers, street addresses, dates of birth, case and docket numbers, driver's licence numbers, bank and routing numbers, payment card numbers, and IP addresses with redaction markers. Two limits are worth stating plainly: it does not remove people's names, and because it matches patterns rather than meaning, it can miss an identifier written in an unusual format.
Both Anthropic and ElevenLabs are contractually prohibited from training on or retaining your content. Outputs are stored in your account alongside the original, full-fidelity capture.
How we harden the AI pipeline. Every AI request is wrapped in safety instructions that tell the model to treat the contents of your image or PDF as data, not commands, so a document containing hidden text cannot hijack the parser. We enforce an 8 MB input ceiling, and every output field is clamped to a safe maximum length. If a parsing error is logged for diagnostics, document contents and extracted personal information are stripped from the log first.
AI output is informational only. It is not legal advice and may contain errors; always confirm with your attorney before relying on it.
Bitcoin anchoring of evidence
When you save a capture, CaseGuardian creates a 32-byte SHA-256 hash (cryptographic fingerprint) of the file on your device and forwards only that hash through CaseGuardian's servers to the public OpenTimestamps calendar network. Your file, filename, case, identity, and IP address are never sent to the calendar operators.
We retain the returned receipt in your account so you (or anyone you share a verification link with) can later prove the capture existed exactly as recorded, on the exact date and time recorded.
You are not buying, holding, or transacting in Bitcoin. The blockchain is used solely as a public, independently checkable ledger of fingerprints. There is no wallet, no purchase, no transaction fee, and no cryptocurrency activity by you. CaseGuardian L.L.C. is not registered as a money service business.
Review before sealing
Every sealed package is shown to you in a full review screen before anything leaves your device. You can remove items, edit captions, or cancel the seal entirely. Nothing is uploaded or transmitted until you explicitly confirm the seal.
Biometric protection of destructive actions
Account deletion, profile deletion, and certain other destructive actions are gated behind your device's biometric authentication (Face ID, Touch ID, or Android biometric prompt) where available, with a passcode fallback. We do not see or store your biometric data.
Sharing and third-party processors
We do not sell, rent, or share personal information, phone numbers, opt-in data, or consent records with third parties for their marketing. We use vetted sub-processors under written agreements that prohibit secondary use:
- Sent.dm - approved and active SMS provider for verification, share-link delivery, and separately opted-in marketing SMS (phone number, message body, delivery status).
- Supabase - application database, authentication, and file storage. Traffic is encrypted in transit and the underlying disks are encrypted by the hosting provider. Disk encryption protects against physical theft of hardware; it does not prevent a database read, so it is not a substitute for the field-level encryption described under Security below.
- Apple App Store / Google Play - in-app purchase and subscription billing.
- RevenueCat - subscription entitlement and receipt validation.
- Anthropic - AI parsing of items you specifically opt in for; the contract prohibits training on or retaining your content. The item is transmitted without redaction; redaction is applied to the extracted text after it returns, and does not remove names. See the AI parsing section above.
- ElevenLabs - speech-to-text transcription of voice notes you specifically opt in for. Audio is routed through our infrastructure provider's AI gateway. The recording is transmitted without redaction; redaction is applied to the returned transcript and does not remove names.
- OpenTimestamps calendar network - receives the cryptographic hash (fingerprint) of evidence items for Bitcoin anchoring; receives no file contents, filenames, identities, or IP addresses traceable to you.
- Stripe - payment processing for web subscriptions.
We may also disclose information when required by law, valid legal process, or to protect the rights, safety, or property of users or the public.
Apple App Store and Google Play disclosures
When you subscribe inside CaseGuardian, payment is processed by Apple (iOS) or Google (Android). We never see your card number, CVV, or full billing address. We receive only the receipt and entitlement status needed to grant or revoke access.
We do not use the iOS Advertising Identifier (IDFA), Google Advertising ID, fingerprinting, or any cross-app tracking SDKs. No App Tracking Transparency prompt is shown because we do not track you across apps.
You can manage or cancel subscriptions at any time in Settings → [your name] → Subscriptions on iOS, or Play Store → Profile → Payments and subscriptions on Android.
Data retention
- Account data: retained for the life of your account.
- Evidence content: when you delete your account, every file you have stored is removed from our file storage and the associated database rows are deleted in the same operation, during the request itself rather than on a delay; encrypted backups are overwritten within 90 days. When you delete a single item or a single case inside the app, it is removed from your vault and from our database, but the underlying stored file may remain in our storage system until you delete your account. We are fixing that; until we do, account deletion is the reliable way to remove stored files.
- SMS consent and opt-in / opt-out logs: retained for 4 years to meet carrier and regulatory requirements.
- Diagnostic / security logs: retained for up to 12 months.
- App-open dates: individual rows are deleted within 90 days and reduced to anonymous weekly totals that cannot be tied to any person.
- AI parsing requests: neither Anthropic nor ElevenLabs retains content; we keep only the structured output or transcript you saved. Diagnostic logs for AI errors are stripped of document contents and personal information before they are written.
- Bitcoin anchors: cryptographic fingerprints exist in the public Bitcoin ledger forever, by design. No personal information is included on-chain. Account deletion does not remove past anchors.
- Records we are legally required to keep are retained for the period required by law.
Age requirement and children's privacy
CaseGuardian is intended for users 18 years of age or older. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact support@case-guardian.com and we will delete it.
Regional rights (CCPA, GDPR, UK GDPR)
Depending on where you live, you may have rights including: access, correction, deletion, portability, restriction of processing, and objection to processing. California residents have rights under the CCPA / CPRA; we do not sell or share personal information as those terms are defined under the CCPA. To exercise any right, email support@case-guardian.com. We will not discriminate against you for exercising your rights.
For users in the EU / UK, we rely on: performance of a contract, legitimate interests (security, fraud prevention), consent (SMS, AI parsing, optional integrations), and legal obligation. International transfers are protected by Standard Contractual Clauses where applicable.
Security
We would rather you check this against the app than take our word for it, so this section says exactly where the line is today rather than where we intend it to be.
Encrypted with a key we never receive
These are encrypted on your device before they are uploaded, using a per-case key that is held in your device's secure hardware and never transmitted to us:
- The title, written summary, and transcript of every entry.
- The contents of every file you attach - photos, videos, audio recordings, and documents.
For these we hold ciphertext only. We cannot read them. We could not produce them in readable form in response to a subpoena, and if our database were copied they would remain unreadable.
Stored in a form we can read
These are stored without that encryption, which means CaseGuardian staff with database access, and anyone who could lawfully compel or unlawfully obtain that access, could read them:
- The name, subject, and category of each case.
- The location label and GPS coordinates saved with an entry.
- The date and time of each entry, and its type, duration, and tags.
- Whether an entry was captured in Safety Mode.
- The name, relationship, phone number, email address, and notes for every witness you add.
- The text of any court order you upload and have parsed, including the full parsed result.
- The camera metadata (EXIF) of attached photos, which can include its own GPS coordinates and timestamp.
- Your account details - email address, phone number, ZIP code, and preferred name.
We are changing this. Extending encryption to every field in the second list is our highest-priority engineering work, and we will update this section as each field moves across. We publish the list in this state because a privacy policy that describes an unbuilt system is not a privacy policy.
Note on EXIF specifically: we will encrypt it, not strip it. Camera metadata is part of what makes a photograph evidence, and removing it would weaken the record you are trying to build.
True today, without qualification
- TLS 1.3 in transit on every connection.
- Database-level Row-Level Security on every table, so no account can read another account's rows.
- Zero third-party trackers, zero ad SDKs, zero IDFA collection. Your evidence never trains a model and never feeds an ad network.
- Nothing is uploaded until you review and approve it.
Your rights and account deletion
You can access, export, correct, or delete your data at any time from inside the app under Profile → Legal and Privacy, including a one-tap Delete Account option (gated by biometric authentication), or by emailing support@case-guardian.com from your registered address. We will action verified requests within 30 days. Deleting the app from your device does not delete your account.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced in-app or by email at least 7 days before they take effect, with an updated effective date at the top of this page.
Ownership and intellectual property
CaseGuardian and the CG Share Link feature are copyrighted works and the exclusive property of CaseGuardian L.L.C. All software, branding, designs, and content are protected by copyright and trademark laws. © CaseGuardian L.L.C. All rights reserved. See our Terms of Service for license details.
Contact
CaseGuardian L.L.C.
30 N. Gould St., Ste. R, Sheridan, WY 82801, USA
Phone: (307) 363-9369
Email: support@case-guardian.com
© CaseGuardian L.L.C. All rights reserved.