Privacy Policy
Last updated August 22, 2026
Scope of this policy
This Privacy Policy explains how Astrid Labs, Inc. ("Astrid," "we," "us," or "our") collects, uses, discloses, and protects information in connection with our website at astrid.legal and our meeting-capture and matter-management software (together, the "Service").
Astrid is built for law firms. Most of the personal information the Service processes is provided by a law firm we serve (a "Firm") or by the Firm's own clients and case contacts, in the course of the Firm using Astrid to capture and manage client-matter communications. This policy describes our practices as the provider of that software. It does not describe, and we do not control, how a Firm itself handles information outside the Service, or the professional obligations a Firm owes its own clients under applicable law or rules of professional conduct.
Who we are
Astrid Labs, Inc. is a Delaware corporation with a mailing address at 215 N Payne St STE 87379, Alexandria, VA 22314. You can reach us at jason@astrid.legal.
Information we collect
We collect the following categories of information:
- Account and identity information. Name, work email address, phone number, firm name, and seat role (attorney, staff, or firm administrator) for anyone who signs up for or is invited to an Astrid account.
- Call and meeting content. Audio recordings, transcripts, and Astrid-generated summaries of client and case-related calls and meetings a Firm captures through the Service, whether captured over Zoom Phone, a dial-in bridge, an uploaded audio file, a meeting bot joining a video call, or an attorney dictating notes directly.
- Matter and contact information. Case or matter names, client names, and client contact details (phone, email) that a Firm enters directly or that are imported from a case management system a Firm connects to Astrid.
- Consent and disclosure records. A Firm's configured consent mode, and any automatically detected or self-attested indication of whether recording consent was addressed on a given call, kept as part of the record of that call.
- Usage and device information. Log data, IP address, browser and device information, and how an account interacts with the Service.
- Billing information. Information needed to process payment for a Firm's subscription, collected and processed on our behalf by our payment processor.
How we use information
We use the information above to:
- provide, operate, and maintain the Service, including transcribing calls, drafting file notes and client recap emails, and organizing that content by matter;
- authenticate accounts and enforce a Firm's configured seat roles and access controls, including restricting privileged or marked-confidential calls to authorized attorneys and firm administrators;
- sync notes and action items to a case management system a Firm has connected, when the Firm chooses to;
- send calendar-derived meeting reminders and, when an attorney connects their own email account, deliver client recap emails on their behalf;
- bill for the Service and communicate with Firms about their account;
- maintain the security of the Service and investigate suspected misuse; and
- comply with legal obligations.
AI processing
The Service uses third-party transcription and large-language-model providers to convert call audio into text and to draft file notes and client recap emails from that text. These providers process content solely to return the requested output to Astrid; we do not permit them to use Firm content to train models for their own or any other customer's benefit.
Every note and recap email Astrid drafts is a draft. It is not treated as a Firm's official record, and is not sent to a client, until a licensed attorney at the Firm reviews and approves it. A Firm may also configure Astrid to redact categories of personally identifying information from a transcript before it is stored or used to draft a note.
Consent and call recording
Laws governing consent to record a phone call or meeting vary by state and can require the consent of one or all parties to the call. Astrid provides tools to help a Firm document and, where configured, automatically check for recording consent, including a self-attestation setting, automatic detection from the conversation itself, and an audible disclosure played when a meeting bot joins a video call. The Firm, not Astrid, is responsible for determining which consent rules apply to its calls and for complying with them. Astrid's consent tools assist that compliance; they do not replace a Firm's own legal judgment about a specific call or jurisdiction.
Case management system sync
A Firm may connect a supported case management system (currently Clio, Smokeball, CasePeer, or MyCase) to Astrid. When connected, and only when an attorney chooses to at the point of approving a note, Astrid sends the note and its associated action items to that system as a case note (or the equivalent object the provider uses) and as tasks. This is a one-directional, Firm-initiated action. Astrid does not otherwise pull data from a connected case management system beyond what is needed to search for and link the correct matter. Once information leaves Astrid through this sync, it is governed by that case management provider's own privacy practices, not this policy.
Calendar and email integration
An individual attorney or staff member may separately connect their own Google or Microsoft account to Astrid. If connected, Astrid reads that person's calendar (read-only) to surface upcoming meetings for capture, and, only when that person chooses to send a client recap email from within Astrid, sends the email through their own connected Gmail or Outlook account. The email is sent as that person, from their own mailbox, not from an Astrid-controlled address. Astrid does not read the contents of an attorney's existing mailbox.
Google API Limited Use compliance
Astrid's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Calendar data obtained through a Google account connection (read-only) is used only to surface a connected attorney or staff member's upcoming meetings within Astrid and to determine when to dispatch a meeting-join bot; Gmail access is used only to send a client recap email that the connected person has reviewed and chosen to send, from their own mailbox. Neither Calendar nor Gmail data is used to develop, improve, or train any artificial intelligence or machine-learning model, generalized or otherwise, and neither is transferred to Astrid's transcription or AI drafting providers described under AI processing, above.
How we share information
We disclose information only in the following circumstances:
- Service providers. We share information with vendors who host, transcribe, or process content on our behalf (including our cloud infrastructure provider, our transcription provider, and our AI processing providers) under contracts that limit their use of that information to providing services to us.
- Case management, calendar, and email integrations. As described above, and only when a Firm or individual user has connected and authorized the integration.
- Legal and safety. When required to comply with a subpoena, court order, or other legal process; to enforce our agreements; or to protect the rights, property, or safety of Astrid, our users, or others.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply to previously collected information.
We do not sell your information
Astrid does not sell personal information, and does not share personal information with third parties for cross-context behavioral advertising. We do not run advertising on the Service, and we do not use call content, transcripts, or matter data for marketing purposes.
Data security
We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction, including encryption in transit, role-based access controls, and restricted access to calls and matters marked privileged. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Data retention
We retain call recordings, transcripts, notes, and matter data for as long as a Firm's account remains active, and for a reasonable period after the account closes to allow the Firm to export its records and to meet our own legal and accounting obligations. A Firm may request earlier deletion of specific content, subject to any retention we or the Firm are separately required to maintain by law or professional obligation. We retain website usage data only as long as reasonably necessary for the purposes described in this policy.
Your privacy rights
Depending on where you live, you may have the right to know what personal information we have about you, to access or receive a copy of it, to correct it, to delete it, and to not be discriminated against for exercising these rights. Because most call, transcript, and matter content in the Service is created and controlled by a Firm as part of its own client relationships, we ask that you first direct a request about that content to the Firm; we will assist the Firm in responding to a verified request. You can reach us to exercise these rights, or with any question about this policy, at jason@astrid.legal.
Cookies and tracking
Our website and application use a small number of strictly necessary cookies to keep you signed in and to remember your preferences. We do not use advertising or cross-site tracking cookies. If that changes, we will update this policy and provide a way to manage your preferences.
Where information is processed
We process and store information on servers located in the United States. The Service is intended for use by law firms and individuals located in the United States; we do not currently direct the Service to, or knowingly process personal information of, individuals located in the European Union or United Kingdom.
Children's privacy
The Service is intended for business use by legal professionals and is not directed at, or knowingly used by, individuals under the age of 18. If we learn we have collected personal information from a minor in a manner inconsistent with this policy, we will delete it.
Processing detail by relationship
The tables below describe our processing of personal information in more detail, organized by relationship.
Website visitors
| Categories of information | Contact details voluntarily submitted (e.g., through a demo request or contact form); IP address and browsing information collected automatically. |
|---|---|
| Source | Provided directly by the visitor, or collected automatically by the website. |
| Purpose | To respond to inquiries, schedule demos, and understand how our website is used. |
| Shared with | Service providers who host our website and process form submissions. |
| Sold or shared for advertising | No. |
Firms and their authorized users (attorneys and staff)
| Categories of information | Account and identity information; billing information; usage information; and, in their role administering the account, access to the Firm's own call, matter, and client-contact data described below. |
|---|---|
| Source | Provided directly by the Firm or its authorized users at signup and during use of the Service. |
| Purpose | To provide the Service under our agreement with the Firm. |
| Shared with | Service providers described above; a case management, calendar, or email provider the Firm or user separately connects. |
| Sold or shared for advertising | No. |
The Firm's clients and case contacts
| Categories of information | Name and contact details on file with the Firm; the content of recorded calls and meetings, including anything discussed on those calls (which, in the ordinary course of a legal matter, may include sensitive subjects such as medical history, family matters, or financial information as relevant to the case). |
|---|---|
| Source | Collected by the Firm in the course of representing its client, and processed by Astrid on the Firm's behalf and instruction. |
| Purpose | To provide the Service to the Firm. Astrid acts as the Firm's service provider for this data, not as an independent controller of it. |
| Shared with | Service providers described above; a case management system the Firm connects, for that Firm's own matter, when an attorney approves the sync. |
| Sold or shared for advertising | No. |
Changes to this policy
We may update this policy from time to time. If we make a material change, we will notify Firm administrators by email or through the Service and update the "Last updated" date above.
Contact us
Astrid Labs, Inc.
215 N Payne St STE 87379
Alexandria, VA 22314
jason@astrid.legal