Privacy Policy
Effective: July 2026
1. About this policy
Ruby Law Professional Corporation (referred to in this Policy as "Ruby Law", "we", "us", or "our") is a licensed law firm that operates an AI-native legal services platform (the "Service") at rubylegal.ai. The technology platform is provided by Ruby AI Inc. under a technology licence. This Policy explains how we collect, use, disclose, retain, and protect personal information when you interact with us. It applies to:
- founders, businesses, and individuals who create a Ruby Law account to obtain legal agreements, legal review, or legal advisory services;
- users who interact with Ruby Law's AI-powered intake tools, document assembly features, or Ask Ruby AI assistant;
- individuals whose personal information is included in legal matters submitted to Ruby Law (for example, counterparties named in agreements, employees described in employment contracts, or investors identified in financing documents);
- visitors to our website, blog, and marketing materials; and
- any person who contacts us by email, chat, or other means.
We comply with the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA"), Quebec's Act respecting the protection of personal information in the private sector (as amended by Law 25), Alberta's Personal Information Protection Act, British Columbia's Personal Information Protection Act, and, where applicable, the Canada's Anti-Spam Legislation ("CASL") (collectively, "Applicable Privacy Laws"). Where any provision of this Policy conflicts with Applicable Privacy Laws, the law prevails and we will treat the inconsistent provision as modified to the minimum extent necessary to comply.
By creating an account, using the Service, submitting information through our intake workflows, or continuing to browse the website after being shown our cookie banner, you acknowledge that you have read and understood this Policy and consent to our collection, use, and disclosure of personal information as described, subject to the choices set out in Section 10 (Your Privacy Choices and Rights).
2. Who is responsible for your personal information
The data controller (and, under Quebec Law 25, the enterprise responsible for the protection of personal information) is:
Ruby Law Professional Corporation.
Privacy Officer: Brooke Ash
Contact: clientservices@rubylegal.ai
Our Privacy Officer is accountable for Ruby Law's compliance with this Policy and with Applicable Privacy Laws, including responding to access and correction requests, investigating complaints, and acting as the point of contact for the Office of the Privacy Commissioner of Canada and provincial regulators.
3. The Ruby Law Service, in plain terms
Ruby Law is an AI-native law firm licensed and regulated by the Law Society of Ontario. We combine proprietary artificial intelligence with licensed Canadian lawyers to deliver legal agreements, review, and advisory services. The features of the Service that involve personal information are:
- AI-Powered Legal Intake. You complete a structured intake questionnaire that captures the details of your legal matter, including your business structure, jurisdiction, and preferred positions on key legal terms. Our AI uses your responses to configure the right agreement for your situation.
- Agreement Drafting and Assembly. Ruby Law's AI selects and assembles clauses from our proprietary clause libraries, applying three negotiating positions (client-favourable, balanced, and counter-party) based on your intake responses.
- Automated Compliance Checking. Regulatory compliance modules (covering employment standards, corporate statutes, privacy, anti-spam, securities exemptions, provincial requirements, and Law Society conduct rules) run automatically on every agreement.
- Lawyer Review. For our Counsel tier, a licensed Canadian lawyer reviews the drafted agreement, provides legal advice, and signs off before delivery. Your communications with our lawyers are protected by solicitor-client privilege.
- Ask Ruby AI. Our AI assistant helps you answer legal questions, understand your agreements, and navigate the platform.
- Client Portal. You manage your legal matters, track agreement status, review documents, and communicate with our team through a secure client portal.
- Document Storage. Completed agreements and related documents are stored securely for your retrieval.
4. What personal information we collect
We collect only the categories of personal information reasonably necessary to provide and improve the Service.
a. Account and identity information
- Your name, email address, phone number (if you choose to provide one), password (stored only in hashed form), company name, role or title, and account preferences.
- If you are referred by another user or partner, the name and email used to refer you.
b. Legal matter intake responses
- The business details you provide during intake, including your company's legal name, jurisdiction of incorporation, business address, industry, corporate structure, and the names and roles of founders, directors, and officers.
- Your positions on legal terms and negotiating preferences selected during the intake process.
- Any additional information, instructions, or context you provide in free-text fields or supplementary documents.
c. Information about third parties included in your legal matters
- Counterparty names, addresses, and contact details provided for inclusion in agreements.
- Employee or contractor details provided for employment, consulting, or independent contractor agreements.
- Investor or shareholder details provided for financing, shareholder, or equity incentive plan agreements.
- Other third-party information you choose to include in your legal matters.
Important: when you provide information about another person or entity, you represent and warrant that you have the right to share that information with Ruby Law for the purposes of your legal matter and that you have provided any notices to that person that Applicable Privacy Laws require. You agree to defend and indemnify Ruby Law against any claim brought by a third party arising out of a breach of this representation.
d. Generated legal documents
Agreements, memoranda, and other legal documents drafted by Ruby Law on your behalf, including all versions and revisions.
e. Subscription, billing, and payment information
- Your selected plan (Precision or Counsel), billing cycle, and subscription status.
- Billing name and address. Payment card information is collected and held directly by our payment processor (see Section 6); we do not store full card numbers on our systems.
- Records of payments, refunds, credits, and subscription changes.
f. Technical, device, and usage information
- IP address, approximate location derived from IP, device and browser identifiers, operating system, referring page, pages and features viewed or used, and time-stamped event logs.
- AI interaction logs, including your queries to Ask Ruby AI and the responses provided.
- Cookies, pixels, local storage, and similar technologies (see Section 14).
g. Communications
Messages, emails, and other communications between you and our team, including communications with our lawyers during the Counsel-tier review process.
h. Sensitive information that may be inferred from your legal matters
Ruby Law does not ask you to disclose religion, health, ethnicity, or other sensitive personal categories. However, the details of certain legal matters you submit may reveal or imply sensitive information when read in context. For example, an employment agreement addressing a human rights accommodation, a restrictive covenant relating to a health-sector business, or intake responses describing a dispute involving a protected ground may contain information from which sensitive categories can be inferred. We treat any such information as sensitive personal information, collect it only because you have chosen to provide it in connection with your legal matter, and apply heightened safeguards in storage and access.
5. How we collect personal information
- Directly from you when you create an account, complete an intake questionnaire, upload documents, interact with Ask Ruby AI, or send us a message.
- Through your use of the Service, including AI interaction logs and feature-usage events.
- Automatically through cookies, server logs, and product-analytics events when you interact with the website or the platform.
- From our service providers, including the payment processor confirming a successful charge and the email-delivery provider confirming delivery status.
6. Why we collect, use, and disclose personal information
Consistent with PIPEDA Principle 2 (Identifying Purposes) and Quebec Law 25, we use personal information only for the purposes set out below.
- To create and administer your account and authenticate you when you sign in.
- To deliver the features of the Service, including AI-powered intake, agreement drafting, compliance checking, lawyer review, Ask Ruby AI, and document storage.
- To process payments, manage subscriptions, issue receipts and refunds, and comply with tax obligations.
- To send transactional and administrative messages that are necessary to provide the Service (account notices, security alerts, billing receipts, matter-status updates, agreement-delivery notifications, and updates to this Policy or our Terms of Service). You cannot opt out of these messages while you have an active account.
- To provide customer support and respond to your requests.
- To enable our lawyers to provide legal review, advice, and sign-off on Counsel-tier matters.
- To monitor, secure, and protect the Service, including detecting and preventing fraud, abuse, and unauthorized access.
- To improve the Service by analyzing usage patterns in aggregate or de-identified form. We do not use your legal matter data to train AI models (see Section 16).
- With your separate opt-in consent, to send marketing communications about Ruby Law features, legal updates, or partner offers. You can withdraw that consent at any time using the unsubscribe link in the email or by contacting our Privacy Officer.
- To comply with our legal, regulatory, tax, accounting, audit, and Law Society obligations, and to establish, exercise, or defend legal claims.
- For any other purpose with your consent, or where the use is permitted or required by Applicable Privacy Laws.
7. Service providers, sub-processors, and the technology we use
We engage carefully selected service providers (also called sub-processors or processors) to operate the Service. We require each of them, by written contract, to use personal information only on our instructions, to keep it confidential, to apply security safeguards comparable to ours, and to assist us with our obligations under Applicable Privacy Laws. Our current service providers are:
| Category | Provider | Function | Where data is processed | Privacy policy |
|---|---|---|---|---|
| Hosting & infrastructure | Microsoft Azure | Cloud hosting and deployment infrastructure for the Service (Azure App Service), the relational database (Azure SQL Server), document storage (Azure Blob Storage), secrets management (Azure Key Vault), and caching (Azure Cache for Redis). | Canada (Canadian data centres) | View policy |
| Artificial intelligence | Anthropic PBC | Large-language-model API powering Ruby Law's AI intake, agreement drafting, compliance checking, and Ask Ruby AI features. Ruby Law sends structured prompts containing your intake responses and matter details to Anthropic's API; Anthropic processes these prompts and returns outputs to Ruby Law. Anthropic does not retain your data for model training under our commercial API agreement. | United States | View policy |
| Payments | Stripe, Inc. | Payment processing, subscription billing, checkout sessions, and payment reconciliation. Stripe collects and holds your payment card information directly; Ruby Law does not store full card numbers on its systems. | United States | View policy |
| Resend, Inc. | Transactional email delivery (account notices, billing receipts, matter-status updates, security alerts). | United States | View policy | |
| Loops Inc. | Lifecycle and marketing email (where you have opted in to receive marketing communications). | United States | View policy | |
| SMS | Twilio Inc. | SMS delivery for multi-factor authentication codes and account notifications. | United States | View policy |
| Analytics & forms | HubSpot, Inc. | Website analytics on rubylegal.ai and processing of contact-form submissions through the HubSpot Forms API. | United States | View policy |
| Content management | Sanity Inc. (Sanity.io) | Headless CMS storing rubylegal.ai website and blog content. | United States | View policy |
| Source code management | GitHub, Inc. (a Microsoft company) | Source-code management, CI/CD pipeline, and engineering operations. Personal information may be referenced only in support tickets or bug reports. | United States | View policy |
We do not currently have a dedicated error-tracking or application monitoring sub-processor recorded for the Service. If one is introduced, we will add it to this table and, where required, notify you in advance.
We may update this list from time to time. The current list is always available in this Policy. If we add a new sub-processor that performs a materially different function, we will update the Policy and, where required, notify you in advance.
8. Solicitor-client privilege and confidentiality
Ruby Law is a licensed law firm regulated by the Law Society of Ontario. Where you engage Ruby Law for Counsel-tier legal services, the relationship between you and Ruby Law is a solicitor-client relationship, and your communications with our lawyers, our legal advice to you, and our work product are protected by solicitor-client privilege.
You should be aware of the following:
- Privileged communications include your intake responses, instructions to our lawyers, our lawyers' advice and analysis, and draft and final agreements prepared in the course of providing legal services to you.
- Ruby Law's AI tools process your information as part of delivering legal services under the direction and supervision of our lawyers. Information processed by our AI sub-processors in the course of providing legal services remains subject to privilege.
- We will not voluntarily disclose privileged information to any third party without your express written consent, except as required by law, court order, or the rules of professional conduct.
- If you use the Precision (self-serve) tier without lawyer review, the agreements produced are generated by our platform based on your intake responses. While we treat your information as confidential, the full protections of solicitor-client privilege attach only where a lawyer-client relationship has been established through the Counsel tier.
- Nothing in this Policy limits or waives any privilege, immunity, or protection to which you are entitled under Applicable Privacy Laws or the common law.
9. International transfers of personal information
As the table in Section 7 indicates, several of our service providers store and process personal information outside Canada, primarily in the United States. This includes Anthropic PBC, which processes the AI prompts that contain your intake responses and matter details. We rely on contractual safeguards (data-processing agreements, security commitments, and, where applicable, standard contractual clauses) to ensure that personal information receives a comparable level of protection wherever it is processed.
You should be aware that, while personal information is held outside Canada, it may be subject to the laws of that jurisdiction and may be accessible to courts, law enforcement, and national-security authorities of that jurisdiction. Where Quebec Law 25 applies, we have completed a transfer assessment for each of the sub-processors listed and concluded that the protections are adequate; you may request a summary from our Privacy Officer.
10. Your privacy choices and rights
Subject to Applicable Privacy Laws and to reasonable verification of your identity, you have the following rights with respect to your personal information:
- Access. You may ask us for a copy of the personal information we hold about you and information about how it is used.
- Correction. You may ask us to correct or update information that is inaccurate or incomplete.
- Withdrawal of consent. You may withdraw consent for any optional use of your personal information, including marketing.
- Deletion. You may ask us to delete your account and the personal information associated with it, subject to our right to retain information where required by law, regulatory obligation, or as set out in Section 12.
- Portability (Quebec residents and certain other jurisdictions). You may request your personal information in a structured, commonly used technological format.
- Objection to or review of an automated decision. If a decision affecting you was based exclusively on the automated processing of your personal information, you may request information about the principal factors and parameters involved and ask us to review it (see Section 16).
To exercise any of these rights, contact our Privacy Officer, Brooke Ash, at clientservices@rubylegal.ai. We will respond within the time frame required by Applicable Privacy Laws (generally 30 days under PIPEDA, with extensions where permitted). We may charge a reasonable, cost-recovery fee for unfounded or excessive requests, and we will let you know before we do so.
11. When we share personal information
We do not sell personal information. We share personal information only as follows:
- With our service providers, as listed in Section 7, and only to the extent necessary for them to perform their functions.
- With our lawyers. Your legal matter data is shared with the licensed Canadian lawyer(s) assigned to review your Counsel-tier matter.
- With professional advisors (our own lawyers, accountants, auditors, insurers) bound by duties of confidence.
- In connection with a corporate transaction. If Ruby Law is involved in a financing, merger, acquisition, reorganisation, or sale of all or part of its assets, your personal information may be transferred to the counterparty under appropriate confidentiality protections, and we will notify you in advance where required by Applicable Privacy Laws.
- To comply with law. We may disclose personal information where required by law, court order, subpoena, or other lawful request, or where we believe in good faith that disclosure is necessary to protect our rights, the safety of any person, or to investigate fraud or security incidents.
- With your consent in any other case.
12. Plans, billing, and subscription communications
Ruby Law offers subscription-based access to legal services. By providing payment information, you authorise Ruby Law (and our payment processor) to charge the applicable fees, and to charge any applicable taxes. You can manage your subscription at any time from your account settings.
Service emails relating to your account, billing, security, matter status, and changes to this Policy or our Terms of Service are essential to the Service. While you have an active account, you cannot opt out of these messages.
We retain transactional and billing records for the period required by tax and accounting law (typically six to seven years in Canada).
13. How long we keep personal information
We retain personal information for as long as your account is active and for a reasonable period thereafter to operate the Service, comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements. Specifically:
- Account profile and login records: for the life of the account, plus 24 months after closure.
- Legal matter intake responses, generated agreements, and related work product: for the life of the account, plus a 24-month wind-down period during which you can retrieve your documents. After that, we delete or anonymise the data unless retention is required by law or regulatory obligation.
- Lawyer-client communications (Counsel tier): retained in accordance with the Law Society of Ontario's record-keeping requirements and our professional obligations.
- Billing and tax records: for the period required by tax and accounting law (typically six to seven years).
- Records of breaches of security safeguards: for the 24-month period required by the PIPEDA Breach of Security Safeguards Regulations.
- AI interaction logs (Ask Ruby AI queries and responses): for a maximum of 24 months, then deleted or anonymised.
- Backup snapshots: rotated on a defined schedule and overwritten in the ordinary course.
14. How we protect personal information
We maintain physical, organisational, and technical safeguards proportionate to the sensitivity of the information. Our safeguards include encryption of personal information in transit (TLS 1.2 or higher) and at rest (AES-256), Canadian data centres for primary data storage, access controls and least-privilege permissions for our personnel, multi-factor authentication, secure development practices, code review and dependency monitoring, isolated environments for development and production, and routine vulnerability assessments. We maintain appropriate insurance coverage for cybersecurity incidents. No method of transmission or storage is perfectly secure; while we take security seriously, we cannot guarantee absolute security and you use the Service at your own risk.
15. Cookies and tracking technologies
We use cookies, pixels, local storage, and similar technologies to authenticate users, remember your preferences, secure the Service, measure performance, and (where you opt in) to deliver marketing. You can manage your cookie preferences at any time through the cookie banner or the cookie settings link in the footer of the website. For detailed information about the cookies we use, see our Cookie Policy at rubylegal.ai/cookies.
16. AI, automated decision-making, and training data
Ruby Law uses artificial intelligence extensively to power its legal services. We believe in transparency about how AI is used in your legal matters.
a. How we use AI
Our AI processes your intake responses and matter details to select appropriate agreement types, configure clauses based on your chosen negotiating positions, run compliance checks against eight regulatory modules, and assemble draft agreements. For Counsel-tier matters, a licensed Canadian lawyer reviews and approves the AI-generated output before delivery. For Precision-tier matters, the AI-generated agreement is delivered to you without individual lawyer review.
b. We do not train AI models on your data
We do not use the content of your legal matters, intake responses, agreements, or communications to train, fine-tune, or improve any AI or machine-learning model, whether our own or any third party's. Our commercial API agreement with Anthropic PBC prohibits Anthropic from using your data for model training. Your legal matter data is used solely to deliver the Service to you.
c. Automated decisions
Ruby Law's AI makes recommendations and assembles agreements based on your intake responses, but it does not make decisions about you that produce legal or similarly significant effects without human involvement. Clause selection and compliance checking are decision-support functions; the final agreement is either reviewed by a lawyer (Counsel tier) or accepted by you (Precision tier) before it takes effect. If we introduce processing that qualifies as an automated decision under Quebec Law 25, we will update this Policy, notify affected users, and provide the rights to information, explanation, and review required by Law 25 and other Applicable Privacy Laws.
17. Breach notification
If we determine that a breach of security safeguards involving personal information under our control creates a real risk of significant harm to an individual, we will notify the affected individual and the Office of the Privacy Commissioner of Canada (and, where applicable, the Alberta OIPC and the Commission d'accès à l'information du Québec) as soon as feasible. We will also notify other organisations or government institutions that may be in a position to reduce the risk of harm. Notification will include the information required by the PIPEDA Breach of Security Safeguards Regulations and equivalent provincial rules.
18. Children and minors
The Ruby Law Service is intended for adults who are obtaining legal services for business purposes. We do not knowingly collect personal information directly from individuals under the age of 16. If you believe we have inadvertently collected personal information about a child, please contact our Privacy Officer and we will take appropriate action.
19. Additional information for Quebec residents
If you reside in Quebec, the following supplemental information applies:
- Our Privacy Officer (responsable de la protection des renseignements personnels) is identified in Section 2 above.
- We have completed transfer impact assessments for the cross-border transfers described in Section 9 and concluded that the personal information will receive adequate protection.
- You have the right to portability of your computerised personal information.
- You may file a complaint with the Commission d'accès à l'information du Québec (cai.gouv.qc.ca) if you are not satisfied with our response.
- French-language services. Une version française de la présente politique est disponible sur demande auprès du responsable de la protection des renseignements personnels.
20. Changes to this policy
We may update this Policy from time to time to reflect changes in our practices, our service providers, our technology, or the law. The 'Last updated' date at the top indicates when it was last revised. If we make a material change, we will provide reasonable advance notice (by email to your account address, an in-app notice, or a banner on the website) and, where required by Applicable Privacy Laws, refresh your consent before the change takes effect. Your continued use of the Service after the effective date of an updated Policy constitutes your acceptance of the changes.
21. How to contact us or make a complaint
If you have a question, request, or complaint about this Policy or how we handle personal information, please contact our Privacy Officer first so we have the opportunity to address it:
Privacy Officer: Brooke Ash
Email: clientservices@rubylegal.ai
We will acknowledge your communication promptly and respond substantively within the time period required by Applicable Privacy Laws. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca), the Alberta OIPC, the BC OIPC, the Commission d'accès à l'information du Québec, or the equivalent regulator in your province of residence.
22. Defined terms, governing law, and severability
Capitalised terms used and not defined in this Policy have the meanings given to them in our Terms of Service. This Policy is governed by the laws of Ontario and the federal laws of Canada applicable in that province, without giving effect to any choice or conflict of laws rules. If any provision of this Policy is held to be invalid, illegal, or unenforceable, the remainder of the Policy will continue in full force and effect, and the invalid provision will be modified to the minimum extent necessary to give effect to the original intent of the parties.
Ruby Law Professional Corporation · rubylegal.ai · clientservices@rubylegal.ai