Privacy Policy
Effective date: September 17, 2026 · Version 1.1 · ClearlyConcise, Inc., 428 20th Street, Santa Monica, California 90402 · privacy@johnmjensen.com
This policy explains what ClearlyConcise, Inc. (“ClearlyConcise,” “we”) collects, how we use it, and the choices you have. It covers two things: our website at clearlyconcise.com (Part A), and the ClearlyConcise Service, the workspace that law firms and their clients use (Part B). We wrote it to be read, not skimmed. If anything here is unclear, write to us and we will answer in plain terms.
Part A — The website, clearlyconcise.com
What the website collects: almost nothing. The website is a set of informational pages. It has no sign-up form, no contact form, no comments, and no account. If you want to reach us, the page offers an email address, and what we receive is whatever you choose to send.
Cookies and tracking. The website sets no cookies. It uses no analytics, no advertising technology, and no tracking pixels. It does not respond to “Do Not Track” signals because it does not track anyone in the first place.
What happens automatically. Two things happen when any web page loads, and we say so here. First, our hosting provider (Hostinger) keeps standard server logs — the network address of the visitor, the browser type, the pages requested and when — for its security and operational purposes and for a limited period, under its own privacy policy. Second, the page’s typefaces are loaded from Google Fonts, so Google’s servers receive the network address of the browser requesting them, under Google’s privacy policy. We do not receive personal information from either of these.
If you email us. We keep your message and our reply in our business email for as long as we need them to respond to you and to keep a record of our correspondence. We do not add you to any mailing list; we do not have one.
Part B — The ClearlyConcise Service
The Service is a private workspace that a law firm and its clients use together on the firm’s legal matters. It is offered to law firms under a written agreement (the ClearlyConcise Platform Agreement), and a person uses it only because a law firm gave them a seat. That shapes everything below.
1. Whose data it is, and our role. The information in the Service belongs to the law firm and its clients. The law firm decides what goes in, who may see it, and when it leaves. ClearlyConcise handles that information only as the firm’s service provider — to run the Service at the direction of the firm’s recorded acts, and for no purpose of our own. We do not sell it, share it for advertising, use it to build profiles, or use it to train any artificial-intelligence model, ours or anyone else’s. If you are a client of a law firm using the Service, your law firm is responsible to you for the information in your matter; ask your law firm first, and it can ask us anything on your behalf.
2. What we collect, and why.
Account information. Your name, your email address, your role (attorney, staff, or client), and for a supervising attorney the state bar number we verify against the bar’s public records. We need these to create your seat, to sign you in, and to know which firm and which matters you belong to. Sign-in is handled by Amazon Cognito, a service of Amazon Web Services.
Sign-in and security records. When you sign in, we record the fact and the time, and whether the second factor of authentication was used. We keep these to protect accounts and to investigate anything suspicious.
The content of the matter. Everything a law firm or its client puts into a matter — a client’s account of what happened, documents, drafts, questions and answers. This is the firm’s and its clients’ information, held for them. Each matter’s content is encrypted under that matter’s own keys, and it can be read only by the people the firm has recorded as members of that matter. There is no fallback access: not for our personnel, not for anyone.
The record of acts. The Service keeps a trail of who did what and when — who approved a delivery to a client, who exported a file, who changed a designation. This trail is part of the firm’s own record. It records acts, not the content of what was acted on.
Operational logs. The Service writes logs to run and to be repaired — errors, response times, the fact that a request happened. These logs are designed to be content-free: they do not carry the text of any matter.
3. Artificial intelligence. Parts of the Service use artificial-intelligence models to organize and explain a matter’s information for the attorney’s review. Those models run inside Amazon Web Services, through its Amazon Bedrock service, under a configuration in which the content sent to the model is not retained after it is processed, subject only to the exception Amazon documents for the automated detection of child sexual abuse material. The company that makes the models receives none of the firm’s content from us. No content is used to train any model.
4. Who else touches the data. Amazon Web Services hosts the Service, its database, its files and its models, in the United States, and is the only outside company that processes the firm’s content for us. We will tell a firm at least fifteen days before we add or change that. Our hosting, email and security-software providers see our own business information, not the content of any matter.
5. Where it is kept, and for how long. The Service runs in Amazon Web Services data centers in the United States. A firm’s content stays in the Service for as long as the firm keeps its account and the matter open. A firm may export a matter’s complete file at any time. When a firm closes a matter and directs deletion, the matter’s content is destroyed by destroying the keys that encrypt it, and that act is recorded; backup copies made before the deletion, including backup copies of the keys, are held in an isolated vault that no one, including us, can alter or delete early, and they expire within thirty-five days. Until they expire, the deleted content could be recovered only by a deliberate restoration from that vault, which we do not perform for a deleted matter except at the firm's written direction or as the law requires. After they expire, the content is permanently unreadable. If a firm ends its agreement with us, export stays available for thirty days and then its content is deleted the same way, except for what the law requires us to keep and the minimum record of the deletion itself. Account information is kept while the seat exists and for a short period afterward to answer questions about it.
6. Cookies in the Service. The Service sets one cookie to keep you signed in. It is marked so that scripts on the page cannot read it, it travels only over encrypted connections, and it ends when you sign out or when it expires. During sign-in, a few short-lived cookies carry the sign-in handshake and are deleted when it completes. The sign-in service, Amazon Cognito, sets its own cookies on its own address for the same purpose. There are no analytics, advertising or tracking cookies in the Service, and the Service does not respond to “Do Not Track” signals because it does not track.
7. Security. We describe the Service’s security controls in a written Operating Description that every firm using the Service receives, and we operate the controls it marks as live. In summary: encryption of every matter under its own keys; access decided by the database against the identity of the person asking, on every read and write; a second factor required on every sign-in; a recorded trail of consequential acts; and independent review of the design by outside security firms. No system is perfectly secure. If we confirm that someone gained unauthorized access to a firm’s content, we will tell that firm without undue delay, with the facts we have, and the firm will tell its clients as its duties require.
8. Legal requests. If anyone outside the firm demands the firm’s information from us, we will tell the firm promptly where the law allows, we will assert the firm’s designations of privilege and protection rather than waive them, and we will produce nothing without legal compulsion or the firm’s written direction.
9. Children. The Service is for adults acting in legal matters. A law firm may not give a seat to a person under eighteen; if a minor is a party to a matter, the adult responsible for the minor acts in the Service.
10. Your choices and rights. You may see and correct your account information by asking us or your firm. For the content of a matter, ask your law firm; it controls that content and can export or delete it as its duties allow, and we will act on the firm’s direction. California residents have rights under California privacy law to know what personal information a business holds about them, to have it corrected or deleted, and not to be discriminated against for asking. ClearlyConcise is currently below the thresholds at which the California Consumer Privacy Act applies to a business, and we honor these requests anyway: write to the address at the top of this policy, tell us who you are and what you want, and we will respond within forty-five days. We do not sell or share personal information, so there is nothing to opt out of. We do not disclose personal information to third parties for their direct marketing, so there is nothing to request under California’s “Shine the Light” law.
11. Changes to this policy. When we change this policy we will post the new version here with its effective date and version number. If a change reduces what we promise about a firm’s content, we will tell each firm’s supervising attorney at least fifteen days before it takes effect, as the Platform Agreement provides, and the earlier version governs until then.
12. Contact. ClearlyConcise, Inc., 428 20th Street, Santa Monica, California 90402 · privacy@johnmjensen.com. John M. Jensen, Chief Executive Officer, is responsible for this policy.
Version history. 1.1 (September 17, 2026) corrects Section 5: version 1.0 said backup copies became unreadable at the moment of deletion; they remain recoverable by a deliberate restoration for up to thirty-five days and are permanently unreadable after that. No firm had an account when 1.1 took effect, so no notice under Section 11 was owed. 1.0 (September 16, 2026) was the first version.