Privacy Notice
Version 1. Effective .
Permanent address of version 1: https://toposphora.com/legal/privacy-v1.html
1. Who we are and what this notice covers
1.1 Toposphora LLC is a Mississippi limited liability company. Our mailing address is 1220 Northside Dr., Ste 170, PMB #176, Jackson, MS 39211. “We”, “us” and “our” mean Toposphora LLC. “You” means our customer, including each person who uses the customer’s account. Section 13.2 speaks to other people.
1.2 This notice covers our website at toposphora.com, the Toposphora app at app.toposphora.com, our iOS app for iPhone, our add-on for Gmail, our add-in for Outlook, and email sent to our addresses. Together these are the Service.
1.3 This notice applies to all three practice profiles: expert witness, attorney, and Toposphora Core. A workspace is the private area of the Service that holds one customer’s records.
1.4 Our Terms of Service govern use of the Service. Our Business Associate Agreement applies to customers who have one. Our Security page describes how we protect information.
2. Our two roles
2.1 We decide how we use account information, subscription and payment references, records of Terms acceptance, technical and log data, information from our website, and messages you send us.
2.2 We process workspace content for our customer. Workspace content is what a customer and its users put into a workspace or receive there. Our Terms call it “your content”. The customer decides what to store, whom to share it with, and how long to keep it. We handle workspace content only to provide the Service to that customer, under our Terms and any Business Associate Agreement in effect.
2.3 Workspace content often names other people, such as clients, attorneys, witnesses, patients and correspondents. If you are one of them, the customer that holds the workspace is the right contact for your questions. Section 13.2 explains what we do if you contact us.
3. Information we collect
3.1 Account and profile. We collect the name and email address of the account holder, the person whose sign-in opens the customer’s workspace. We also keep the practice profile, business details, settings, and documents added to the profile. Amazon Web Services keeps the password for sign-in. We do not store it.
3.2 Subscription, payments and the AI Wallet. Stripe processes payments for the subscription, the Business add-on (offered on Toposphora Core), and top-ups of the AI Wallet, the prepaid balance that pays for AI features. Card numbers go to Stripe and never pass through Toposphora. We keep Stripe’s references for your subscription and payments, with the plan, billing status and dates. We keep a record of each AI Wallet top-up and charge, with usage in tokens.
3.3 Workspace content. This includes files, contacts, leads, matters and cases, calendar entries, tasks, notes, time entries, invoices, agreements, email and attachments, and AI results you save. It can include health information, such as medical records in a case file. It nearly always includes information about people other than the account holder. It can include files that others upload through a share link the customer sends them.
3.4 Email that reaches a workspace. Each workspace has an intake address. Email sent or forwarded to it reaches Toposphora with its sender, recipients, subject, text and attachments. When a message passes Toposphora’s sender checks, Toposphora saves it on the contact of the other person in the exchange, and creates that contact if there is none. Other messages wait for you to decide where they go. You can also file the message you have open from the Outlook add-in or the Gmail add-on (section 8). The Outlook add-in reads the open message’s sender, recipients and subject to show the matching contact. When you file it, it sends the whole message and its attachments.
3.5 AI and text extraction. When an AI feature runs, or Toposphora reads the text of a scanned document, we process the document text, your instructions and the results. We keep the text read from your documents, the results you save, and a record of each AI job and its token usage.
3.6 Signup, invitations and activation. To start a trial, you give your name and email address. We then create a customer record at Stripe. If we invite you, we use your name and email address to send the invitation and activation email.
3.7 Website contact form. The form asks for your email address. You can add a phone number and a message. We send your message to our support mailbox by email. It creates no workspace record.
3.8 Technical and log data. Our servers record technical data: IP address, browser and device type, the address requested, the time, and errors. Inside a workspace, we record file activity, such as uploads and downloads, with the time and IP address. We use this data to run and secure the Service.
3.9 The iOS app. The iOS app is for existing accounts. For its time, billing and calendar features it collects the same information as the web app. It keeps your sign-in in the iPhone Keychain. To work offline, it keeps running timers, confirmed time not yet uploaded, and a copy of your account details on the phone. Confirmed time stays there until it uploads or you remove it, even after you sign out. Optional calendar reminders stay on the phone and show generic text. The app asks for camera or photo access only if you choose to attach a photo. It collects no location, contacts, advertising identifier or usage analytics.
3.10 Records of your agreement. When you accept our Terms, we record the email address you used, the document version and its web address, the time, where you accepted (for example, Stripe Checkout or the app), and any Stripe Checkout reference.
3.11 Messages you send us. When you write to support@toposphora.com or legal@toposphora.com, or use the app’s support form, we keep your message and our reply.
4. How we use information
4.1 We use information to:
- create and secure accounts;
- provide the workspace and its features, including email intake, AI features and malware scanning;
- bill the subscription, the Business add-on and AI Wallet use, and keep financial records;
- send email about the account and the Service, such as activation, trial, billing and security notices;
- answer support requests and contact-form messages;
- prevent abuse, investigate security problems, and keep the Service working;
- record acceptance of our Terms, meet legal obligations, and enforce our Terms.
4.2 We use workspace content only to provide the Service to the customer that holds it, to keep it secure, or when the law requires it.
4.3 Our staff do not open workspace content unless you ask for help with specific content and agree, we must investigate a security problem or abuse, or the law requires it. Our billing and support tools show the file name next to each AI Wallet charge. They do not show the file.
5. Who receives information
5.1 Companies that do specific work for us. Each handles information under its own terms. Some, such as Stripe, also use it for their own legal and fraud-prevention duties.
- Amazon Web Services hosts the Service in the United States, including storage, sign-in, inbound email, malware scanning, text extraction and logs. AI features run on Amazon Bedrock, an Amazon Web Services service.
- Stripe processes payments for the subscription, the Business add-on and the AI Wallet. If you connect your own Stripe account to send invoices, Stripe also sends your invoices and payment links to your clients and processes their payments, under the Stripe Privacy Policy.
- SignWell delivers the agreements you send for signature and collects the signatures. It also receives your IP address and browser details when the app loads its script (section 9.2).
- Resend delivers the email the Service sends, including email you write to your contacts and messages you send us through our forms.
- Cloudflare runs the bot check on our public forms and the signup page. It receives your IP address and browser signals. Cloudflare states that the check does not read what you type in the form. See Cloudflare’s privacy terms for the check.
- Google runs the platform for the Gmail add-on (section 8) and delivers our website’s fonts to visitors (section 9).
No other company receives workspace content from us, except as sections 5.2, 5.3 and 5.5 describe.
5.2 People you choose. The Service sends information where you direct it: to the recipients of your email, people who open a share link, signers, invoice recipients, and the calendar app that reads your calendar feed. The recipient’s copy is outside our control.
5.3 Legal and safety reasons. We disclose information when the law requires it, such as in answer to a valid subpoena or court order. If the law allows, we tell the affected customer first. We may also disclose account, billing and technical information to protect people, the Service or our rights, or to investigate fraud or abuse.
5.4 Our advisers. Our lawyers, accountants and insurers may receive account, billing and technical information to advise us. They must keep it confidential.
5.5 A sale of the business. If Toposphora LLC merges or is sold, information may pass to the new owner, which must handle it as this notice describes. Google user data passes only with your explicit consent.
6. What we do not do
- We do not sell personal information.
- We do not share personal information for cross-context behavioral advertising.
- We do not show advertising in the Service.
- Our website, apps and add-ins contain no advertising or analytics trackers.
- We do not use workspace content to train AI models.
- We do not read your mailbox.
Because we use no advertising trackers, a Do Not Track or Global Privacy Control signal has nothing to switch off.
7. AI processing
7.1 AI features run on Amazon Bedrock in our own Amazon Web Services account. Reading text from scanned documents also runs on Amazon Web Services.
7.2 Most AI features run only when you start them, and read only the files you choose. Two run on their own when your AI Wallet has funds. When you upload a file with no preset type, Toposphora sends the file name to Amazon Bedrock to label the document’s type. When email arrives at an intake address, Toposphora writes a short summary and suggests details, such as contact or inquiry fields, for you to review. Nothing the email step suggests is applied until you approve it. Filing from the Gmail add-on or the Outlook add-in runs no AI.
7.3 AI use is paid from your prepaid AI Wallet. The AI Wallet record shows each charge in dollars, and usage appears in tokens.
7.4 The help assistant answers questions about using Toposphora. It sends your question, the recent conversation, our User Guide and your practice profile to Amazon Bedrock. We do not store your questions or its answers. We keep a daily count of answers.
7.5 Amazon states that content sent to Amazon Bedrock is not used to improve its base models, is not shared with model providers, and is not stored by default. We keep results in your workspace as section 3.5 describes.
7.6 AI results can be wrong or incomplete. Review them before you rely on them.
8. Google user data and the Gmail add-on
8.1 The Toposphora add-on for Gmail shows a panel beside the message you have open and lets you file that message into your workspace. You choose whether to install it. It asks Google for permission to run in Gmail, to read the message you have open, to add a link to a draft you have open, and to know your Google account and email address. It asks for nothing else.
8.2 What the add-on reads.
- When you open the add-on on a message, it reads that message’s headers: message ID, subject, sender, recipients, copy recipients and date. It uses them to show the other person, find the matching contact, and show whether you filed the message already.
- When you open the add-on while writing a message, it reads the draft’s recipients to offer the matching contact’s links. It cannot read the text of the draft.
- When you select File, it reads the whole message and its attachments, and saves them in your workspace where you chose.
- It reads no other message. It does not search your mailbox or read in the background.
- When you connect, Google gives us your Google account ID and Gmail address. We keep them to recognize your Gmail account. We send a notice of the connection to your Gmail address and to your Toposphora account address.
- We do not keep your Google access token. It is used only for the request that carries it.
8.3 How we use it. We use Google user data only to provide the add-on features you see: to show the panel, to file the messages you choose, and to add a Toposphora link to a draft you opened. The panel shows details from your workspace, such as contact and matter names, which Google displays in Gmail. A filed message becomes workspace content and follows the rules in section 10. If you later run an AI or text-extraction feature on a filed document, it goes to Amazon Web Services for that work.
8.4 What we do not do with Google user data.
- We do not use it for advertising.
- We do not sell it.
- We do not use it to train or improve artificial intelligence or machine learning models.
- We do not transfer it to others, except to the service providers that host and run Toposphora for you, when you ask us to, when needed for security or to investigate abuse, to follow the law, or in a merger or sale of the business with your explicit consent.
- Our staff do not read it unless you ask us to look at specific data and agree, it is needed to investigate abuse or a security problem, or the law requires it. A file name can show next to an AI Wallet charge, as section 4.3 says.
- The add-on does not label, move, delete or send any message.
8.5 Limited Use. Toposphora’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8.6 Your choices. To disconnect Gmail, use Disconnect for the Google account in Toposphora’s Setup. We then delete the stored Google account ID and Gmail address. To remove the add-on’s permission, remove Toposphora from the third-party apps with access in your Google Account settings. Deleting a filed message in Toposphora does not delete it from Gmail. Deleting it in Gmail does not delete the filed copy.
9. Cookies and similar storage
9.1 Our website. Our website’s own code sets no cookies. Your browser loads our fonts from Google Fonts, so Google receives your IP address and browser details. The contact form loads Cloudflare’s bot check when you open it.
9.2 The app. The app keeps your sign-in in your browser’s session storage, which the browser clears when you close the window. The sign-in page, which Amazon Web Services runs for us, sets a cookie for your sign-in session. The app uses your browser’s local storage for preferences and for time you are recording, such as a running timer. Payment pages come from Stripe and the signature editor comes from SignWell, under their own terms. The app also loads a script from SignWell on every page, including the sign-in page and share links, so SignWell receives your IP address and browser details.
9.3 The add-in and the iOS app. The Outlook add-in keeps a sign-in token in its own storage inside Outlook, so you do not have to sign in each time you open it. Section 3.9 describes what the iOS app keeps on the phone.
9.4 We use no cookies or storage for advertising or analytics, so we show no cookie banner.
10. How long we keep information
10.1 General rule. We keep account information and workspace content while the account is open, unless you delete it sooner. We keep other information only while we need it for the purposes in section 4.
10.2 Deleted items and permanent deletion. A file you delete moves to Deleted items, where you can restore it. It stays there until you restore it or delete it permanently. Permanent deletion removes the current file and its record at once. It cannot be undone. Permanent deletion does not remove the records of AI jobs run on the file, including their results and any chat text, or the AI Wallet entries that name it. For some files it also leaves the text read from the file. Account deletion removes all of these (section 10.9).
10.3 Older versions of files. We keep earlier versions of a file for a time after a newer version replaces it or after you delete it permanently. Their removal is scheduled as follows, and it is not instant:
- Matter documents: 90 days.
- Profile and package documents: 15 days.
- Personal workspace files and saved AI replies: no automatic schedule. These older versions are removed when the account is deleted, or sooner if you ask us.
10.4 Temporary copies. Temporary copies made while filing email are scheduled for removal after 35 days. The temporary copy of a file received through an upload link is scheduled for removal after 1 day, once the file is in your matter.
10.5 Email.
- The raw incoming message is deleted once it is processed. Any leftover copy is scheduled for removal after 1 day.
- A message saved on a contact, or filed to a matter or lead, keeps its text until you delete the record.
- A message that waits for your decision and is never filed is deleted after 30 days, with its attachments.
- A message you send stays in the workspace until you delete it. Deleting it does not remove the recipient’s copy.
10.6 Confirmed testimony. On the expert witness profile, a testimony entry you confirm keeps its case name, jurisdiction, dates and parties after you delete the matter or case it came from. It stays until you delete the entry or the account.
10.7 Backups and logs. Database backups are kept for 35 days. Technical logs are kept for a limited time and then expire on a schedule. We keep security audit logs longer. They can hold file names.
10.8 When a subscription or other access ends. The account holder can no longer open the workspace. Signing in shows only a screen to subscribe again. The workspace’s share links and its intake address stop working. We keep the workspace for three months from the end date. You can return by subscribing again during that time. We can extend the time if you ask. After that time we may delete the workspace permanently. Messages that wait for a decision are still deleted after 30 days. During the three months you can still ask for an export or for deletion (section 11).
10.9 Account deletion. When we delete an account, we delete the workspace’s records and files, including earlier versions of the files. We close the sign-in and cancel the subscription at Stripe. Database backups that hold the account age out over 35 days. Copies that already left Toposphora stay where they are, such as email you sent, downloaded files, and the copies Resend, SignWell and Stripe keep under their own terms.
10.10 Records we keep after account deletion.
- Terms acceptance records (section 3.10), with the link to the account removed. We keep each one as long as we may need to show what was agreed, and at least three years, or one year after the account ends if that is later.
- Payment records at Stripe. Stripe keeps its own records under its terms and the law.
- Correspondence with us. We keep support and legal email as long as we need it to answer you and keep our business records.
11. Export and deletion requests
11.1 How to ask. The account holder can ask for a full export or for account deletion from inside the app, or by email to support@toposphora.com. We complete the request.
11.2 Full export. A full export is a copy of the workspace: contacts, matters, email and attachments, sent messages, documents, deleted items, time entries, invoices, calendar entries and the AI Wallet record. It leaves out passwords and sign-in secrets. We deliver it through a download link that expires, and our copy of the export is then removed on a schedule.
11.3 Account deletion. Account deletion cannot be undone, so we confirm the request with the account holder before we delete anything.
11.4 How we verify the request. The sign-in verifies a request made inside the app. We confirm an email request with the account holder at the account’s email address, and we may ask for details only the account holder would know. We never ask for your password. We send an export link only to the account holder’s email address. A person who asks for the account holder needs the account holder’s written permission, which we confirm with the account holder.
12. Security
We encrypt information in transit and at rest, keep each workspace separate in the database, and scan every uploaded file for malware. Our Security page describes these controls. No system is perfectly secure, and if a breach affects your information, we will tell you as the law requires.
13. Your choices and privacy rights
13.1 Account holders. An account holder may ask to see, correct or delete their account information. Email support@toposphora.com. We answer within 45 days. Some records stay, as section 10.10 explains.
13.2 People who are not our customers. You may appear in a workspace, receive a share link, signature request, invoice or email sent through Toposphora, or upload files through a share link. In each case we handle your information for our customer, who is the right contact for your request. If you contact us, we send your request to that customer and tell you that we did.
13.3 State privacy laws. Some U.S. states give their residents more privacy rights. Many of those laws apply only to larger businesses and may not apply to us. We still answer the requests in section 13.1 from every account holder, wherever they live.
13.4 Other choices. You can disconnect the Gmail add-on (section 8.6), sign out of the Outlook add-in or the iOS app, and turn off Toposphora notifications in the iPhone Settings app.
14. Health information and the Business Associate Agreement
14.1 Toposphora signs a Business Associate Agreement with customers who need one. If you are a HIPAA covered entity or business associate, ask for our Business Associate Agreement at legal@toposphora.com before you put protected health information into Toposphora. It takes effect when we confirm it in writing.
14.2 It covers the workspace, its storage and database, inbound email capture, share-link uploads, filing from the Gmail and Outlook add-ins once a message reaches Toposphora, AI features, text extraction, malware scanning, the help assistant and backups.
14.3 It does not cover email you send from Toposphora, e-signature, payments and invoices, what your own email or calendar provider holds, or email you send to Toposphora outside the workspace, such as to our support or legal addresses or through the app’s support form. Do not put protected health information into those, other than what your own providers hold.
14.4 For an account with a Business Associate Agreement, replies sent from Toposphora do not quote the earlier email.
14.5 If the Business Associate Agreement and this notice differ about protected health information, the Business Associate Agreement controls.
15. Children
The Service is a professional tool, not for anyone under 18. We do not knowingly create accounts for children. If we learn that a child has an account, we close it. Workspace content can mention minors, for example in a case file. We handle that content for the customer, as section 2.2 describes.
16. Where we process information
We host the Service on Amazon Web Services in the United States. AI processing on Amazon Bedrock also runs in the United States. Some companies in section 5 may process information in other countries under their own terms. The Service is meant for users in the United States, and we offer the iOS app in the United States only.
17. Changes to this notice
When we change this notice, we publish a new version at a new permanent web address. The current version is always at /privacy.html. This version stays at /legal/privacy-v1.html. If a change is material, we tell account holders by email or in the app before it takes effect.
18. Contact us
- Privacy questions and requests: support@toposphora.com
- Legal notices and Business Associate Agreement requests: legal@toposphora.com
- Mail: Toposphora LLC, 1220 Northside Dr., Ste 170, PMB #176, Jackson, MS 39211