Habeas Tech
Back to Home

Privacy Policy

Last updated: August 15, 2026

1. Overview

Habeas Tech ("we," "our," or "us") provides specialized software tools for Wisconsin legal professionals at habeas.tech. We prioritize attorney-client privilege, data security, and transparent privacy practices.

2. Clio OAuth Data & On-Demand Fetching

When you connect your Clio Manage account to Habeas Tech via OAuth 2.0:

  • We store encrypted OAuth access and refresh tokens in our secure database to communicate with Clio on your behalf.
  • We do not store your client names, matter descriptions, or contact records. Matter and activity data is fetched from Clio on demand and validated in memory; we keep no database copy of it.
  • Time entries pulled for the SPD CSV Generator are processed in memory. The generated invoice file is then retained under Section 3 below.

3. Generated Invoices & Retention

When you generate an SPD invoice, the resulting CSV is stored so you can download it again. It contains what SPD requires: dates, activity categories, hours, and your activity descriptions.

  • The invoice file is deleted 30 days after it is generated. The file itself, not just the link. This runs automatically; there is nothing to opt out of and nothing to clean up.
  • You can delete any invoice sooner from the Files page in your dashboard.
  • The record that an invoice was generated is deleted after 60 days. This includes the notification and the job history.
  • A note on matter numbers. We do not ask for or store client names. But the invoice is named using the matter number you set in Clio, and many attorneys use a convention that includes a client's name. Where that is true, that name is stored with the record and deleted with it — within 30 days for the file, 60 for the record.
  • Notification emails include the matter number so you can tell which invoice is ready. Those emails are delivered through Resend, our email provider.
  • Each invoice is also filed to its matter in Clio at generation time. That copy is in your own system, under your own retention policy, and we neither manage nor delete it.

4. Information We Collect

We collect basic user account information necessary to provide the service:

  • Name and email address for account authentication and subscription management.
  • Hashed password credentials (stored using industry-standard bcrypt hashing).
  • Stripe subscription IDs and customer references for active paid tool packages.

5. Security & Encryption

All data in transit is encrypted using TLS 1.3. Clio OAuth refresh tokens are encrypted at rest using AES-256-CBC encryption algorithms. Our infrastructure runs on Google Cloud Platform with restricted secret management.

6. Contact Us

If you have questions regarding this Privacy Policy or data handling practices, please contact us at support@habeas.tech.