Privacy Policy
Effective date: August 9, 2026
This Privacy Policy explains how Innolope LLC, a Delaware limited liability company with its registered address at Ste A, 8 The Green, Dover, DE, Kent, US, 19901 ("Innolope," "we," "us," or "our"), collects, uses, discloses, and protects personal information in connection with the Medi8 platform, including our website, applications, and related services (collectively, the "Service"). Medi8 is a platform for AI-facilitated resolution of business disputes, which means the information you entrust to it is often sensitive; this Policy is written to be read in full, and we encourage you to do so before participating in a case. By using the Service, you acknowledge the practices described in this Policy. If you have any questions, you can reach us at [email protected].
For the purposes of data-protection laws that use these terms, Innolope LLC is the controller of personal information processed through the Service, except where we process information strictly on the documented instructions of another party, in which case we act as a processor or service provider.
1. Information We Collect
We collect account information when you register or sign in, including your name, email address, and the authentication identifiers provided by our sign-in provider. If you are invited to a case, the party who invited you provides us with your name and email address so that we can deliver the invitation and associate you with the case when you join. Where a settlement agreement is to be executed, we collect the full legal name you provide for signature purposes.
We collect case content that you and the other party submit in the course of a resolution process. This includes your private intake interview, your messages in private sessions with the AI facilitator, messages in the joint session, positions and interests you confirm, releases you approve, opening statements, proposed and agreed settlement terms, any advisory determination issued at the parties' joint request, and executed settlement documents. If you use voice input, we process the audio you record for the purpose of transcribing it into text, and the resulting transcript becomes part of your case content. Case content frequently contains information about businesses, finances, contracts, and other individuals; you are responsible for ensuring that you are entitled to share the information you submit.
We collect payment records when you pay a case fee. Payments are processed by our payment provider, Creem, which acts as merchant of record; we receive and store records of the transaction, such as the amount, its status, and provider-generated identifiers, but we never receive or store your full payment card number.
We collect signature and audit records when consequential actions occur in a case. When you sign a settlement document, we record your typed legal name, your consent to transact electronically, a cryptographic hash of the exact document you signed, the time of signing, your IP address, and your browser's user-agent string; this record exists to make the executed agreement verifiable. More generally, the Service maintains an append-only audit log of significant case events, such as the approval of a release, a change of case phase, a payment, or a signature.
Finally, we collect technical information automatically when you use the Service, including log data such as IP addresses, timestamps, request paths, and device and browser characteristics, together with error and performance diagnostics. We use this information to operate, secure, and debug the Service.
2. How We Use Information
We use personal information to provide the Service: to create and manage accounts and cases, to deliver invitations, to run the intake, private-session, joint-session, drafting, and signing flows, to process payments through our payment provider, to generate the documents the parties request, and to make executed settlements available to both parties. We also use information to secure the Service, including enforcing access controls between the parties to a case, detecting and preventing fraud and abuse, and maintaining the audit records described above; to comply with legal obligations; to respond to your requests and provide support when you contact us at [email protected]; and to analyze and improve the reliability and quality of the Service using technical and diagnostic data.
Where the law of your jurisdiction requires a legal basis for processing, we rely on the performance of our contract with you for the core operation of the Service; on our legitimate interests in securing, improving, and supporting the Service, balanced against your rights; on compliance with legal obligations where processing is required by law; and on your consent where we expressly ask for it, such as when both parties request an advisory determination that will consider their confirmed intake submissions.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not send marketing communications to case participants without their consent.
3. How Case Content Is Scoped Between the Parties
The defining privacy feature of the Service is the separation between each party's private content and the shared record. Your private intake interview and your private sessions with the AI facilitator are stored in threads that are accessible only to your account; access control is enforced at the database-query level, so requests made by the other party simply cannot return your private threads. Content moves from your private sessions to the other party only through a release that you explicitly approve, and only the exact approved text crosses. The joint session, approved releases, approved opening statements, settlement terms, settlement documents, and, where jointly requested, advisory determinations form the shared record visible to both parties.
You should understand two limits of this design. First, the other party is a recipient of everything in the shared record, and once information has been shared with them we cannot un-share it or control their further use of it outside the Service; the parties' mutual confidentiality obligations are set out in the Terms of Service. Second, because the process is not conducted by a human mediator, communications made through the Service may not benefit from mediation privilege or similar evidentiary protections in your jurisdiction, and could be subject to compelled disclosure in legal proceedings notwithstanding contractual confidentiality.
4. Artificial-Intelligence Processing
The facilitation, summarization, transcription, drafting, and advisory-determination features of the Service are provided using large language models and speech services, currently Google's Gemini models accessed through the Google AI Studio API. Case content is transmitted to the AI provider to generate these outputs. Prompts are assembled so that content from one party's private sessions is never included in generations that are shown to the other party; the other party's contributions enter a generation only through the shared record, including releases that the contributing party approved. Advisory determinations are generated only when both parties have requested one, and they draw on the formal record described in the Terms of Service rather than on private-session conversations. We do not use your case content to train artificial-intelligence models, and we have configured our use of AI providers with the aim that they do not do so either.
5. When We Disclose Information
We disclose personal information to service providers that process it on our behalf and under contractual confidentiality and data-protection obligations. These currently include our cloud hosting and infrastructure providers, our database provider, our authentication provider, our AI provider as described above, our payment provider, and our error-monitoring provider. We disclose the relevant parts of the shared record to the other party to your case, which is the purpose of the Service. We may disclose information if we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request, or is necessary to protect the rights, property, or safety of Innolope, our users, or the public; where legally permitted, we will attempt to notify affected users of compelled disclosures of case content. Finally, if Innolope is involved in a merger, acquisition, financing, or sale of all or part of its business, personal information may be transferred as part of that transaction, subject to this Policy or to protections no less protective in substance.
6. Data Retention and Deletion
We retain case content while a case is open and for ninety days after it reaches a closed state, so that both parties have a reasonable window to download the shared record and any executed settlement. After that period, private-session content, including intake interviews and private caucus conversations, is scheduled for deletion. Executed settlement documents, their signature certificates, and the case audit log are retained for as long as either party maintains an account, because they constitute the record of a signed contract and of the process that produced it; the parties may also retain their own downloaded copies indefinitely. Account information is retained for as long as your account exists. Payment records are retained as required for tax, accounting, and fraud-prevention purposes. Technical logs and diagnostics are retained for shorter operational periods.
You may request deletion of your account and associated personal information at any time by contacting [email protected]. We will honor such requests subject to narrow exceptions: we may retain executed settlement documents, signature records, and audit entries in which you appear, because the other party has a legitimate interest in preserving the record of an executed agreement, and we may retain information we are legally required to keep or that is reasonably necessary to establish or defend legal claims. Where full deletion is not possible for these reasons, we will restrict the retained information to what the exception requires.
7. Security
We take the security of case content seriously. Information is encrypted in transit using TLS and encrypted at rest by our storage providers. Access to case content is scoped per party at the query level as described in Section 3, and consequential actions are recorded in an append-only audit log. Settlement documents are bound to cryptographic hashes so that any alteration after signing is detectable. Access to production systems is restricted and monitored. No system can be guaranteed absolutely secure, and you should use a strong, unique password for your sign-in method; if we learn of a breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law.
8. Your Rights and Choices
Depending on where you live, you may have rights under data-protection law with respect to your personal information, which may include the right to access the information we hold about you, to receive a copy of it in a portable format, to correct inaccurate information, to request deletion, to restrict or object to certain processing, and to withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal. You may exercise these rights by emailing [email protected]; we will verify your identity before acting on a request and will respond within the time required by applicable law. Please note that rights requests concerning case content are subject to the shared-record considerations described in Section 6: we cannot delete or alter the other party's copy of information that was validly shared with them, and executed agreements are retained as described above. If you are in the European Economic Area, the United Kingdom, or another jurisdiction with a supervisory authority, you also have the right to lodge a complaint with that authority, although we would welcome the chance to address your concern first.
If you are a California resident, the rights described above correspond to your rights to know, access, correct, and delete personal information under the California Consumer Privacy Act, as amended. We do not sell or share personal information as those terms are defined in that Act, and we do not use or disclose sensitive personal information for purposes other than those permitted by it. We will not discriminate against you for exercising your privacy rights.
9. International Data Transfers
We are based in the United States, and the Service is operated from the United States using service providers that may store or process information in the United States and other countries. If you use the Service from outside the United States, you understand that your information will be transferred to and processed in jurisdictions whose data-protection laws may differ from those of your home jurisdiction. Where required by applicable law, we rely on appropriate safeguards for such transfers, such as standard contractual clauses with our service providers.
10. Children
The Service is intended for business use by adults. It is not directed to children, and we do not knowingly collect personal information from anyone under the age of eighteen. If you believe a child has provided personal information through the Service, please contact us at [email protected] and we will delete it.
11. Cookies and Similar Technologies
The Service uses cookies and similar technologies that are necessary for it to function, such as maintaining your authenticated session and remembering essential preferences. We do not use third-party advertising cookies. Your browser may allow you to block or delete cookies, but blocking essential cookies may prevent the Service from working.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Service, our practices, or applicable law. If we make material changes, we will provide notice through the Service or by email to the address associated with your account before the changes take effect. The effective date at the top of this Policy indicates when it was last revised, and your continued use of the Service after the effective date of an updated Policy constitutes acknowledgment of it.
13. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or to your personal information, contact us at [email protected], or by mail at Innolope LLC, Ste A, 8 The Green, Dover, DE, Kent, US, 19901.