Privacy Notice
Last updated 2026
Who we are
co & co operates The Advocate and is the data controller for the personal data described here — meaning we decide why and how it is processed.
What we collect, and why
- Account data — email address and login credentials. Used to create and secure your account. Legal basis: performance of our contract with you.
- Content you write — decisions, predictions, confidence values, check-in answers and the objections generated from them. Used to provide the service and your calibration record. Legal basis: performance of our contract.
- Usage and technical data — case counts, timestamps, device and browser information, IP address, and error logs. Used for security, fraud prevention, abuse limits and improving the product. Legal basis: our legitimate interests in running a secure, working service.
- Support messages — anything you send us. Used to answer you. Legal basis: legitimate interests.
- Marketing email — only if you opt in. Legal basis: consent, withdrawable at any time.
Who we share it with
- Service providers / subprocessors — hosting, database and authentication infrastructure, and the AI model provider that generates objections from the text you submit.
- Paddle, our merchant of record, for the sale of subscriptions, subscription management, payments, tax compliance and invoicing.
- Professional advisers — legal and accounting, where necessary.
- Authorities — where we are required to by law.
We do not sell personal data.
International transfers
Our providers may process data outside the UK/EEA. Where that happens we rely on adequacy decisions or Standard Contractual Clauses as appropriate safeguards.
Retention
Account and case data is kept while your account is open and for up to 30 days after deletion, after which it is deleted or anonymised. Billing records are kept as long as tax and accounting law requires.
Your rights
You may request access, rectification, erasure, restriction, portability, or object to processing, and withdraw consent at any time. We respond within one month. If you are in the UK/EEA you may also complain to your supervisory authority.
Security
We use appropriate technical and organisational measures, including encryption in transit, access controls, and row-level database rules so one account cannot read another's cases.
Cookies and local storage
We use essential storage only: a session token to keep you signed in, and local browser storage for a working copy of your casefile and interface preferences. No advertising or third-party tracking cookies are set. Clearing your browser storage signs you out.