Privacy Policy
IntakeIQ, Inc.
1. Introduction
IntakeIQ, Inc. ("we," "our," or "us") provides an AI-powered legal intake platform that helps law firms pre-qualify potential cases. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website at intakeiq.io and our services (collectively, the "Service").
By using IntakeIQ, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
2. Information We Collect
2.1 Information Provided Through Intake Forms
When a potential client completes an intake form, we may collect:
- Full name and contact information (email, phone number)
- Employment details (employer name, job title, dates of employment)
- Description of the legal matter or dispute
- Relevant dates and timelines
- Uploaded documents and supporting files
- Any other information voluntarily provided in the intake form
2.2 Sensitive Personal Information
Depending on the nature of your legal matter, information you provide through intake forms may include categories of data considered "sensitive personal information" under applicable law. This may include, but is not limited to, information revealing racial or ethnic origin, religious beliefs, disability status, sexual orientation, immigration status, or the contents of private communications.
We process sensitive personal information solely for the purpose of evaluating your potential legal case and sharing it with the subscribing law firm. We do not use sensitive personal information for profiling, advertising, or any purpose unrelated to case intake and evaluation.
Under the California Consumer Privacy Act (CCPA/CPRA) and similar state laws, you may have the right to limit the use and disclosure of your sensitive personal information. To exercise this right, please contact us using the information in Section 17.
2.3 Account and Subscription Information
For law firm users and attorneys, we collect:
- Name and professional contact information
- Law firm name and practice area details
- Payment and billing information (processed securely through Stripe)
- Clio practice management integration credentials (via OAuth)
- Scheduling preferences (via Cal.com integration)
2.4 Automatically Collected Information
We automatically collect certain information when you use the Service, including:
- Browser type and device information
- IP address and general location data
- Pages visited and interaction patterns
- Analytics data collected via Google Analytics 4 (GA4) and Google Tag Manager. IP anonymization is enabled by default in GA4. We use these tools to understand aggregate usage patterns. Google acts as a data processor for this information and processes it in accordance with its data processing terms.
3. Legal Basis for Processing
We process your personal information on the following legal bases:
- Consent: When you voluntarily submit an intake form, you consent to the processing of your information for case evaluation purposes. You may withdraw consent at any time by contacting us, though this will not affect the lawfulness of processing prior to withdrawal.
- Contractual Necessity: For subscribing law firms and attorneys, we process account and subscription information as necessary to perform our contractual obligations under the service agreement.
- Legitimate Interests: We process automatically collected information (such as analytics data) based on our legitimate interest in improving and securing the Service, provided these interests are not overridden by your rights and freedoms.
- Legal Obligations: We may process information as necessary to comply with applicable laws, regulations, or legal processes.
4. AI Processing and Third-Party AI Providers
IntakeIQ uses a multi-model consensus scoring system to evaluate and score potential legal cases. Each intake form submission is evaluated by multiple foundation models simultaneously to generate independent assessments. All of this AI processing is performed through a single third-party subprocessor:
- Amazon Web Services (AWS), via AWS Bedrock
4.1 How Your Data Is Handled During AI Processing
Every foundation model we use is hosted and run within AWS Bedrock — Amazon's fully managed AI service — inside Amazon's secure environment. The models currently used for case scoring include Anthropic Claude and Meta Llama, with additional Amazon foundation models used for supporting tasks such as text embeddings. Because these models run inside AWS Bedrock, your data is not transmitted to the model developers (such as Anthropic or Meta); AWS operates the models on our behalf.
- Single subprocessor: Case data is transmitted only to AWS Bedrock. It is not sent to any other AI provider, and it does not leave AWS's environment during processing.
- No retention: AWS Bedrock does not store or retain any input or output data after a request completes.
- No training: Your data is never used to train or improve any foundation model.
- BAA coverage: All AI processing is covered under our Business Associate Agreement (BAA) with AWS.
Your data is transmitted to AWS Bedrock solely for the purpose of generating a case evaluation score and summary.
We regularly review the data handling policies of AWS. If our AI processing arrangements materially change, we will update this section and notify subscribing law firms. The references above were last verified as of the effective date of this Privacy Policy.
5. No Attorney-Client Relationship; Confidentiality
An attorney-client relationship is only formed when a licensed attorney explicitly agrees to represent you, typically through a signed engagement or retainer agreement.
Information submitted through intake forms may not be protected by attorney-client privilege. While we implement technical safeguards to protect the confidentiality of your submissions (including encryption in transit and at rest, access controls, and restricted sharing solely with the subscribing law firm), the transmission of information through the Service does not create a privileged communication.
We strongly recommend that you do not include highly sensitive or privileged information in your intake form submission beyond what is necessary to describe your legal matter in general terms. Detailed privileged communications should be shared directly with your attorney after a formal engagement has been established.
Subscribing law firms are independently responsible for their own ethical obligations regarding confidentiality, conflicts of interest, and the formation of attorney-client relationships.
6. HIPAA Compliance
6.1 Business Associate Agreements (BAAs)
IntakeIQ maintains signed Business Associate Agreements (BAAs) with all service providers that process Protected Health Information:
- Amazon Web Services (AWS) — hosting, database, file storage, email delivery, and all AI processing via AWS Bedrock
- Google — calendar integration via Google Workspace (only for firms that connect Google Calendar)
- Subscribing law firms may request a BAA with IntakeIQ by contacting legal@intakeiq.io
6.2 Technical Safeguards
IntakeIQ implements comprehensive technical safeguards to protect PHI:
- AES-256 encryption at rest for all databases and file storage
- TLS 1.2+ encryption in transit for all data transmissions
- Field-level encryption for sensitive data fields (contact information, medical details)
- Dedicated encrypted storage for medical records with versioning and access logging
- Zero data retention for all AI processing — no case data is used to train models
- Comprehensive audit logging for all PHI access (user identity, timestamp, resource, IP address)
- Role-based access control with multi-tenant data isolation
6.3 Medical Records and PHI
IntakeIQ supports the secure upload and processing of medical records and other PHI for practice areas that require it, including employment law (ADA, FMLA, workers' compensation), personal injury, and related areas. Medical records are stored in dedicated encrypted S3 buckets with AWS CloudTrail audit trails.
6.4 PHI in Communications
Email notifications from IntakeIQ include only client names and practice area categories. Detailed case information, AI analyses, medical details, and financial data are accessible only through the authenticated dashboard and are never included in email communications.
7. How We Use Your Information
We use the information we collect for the following purposes:
- To process and evaluate potential legal cases using AI-powered scoring
- To generate case summaries and qualification assessments for attorneys
- To facilitate communication between potential clients and law firms
- To process payments and manage subscriptions via Stripe
- To integrate with practice management software (Clio) as authorized
- To schedule consultations via Cal.com
- To improve and optimize our Service through analysis of aggregate, de-identified usage patterns and system performance metrics. We do not use identifiable intake form data for product improvement, analytics, benchmarking, or internal model training. Any analysis for service improvement purposes is performed only on anonymized or aggregated data from which individual intake submissions cannot be identified.
- To comply with legal obligations
8. Data Storage and Security
All data is processed and stored on HIPAA-compliant AWS infrastructure in the United States (US-East-1 region). Specific safeguards include:
- Amazon RDS PostgreSQL with AES-256 encryption at rest and SSL/TLS connections
- Amazon S3 with server-side encryption for file storage and medical records
- Amazon CloudFront with TLS 1.2+ for secure content delivery
- AWS Secrets Manager for credential management (no hardcoded secrets)
- AWS CloudTrail for infrastructure-level audit logging
- AWS CloudWatch for real-time monitoring and alerting
While we take reasonable measures to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.
9. Data Breach Notification
In the event of a data breach that compromises your personal information, we will take the following steps:
- We will investigate and contain the breach as promptly as practicable upon discovery.
- We will notify affected subscribing law firms without unreasonable delay, and in no event later than 72 hours after confirming a breach that is reasonably likely to have compromised personal information.
- We will notify affected individuals as required by applicable state and federal law, within the timeframes mandated by each applicable jurisdiction.
- Notifications will include, to the extent known: a description of the nature of the breach, the categories of information affected, the approximate date of the breach, the steps we are taking in response, and contact information for further inquiries.
- We will cooperate with applicable regulatory authorities and law enforcement as required by law.
We maintain an incident response plan and conduct periodic security assessments to minimize the risk of unauthorized access to your data.
10. Data Sharing and Disclosure
We do not sell your personal information. We do not "share" your personal information for cross-context behavioral advertising as defined under the California Consumer Privacy Act (CCPA/CPRA). We may share your information in the following circumstances:
- With Subscribing Law Firms: Intake form submissions and AI-generated case evaluations are shared with the law firm whose intake form you completed.
- With AI Providers: As described in Section 4, your intake data is processed by foundation models hosted within AWS Bedrock (Amazon Web Services) for case evaluation purposes. All AI processing is covered by our signed Business Associate Agreement with AWS, and the data is not retained or used for training.
- With Service Providers: We use third-party service providers including Stripe (payments), Google Calendar (scheduling), and Clio (practice management) to operate the Service. All service providers that process PHI have signed Business Associate Agreements or equivalent data processing agreements. These providers only receive the data necessary to perform their specific functions.
- As Required by Law: We may disclose your information if required by law, regulation, legal process, or governmental request.
10.1 International Data Transfers
Your information may be transferred to and processed in the United States and other countries where our AI providers and service providers maintain servers. These countries may have data protection laws that differ from the laws of your jurisdiction. By using the Service, you consent to the transfer of your information to the United States and other jurisdictions as described in this Policy. Where required by applicable law (such as the EU General Data Protection Regulation), we will ensure that appropriate safeguards are in place for international transfers, such as Standard Contractual Clauses approved by the European Commission.
11. Data Retention
Intake form data and associated case evaluations are retained for as long as the subscribing law firm maintains an active account or as required by applicable law. The following specific retention rules apply:
- Active accounts: Intake data is retained for the duration of the law firm's active subscription.
- Rejected or unactioned intakes: If a subscribing law firm has not acted on an intake submission within 24 months, we will automatically delete the associated intake data unless the law firm has flagged it for retention.
- Account termination: Upon account termination, all associated intake data will be deleted within 90 days unless retention is required by applicable law or the law firm requests earlier deletion.
- Individual deletion requests: Individuals who submitted intake forms may request deletion of their data at any time by contacting us. We will process such requests within 45 days, subject to any legal obligations requiring continued retention.
Law firms may request deletion of intake records through their account dashboard or by contacting us directly.
12. Data Processing Agreements
IntakeIQ offers a standard Data Processing Agreement (DPA) to subscribing law firms. The DPA governs IntakeIQ's processing of personal data on behalf of the law firm and addresses:
- The scope, nature, and purpose of data processing
- Obligations of both parties regarding data protection
- Sub-processor management and notification procedures
- Data breach notification commitments
- Audit rights and cooperation with regulatory authorities
- Data return and deletion upon termination
Law firms that require a DPA for compliance with their own ethical obligations, bar association rules, or applicable data protection laws may request one by contacting us at privacy@intakeiq.io. We encourage all subscribing law firms to execute a DPA with IntakeIQ.
13. Your Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information. Below we describe rights available under applicable law.
13.1 General Rights
All users may have the following rights:
- The right to access the personal information we hold about you
- The right to request correction of inaccurate information
- The right to request deletion of your personal information
- The right to opt out of certain data processing activities
- The right to data portability
13.2 California Residents (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA):
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purposes for collection, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions permitted by law.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt Out of Sale/Sharing: We do not sell your personal information or share it for cross-context behavioral advertising. Therefore, there is no need to opt out of such activities.
- Right to Limit Use of Sensitive Personal Information: You may request that we limit our use of sensitive personal information to only what is necessary to perform the Service.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
To submit a request, please contact us at the information provided in Section 17. We will respond to verified requests within 45 days. If we need additional time, we will notify you of the extension and the reason. You may designate an authorized agent to make a request on your behalf. If you are not satisfied with our response, you have the right to appeal by contacting us with a description of your concern, and we will respond within 45 days of receiving your appeal.
13.3 Other U.S. State Privacy Laws
Residents of other states with comprehensive privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana) may have similar rights to access, correct, delete, and opt out of certain processing. Please contact us using the information in Section 17 to exercise your rights. We will respond in accordance with the timelines and procedures required by your state's applicable law.
13.4 European Economic Area, UK, and Other International Users
If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction with applicable data protection laws, you may have additional rights including the right to lodge a complaint with your local data protection authority. Please contact us to exercise your rights, and we will respond in accordance with applicable law.
To exercise any of these rights, please contact us at the information provided in Section 17.
15. Third-Party Links and Integrations
The Service may contain links to third-party websites or integrate with third-party services (such as Clio, Cal.com, and Stripe). We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you interact with through IntakeIQ.
16. Children's Privacy
IntakeIQ is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. Intake forms include an age affirmation requiring users to confirm they are 18 years of age or older before submitting. If you believe a child under the age of 13 has provided us with personal information, please contact us immediately and we will promptly investigate and delete such information in compliance with the Children's Online Privacy Protection Act (COPPA). For individuals between 13 and 17, we will delete their information upon request from a parent or guardian.
17. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
IntakeIQ, Inc.
Privacy Inquiries: privacy@intakeiq.io
General Support: support@intakeiq.io
Website: https://intakeiq.io
For CCPA/CPRA requests specifically, you may also submit a request through our website at intakeiq.io/privacy or contact us via email. We will verify your identity before processing any rights request.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by:
- Posting the updated policy on our website with a revised effective date
- Sending email notification to subscribing law firms for material changes
- Displaying a prominent notice within the Service dashboard for at least 30 days following material changes
Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.
19. Frequently Asked Questions
Is IntakeIQ HIPAA compliant?
Yes. IntakeIQ maintains HIPAA compliance through signed Business Associate Agreements (BAAs) with all service providers, AES-256 encryption at rest, TLS encryption in transit, field-level encryption for PHI, comprehensive audit logging, and zero data retention for AI processing.
Can I upload medical records?
Yes. Medical records are stored in dedicated encrypted storage with versioning and access logging. All access to medical records is audited and tracked.
Is my data used to train AI models?
No. All AI processing runs within AWS Bedrock, which is configured for zero data retention and does not use your data to train or improve any model. Your case data is never used to train or improve any AI model.
Where is my data stored?
All data is stored on AWS infrastructure in the United States (US-East-1 region). We do not transfer data outside the United States without prior written consent.
Can I get a Business Associate Agreement (BAA)?
Yes. Subscribing law firms may request a BAA by contacting legal@intakeiq.io.
How do I request deletion of my data?
You may request deletion of your data at any time by contacting privacy@intakeiq.io. We will process deletion requests within 45 days.
© 2026 IntakeIQ, Inc. All rights reserved.