CICERRO

Privacy

Last updated 24 September 2026

CICERRO is a legal-research tool operated by an individual, currently in private testing. It searches the published judgments of the Supreme Court of India and the Calcutta High Court. This page says plainly what it collects and who else sees it.

What we collect

Your account. You sign in with an email address and a password. We store the address; the password is held by our authentication provider as a salted hash and is never visible to us. Access is by invitation.

What you type and upload. The facts you describe, the questions you ask, the matters you create and any documents you attach. Assume that anything you paste here is stored.

Usage records. A timestamped count of the analyses you run, so quotas can be enforced and abuse spotted. No advertising trackers, no third-party analytics, no cookies beyond the one that keeps you signed in.

Where it is stored

In a Supabase Postgres database hosted on AWS in Mumbai (ap-south-1) — your data does not leave India at rest. Rows are scoped to your user id and enforced with row-level security, so one account cannot read another’s matters or documents.

Who processes it

To answer a question, the text of that question — and the passages retrieved for it — is sent to two processors: OpenAI (to convert text into search vectors) and Anthropic (to draft the analysis). Both are used under their commercial API terms, under which submitted content is not used to train their models. These calls leave India.

Nothing is sold, and nothing is shared with anyone else — no advertisers, no data brokers, no other users.

Client confidentiality

This is a research tool in private testing, not a secure client file. If a matter is privileged or sensitive, describe the legal question with the facts anonymised. That is good practice with any cloud tool, and it is our explicit advice here.

Keeping and deleting

Your matters and documents are kept until you delete them or ask us to close your account. Email gauravkguha@gmail.com from your registered address and we will delete your account and everything attached to it within 30 days, and confirm when it is done. You can ask for a copy of your data the same way.

Security and honesty about it

Traffic is encrypted in transit, data is encrypted at rest, access is restricted to the operator, and every request is authenticated. No system is perfect; if data is ever exposed we will tell affected users directly rather than quietly.

Changes and contact

If this policy changes materially, testers are emailed before it takes effect. Questions, complaints or deletion requests: gauravkguha@gmail.com.