Privacy Policy

Version: 2026-09-05

1. Introduction

Neural Motion Ltd ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal information when you use Common Laws.ai and Common Laws (together, "the Service") — our AI-powered legal research service for Hong Kong law.

The Service includes our websites and applications that provide Common Laws functionality, including the Common Laws Microsoft Word / Office add-in (Common Laws for Word). This Privacy Policy applies to the Service overall, not only to our website.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your name, email address, and organisation (if provided). For Student plan applicants (including law students, trainee solicitors and barrister pupils), we also collect a copy of your eligibility ID for verification purposes.

2.2 Usage Data

We collect information about how you use the Service, including search queries, pages visited, features used in our web application and Word add-in, and related product analytics. This data helps us improve the Service and provide a better experience.

2.3 Payment Information

Payment processing is handled by Stripe. We do not store your full credit card number or payment details on our servers. Stripe's privacy policy governs the handling of your payment information.

2.4 Uploaded Documents (Research)

When you attach a document to a research conversation, we collect the file (PDF, DOCX, DOC, ODT, or TXT, up to 100MB), its filename, size, and extracted text for indexing and analysis. After successful indexing, the original file is removed from storage; extracted text, chunks, and embeddings remain associated with the conversation until you remove the document or delete the conversation. Other users — including collaborators on shared research threads — cannot access your uploaded file or its extracted text, though a shared research narrative may still reflect analysis performed on that document.

2.5 Word Add-in Document Text

When you use the Common Laws for Word add-in, we may process text from your Word document that you select or that a feature reads to fulfil your request — for example search queries and document context, research questions, citation strings, excerpts, and body text used for document checks (such as table of authorities, cite-check, or unsupported claim scans). That text is processed to provide the requested feature and is not treated the same as a research document upload unless you separately upload a file on the website. See our Terms of Service for how this relates to User Content and confidentiality.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service.
  • Process your search queries and deliver results, including AI analysis of documents you upload to research conversations and document text you process through the Word add-in.
  • Manage your account and subscription.
  • Communicate with you about the Service, including updates and support.
  • Comply with legal obligations.

4. Third-Party AI Providers

To power our search and AI features, your search queries and (where applicable) uploaded document content or Word add-in document text are processed by the following third-party services:

  • Amazon Web Services (AWS) — Bedrock: We use Amazon Titan EmbedText V2 for generating search embeddings, and Amazon Nova models (including Nova Pro and, where needed, Nova Lite) for intent classification, query enhancement, grounded research responses, and related AI features — including analysis of uploaded document text when you attach a file to a research thread. Your search query text and relevant document excerpts are sent to these services for processing. We do not use your content to train these models.
  • Amazon Web Services (AWS) — Textract: If OCR is enabled for scanned PDFs, document pages may be temporarily staged in a private AWS S3 bucket in the Asia Pacific (Singapore) region for Textract processing, then deleted on a best-effort basis after OCR completes (with a short lifecycle retention as a fallback). We do not use OCR content to train models.
  • Google Cloud — Vertex AI (Gemini): For certain research composition tasks (for example longer research questions or analysis involving uploaded document text), we may use Google Gemini models via Google Cloud Vertex AI (or, where configured, the Gemini API). Your research query text and relevant document excerpts may be sent to these services for processing. We do not use your content to train these models.

These AI providers process your content solely to deliver results to you. We do not send your personal contact details (name, email, organisation) to these AI providers as part of those model requests. Each provider's own privacy policy governs their handling of data.

5. Data Sharing

We do not sell your personal information. We share your information only in the following circumstances:

  • Service providers: With trusted third parties who assist in operating the Service, subject to confidentiality obligations. These currently include:
    • Supabase — authentication, database, file storage, and edge functions that host account data, research content, and related Service data;
    • Vercel — hosting for our web application and Word add-in;
    • Stripe — payment and subscription processing (see Section 2.3);
    • Plunk — transactional and service-related email delivery (and, where you have opted in or it is otherwise permitted, marketing email);
    • PostHog — product analytics and usage measurement to help us operate and improve the Service (subject to cookie / consent settings where applicable);
    • Google and Microsoft — if you choose to sign in with Google or Microsoft, those providers authenticate you and share account profile information (such as name and email) with us as described in their policies.
  • Legal requirements: When required by law, regulation, or legal process.
  • Business transfers: In connection with a merger, acquisition, or sale of assets.

6. Contact Details

Your contact details (name, email address, organisation) are kept confidential and are never shared with third parties except as described in Section 5 above.

7. Data Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. Uploaded research documents are protected by row-level security and private storage policies so only you can access your files. However, no method of transmission over the Internet is 100% secure.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Uploaded research documents and extracted text are retained until you remove them or delete the associated conversation. If you delete your account, we will delete or anonymise your personal information within a reasonable period, except where retention is required by law.

9. Cookies

We use cookies and similar technologies to maintain your session, remember your preferences, and analyse usage. You can manage your cookie preferences through the cookie settings link in the footer.

10. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or restrict the processing of your personal information. To exercise these rights, please contact us via the Contact page.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the version date above and may notify you through the Service. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

12. Contact

If you have questions about this Privacy Policy, please contact us via the Contact page.