Privacy Policy
IntakeIQ, Inc.
1. Introduction
IntakeIQ, Inc. ("we," "our," or "us") provides an AI-powered legal intake platform that helps law firms pre-qualify potential cases. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website at intakeiq.io and our services (collectively, the "Service").
By using IntakeIQ, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
2. Information We Collect
2.1 Information Provided Through Intake Forms
When a potential client completes an intake form, we may collect:
- Full name and contact information (email, phone number)
- Employment details (employer name, job title, dates of employment)
- Description of the legal matter or dispute
- Relevant dates and timelines
- Uploaded documents and supporting files
- Any other information voluntarily provided in the intake form
2.2 Sensitive Personal Information
Depending on the nature of your legal matter, information you provide through intake forms may include categories of data considered "sensitive personal information" under applicable law. This may include, but is not limited to, information revealing racial or ethnic origin, religious beliefs, disability status, sexual orientation, immigration status, or the contents of private communications.
We process sensitive personal information solely for the purpose of evaluating your potential legal case and sharing it with the subscribing law firm. We do not use sensitive personal information for profiling, advertising, or any purpose unrelated to case intake and evaluation.
Under the California Consumer Privacy Act (CCPA/CPRA) and similar state laws, you may have the right to limit the use and disclosure of your sensitive personal information. To exercise this right, please contact us using the information in Section 17.
2.3 Account and Subscription Information
For law firm users and attorneys, we collect:
- Name and professional contact information
- Law firm name and practice area details
- Payment and billing information (processed securely through Stripe)
- Clio practice management integration credentials (via OAuth)
- Scheduling preferences (via Cal.com integration)
2.4 Information From Connected Firm Mailboxes (Email Triage)
Subscribing law firms may optionally connect a firm email mailbox (Microsoft Outlook or Google Gmail) to IntakeIQ's Email Triage feature. When a firm enables this, IntakeIQ periodically reads messages newly received in that mailbox's inbox in order to identify prospective-client inquiries. IntakeIQ never modifies, labels, archives, or deletes mail in a connected mailbox. Where the firm has enabled automatic replies, the reply to an identified inquiry may be sent from the connected mailbox itself — so the prospective client receives a reply from the address they wrote to, in the same conversation. That automatic reply is the only mail ever sent from a connected mailbox. See Section 4.2.
For each newly received message, IntakeIQ reads the sender name and address, the subject line, the message body, and the received timestamp. What is retained depends on the outcome of that evaluation:
- Messages that are evaluated: we store the sender name and address, the subject line, an excerpt of the message body (up to the first 500 characters), the received timestamp, and the classification result — including the reason the AI gave for its decision. This applies whether or not the message was identified as a prospective legal inquiry. Messages judged not to be inquiries are retained so the firm can verify what the system decided and correct it where the AI was wrong; they are filtered out of the firm's default view rather than deleted. Only messages identified as inquiries are acted on.
- Messages never evaluated at all: messages from mail-system senders (for example addresses beginning "no-reply@" or "mailer-daemon@") and messages the connected mailbox sent to itself are filtered out before any evaluation occurs. Where the firm's mailbox uses its own custom domain, other messages from that same domain (firm-internal mail) are also filtered out; this domain filter does not apply to mailboxes on shared consumer providers such as gmail.com or outlook.com, where sharing a domain does not indicate a colleague.
Mailbox access is granted by the firm through the mail provider's standard OAuth consent flow and can be revoked at any time, either from the IntakeIQ Integrations page or directly through the firm's Google or Microsoft account security settings. Revoking access stops all further reading immediately. Firms may also use Email Triage without connecting a mailbox, by forwarding messages to an IntakeIQ-provided intake address.
2.5 Automatically Collected Information
We automatically collect certain information when you use the Service, including:
- Browser type and device information
- IP address and general location data
- Pages visited and interaction patterns
- Analytics data collected via Google Analytics 4 (GA4) and Google Tag Manager. IP anonymization is enabled by default in GA4. We use these tools to understand aggregate usage patterns. Google acts as a data processor for this information and processes it in accordance with its data processing terms.
3. Legal Basis for Processing
We process your personal information on the following legal bases:
- Consent: When you voluntarily submit an intake form, you consent to the processing of your information for case evaluation purposes. You may withdraw consent at any time by contacting us, though this will not affect the lawfulness of processing prior to withdrawal.
- Contractual Necessity: For subscribing law firms and attorneys, we process account and subscription information as necessary to perform our contractual obligations under the service agreement.
- Legitimate Interests: We process automatically collected information (such as analytics data) based on our legitimate interest in improving and securing the Service, provided these interests are not overridden by your rights and freedoms.
- Legal Obligations: We may process information as necessary to comply with applicable laws, regulations, or legal processes.
4. AI Processing and Third-Party AI Providers
IntakeIQ uses a multi-model consensus scoring system to evaluate and score potential legal cases. Each intake form submission is evaluated by multiple foundation models simultaneously to generate independent assessments. All of this AI processing is performed through a single third-party subprocessor:
- Amazon Web Services (AWS), via AWS Bedrock
4.1 How Your Data Is Handled During AI Processing
Every foundation model we use is hosted and run within AWS Bedrock — Amazon's fully managed AI service — inside Amazon's secure environment. The models currently used for case scoring include Anthropic Claude and Meta Llama, with additional Amazon foundation models used for supporting tasks such as text embeddings. Because these models run inside AWS Bedrock, your data is not transmitted to the model developers (such as Anthropic or Meta); AWS operates the models on our behalf.
- Single subprocessor: Case data is transmitted only to AWS Bedrock. It is not sent to any other AI provider, and it does not leave AWS's environment during processing.
- No retention: AWS Bedrock does not store or retain any input or output data after a request completes.
- No training: Your data is never used to train or improve any foundation model.
- BAA coverage: All AI processing is covered under our Business Associate Agreement (BAA) with AWS.
Your data is transmitted to AWS Bedrock solely for the purpose of generating a case evaluation score and summary.
4.2 AI Processing of Email Triage Messages
Where a subscribing law firm uses the Email Triage feature (see Section 2.4), the sender, subject, and body excerpt of an inbound message are transmitted to AWS Bedrock for a single purpose: determining whether the message is a prospective legal inquiry and, if so, its likely practice area, urgency, and language. The same protections described in Section 4.1 apply — AWS Bedrock retains no input or output after the request completes, the content is never used to train any foundation model, and it is covered by our BAA with AWS.
Where a firm has enabled automatic responses, IntakeIQ replies to messages identified as prospective legal inquiries with a link to that firm's intake form, so an inquiry can be answered promptly without waiting for someone at the firm to read it. This applies both to messages forwarded to an IntakeIQ intake address and, where the firm has enabled inbox scanning and automatic replies for it, to inquiries found in a connected mailbox. Automatic replies are sent only above a confidence threshold the firm controls; less certain inquiries are listed for the firm without any reply being sent. Where a firm has additionally enabled AI-drafted replies, the same subprocessor generates the response text.
Automatic replies identify themselves as automated and are sent on behalf of the subscribing law firm. Where the firm's mailbox connection permits sending, the reply is sent from the firm's own mailbox and appears in the same conversation as the original inquiry; otherwise it is sent by IntakeIQ on the firm's behalf. IntakeIQ never sends any other mail from a connected mailbox, and never modifies, labels, or deletes messages in it.
We regularly review the data handling policies of AWS. If our AI processing arrangements materially change, we will update this section and notify subscribing law firms. The references above were last verified as of the effective date of this Privacy Policy.
5. No Attorney-Client Relationship; Confidentiality
An attorney-client relationship is only formed when a licensed attorney explicitly agrees to represent you, typically through a signed engagement or retainer agreement.
Information submitted through intake forms may not be protected by attorney-client privilege. While we implement technical safeguards to protect the confidentiality of your submissions (including encryption in transit and at rest, access controls, and restricted sharing solely with the subscribing law firm), the transmission of information through the Service does not create a privileged communication.
We strongly recommend that you do not include highly sensitive or privileged information in your intake form submission beyond what is necessary to describe your legal matter in general terms. Detailed privileged communications should be shared directly with your attorney after a formal engagement has been established.
Subscribing law firms are independently responsible for their own ethical obligations regarding confidentiality, conflicts of interest, and the formation of attorney-client relationships.
6. HIPAA Compliance
6.1 Business Associate Agreements (BAAs)
IntakeIQ maintains signed Business Associate Agreements (BAAs) with all service providers that process Protected Health Information:
- Amazon Web Services (AWS) — hosting, database, file storage, email delivery, and all AI processing via AWS Bedrock
- Google — calendar integration via Google Workspace (only for firms that connect Google Calendar)
- Subscribing law firms may request a BAA with IntakeIQ by contacting legal@intakeiq.io
6.2 Technical Safeguards
IntakeIQ implements comprehensive technical safeguards to protect PHI:
- AES-256 encryption at rest for all databases and file storage
- TLS 1.2+ encryption in transit for all data transmissions
- Field-level encryption for sensitive data fields (contact information, medical details)
- Dedicated encrypted storage for medical records with versioning and access logging
- Zero data retention for all AI processing — no case data is used to train models
- Comprehensive audit logging for all PHI access (user identity, timestamp, resource, IP address)
- Role-based access control with multi-tenant data isolation
6.3 Medical Records and PHI
IntakeIQ supports the secure upload and processing of medical records and other PHI for practice areas that require it, including employment law (ADA, FMLA, workers' compensation), personal injury, and related areas. Medical records are stored in dedicated encrypted S3 buckets with AWS CloudTrail audit trails.
6.4 PHI in Communications
Email notifications from IntakeIQ include only client names and practice area categories. Detailed case information, AI analyses, medical details, and financial data are accessible only through the authenticated dashboard and are never included in email communications.
7. How We Use Your Information
We use the information we collect for the following purposes:
- To process and evaluate potential legal cases using AI-powered scoring
- To generate case summaries and qualification assessments for attorneys
- To facilitate communication between potential clients and law firms
- To process payments and manage subscriptions via Stripe
- To integrate with practice management software (Clio) as authorized
- To schedule consultations via Cal.com
- To improve and optimize our Service through analysis of aggregate, de-identified usage patterns and system performance metrics. We do not use identifiable intake form data for product improvement, analytics, benchmarking, or internal model training. Any analysis for service improvement purposes is performed only on anonymized or aggregated data from which individual intake submissions cannot be identified.
- To comply with legal obligations
8. Data Storage and Security
All data is processed and stored on HIPAA-compliant AWS infrastructure in the United States (US-East-1 region). Specific safeguards include:
- Amazon RDS PostgreSQL with AES-256 encryption at rest and SSL/TLS connections
- Amazon S3 with server-side encryption for file storage and medical records
- Amazon CloudFront with TLS 1.2+ for secure content delivery
- AWS Secrets Manager for credential management (no hardcoded secrets)
- AWS CloudTrail for infrastructure-level audit logging
- AWS CloudWatch for real-time monitoring and alerting
While we take reasonable measures to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.
9. Data Breach Notification
In the event of a data breach that compromises your personal information, we will take the following steps:
- We will investigate and contain the breach as promptly as practicable upon discovery.
- We will notify affected subscribing law firms without unreasonable delay, and in no event later than 72 hours after confirming a breach that is reasonably likely to have compromised personal information.
- We will notify affected individuals as required by applicable state and federal law, within the timeframes mandated by each applicable jurisdiction.
- Notifications will include, to the extent known: a description of the nature of the breach, the categories of information affected, the approximate date of the breach, the steps we are taking in response, and contact information for further inquiries.
- We will cooperate with applicable regulatory authorities and law enforcement as required by law.
We maintain an incident response plan and conduct periodic security assessments to minimize the risk of unauthorized access to your data.
10. Data Sharing and Disclosure
We do not sell your personal information. We do not "share" your personal information for cross-context behavioral advertising as defined under the California Consumer Privacy Act (CCPA/CPRA). We may share your information in the following circumstances:
- With Subscribing Law Firms: Intake form submissions and AI-generated case evaluations are shared with the law firm whose intake form you completed.
- With AI Providers: As described in Section 4, your intake data is processed by foundation models hosted within AWS Bedrock (Amazon Web Services) for case evaluation purposes. All AI processing is covered by our signed Business Associate Agreement with AWS, and the data is not retained or used for training.
- With Service Providers: We use third-party service providers including Stripe (payments), Google Calendar (scheduling), and Clio (practice management) to operate the Service. All service providers that process PHI have signed Business Associate Agreements or equivalent data processing agreements. These providers only receive the data necessary to perform their specific functions.
- As Required by Law: We may disclose your information if required by law, regulation, legal process, or governmental request.
10.1 International Data Transfers
Your information may be transferred to and processed in the United States and other countries where our AI providers and service providers maintain servers. These countries may have data protection laws that differ from the laws of your jurisdiction. By using the Service, you consent to the transfer of your information to the United States and other jurisdictions as described in this Policy. Where required by applicable law (such as the EU General Data Protection Regulation), we will ensure that appropriate safeguards are in place for international transfers, such as Standard Contractual Clauses approved by the European Commission.
11. Data Retention
Intake form data and associated case evaluations are retained for as long as the subscribing law firm maintains an active account or as required by applicable law. The following specific retention rules apply:
- Active accounts: Intake data is retained for the duration of the law firm's active subscription.
- Rejected or unactioned intakes: If a subscribing law firm has not acted on an intake submission within 24 months, we will automatically delete the associated intake data unless the law firm has flagged it for retention.
- Account termination: Upon account termination, all associated intake data will be deleted within 90 days unless retention is required by applicable law or the law firm requests earlier deletion.
- Individual deletion requests: Individuals who submitted intake forms may request deletion of their data at any time by contacting us. We will process such requests within 45 days, subject to any legal obligations requiring continued retention.
- Email Triage records: Records created from inbound email (see Section 2.4) are retained for the duration of the law firm's active subscription and deleted on the same schedule as intake data above. Records for messages judged not to be prospective inquiries are retained for 90 days and then deleted automatically, since their only purpose is to let the firm verify and correct the AI's decisions. Disconnecting a mailbox stops further reading immediately; a firm may also delete individual triage records from its dashboard at any time.
Law firms may request deletion of intake records through their account dashboard or by contacting us directly.
12. Data Processing Agreements
IntakeIQ offers a standard Data Processing Agreement (DPA) to subscribing law firms. The DPA governs IntakeIQ's processing of personal data on behalf of the law firm and addresses:
- The scope, nature, and purpose of data processing
- Obligations of both parties regarding data protection
- Sub-processor management and notification procedures
- Data breach notification commitments
- Audit rights and cooperation with regulatory authorities
- Data return and deletion upon termination
Law firms that require a DPA for compliance with their own ethical obligations, bar association rules, or applicable data protection laws may request one by contacting us at privacy@intakeiq.io. We encourage all subscribing law firms to execute a DPA with IntakeIQ.
13. Your Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information. Below we describe rights available under applicable law.
13.1 General Rights
All users may have the following rights:
- The right to access the personal information we hold about you
- The right to request correction of inaccurate information
- The right to request deletion of your personal information
- The right to opt out of certain data processing activities
- The right to data portability
13.2 California Residents (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA):
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purposes for collection, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions permitted by law.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt Out of Sale/Sharing: We do not sell your personal information or share it for cross-context behavioral advertising. Therefore, there is no need to opt out of such activities.
- Right to Limit Use of Sensitive Personal Information: You may request that we limit our use of sensitive personal information to only what is necessary to perform the Service.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
To submit a request, please contact us at the information provided in Section 17. We will respond to verified requests within 45 days. If we need additional time, we will notify you of the extension and the reason. You may designate an authorized agent to make a request on your behalf. If you are not satisfied with our response, you have the right to appeal by contacting us with a description of your concern, and we will respond within 45 days of receiving your appeal.
13.3 Other U.S. State Privacy Laws
Residents of other states with comprehensive privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana) may have similar rights to access, correct, delete, and opt out of certain processing. Please contact us using the information in Section 17 to exercise your rights. We will respond in accordance with the timelines and procedures required by your state's applicable law.
13.4 European Economic Area, UK, and Other International Users
If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction with applicable data protection laws, you may have additional rights including the right to lodge a complaint with your local data protection authority. Please contact us to exercise your rights, and we will respond in accordance with applicable law.
To exercise any of these rights, please contact us at the information provided in Section 17.
15. Third-Party Links and Integrations
The Service may contain links to third-party websites or integrate with third-party services (such as Clio, Cal.com, and Stripe). We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you interact with through IntakeIQ.
15.1 Connected Email Mailboxes — Limited Use Commitments
IntakeIQ's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We make the same commitments for mailbox data accessed through Microsoft Graph. Specifically, data obtained from a connected mailbox is:
- Used only to provide and improve the Email Triage feature — identifying prospective-client inquiries for the firm that connected the mailbox — and for no other purpose;
- Never transferred to others, except as necessary to provide that feature (see the AWS Bedrock disclosure in Section 4.2), to comply with applicable law, or as part of a merger or acquisition following notice and consent as required by law;
- Never used for advertising, marketing, profiling, or resale;
- Never used to train, fine-tune, or otherwise improve generalized artificial intelligence or machine learning models. The models that classify inbound messages are pre-trained third-party models run inside AWS Bedrock, which retains no input or output after a request completes;
- Never read by a human, except with the firm's explicit consent for a specific purpose (such as support troubleshooting the firm requests), where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized.
A firm may revoke IntakeIQ's mailbox access at any time from the IntakeIQ Integrations page, or directly through its Google account permissions or Microsoft account settings.
16. Children's Privacy
IntakeIQ is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. Intake forms include an age affirmation requiring users to confirm they are 18 years of age or older before submitting. If you believe a child under the age of 13 has provided us with personal information, please contact us immediately and we will promptly investigate and delete such information in compliance with the Children's Online Privacy Protection Act (COPPA). For individuals between 13 and 17, we will delete their information upon request from a parent or guardian.
17. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
IntakeIQ, Inc.
Privacy Inquiries: privacy@intakeiq.io
General Support: support@intakeiq.io
Website: https://intakeiq.io
For CCPA/CPRA requests specifically, you may also submit a request through our website at intakeiq.io/privacy or contact us via email. We will verify your identity before processing any rights request.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by:
- Posting the updated policy on our website with a revised effective date
- Sending email notification to subscribing law firms for material changes
- Displaying a prominent notice within the Service dashboard for at least 30 days following material changes
Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.
19. Frequently Asked Questions
Is IntakeIQ HIPAA compliant?
Yes. IntakeIQ maintains HIPAA compliance through signed Business Associate Agreements (BAAs) with all service providers, AES-256 encryption at rest, TLS encryption in transit, field-level encryption for PHI, comprehensive audit logging, and zero data retention for AI processing.
Can I upload medical records?
Yes. Medical records are stored in dedicated encrypted storage with versioning and access logging. All access to medical records is audited and tracked.
Is my data used to train AI models?
No. All AI processing runs within AWS Bedrock, which is configured for zero data retention and does not use your data to train or improve any model. Your case data is never used to train or improve any AI model.
Where is my data stored?
All data is stored on AWS infrastructure in the United States (US-East-1 region). We do not transfer data outside the United States without prior written consent.
Can I get a Business Associate Agreement (BAA)?
Yes. Subscribing law firms may request a BAA by contacting legal@intakeiq.io.
How do I request deletion of my data?
You may request deletion of your data at any time by contacting privacy@intakeiq.io. We will process deletion requests within 45 days.
© 2026 IntakeIQ, Inc. All rights reserved.