Privacy Policy

Last Updated: January 10, 2025

Overview

CanLII Search ("we", "our", "the Service") is committed to being transparent about data collection and usage. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.

Key Point: ALL searches performed on this tool are logged and stored, whether you are signed in or not. There is no fully anonymous option for using this service.

Information We Collect

1. Search Data (All Users)

For every search performed, we automatically collect and store:

  • Your search query (the natural language input)
  • The generated Boolean output
  • The search mode selected (Standard, Wider, or Narrower)
  • Language preference (English or French)
  • Timestamp of the search
  • Browser user agent string
  • Whether you were signed in (if yes, your email address)

2. Account Information (Signed-in Users)

When you choose to sign in, we additionally collect:

  • Your email address
  • Authentication tokens from Firebase Auth
  • Association between your email and all searches performed while signed in

3. Technical Data

We use Firebase Analytics and Firestore, which may collect:

  • IP address (processed by Firebase, not directly stored by us)
  • Device and browser information
  • Session duration and interaction metrics
  • Geographic location (country/region level)

đź”´ Critical Privacy Notice: US Data Processing

Your data is PROCESSED and STORED in the United States

This means:
  • ✉️ Your email address → Processed & stored in the US
  • 🔍 Your search queries → Sent to US servers for AI processing
  • đź’ľ Your search history → Permanently stored in US databases
  • 📊 Your usage data → Analyzed by US-based systems

Specific Data Flows

Your Data Where It Goes Who Processes It
Search queries US (Virginia) OpenAI API
Email & account US (Multiple regions) Google Firebase Auth
Search history US (Multiple regions) Google Firestore
Analytics US (Multiple regions) Google Analytics

For Canadian Users - PIPEDA Notice

Under Canadian Privacy Law (PIPEDA):
  • We must inform you that your personal information will be processed and stored outside Canada
  • US authorities can access your data under US laws (FISA, CLOUD Act, Patriot Act)
  • US privacy protections differ from Canadian protections
  • By using this service, you consent to your data being processed in the United States

For International Users

If you're outside Canada:
  • This service is designed for Canadian legal research
  • We follow Canadian privacy law (PIPEDA), not GDPR or CCPA
  • Your data is processed in the US regardless of your location
  • You waive rights under non-Canadian privacy laws by using this service

How We Use Your Information

Search Data is Used To:

  • Improve the accuracy of Boolean query generation
  • Understand common search patterns and legal research needs
  • Identify and fix bugs or issues with the conversion algorithm
  • Develop new features based on usage patterns
  • Generate aggregate analytics about service usage

Email Addresses are Used To:

  • Authenticate your account via passwordless sign-in links
  • Associate your searches with your account for personalized features
  • Send important service notices or updates about the tool
  • Contact you about significant changes to the service or privacy policy
  • Respond to your support requests or feedback
Marketing Communications: We may occasionally send you updates about new features or improvements to the service. You can opt out of these communications at any time by clicking the unsubscribe link in the email.

Data Storage and Security

Your data is stored using Google Firebase services:

  • Firebase Firestore: Stores search queries and user data
  • Firebase Authentication: Manages secure sign-in
  • Firebase Analytics: Processes usage metrics

All data is transmitted over encrypted HTTPS connections. Firebase services comply with industry-standard security practices and are SOC 2 Type II certified. Authentication is handled securely through Firebase Authentication with encrypted password storage.

Data Retention

  • Search logs: Retained indefinitely for service improvement
  • Account data: Retained as long as your account exists
  • Analytics data: Aggregated and anonymized after 14 months (Firebase default)

You may request deletion of your account and associated data by contacting us (see contact information below).

Data Sharing

We DO NOT:

  • Sell your personal information to third parties
  • Share individual search queries with external parties
  • Use your data for advertising purposes
  • Transfer data outside of Firebase's secure infrastructure

We MAY share data only in these limited circumstances:

  • With your explicit consent
  • To comply with legal obligations or valid legal requests
  • To protect our rights, privacy, safety, or property
  • In aggregated, anonymized form for research or statistical purposes

Your Rights

You have the right to:

  • Access: Request a copy of the data we have about you
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your account and associated data
  • Portability: Receive your data in a portable format
  • Opt-out: Unsubscribe from non-essential email communications

To exercise these rights, contact us using the information below.

Cookies and Local Storage

We use:

  • Local Storage: To save your language preference
  • Session Storage: For temporary authentication state
  • Firebase Cookies: For authentication and analytics (set by Firebase)

These are essential for the service to function and cannot be disabled while using the tool.

Children's Privacy

This service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided us with personal information, we will delete such information from our systems.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users via email of any material changes. The "Last Updated" date at the top of this policy indicates when it was last revised.

Third-Party Services

This service integrates with:

  • OpenAI API: For generating Boolean queries (search text is sent to OpenAI)
  • Google Firebase: For authentication, database, and analytics
  • CanLII.org: Users manually copy queries to search on CanLII

These services have their own privacy policies and data handling practices.

Contact Information

For privacy-related questions or requests:

Email: thechatbotgenius1@gmail.com
Response Time: We aim to respond within 30 days

When contacting us, please include your email address (if you have an account) and clearly describe your request.