Skip to content
Back to resources
Trust and privacy

Security and confidentiality

Understand who can see your case, how documents are processed and what to consider before sharing sensitive information.

01 · Sharing your case

You choose when funders see it.

Three stages of disclosure to funders
  1. 01

    Private assessment

    Upload your record and receive your assessment. It is not automatically listed.

  2. 02

    You list a summary

    Approved professional funders can see the anonymised summary you choose to list.

  3. 03

    You approve full access

    A specific funder receives the full report through an active NDA for that case.

Who can see what
WhoAccess
You, as the case ownerYour own assessment and case record.
Visitors to the public websitePublic guides and fictional examples, not your private case.
Approved professional fundersAn anonymised summary, if you choose to list the case.
A funder with an active NDA for your caseThe full assessment, including party identities and detailed findings, after your approval.
JusFund administrators and service providersCase data used to operate the service, process assessments and provide support, as described in the Privacy Notice.

Full-report access and access to original uploaded files are separate. An active NDA does not automatically give a funder a download of the original files.

02 · Your documents

Storage is one part of the picture.

Storage and encryption

Case documents are held in private storage. The Privacy Notice identifies Supabase, hosted in Paris, France, as the primary database and file-storage provider. The AI Ethics Policy sets out encryption in transit and at rest.

Processing an assessment

Document-reading and AI services process case material to produce and check the assessment. Search services receive queries derived from the case. Some processing takes place outside the UK and EU, even though primary storage is in France.

Training and provider retention

Our policy prohibits using your case documents to train models. Provider retention terms are separate from platform retention and may include limited service or abuse-monitoring periods. Ask for the current provider list and relevant terms if your matter has specific confidentiality requirements.

03 · Access controls

Access belongs to a case.

Approval and withdrawal

A funder’s NDA access applies to the specific case you approve. You can revoke that access through the NDA controls. Revocation cannot retract information already seen, copied or retained by a recipient.

Activity records

The platform records activity such as report openings, listing decisions and NDA actions. These records help trace platform activity; they cannot show everything a recipient does with information after viewing it.

Keep account credentials and private document links confidential. Contact us if you suspect someone has accessed your account or case without permission.

04 · Keeping and deleting data

Different records have different lifetimes.

The Privacy Notice sets out the retention schedule. Removing a case does not mean every associated record is deleted immediately.

Retention periods stated in the Privacy Notice
RecordPolicy period
Case documents and assessmentsWhile the case exists, then deletion 90 days after you delete the case or close the account.
Access, listing and NDA records6 years from the event.
Verification documents5 years after the account closes or verification is withdrawn.

Other records have their own periods. Legal duties or disputes may require longer retention, and backups follow their ordinary replacement cycle. The full notice explains these exceptions and your rights.

05 · Before you share

Confidentiality needs judgement too.

Anonymisation has limits

Names can be removed while other details still identify a dispute. Review the proposed summary against information that is already public before choosing to list it.

An NDA does not establish privilege

Confidentiality obligations and legal privilege are different. Check your authority to upload or disclose documents and take advice where privilege, court orders or third-party confidentiality duties are involved.

Encryption, access controls and activity records are safeguards, not a guarantee against every incident. AI review can also miss sensitive details or make mistakes.

Something needs our attention?

For a suspected vulnerability or unauthorised access, start with a short description. Do not include case documents, passwords or access tokens in your first message.