First Chair, Inc., doing business as inSession ("inSession," "we," "us," or "our"), respects your privacy and recognizes the particular sensitivity of information used in connection with legal matters.
This Privacy Policy describes how we collect, use, disclose, and protect information when you visit inSession.law, create or use an inSession account, use our trial simulation and litigation preparation services, or otherwise interact with us.
inSession is designed for legal professionals, law firms, law students, educational institutions, and other authorized users. Because users may provide information relating to legal matters, we distinguish between ordinary personal information and information submitted in connection with cases, simulations, and legal work.
Personal Information. We may collect personal information that you provide directly to us, including:
We may also automatically collect certain technical information when you use our public website, including IP address, browser type, device information, operating system, pages viewed, referring URLs, approximate location derived from IP address, and information about how users interact with our website.
Payment Information. Payments may be processed through Stripe or other authorized payment processors.
Payment card information is generally provided directly to the payment processor rather than stored by inSession. We may receive information associated with a transaction, such as payment status, subscription level, billing information, and transaction identifiers.
Users may provide information relating to actual or simulated legal matters when using inSession. This information may include:
We refer to this information collectively as "Case-Specific Data." Case-Specific Data is treated differently from ordinary website, account, and marketing information.
inSession does not sell Case-Specific Data.
inSession does not use Case-Specific Data to train artificial intelligence models.
Our third-party service providers are not permitted to use Case-Specific Data processed on behalf of inSession to train their artificial intelligence models.
Case-Specific Data may be processed as necessary to provide functionality requested by the user, including generating AI responses, conducting simulations, analyzing performance, generating reports, maintaining session and practice history, and providing other inSession features.
Users are responsible for ensuring that they have the authority to submit information to inSession and for complying with their professional, ethical, contractual, and legal obligations regarding confidential, privileged, personal, or otherwise protected information.
We may use information we collect to:
We may use aggregated or de-identified information to understand and improve the performance and operation of our services, provided that such information does not identify a user, client, or specific legal matter.
inSession uses vetted third-party service providers for cloud infrastructure, data storage, artificial intelligence processing, voice and avatar technology, security, authentication, communications, payment processing, and other functions necessary to provide the service.
A current list of material service providers and subprocessors is available upon request by contacting [email protected].
These providers may process information on behalf of inSession only as necessary to provide the applicable services and functionality.
inSession's service providers are not permitted to use Case-Specific Data processed on behalf of inSession to train their artificial intelligence models.
inSession uses service providers that maintain SOC 2 compliance or equivalent applicable SOC 2 assurance for the services used by inSession. We also use appropriate enterprise, API, contractual, technical, and security configurations designed to protect information processed through the platform.
Service providers and technologies used by inSession may change as the platform evolves. We evaluate providers with particular consideration for the security and confidentiality requirements associated with legal information.
We may use cookies and similar technologies on the public-facing portions of the inSession website to understand website usage, measure performance, and improve our marketing. These technologies may include Google Analytics and the Meta Pixel.
These services may collect information such as device and browser information, IP address, referring pages, website interactions, and other information concerning use of our public website.
Google Analytics and the Meta Pixel are not used within inSession's authenticated member areas or case-related areas of the platform.
Case-Specific Data is not provided to Google Analytics or the Meta Pixel for advertising or marketing purposes.
We maintain this separation because information concerning the use of legal matters within inSession should not be used for advertising or marketing tracking.
Browser settings and other available privacy controls may allow users to restrict or disable certain cookies used on the public website.
inSession does not sell personal information or Case-Specific Data.
Our business model is based on providing software and services to our customers, not monetizing their personal information or legal information through data sales.
We do not sell Case-Specific Data to data brokers, advertisers, artificial intelligence companies, or other third parties.
The security and confidentiality of information submitted through inSession are important to us, particularly because the platform may process sensitive legal and case-related information.
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
Our technology infrastructure and service-provider relationships are selected and configured with the security requirements of professional legal users in mind. Service providers used to process or store inSession data maintain SOC 2 compliance or applicable SOC 2 assurance appropriate to the services they provide.
No internet-based service or information storage system can guarantee absolute security. Users should therefore exercise appropriate care when determining what information to provide through any online service.
Users should also follow their organization's information-security policies and applicable professional obligations when using inSession.
We retain information for as long as reasonably necessary to provide our services, maintain accounts, fulfill legitimate business purposes, resolve disputes, enforce agreements, comply with legal obligations, and protect the security and integrity of our platform.
Retention periods may differ depending on the type of information, account settings, contractual requirements, applicable law, and the services being used.
Where applicable, deletion of information from active systems may not result in immediate deletion from encrypted backups, disaster-recovery systems, security logs, or other systems maintained for legitimate operational, security, or legal purposes.
Depending on where you live and applicable law, you may have rights regarding your personal information, including the right to request access to, correction of, or deletion of certain personal information.
You may contact us at [email protected] to submit a privacy request.
We may need to verify your identity before processing certain requests. Some information may be retained where permitted or required by law, including for security, fraud prevention, legal compliance, dispute resolution, and other legitimate purposes.
California residents may have additional rights regarding their personal information under applicable California privacy laws.
Depending on whether a particular law applies to inSession or a particular processing activity, these rights may include requesting information about personal information we collect, requesting correction or deletion, and obtaining information regarding certain disclosures of personal information.
inSession does not sell personal information or Case-Specific Data.
California residents may submit privacy-related requests to [email protected].
Nothing in this section is intended to provide rights beyond those required by applicable law.
inSession is designed specifically to support legal preparation, courtroom simulation, litigation strategy, education, and training. Users may therefore submit information that is confidential, privileged, proprietary, protected by court order, or otherwise sensitive.
inSession treats Case-Specific Data as information provided for the purpose of delivering the services and functionality selected by the user.
inSession does not claim ownership of a user's underlying Case-Specific Data.
inSession does not sell Case-Specific Data or use Case-Specific Data to train artificial intelligence models.
Use of inSession does not replace a user's responsibility to evaluate applicable professional-responsibility rules, protective orders, confidentiality agreements, client requirements, court rules, organizational policies, or other restrictions governing information used with technology and artificial intelligence services.
Users are responsible for determining whether their use of inSession and submission of particular information are appropriate under the legal, ethical, contractual, and professional obligations applicable to them.
inSession is intended exclusively for users 18 years of age or older.
Our services are not directed to children or individuals under 18, and we do not knowingly collect personal information from individuals under 18.
If we learn that personal information has been collected from a person under 18 in violation of this policy, we may take reasonable steps to delete that information.
Our website or services may contain links to or integrations with third-party websites, applications, or services.
When users independently interact with third-party services outside of inSession, those services' privacy practices are governed by their own policies. inSession is not responsible for the privacy practices of independent third-party websites or services.
Third-party providers processing information on behalf of inSession as part of the inSession platform are addressed elsewhere in this Privacy Policy.
We may update this Privacy Policy periodically as our services, technology, business practices, or legal obligations evolve.
When we make changes, we will update the effective date shown at the top of this Privacy Policy.
If we make material changes, we may provide additional notice through the website, the inSession platform, email, or other appropriate means.
Questions, concerns, or requests regarding this Privacy Policy or our privacy practices may be directed to:
First Chair, Inc. dba inSession
Email: [email protected]
Website: inSession.law