Never used to train AI models. Never visible to another customer. Deletable by you, any time. This page explains how GleanMark protects the confidential work of trademark practices — in plain language, with real numbers.
Two pages your IT reviewer can clear without a call.
Our agreements with every AI provider we use prohibit training their models on your content. Every provider that touches customer data is named on our public subprocessors page.
Each workspace's data is separated with row-level security — access rules enforced inside the database itself, not just in the application. One customer can never see another's portfolios, documents, or searches.
Account deletion is self-serve and permanent. It is not a hidden "deactivated" flag: billing is cancelled safely first, then your data is actually purged.
Our production database and document storage run in the AWS US East (N. Virginia) region. Customer data does not leave US data centers at rest.
Security that lives in the architecture, not in a policy document.
Row-level security policies plus per-workspace scoping keep every customer walled off. We run recurring internal security audits (most recently July and August 2026), and a job runs every day that alerts us if any table appears with row-level security switched off while still reachable by the public API key. It has run every day since 15 August 2026 and has never found an exposed table.
All traffic is encrypted in transit over TLS. Data is encrypted at rest by our cloud infrastructure provider. Sign-in is via Google, Microsoft, or one-time email codes. No GleanMark account has a password, so there is nothing for an attacker to phish or reuse from another breach. Firm administrators can enforce automatic sign-out after a chosen period of inactivity and a maximum session length for every member. Sensitive actions — inviting or removing members, changing roles, transferring ownership, changing the session policy, exporting or deleting your account — ask you to confirm your identity with a fresh one-time code. You can see every device signed in to your account and sign any of them out.
Five workspace roles — owner, admin, staff, contractor, and client — gate 19 distinct permissions covering members, billing, portfolios, and client access. Roles are enforced in the application and again in the database.
Documents you upload to a matter live in a private storage bucket, reachable only through short-lived signed links generated for authorized users. The exceptions are deliberate and narrow: images you upload to the filing wizard (specimens and design marks) and your firm logo sit at unguessable public URLs so they render in the product and in filings.
Retention limits are enforced by scheduled jobs — and our Privacy Policy matches what the code actually does.
Raw AI prompts and outputs in our diagnostic logs are automatically deleted after 90 days by a scheduled job. Our Privacy Policy states the same ceiling.
When you delete an AI chat, you get a 24-hour undo window. After that it is permanently purged — attachments included — by a daily cleanup job.
Delete your account yourself from Settings, permanently. A reversible archive option exists if you only want to step away.
Everything GleanMark holds about you — profile, portfolios, watches, saved searches, notes, reports, AI conversations — as a single JSON file from Settings, optionally with your uploaded files. Built in your browser; it never touches our servers. Separately, portfolios, deadlines, and alerts export to CSV, deadlines also to a calendar file, and clearance reports and AI drafts to Excel, PDF, and Word.
GleanMark uses outside AI providers for search analysis, drafting, and our AI assistant, Markus. Every provider that processes customer content is named on our public subprocessors page. Our business agreements with each of them prohibit using your content to train their models — a contractual commitment we hold our vendors to.
Raw AI prompts and outputs kept for troubleshooting are automatically deleted after 90 days. Deleted AI chats are permanently purged after a 24-hour undo window, attachments included.
We do not claim AI output is always accurate, and nothing in GleanMark replaces an attorney’s own judgment — the duty to verify is non-delegable. We publish the security posture we have today, not the one we plan to have: we hold no third-party certifications yet, and this page will say so until that changes.
No. Our business agreements with every AI provider we use prohibit training on your content. This is a contractual commitment we hold our vendors to, and every AI vendor that processes customer data is listed on our public subprocessors page. Raw AI prompts and outputs in our diagnostic logs are automatically deleted after 90 days.
No. Every workspace is isolated with row-level security — access rules enforced inside the database on every query, not just in the application code. We audit this isolation on a recurring basis and run a daily automated check for any drift.
In the United States. Our production database and document storage run in the AWS US East (N. Virginia) region.
Yes, yourself, permanently. Account deletion from Settings cancels billing safely and then purges your data — it is a real deletion, not a hidden flag. Deleted AI chats are purged after a 24-hour undo window.
Yes, in one click from Settings → Account → "Download my data." You get a single JSON file with your profile, portfolios, watches, saved searches, notes, reports, and AI conversations, and can include your uploaded files as a zip. The export is generated in your browser under your own permissions and is never stored on our servers.
Firm administrators set the session policy under Organization settings: automatic sign-out after a period of inactivity (from 15 minutes up to 24 hours, with a one-minute warning) and, optionally, a maximum session length regardless of activity. Members who belong to more than one firm get the strictest policy. Sensitive actions (inviting or removing members, changing roles, transferring ownership, changing the session policy, exporting or deleting your account) ask you to confirm your identity with a fresh one-time code, and a firm admin can sign any member out of every device. From Settings → Account you can see each device signed in to your account, sign out any one of them, or sign out of all your other devices with one click. Sign-in is via Google, Microsoft, or one-time email codes.
Not yet — we publish what we have, not what we plan. Our cloud infrastructure providers hold their own certifications, but GleanMark itself does not claim SOC 2 today. If your firm needs specific answers for a security review, our Security Pack PDF covers data handling, isolation, retention, and vendors on two pages, and we will answer questionnaires directly.
Download the Security Pack, or send your firm’s security questionnaire to privacy@gleanmark.com — we answer them directly.