1. Scope, roles, and United States business use
This notice explains how Cannon Creations LLC ("Cannon," "we," or "us") processes information through Cannon Caseworks, its public website, contact and access flows, case workspaces, integrations, and support. The Service is intended for United States business and professional use, not personal or household use.
For case, client, and connected-account content submitted by a firm or other Customer, that Customer ordinarily determines why and how the information is processed. Cannon acts as its processor or service provider under the Data Processing Addendum. Cannon separately determines how it processes website inquiries, account administration, security, support, billing, legal-compliance, and its own service-operation information. A firm's own privacy notice, engagement terms, client instructions, and legal obligations may also apply.
Related materials: Data Processing Addendum · Terms of Service
2. Categories of information we process
We process information users provide, information obtained from sources a user connects or selects, information generated through use of the Service, and limited technical information needed to operate and protect it. Customer Content can contain personal, confidential, privileged, or sensitive information about people who never directly interact with Cannon.
- Identifiers and account data: names, work email addresses, organization, role, Firebase identifiers, invitations, membership, access permissions, acceptance records, and authentication and account-recovery events.
- Contact, professional, and commercial data: firm, job role, support or demo messages, client contacts, invoice recipients, postal addresses, phone numbers, plan, usage, rate, invoice, tax, and payment-status records. Cannon currently uses manual invoicing and does not collect payment-card credentials through the Service.
- Customer Content: documents, files, images, audio, video, email, attachments, extracted text, metadata, custodians, participants, matter details, case context, prompts, questions, notes, annotations, labels, redactions, drafts, reports, productions, and generated work product.
- Connected-account data: provider account identifiers and labels, encrypted OAuth access and refresh tokens, granted scopes, and import selections when a user authorizes an import. For Gmail, this can include the account email address, mailbox profile, message identifiers, headers, sender and recipient data, dates, message bodies, and attachments. For Google Drive, this can include the account display name and email address, file and folder identifiers, names, types, sizes, paths, URLs, timestamps, file contents, and the contents of selected folders. Comparable data can be received from Outlook or OneDrive.
- Internet, device, and operational data: IP address, user agent, device and browser attributes, authentication state, App Check and reCAPTCHA signals, local or session storage values, request and event times, audit activity, feature usage, performance, diagnostic, security, malware-scan, and error information.
- Sensitive information and inferences: Customer Content may reveal government identifiers, financial, health, disability, immigration, criminal, employment, union, religious, racial or ethnic, sexual-orientation, minor, biometric, precise-location, or other sensitive facts. The Service may derive summaries, classifications, relevance or privilege indicators, priority scores, entities, issues, timelines, and other AI-assisted inferences from Customer Content.
- Communications: contact submissions, feedback, privacy or legal requests, support correspondence, transactional emails, invitation emails, requested client communications, and manual invoices.
3. Sources of information
We receive information directly from users and Customers; from firm administrators and people who send invitations or client requests; from documents and media uploaded or imported into a workspace; from Google and Microsoft services a user expressly connects; from Firebase authentication and application-protection services; from devices, browsers, and hosting infrastructure; from service providers; and from public or legal sources when needed to protect the Service or comply with law.
We do not purchase litigation profiles or Customer Content from data brokers. A Customer may independently upload lawfully obtained public records or third-party records as part of its matter.
4. Purposes and use limitations
Except for Google Workspace API data, which is subject to the narrower rules in section 8, we use information to provide, personalize within the authorized workspace, secure, maintain, support, and bill for the Service; create and administer accounts; verify access; ingest and preserve records; scan for malware; extract and index text; run search and AI-assisted functions; create requested work product; deliver invitations and transactional messages; meter usage; maintain audit and acceptance evidence; troubleshoot; prevent fraud and misuse; enforce agreements; comply with law; and establish, exercise, or defend legal claims.
Cannon uses Customer Content only to operate the Customer's workspace and deliver requested functions. Cannon does not sell, rent, broker, advertise against, or disclose Customer Content to other customers. Cannon does not use Customer Content to train, fine-tune, benchmark, evaluate, or improve a Cannon-owned or generally available AI model or dataset and does not opt Customer Content into a provider's voluntary training or data-sharing program.
Cannon uses Operational Data to improve service reliability, security, access, capacity, and onboarding. Matter names, filenames, document text, prompts, and case facts are not used for generalized product analytics. We do not make solely automated decisions about a person's eligibility for employment, housing, credit, insurance, health care, legal services, education, government benefits, or another legally significant opportunity.
5. Disclosures and service-provider categories
Except for Google Workspace API data, which is transferred only as permitted in section 8, we disclose information only as needed for a requested function, at a Customer's direction, under a processor or service-provider arrangement, for security or legal reasons, or in a corporate transaction subject to appropriate protections. The recipients and data involved depend on which features are configured and used.
- Google Cloud and Firebase: Cloud Run backend API, processing workers and supporting compute services; Firebase authentication and email verification; Firestore records; object storage; App Check and reCAPTCHA Enterprise; cloud task infrastructure; malware scanning; Document AI OCR; and optional consent-based Firebase Analytics. These services may receive account, device, network, operational, document, media, and Customer Content appropriate to the selected function.
- OpenAI: bounded text, prompts, case context, images, audio, video, or drafts for configured generative AI analysis, synthesis, image description, or transcription. PDF and image OCR are processed through Google Document AI, not OpenAI.
- Vercel: hosting and delivery of the web application, which involves browser requests, network information, and limited operational data needed to serve the interface. Cannon's backend API, processing workers, supporting compute services, databases, object storage, task execution, and malware scanning are hosted through Google Cloud and Firebase services. Other configured search or infrastructure vendors may process encrypted or service data needed for their assigned function when disclosed and enabled.
- Brevo and communications providers: names, email addresses, delivery metadata, invitation or verification links, contact submissions, requested messages, and invoice information. Case-document content is not ordinarily sent unless a user directs it into a communication.
- Google and Microsoft source services: account, scope, token, selection, message, file, attachment, and metadata exchanges needed to preview and perform an authorized Gmail, Drive, Outlook, or OneDrive import.
- Professional advisers, authorities, and transaction parties: limited information when reasonably necessary for confidential legal, accounting, insurance, security, financing, merger, acquisition, reorganization, or asset-sale purposes, or when legally required.
6. OpenAI API processing
Cannon may send bounded case context, extracted text, user questions, images, audio, video, or draft content to OpenAI's business API for analysis, reporting, synthesis, drafting, image description, or transcription. Cannon does not use OpenAI for PDF or image OCR. Cannon uses API access rather than a public consumer chat account, sets non-storage options where the endpoint supports them, and does not opt Customer Content into OpenAI model training.
OpenAI states that API data is not used to train or improve its models unless the API customer expressly opts in. Under standard controls, abuse-monitoring logs for many endpoints may contain prompts, responses, or derived metadata and may be retained for up to thirty days, subject to legal and safety exceptions. Endpoint-specific application state, file and image scanning, and prompt-caching rules may also apply. Zero Data Retention, Modified Abuse Monitoring, regional processing, or a business associate agreement applies only if Cannon confirms the control in a signed agreement.
Related materials: OpenAI API data controls
7. Google Document AI processing
When configured, Google Document AI receives documents, images, and related metadata to extract text and layout. It is used for document processing and OCR, not as Cannon's generative model provider.
Google service-specific retention, location, logging, and abuse-monitoring terms depend on the product, account, billing status, and configuration. Do not assume that HIPAA, zero-retention, customer-managed-key, or regional controls apply unless Cannon confirms them in a signed agreement.
Related materials: Google Cloud data processing terms · Document AI security · Firebase privacy and security
8. Google Workspace API data — Limited Use
This section controls over any broader or conflicting statement elsewhere in this notice. "Google Workspace API data" means information Cannon receives from Gmail or Google Drive APIs and any information derived, aggregated, or anonymized from that data. Cannon Caseworks's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Cannon requests the Gmail read-only scope so a user can connect a mailbox, search or preview messages, and copy the messages or mailbox set the user chooses into a case. Cannon requests the Google Drive read-only scope so a user can connect an account, browse accessible files and folders, and copy the files or folders the user chooses into a case. Cannon uses the resulting Google Workspace API data only to provide or improve these prominent, user-facing case features: previewing and importing authorized records; preserving and organizing the imported records in the selected workspace; malware scanning; extracting and indexing content; searching and reviewing the case record; and generating analyses or work product the user requests from that record.
Cannon does not use Google Workspace API data for advertising or marketing; retargeting, personalized, interest-based, or user advertising; sale, rental, brokerage, or transfer to data brokers or information resellers; credit-worthiness or lending decisions; surveillance; building unrelated databases; generalized product analytics; or any purpose unrelated to providing or improving Cannon Caseworks's user-facing functionality.
Cannon does not retain or use Google Workspace API data to develop, improve, train, or fine-tune generalized or non-personalized artificial-intelligence or machine-learning models. Cannon does not transfer Google Workspace API data to another party for those purposes. An imported record may be sent in bounded form to an approved processor, such as OpenAI, only when necessary to provide or improve a specific user-facing feature the user requests or enables, and subject to terms that prohibit the processor from using that data to train generalized or non-personalized AI or ML models.
Cannon transfers Google Workspace API data only with the user's consent when necessary to provide or improve the user-facing features described above; when necessary for security, such as investigating abuse; when required to comply with applicable law; or as part of a merger, acquisition, or sale of assets after obtaining the user's explicit prior consent. Cannon does not permit employees, contractors, or other humans to read Google Workspace API data unless the user affirmatively agrees to the review of specific data, access is necessary for security or legal compliance, or the data has been aggregated for lawful internal operations. Processors receive only the data reasonably necessary for their assigned function and must protect it and follow these limitations.
OAuth credentials are encrypted, restricted to the authorized user, provider, case, and import, and deleted when the import completes, is cancelled, fails, or expires after twenty-four hours. Imported Google records are protected in transit and at rest and remain in the selected workspace until an authorized deletion or case-file purge, subject to a legal hold, limited recovery copies, or law. Revoking Google access stops future API access but does not delete records already imported; an authorized user may delete those records in Cannon or request deletion using the contact in section 16.
Related materials: Google API Services User Data Policy
9. Connected-account imports
Gmail and Google Drive imports use provider-specific read-only scopes. Outlook and OneDrive imports use Microsoft Mail.Read or Files.Read together with the limited identity and refresh access needed for a one-time import. A user chooses the provider, authorizes access on the provider's page, previews results, and selects or confirms the material to copy into a case.
Cannon encrypts OAuth credentials and binds an import grant to one provider, case, user, and import. Grants are configured to expire after twenty-four hours and are deleted on completion, cancellation, failure, or expiry. Provider and infrastructure logs or backups may follow separate retention. Revocation prevents future access but does not remove messages, files, attachments, or metadata already copied into the workspace.
10. Cookies, local storage, analytics, and privacy signals
The Service uses browser local storage, session storage, IndexedDB or similar technology for essential authentication state, tab-scoped tokens, App Check, security, preferences, onboarding handoff, and workspace continuity. Firebase Authentication may maintain a browser-local sign-in session. Google reCAPTCHA Enterprise and App Check process device, interaction, and network signals to distinguish legitimate application traffic from abuse.
Firebase Analytics is optional and disabled unless Cannon enables it and the browser records an affirmative analytics choice. When enabled and accepted, it records limited onboarding and usage events such as signup completion, first case, first upload, first ready record, and first cited answer; those event parameters exclude case names, filenames, document text, prompts, and case facts. Declining analytics does not affect the Service.
Because Cannon does not use tracking for cross-context behavioral advertising, ordinary browser Do Not Track signals do not change essential processing. We treat an enabled Global Privacy Control signal as a direction not to enable optional analytics in that browser. Third-party source providers and links have their own practices.
11. Retention and deletion
We keep information only for the period reasonably necessary for the disclosed purpose, the Agreement, security, dispute resolution, or law. Exact periods vary with workspace instructions, legal holds, provider controls, backup cycles, and the type of record.
- Customer Content remains while the workspace is active and until an authorized deletion or case-file purge, subject to legal holds, provider retention, recovery copies, and signed terms. A case-file purge deletes case-scoped active records and objects but keeps a minimized case shell and deletion audit receipt. Archiving or hiding a case is not a purge.
- OAuth import grants expire after twenty-four hours and are deleted on completion, cancellation, failure, or expiry. Imported material then follows workspace retention.
- Account, membership, acceptance, access, audit, billing, invoice, transaction, security, and legal records may remain for the applicable limitations period, tax or accounting requirement, security need, or claim-preservation period.
- Contact and support records remain while needed to respond, manage the relationship, document the request, prevent abuse, and meet legal obligations.
- Encrypted backups and provider copies are removed or made inaccessible through ordinary provider cycles; standard OpenAI retention may continue after Cannon deletes its active copy.
12. Security and incidents
Cannon uses administrative, technical, and organizational safeguards designed to protect information, including authenticated role-based access, logical firm and case scoping, deny-by-default browser database and storage rules, encrypted transport, provider-managed encryption at rest, short-lived signed file access, encrypted integration credentials, integrity checks, malware screening, audit records, and incident procedures. No internet, cloud, authentication, storage, or AI system can be guaranteed perfectly secure.
After Cannon becomes aware of a security incident involving unauthorized access to, acquisition of, or legally reportable loss of Customer Content, Cannon will notify the affected Customer without undue delay and as required by applicable law, consistent with legitimate containment, investigation, remediation, and law-enforcement restrictions.
13. Privacy rights, appeals, and controller requests
Depending on applicable law, a person may request confirmation, access, correction, deletion, portability, restriction, or an explanation of processing and may appeal a denied request. A person may use an authorized agent where law permits. We verify identity, authority, and workspace ownership and may deny or limit a request when an exception applies, including privilege, another person's rights, litigation holds, court obligations, security, fraud prevention, or legal preservation.
Requests about Customer Content should ordinarily be directed to the firm or Customer controlling the workspace. Cannon will route or assist with those requests under the DPA. Requests about Cannon-controlled website, account, security, support, or billing information may be sent to the contact below. To appeal, reply to Cannon's decision with "Privacy Appeal" in the subject line and explain the basis for the appeal. Cannon will not discriminate against a person for exercising an applicable privacy right.
Cannon does not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or profile consumers for decisions producing legal or similarly significant effects. Those practices therefore have no separate opt-out mechanism beyond the analytics choice below.
Related materials: Texas Attorney General privacy complaints
14. International processing and legal bases
The standard Service is operated for United States business use, and information may be processed in the United States and other locations where approved providers operate. A Customer must not submit data requiring a particular country, region, transfer mechanism, or foreign-law agreement until Cannon confirms an acceptable configuration and signs required terms.
Where foreign law applies to Cannon-controlled data, Cannon relies as appropriate on performance of a contract, legitimate interests in providing and securing the Service, compliance with law, protection of legal rights, or consent for optional analytics. Depending on location, a person may also complain to a competent data-protection authority. No statement in this notice creates a right that applicable law does not provide.
15. Restricted data and children
The Service is not represented as HIPAA-compliant or approved for classified, export-controlled, biometric-identification, criminal-justice, payment-card-authentication, or similarly regulated data unless Cannon signs the required agreement and confirms the controls before upload. The Service is not directed to minors, and minors may not create accounts. A Customer must not submit a minor's sensitive information unless it has a lawful, necessary litigation purpose and the configured providers and written terms permit the processing.
16. Changes and contact
Cannon may update this notice prospectively as providers, features, or law change. Cannon will revise the effective date and provide reasonable notice through the Service, email, or another conspicuous method when a change materially affects the disclosed handling of Customer Content. Prior versions should be retained with Cannon's deployment and acceptance records.
Send privacy requests, authorized-agent requests, and appeals to support@cannoncaseworks.com with "Privacy" or "Privacy Appeal" in the subject line. Security concerns should use "Security" in the subject line. Include the relevant account email, Customer or firm, the right requested, and enough detail to locate the information; do not email case documents or sensitive identifiers unless Cannon provides a secure method.