Privacy Policy

Effective Date: February 26, 2026

This Privacy Policy describes how ReferWise, Inc. (“ReferWise,” “we,” “us,” or “our”) collects, uses, discloses, and protects your personal information when you use the ReferWise platform at referwise.ai and related services (the “Platform”). This Policy applies to all users of the Platform, including attorneys who create accounts and individuals who interact with the Platform through referral intake forms or partner links.

By using the Platform, you consent to the practices described in this Privacy Policy. If you do not agree, please do not use the Platform.

1. Information We Collect

1.1 Information You Provide

We collect information you voluntarily provide when creating an account, using Platform features, or contacting us, including:

  • Account registration data (name, email address, phone number, bar admission number(s), jurisdiction(s) of admission)
  • Professional profile information (practice areas, firm name, years of experience, office address)
  • Matter and referral data (matter descriptions, conflict check information, engagement terms, fee arrangements)
  • Client intake data submitted through referral forms or client pages
  • Documents uploaded to the Platform (engagement letters, consent forms, intake documents)
  • Time tracking entries, billing records, and task notes
  • Payment information (processed by Stripe; we do not store full payment card numbers)
  • Communications through the Platform's messaging and notification systems

1.2 Information Collected Automatically

When you use the Platform, we automatically collect:

  • Device and browser information (device type, operating system, browser type and version)
  • Usage data (pages visited, features used, clickstream data, session duration)
  • IP address and approximate geographic location
  • Performance data (page load times, errors)
  • Cookies and similar tracking technologies (see Section 7)

1.3 Information from Third Parties

We may collect information from public state bar directories (bar admission status, admission date, disciplinary history, license status) and from Stripe in connection with payment processing and identity verification.

2. How We Use Your Information

We use collected information to: provide and operate the Platform, including matching, classification, and referral processing; verify your bar admission status and professional credentials; process payments and manage escrow transactions; send transactional communications; provide AI-assisted features; improve and optimize the Platform; enforce our Terms of Service; comply with legal obligations; and, with your consent, send marketing communications.

3. How We Share Your Information

We do not sell your personal information. We share information only in the following circumstances:

3.1 With Other Platform Users

When you participate in referral transactions, certain profile information is visible to other attorneys involved in the transaction. Matter-specific information is shared only with attorneys who have acknowledged applicable confidentiality requirements.

3.2 Service Providers (Subprocessors)

We share information with third-party service providers who process data on our behalf, subject to contractual data protection obligations:

ProviderPurposeData SharedLocation
SupabaseDatabase hosting, authenticationAll platform dataUS (AWS)
StripePayment processing, escrowPayment & identity dataUS
VercelApplication hosting, CDNApplication data, logsUS (Edge)
ResendTransactional emailEmail addresses, notification contentUS
SentryError monitoring, session replayError data, session recordingsUS
AnthropicAI featuresAnonymized matter data, user queriesUS

3.3 Legal Requirements

We may disclose information if required by law, regulation, legal process, or governmental request.

3.4 Business Transfers

In connection with a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity.

4. Data Security

We implement and maintain administrative, technical, and physical safeguards designed to protect your information, including:

  • Encryption in transit (TLS 1.2+) and at rest
  • Row-level security (RLS) policies ensuring users can only access their own data
  • Hash-chained, append-only audit logging of all data access and modifications
  • Role-based access controls with least-privilege principles
  • SSRF protection on all external-facing endpoints
  • HMAC-SHA256 webhook signature verification
  • Regular security reviews and vulnerability assessments
  • Secret scanning to prevent accidental credential exposure
  • Sentry monitoring for real-time error detection and incident response

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide Platform services. After account termination: account and profile data is retained for 30 days then deleted or anonymized; referral transaction records and audit logs are retained for 7 years; payment records are retained as required by tax and financial regulations; anonymized and aggregated data may be retained indefinitely for analytics.

6. Your Rights and Choices

You may access and download your personal information at any time through account settings. You may request correction, deletion, or a portable copy of your data by contacting privacy@referwise.ai. You may opt out of marketing communications at any time.

California Residents (CCPA/CPRA)

California residents have additional rights including the right to know, delete, opt-out of sale (we do not sell personal information), non-discrimination, and correction of inaccurate personal information.

Other State Privacy Rights

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, and others) may have similar rights. Contact privacy@referwise.ai to exercise your rights.

7. Cookies and Tracking Technologies

We use cookies and similar technologies for essential functionality (authentication, session management, security), performance monitoring, and analytics. We do not use cookies for third-party advertising or cross-site tracking.

8. AI and Automated Processing

The Platform uses AI-powered features provided by Anthropic. We minimize the data sent to AI providers; AI outputs are informational and do not constitute legal advice. Anthropic's data processing is governed by our Data Processing Agreement, which prohibits using your data to train models.

9. Children's Privacy

The Platform is intended for licensed attorneys and is not directed at individuals under 18. We do not knowingly collect personal information from children.

10. International Data Transfers

The Platform is hosted in the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before taking effect.

12. Contact Us

If you have questions about this Privacy Policy, please contact us at:

ReferWise, Inc.
Privacy Officer: privacy@referwise.ai
General: hello@referwise.ai
Website: https://referwise.ai


Last Updated: February 26, 2026 · © 2026 ReferWise, Inc. All rights reserved.