Legal

Privacy Policy

How your data moves through Scopient, who can access it, and the commitments we make to you.

Version 2.1 · Effective 12 June 2026 · Scopient LLC


1. Introduction

Scopient LLC ("Scopient," "we," "us," or "our") operates a billing intelligence platform that provides dashboards, analytics, and written strategic reporting ("Signals") for professional service firms. This Privacy Policy describes how we collect, use, store, share, and protect information when you use our platform at app.scopient.io and any related services (collectively, the "Service").

Most of our customers are law firms and other professional service businesses that handle confidential client information, including information that may be subject to attorney-client privilege and professional confidentiality obligations. We take our responsibility to protect this data seriously, and we have written this policy to describe — plainly and accurately — exactly how your data moves through our Service, who can access it, and the commitments we make to you.

A single principle runs through this policy: Scopient is built to work from outputs, not raw detail. The product is designed so that what we routinely use and see is the analysis it produces for you — your dashboards and Signals — rather than your underlying client and matter records.

Beta status. Scopient is currently in a beta (pre-general-release) phase, provided to a limited number of beta testers for evaluation. The Dashboard is functional but still maturing, the Signal layer is not yet available, and features, integrations, and safeguards continue to develop during this period. We will update this policy as the Service moves toward general availability.

This policy is intended to be read alongside our Terms of Service and any separately signed customer or data processing agreement. Where a signed agreement with you conflicts with this policy, the signed agreement controls. This policy is governed by the laws of the State of New York.

2. Your Role and Ours (Controller and Processor)

You — the firm — decide what billing and matter data enters the Service and for what purpose. With respect to that data, you act as the data controller (or, under U.S. state privacy laws, the "business").

Scopient acts as your data processor (or "service provider"). We process your billing and matter data only to provide the Service to you and on your instructions, as described in this policy and any signed agreement. We do not sell your data, and we do not use it for our own independent purposes.

The Service analyzes your billing data to produce metrics, comparisons against your own firm's history, written strategic reporting (Signals), and related recommendations. This policy is written to cover that analysis as the Service grows, so that adding to or automating these capabilities does not change the commitments we make to you.

You remain responsible for your own professional, ethical, and confidentiality obligations to your clients, including your obligations under applicable rules of professional conduct. We support those obligations; we do not replace them.

3. Information We Collect

3.1 Account Information

When you create an account, we collect: your name, email address, and contact details; your firm name, firm type, and firm size; login credentials managed through our authentication provider (we never see or store your password in plain text); and, if and when you are on a paid plan, billing and payment information for your Scopient subscription, which is handled by our payment processor.

3.2 Billing and Matter Data You Connect or Upload

The core of the Service involves analyzing billing data that you connect from your practice management system (for example, Clio) or upload directly. This may include: client names, matter names, and matter numbers; timekeeper names, titles, billing rates, and hours worked; time entries, narrative descriptions, and billing codes; invoice amounts, payment history, realization rates, and write-offs; cost and expense records; and engagement or matter identifiers and statuses.

Read-only connection. When you connect a practice management system, you authorize Scopient through that system's standard authorization process (OAuth). That connection is read-only: Scopient retrieves a copy of your billing data to analyze it but cannot create, edit, or delete anything inside your source system. You can revoke Scopient's access at any time from your source system, which stops any further synchronization.

Data you should not import. We do not require, and ask that you do not import, privileged attorney-client communications, the substance of legal advice, protected health information (PHI), Social Security numbers, or other special-category personal data. The Service is designed to analyze the economics of your billing — rates, hours, realization, collections — not the content of your legal work.

3.3 Usage Data

We automatically collect information about how you interact with the Service, including pages viewed, features used, dashboard configurations, report activity, browser and device information, IP address, and timestamps.

3.4 Cookies and Tracking Technologies

We use essential cookies to maintain your session and preferences, and we may use privacy-respecting analytics to understand usage patterns. We do not sell data to advertisers and do not use tracking cookies for cross-site ad targeting.

4. How We Use Your Information

We use your information to: provide the Service (generate your dashboards, analytics, and Signals from your billing data); operate, secure, and maintain the platform; provide customer support and troubleshoot issues; detect, prevent, and respond to fraud, abuse, and security incidents; send service-related notices and, with your consent, product updates; and meet our legal obligations.

When we work to improve the Service, we do so using aggregated and de-identified information, our own demo and test data, or general usage patterns — not by mining one customer's billing data to build features for, or deliver insights to, another customer. See Sections 5 and 7.

5. AI and Automated Processing

A defining feature of Scopient is that it turns your billing data into written strategic analysis. To do this, the Service uses two distinct layers, and we want you to understand the difference:

The analytics layer is deterministic code. Your dashboard figures — realization, collections, write-offs, aging, and similar metrics — are calculated by our own software from your data. No third-party AI model is involved in computing these numbers.

The Signal layer uses a large language model. To generate the written narrative of a Signal, relevant figures and context derived from your billing data are processed through a third-party AI model. Our current AI subprocessor is Anthropic, PBC (the provider of the Claude models), accessed under its business terms. We make the following commitments regarding this processing:

  • Your data is sent to the AI subprocessor only to generate or refine your own reports — never to serve another customer.
  • We use the subprocessor under business terms under which your data is not used to train its AI models. Any limited, short-term processing or retention by the subprocessor for security and abuse-prevention purposes is governed by that subprocessor's own terms.
  • Signals and related analysis may be generated through automated processing, with the involvement of authorized Scopient personnel, or a combination of both, and more of this generation may become automated as the Service matures. In every case, the commitments in this policy apply.
  • Signal output is reviewed for quality before it is treated as final. Where review requires checking a figure, that review is limited to confirming the accuracy of your own reporting.
  • We will update the named subprocessor in this policy if we change AI providers, and we will not add a materially different category of AI processing without updating this policy.

If you prefer that your data never be processed by an AI subprocessor, contact us — the deterministic analytics layer can be provided independently of the Signal layer.

6. Who Can Access Your Data

We believe in describing access honestly rather than making promises our architecture cannot keep.

We work from outputs, not raw detail. Within the product, each user's login is tied to a single firm, so we do not open your dashboard from our own account. In normal operation, what we see of your firm is the finished Signal reports generated for you — the deliverables — not your dashboard view or your underlying client and matter records. The points below describe how this works in full, including the operator access that, like any vendor, technically exists.

Tenant isolation. Scopient is a multi-tenant platform. Your data is stored in a shared database but is logically separated from every other customer's data by a unique firm identifier. Every record is keyed to your firm, every request is authenticated and scoped to your firm, and we maintain an automated test that verifies one firm's queries cannot return another firm's data. No other customer can access, see, or query your data.

Operator access. As the operator of the platform, authorized Scopient personnel have administrative access to the systems where your data is stored — as is true of essentially every software provider, including the practice management systems you already use. This capability exists so we can run, secure, and support the Service. Our policy on how we use it:

  • We access your client- and matter-level data only to provide and operate the Service, to generate and quality-check your reports and Signals, to provide support or troubleshoot at your request, or to meet a legal or security obligation.
  • We do not browse your client or matter detail for any other purpose, and we never use it for marketing, resale, or the benefit of another customer.
  • Routine product demonstrations, development, testing, and quality assurance are performed on our own demonstration and test accounts — not on customer data.
  • In normal operation, the customer data we look at is the finished Signal reports generated for you — the deliverables themselves — not your underlying client or matter records. We do not review your detailed billing records as a matter of routine.
  • When operating or supporting the Service requires us to access your specific data (for example, to diagnose a synchronization issue), we limit that access to what the task requires and will tell you when we have done so at your request.

7. How We Protect Your Data

We implement administrative and technical safeguards designed to protect your information, and we rely on our infrastructure providers for physical data-center security. These safeguards include: encryption in transit (TLS 1.2 or higher for all data moving between your browser and our servers); encryption at rest for stored data; access controls that restrict data access to authorized personnel on a need-to-know basis; reputable cloud infrastructure for hosting, deployment, and authentication; and logging and monitoring to detect unauthorized access attempts and to keep the Service running correctly. Our operational and error logs may contain technical and diagnostic information used solely to maintain, secure, and fix the Service; we do not use them to browse your client or matter detail. No method of transmission or storage is perfectly secure, but we work to protect your data using safeguards appropriate to its sensitivity. As Scopient is in a beta phase, our security program continues to mature; we describe the safeguards in place today and will strengthen them as the Service moves toward general availability.

We recognize that legal billing data may contain information connected to attorney-client privilege, work product, or professional confidentiality obligations. We commit that:

  • We will never access, review, or analyze your billing data for any purpose other than providing the Service to you and operating it as described in this policy.
  • We will never sell, share, or disclose your billing data to third parties except as described in Section 9 or with your explicit consent.
  • We will never use one customer's billing data to benefit another customer or competitor.
  • Time entry narratives and matter descriptions are processed only to generate your own analytics and Signals and are not used to train any AI model.
  • We will reasonably cooperate with your firm's ethical and confidentiality obligations, including reasonable requests connected to your duties to your own clients.

9. Subprocessors and Data Sharing

We do not sell your personal information or billing data. We share data only as follows.

9.1 Subprocessors. We use a small set of trusted providers to deliver the Service. As of the effective date, these include:

ProviderPurpose
NeonDatabase hosting (where your billing data is stored)
VercelApplication hosting and deployment
ClerkUser authentication and account management
Anthropic, PBCAI processing for the Signal layer (see Section 5)
A payment processor (e.g., Stripe)Subscription billing — used only if and when you are on a paid plan; not used during free trials or beta
Google WorkspaceBusiness email and communications

Each subprocessor is bound by its own terms and, where applicable, a data processing agreement, to protect your data and to use it only to perform services on our behalf. We maintain a current list of subprocessors and will make it available on request; we will update this policy when we add or change a subprocessor that handles your billing data.

9.2 Legal requirements. We may disclose information if required by law, regulation, legal process, or a governmental request. Where we are legally permitted to do so, we will notify you before disclosing your data so that you may seek a protective order or other relief.

9.3 Business transfers. If Scopient is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a materially different privacy policy.

10. Data Retention and Deletion

We retain your account information and billing data for as long as your account is active or as needed to provide the Service. Upon termination or your written request, we will delete or anonymize your billing data within 90 days (and will use reasonable efforts to do so sooner), except where we are required by law to retain it. You may also request export of your data in a standard format before deletion. Usage logs may be retained in aggregated, de-identified form that cannot reasonably be linked back to you.

11. Data Breach Notification

If we become aware of a security incident that compromises the confidentiality, integrity, or availability of your billing data, we will notify you without undue delay, and where feasible within 72 hours of confirming the incident, with the information reasonably available to us at the time — including what happened, what data was involved, and the steps we are taking in response. We will provide updates as our investigation progresses.

12. Your Rights

Depending on your jurisdiction, you may have the right to: access a copy of the personal information we hold about you; request correction of inaccurate information; request deletion of your personal information and billing data; request a portable export of your data; restrict how we process your information; and withdraw consent where processing is based on consent. To exercise any of these rights, contact us at the address in Section 16. We will respond within 30 days.

For California residents: we do not sell or "share" personal information as those terms are defined under the California Consumer Privacy Act, and we do not discriminate against you for exercising your rights.

13. International Users

Scopient is operated in the United States, and your data is processed and stored in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States.

14. Children's Privacy

The Service is designed for professional use and is not directed at individuals under 18. We do not knowingly collect personal information from minors and will promptly delete any such information we learn we have collected.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy at app.scopient.io and, where appropriate, by email. Material changes affecting how we handle your billing data — including any change to our AI subprocessor — will be communicated before they take effect where reasonably practicable.

16. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

Scopient LLC

Bryan Nearnberg, Founder

Email: hello@scopient.io

Website: scopient.io

Product: app.scopient.io