Vendor terms, cited cell by cell
Legal AI vendor terms index - what the public terms actually say (September 2026)
Small firms are told to "check the vendor's terms" before putting client data into an AI tool - the SRA's warning notice on AI misuse says firms should understand the safeguards that apply and ensure they are appropriate to the sensitivity of the information processed. This index does the first pass for you: what eight legal AI tools actually publish about training use, retention, deletion, subprocessors and hosting, cited to the source page for every cell. Where a vendor publishes nothing on a point, we say "not published" - an absent statement is not a negative term, and the question belongs in your procurement call (our question set: /insights/legal-ai-vendor-data-security-questions/).
The index (checked 15 September 2026)
Harvey (pages checked 15 Sep 2026)
- AI training on customer data: No. Harvey "contractually guarantees through our Platform Agreement" no training on customer data; data used "only... for processing your requests, not for model improvement"; zero data retention required from its model providers. Source: harvey.ai
- Retention: customer-controlled - set your own retention policies, decide what to upload. Source: harvey.ai
- Deletion: "delete data anytime". Source: harvey.ai
- Subprocessors: list maintained at harvey.ai/legal; vendors must maintain consistent security measures (Security Addendum s.6). Source: harvey.ai
- Hosting: customer-selectable region - EU or Switzerland, US, or Australia; order form controls (Addendum s.2.1). Sources: harvey.ai , harvey.ai
Legora (pages checked 15 Sep 2026)
- AI training on customer data: not published on the pages checked (EU DPA and security page). Ask directly.
- Use restriction: Legora certifies it will not "retain, use, or disclose Personal Data outside the context of the relationship... other than to provide the Services" (DPA s.2.7). Source: legora.com
- Deletion: at the subscriber's choice and instruction, delete or return all personal data before DPA expiry, unless law requires storage (s.11.1). Source: same DPA.
- Subprocessors: list maintained with notice of changes and a subscriber right to object (s.4.2). Source: same DPA.
- Processing location: this is an availability/transfer acknowledgment, not a hosting commitment. DPA clause 5.1: the Subscriber acknowledges it may transfer personal data, or make it available by remote access, to Legora in the EU for the provision of the Services; Legora may not process personal data outside the EU/EEA, or engage sub-processors processing outside the EU/EEA, without consent - and consent is deemed given if the Subscriber has not objected to a new sub-processor within the Clause 4.2 window. So outside-EU/EEA processing is possible with (deemed) consent; "EU-only" is not what the DPA says. UK GDPR is covered alongside EU GDPR. Source: same DPA, clauses 5.1 and 4.2.
CoCounsel (Thomson Reuters) (pages checked 15 Sep 2026)
- AI training on customer data: No. "We will not, and will not permit our third-party providers to, develop, train, or fine-tune any generative/foundational AI models with User Prompts, User Content, or Outputs, unless agreed upon separately in writing." These are Thomson Reuters' generic Generative AI Terms: they can be supplemented, and applicable product-specific terms prevail over them - check the CoCounsel Core product-specific terms before relying on this cell. Source: Thomson Reuters Generative AI Terms (PDF), legalsolutions.thomsonreuters.co.uk
- Retention, deletion, subprocessors, hosting: not stated in the generic GenAI Terms document checked; the CoCounsel Core product-specific terms (which prevail over the generic terms) are linked from the same TR page and should be read before purchase.
Lexis+ AI (LexisNexis) (pages checked 15 Sep 2026)
Regional applicability: the training, retention, deletion and hosting statements below come from LexisNexis Australia's November 2024 security sheet. Confirm whether the same controls apply to a UK subscription. The subprocessors statement comes from the global processor terms.
- AI training on customer data: No - "LexisNexis Large Language Model partners are bound by our agreement to not train our custom models based on your data." Source: Lexis+ AI Security Information (PDF, LexisNexis Australia, November 2024), lexisnexis.com
- Retention: conversation history purged after 90 days or when the user deletes, whichever first; uploaded documents retained only for the active session and purged after 10 minutes of inactivity. Source: same PDF.
- Deletion: user can delete the session conversation thread. Source: same PDF.
- Subprocessors: public list, updated with at least 14 days advance notice and an objection route (global processor terms). Source: lexisnexis.com
- Hosting: private models on AWS Bedrock and Azure; prompts sent over TLS 1.2. Source: security PDF above.
Clio (Clio Duo) (pages checked 15 Sep 2026)
- Clio's Trust Center lists a Data Processing Agreement, a subprocessors page and an AI section including third-party AI diligence. Source: trust.clio.com
- AI training, retention, deletion and hosting terms specific to Clio Duo: not published in extractable form on the public pages checked (clio.com/security, trust.clio.com, clio.com/tos). Ask directly; the DPA route exists.
Spellbook (pages checked 15 Sep 2026)
- AI training / LLM retention: zero data retention agreements with both OpenAI and Anthropic - customer data in requests and responses "is not persisted and exists only in memory in order to process a request". Source: spellbook.com
- Hosting: cloud providers with data centers in Canada and the US. Source: same page.
- Subprocessors: full list in the Spellbook Trust Center. Source: same page.
- Compliance (vendor-stated): SOC 2 Type II, GDPR; EU AI Act classification as low-risk supported by an independent legal opinion (vendor-stated). Source: same page.
Robin AI (pages checked 15 Sep 2026)
- Use of data for improvement: usage data and similar information may be used "in aggregate and de-identified form, to improve and enhance the Services". Source: robinai.com
- AI training on customer data: no separate training clause found on the page checked; the aggregate/de-identified improvement clause is the relevant term. Ask directly about model training specifically.
- International transfer: customer acknowledges LLM interactions may require transfer to jurisdictions where models are hosted or operated. Source: same page.
- Deletion: on termination, securely delete or destroy, or return if directed in writing, to the extent technically possible. Source: same page.
- Subprocessors: website list with notice and objection route. UK GDPR Article 28(3) DPA. Source: same page.
Juro (pages checked 15 Sep 2026)
- AI training on customer data: No, with one carve-out - "Juro may not use Customer Data as training data for any AI models, unless the AI model is used only to provide Services to Customer (Customer-Specific Model)." Juro also assigns the customer all its rights in AI output. Source: Juro AI Terms (PDF, 11.03.25), 3786704.fs1.hubspotusercontent-na1.net
- Retention, deletion, subprocessors, hosting: Juro publishes a separate DPA (07.03.25) at its terms page; not extracted in this pass.
How to use this index
Two rules. First, "not published" is a question for your procurement call, not a mark against the vendor - absence of a public statement is not a negative term. Second, terms change: every cell carries the date we checked it, and the source link is the version of record. If you want the full question set to put to any vendor on this list, it is at /insights/legal-ai-vendor-data-security-questions/; the evaluation method is at /insights/how-to-evaluate-a-legal-ai-tool/. Firms that want this analysis run on their own shortlist: Margo Legal's readiness-audit scope and price are not yet published; the page currently describes the Workflow Value Workshop at GBP 2,500 fixed - one workflow, one half-day, ending in a written recommendation: fix, buy, pilot or stop (/consultancy/).