Version 2026-09-01 · Last updated 13 September 2026
If you read nothing else, read this. The full notice follows underneath and is the one that governs.
Nautilus is operated by LEGAL ENTITY NAME, legal form, registered at REGISTERED ADDRESS, company number NUMBER ("Nautilus", "we", "us").
Contact for privacy matters: privacy@nautilus.legal Data Protection Officer: NAME / EXTERNAL FIRM, dpo@nautilus.legal EU representative (Art. 27 GDPR), if applicable: NAME AND ADDRESS
Which role we play depends on the kind of account you hold. The account type is set when the account is created and is visible in your account settings.
Firm accounts — a seat provided to you by a law firm or other organisation. For the matters you bring through that seat, your firm is the controller and we act as its processor: we act on its documented instructions under a data processing agreement, and the firm decides what is collected, why, and for how long it is kept. Questions about that material go to your firm first. We remain the controller of your login credentials and of our own security and billing records.
Consumer accounts — an account you opened yourself, as a private individual. Here there is no firm above you, so Nautilus is the sole controller of everything you type, upload and receive. Every obligation in this notice lands on us directly.
We collect only what the service needs. There is no tracking pixel, no advertising identifier and no behavioural profile.
| Data | Where it comes from |
|---|---|
| Email address (your username) | You, at registration or from Google sign-in |
| Password hash | You, at registration — we never store the password itself |
| Email verification status | Our verification flow, or Google's email_verified claim |
Google account identifier (sub) and email |
Google, only if you choose Google sign-in |
| Account type (firm or consumer), age confirmation | You, at registration |
| Domain entitlements, administrator flag, usage allowance | Us |
| Invite code used, and the codes you issued if you are an administrator | You / us |
| Data | Notes |
|---|---|
| The messages you send | Stored on the conversation, and separately as a search query |
| A numerical representation (embedding) of your question | Used to find relevant law; it is still your data |
| Documents you upload | The extracted text, plus the file where a draft references it |
| Answers, drafts, arguments and summaries we generate | Stored so you can return to them |
| Feedback and issue reports you submit | Including any free text you write |
Uploaded documents are limited to 50 pages per document and 150 pages per chat session. Scanned documents are put through optical character recognition — see section 9.
| Data | Notes |
|---|---|
| Token and cost usage per request | How your allowance is counted |
| Login sessions (device-bound refresh token records) | So you can log out, everywhere |
| Failed login counts | Rate limiting, to stop password guessing |
| Consent records | Append-only: every grant and every withdrawal, with the policy version you saw |
| Audit records | Data-subject requests, deletions, sub-processor changes, and every administrator access to customer content |
| Server and application logs | Technical operation and security |
We do not operate a marketing analytics stack, session replay, or any
non-essential cookie. Our /api/analytics endpoint is an internal, aggregate
operational view for administrators.
A dismissal question contains health data. A family matter contains data about children. A question about a religious holiday at work contains religious belief. We cannot filter that out of legal questions — it is the legal question.
If you hold a consumer account, we ask for your explicit consent before your first legal-research question, in a separate step that is not bundled into these terms or into registration. Until you give it, the assistant will not search or answer — the request stops before anything is retrieved, and nothing is sent to the AI model.
Withdrawing is one click, in account settings, and takes effect on your very next question. Withdrawal does not undo processing that already happened lawfully, and it does not delete your history — use the deletion right in section 8 for that.
If you hold a firm account, your firm's lawful basis covers this material (Art. 9(2)(f) GDPR — the establishment, exercise or defence of legal claims, backed by professional secrecy rules), and we process it on your firm's instruction. We do not ask you individually for consent, because it would not be ours to collect.
Data about criminal offences — including suspicions, charges and allegations, not just convictions — may be processed only under the control of an official authority or where a national law authorises it. Consent is not a route.
So, for consumer accounts, we take the cautious position: where your question concerns a criminal matter, we decline it and refer you to a criminal defence lawyer or the appropriate public service in your country. The message you sent is not stored. If you reopen that conversation you will see a placeholder where your text was; that is deliberate, not a bug.
This restriction is set per market. It is enabled for every market we currently serve and will only be lifted where we can name the national provision that authorises it.
Firm accounts are not affected, because a law firm acts under its own professional authority.
Worth stating plainly, because it is easy to assume otherwise: if you are a private individual, your conversation with Nautilus is not privileged legal correspondence. It does not have the protection from disclosure that a conversation with your own instructed lawyer would have. Consider that before you describe something to us that you would not want read by anyone else.
Consumer accounts are for people aged 18 or over, and you confirm your age at registration. We do not verify identity — that would mean collecting more data about you, not less — but if we learn that an account belongs to a minor we will close it and erase the data. Nautilus is not designed or intended for children.
| Purpose | Legal basis |
|---|---|
| Creating and running your account; authenticating you | Art. 6(1)(b) — performance of our contract with you |
| Answering your legal questions, storing your conversations, generating drafts | Art. 6(1)(b), and for consumer accounts Art. 9(2)(a) explicit consent for the sensitive part |
| Sending verification, password-reset, export and account emails | Art. 6(1)(b) |
| Google sign-in, where you choose it | Art. 6(1)(b) — an alternative way of performing the same login |
| Rate limiting, abuse prevention, security logging | Art. 6(1)(f) — our legitimate interest in keeping the service and your case material secure. We have documented the balancing test and you may ask for a summary |
| Counting usage against your allowance | Art. 6(1)(b) |
| Consent and access audit records | Art. 6(1)(c) with Art. 5(2) — we are required to be able to demonstrate compliance |
| Responding to your data-subject requests | Art. 6(1)(c) |
| Processing your content for firm-account matters | Art. 28 — on your firm's documented instructions; the basis is your firm's |
We do not process your content to train, fine-tune or evaluate AI models. If we ever want to, we will ask for separate, opt-in consent, and you will be able to say no and carry on using the service exactly as before.
Nautilus produces legal research, drafts and summaries. A person — you, or your lawyer — decides what to do with them. We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR.
Two automated steps do run before an answer is produced, and you should know about them:
The second may pause the turn to ask you a clarifying question; the first may decline the turn as described in section 3.2. Neither produces a decision about you. If you think a decline was wrong, contact us — a human will look at it.
Under Art. 50 of the EU AI Act, we tell you clearly and in every answer that you are interacting with an AI system and that the output is AI-generated. That disclaimer is delivered by the server with every answer so it cannot be accidentally omitted by an app.
| Recipient | What they do | Where | What they see |
|---|---|---|---|
| Hetzner Online GmbH | Hosting, database, file storage | Finland / Germany | Everything, at rest |
Anthropic PBC — DIRECT API / AWS Europe, Bedrock eu-central-1 |
Generates the answers | United States / Frankfurt, EU — CONFIRM WHICH IS LIVE | Your question, your uploaded document text, and the retrieved law |
| Mistral AI SAS | Optical character recognition on scanned uploads | France | Scanned documents you upload |
| Scaleway SAS (Transactional Email) | Sends account emails | Paris, France | Your email address and the message body |
Each of these is bound by a written data processing agreement under Art. 28(3) GDPR, including confidentiality obligations, security measures, and deletion or return at the end of the contract. Our AI providers are contractually bound not to retain your content beyond the request and not to train on it.
Sub-processor changes. The current list is published at nautilus.legal/subprocessors. We will give at least 30 days' notice before adding a new sub-processor, and firm customers may object.
Google Ireland Limited, only if you choose "Sign in with Google". We ask
Google for the minimum — openid and email — and store three things: the
stable Google account identifier, the email address, and whether Google says it
is verified. We request no access to your mailbox, your files or your contacts,
and we do not hold a refresh token. Google processes the sign-in under its own
privacy policy, as a controller in its own right. You can revoke our access at
any time at myaccount.google.com/permissions.
To build the corpus of laws and court decisions that Nautilus searches, we process published legislation and published judgments — public documents, not your content. That work uses OpenAI, L.L.C. (United States) for text extraction. It never touches a customer account, a conversation or an upload. We list it here because published judgments do contain personal data about the parties, and you are entitled to know it happens.
We disclose data to public authorities only where we are legally obliged to, and to professional advisers under confidentiality. If Nautilus is ever sold or merged, your data may transfer to the acquirer under this notice; we will tell you before it happens.
We never sell your data and we never share it for advertising.
| Data | Retention |
|---|---|
| Your account and conversations | For as long as your account is open |
| Conversations you delete ("bin") | Purged 30 days after you delete them |
| The text of your questions and their embeddings | Cleared after 90 days; the usage row survives without them |
| Uploaded document text held in the working cache | 12 hours |
| Uploaded files | For the life of the conversation that references them |
| Feedback and issue reports | 24 months |
| Login sessions (refresh tokens) | 30 days, or until you log out; expired records are swept |
| Email verification and password-reset links | 1 hour for export links; short-lived, single-use for the rest |
| Data export archives | 1 hour after the download link is issued |
| Inactive consumer accounts | Warned by email at 24 months of inactivity, erased at 30 months |
| Accounts you have asked us to delete | Erased 30 days after the request — see section 8 |
| Consent records | For the life of the account plus the limitation period — they are the evidence of what you agreed to |
| Audit records | Retained after erasure, with you replaced by an irreversible pseudonym |
| Server and security logs | 90 days |
| Backups | 35-day rolling window — see section 8 |
These windows are enforced by a scheduled job, not by hand.
Under the GDPR you have the right to access your data, to rectify it, to have it erased, to restrict or object to processing, to portability, and to withdraw consent at any time. Exercising any of these costs nothing and will never degrade the service you receive.
| Right | How |
|---|---|
| Access and portability (Art. 15, 20) | Account settings → Download my data. We build a complete machine-readable JSON archive of every table that holds your data and email you a download link. The link expires after one hour and requires you to be logged in |
| Erasure (Art. 17) | Account settings → Delete my account. Access ends immediately; erasure happens after a 30-day grace period |
| Withdraw consent (Art. 7(3)) | Account settings → sensitive-data consent toggle. One click, effective on your next question |
| Rectification (Art. 16) | Account settings, for your email address and account details |
We do not ask a logged-in user to prove their identity to exercise a right — you are already authenticated, and demanding ID would itself be excessive collection.
Signing in again during the 30-day grace period cancels the deletion. After that:
Erasure is immediate in the live system. Backups rotate on a 35-day cycle, so a copy may persist in an offline backup for that long; backups are not used for anything except disaster recovery, and a restored backup has the deletion re-applied.
Send these to privacy@nautilus.legal. We answer within one month, and will tell you if we need the extension the GDPR allows for complex requests.
If you hold a firm seat, address requests about matter content to your firm, which is the controller. We will assist it in answering you, and we will forward your request to it if you send it to us.
Tell us first — privacy@nautilus.legal — and we will try to fix it. You are entitled to complain to a supervisory authority regardless, in the EU/EEA country where you live, where you work, or where you think the problem happened. Our lead supervisory authority is AUTHORITY NAME. In Switzerland, the Federal Data Protection and Information Commissioner. In Montenegro, the Agency for Personal Data Protection and Free Access to Information.
Our hosting is in Finland, our OCR provider is in France, and our email sender is in France. That is the whole picture for those flows — no transfer mechanism is needed.
The one exception is AI inference. Where answers are generated through the Anthropic API, your question and any uploaded document text are transferred to the United States. We rely on the EU–US Data Privacy Framework where the recipient is certified, and on the 2021 Standard Contractual Clauses otherwise, supported by a transfer impact assessment, encryption in transit, and a contractual no-retention, no-training commitment. You can request a summary of that assessment.
REMOVE THIS BLOCK ONCE EU INFERENCE IS LIVE — and replace section 9 with "all processing takes place within the EU/EEA". The code already supports
LLM_PROVIDER=Bedrockwithaws_region=eu-central-1.
If a personal data breach occurs, we notify the competent supervisory authority within 72 hours where required, and we tell you without undue delay where the breach is likely to result in a high risk to you.
We use the browser's local storage for exactly one thing: keeping you signed in. Your session token is stored on your device so you do not have to log in on every page load. That is strictly necessary for a service you asked for, so no consent banner is required and none is shown.
We set no advertising cookies, no analytics cookies and no third-party trackers. If that ever changes, you will be asked first, with rejecting as easy as accepting.
Nautilus serves English, German, Dutch and Serbian markets. This notice is published in each of those languages, and the version in your own language governs your relationship with us. Where a translation and the English text conflict on a point of substance, tell us — it is a mistake we want to fix.
We will update this notice as the service changes. The version identifier at the top tells you which version you are reading, and your consent records store the version you saw when you agreed. For material changes we will notify you by email and, where the change affects processing that rests on your consent, ask you again rather than assume.
LEGAL ENTITY NAME Registered address Privacy: privacy@nautilus.legal · Data Protection Officer: dpo@nautilus.legal
| Placeholder | Needed from |
|---|---|
| Legal entity name, form, address, company number | Company records |
| Establishment country → lead supervisory authority | Counsel (also decides whether an Art. 27 representative is needed) |
| DPO name and contact | Appointment (A-03 in the compliance plan treats this as likely mandatory) |
| Art. 27 EU representative, Swiss representative | Only if the entity sits outside the EU / CH |
Whether AI inference runs on the Anthropic US API or Bedrock eu-central-1 |
Deployment — this decides whether section 9 survives at all |
| Backup rotation window (assumed 35 days) | Infrastructure |
| Sub-processor list URL | Web |
| Privacy and DPO email addresses | Web |