Privacy & Legal

Privacy Policy & Legal Notices

Last updated: July 23, 2026

Ross helps law firms send routine client updates from attorney-approved templates, with a human reviewing what you choose before anything sends. Because that work touches privileged client information, we keep our data practices and the terms of service in plain sight. This page covers both: how we handle data, and the terms and legal notices that govern the service.

Privacy Policy

Operated by {{LEGAL ENTITY NAME}} ("Truth Computing", "we", "us"), the maker of Ross.

This policy explains what information Ross collects, why, and what we do with it. Ross is a business-to-business service used by law firms (our "customers"). Most of the personal information in Ross belongs to the firm's own clients and matters; the firm decides what to put into Ross and remains responsible for it. We handle that information on the firm's behalf and under its instructions.

In short

Your data is yours. We process it to run the service you asked for, we do not sell it, we do not use your clients' information or your documents to train external or third-party AI models, and you can export or delete it. The rest of this section is the detail.

1.Information we handle

Depending on how your firm configures Ross, this can include:

  • Firm & account data. Names, work email addresses, roles, and login credentials of the attorneys, paralegals, and administrators you invite. Passwords are stored only as salted hashes.
  • Client & matter data. Client names, mobile phone numbers, case or matter identifiers, case-file events, cadence preferences, and the consent status of each client.
  • Messages & communications. The template-based updates drafted for and sent to clients, inbound replies (including opt-out keywords such as STOP), and the approval decisions your team makes.
  • Documents. Legal documents, matter files, and their extracted events that your firm uploads or connects for drafting, review, deadline, and retrieval features.
  • Billing data. Your plan, active-case count, and billing contact. Card and bank details are entered directly with our payment processor and are never received or stored by us.
  • Operational logs. A tamper-evident, hash-chained audit trail of who drafted, approved, edited, and sent what and when, plus standard security and diagnostic logs. Audit and integration logs are designed not to record message bodies, document contents, full email bodies, or secrets.

2.How we use it

We use the information above only to provide and support the service, specifically to:

  • Draft client updates by selecting from your attorney-approved template library, and route anything uncertain to a human for review;
  • Capture and honor client consent and opt-outs, and send messages only within permitted local time windows;
  • Run the document, deadline, filing-check, review, and fact-retrieval features your firm enables;
  • Maintain the audit trail, enforce access controls, secure the service, and prevent abuse;
  • Provide support, and bill you for your plan.
On AI

Ross does not write free-form, client-facing prose about legal matters. For client messaging, the model's only role is to pick an approved template variant or to escalate to a human. We do not use your clients' personal information, your matter data, or your documents to train models that serve anyone other than your firm, and we do not sell or share that information for advertising.

For client and matter data, your firm is the controller (or "business") and Ross acts as a processor (or "service provider"): we process that data under your instructions and the agreement between us. For your own account and billing data, and for securing the service, we act as controller. Where data-protection law applies, we rely on the performance of our contract with you, our legitimate interest in operating and securing the service, and - for communications to clients - the consent your firm is responsible for obtaining and that Ross records. Where a firm processes protected health information, a Business Associate Agreement (BAA) is required before that data is placed in Ross.

4.Sub-processors

We use a small set of vetted providers to run the service. Each receives only what it needs, and only when your firm enables the relevant feature:

ProviderPurposeData involved
StripePayment processingBilling and card data (entered directly with Stripe)
SMS carrier / messaging providerDelivering and receiving text messagesClient phone numbers and message content
Google (Gmail / Drive)Optional mailbox drafts and document access, when connectedEmails and documents you authorize
Microsoft (Outlook)Optional mailbox drafts, when connectedEmails you authorize
Cloud hosting & object storageRunning the service and storing documents (tenant-scoped keys)All service data, isolated per firm

The current list of sub-processors is available on request at the contact below. We will make commercially reasonable efforts to notify customers of material changes.

5.Retention & deletion

We keep your data for as long as your account is active or as needed to provide the service. The audit trail is intentionally append-only and tamper-evident, so it is retained for the life of the account as a record of what was sent and approved. You can export your data, including the audit trail, at any time. On request, or after your account closes, we will delete or return customer data within a commercially reasonable period, except where we must retain it to comply with law. Your data isolation to your firm is enforced throughout.

6.Security

  • Data is isolated per firm (tenant-scoped), and access is role-enforced and logged.
  • Documents pass an egress gate before any storage or model call.
  • Passwords are salted and hashed; sessions and cookies are secured in production.
  • The hash-chained audit log makes tampering with the record detectable.
  • Secrets, document contents, and full message bodies are kept out of integration and audit logs.

No service can promise perfect security, but we work to protect your data and to be honest about how it is handled.

7.Your rights & choices

Individuals whose data a firm has placed in Ross (for example, a firm's clients) should contact that firm to exercise access, correction, deletion, or opt-out rights, because the firm controls that data; we will assist our customer in responding. Firm users can update their own account details or ask us to do so. Clients can opt out of messages at any time by replying STOP (or CANCEL, END, QUIT, UNSUBSCRIBE), which revokes consent immediately. Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA/CPRA; contact us and we will honor those rights as the law requires.

↑ Back to top of Privacy Policy

Terms of Service & Legal Notices

These terms govern access to and use of Ross. By using Ross, your firm agrees to them. If a signed master agreement exists between your firm and Truth Computing, that agreement controls where it conflicts with these terms.

8.Ross is not a law firm

Important

Ross is a software tool, not a law firm, and does not provide legal advice. Using Ross does not create an attorney-client relationship with Truth Computing. Ross does not practice law: it drafts from your attorney-approved templates and never sends a substantive legal reply on its own. A licensed member of your firm remains responsible for supervising client communications and for all legal judgment. Descriptions of Ross reflect its system design, not a guarantee of any particular outcome or performance.

9.Your responsibilities

As a condition of using Ross, your firm agrees that it will:

  • Obtain consent. Secure any consent required by law (including under the TCPA and similar rules) before messaging a client, and maintain the lawful basis for each contact. Ross records consent and enforces opt-outs, but obtaining valid consent is the firm's obligation.
  • Supervise communications. Have a qualified person review what your plan is set to review, and remain responsible for the accuracy and appropriateness of every message, draft, and document Ross assists with.
  • Curate templates and inputs. Approve the template library and clauses Ross draws from, and ensure the matter data and documents you place in Ross are accurate and that you are permitted to process them.
  • Handle sensitive data properly. Not place protected health information in Ross without a signed BAA, and comply with your own professional, ethical, and confidentiality obligations.
  • Use it lawfully. Not use Ross to send unlawful, harassing, or deceptive messages, to violate anyone's rights, or to breach applicable law or bar rules.
  • Secure your accounts. Keep credentials confidential and manage your users' access and roles.

10.Your data & ownership

As between the parties, your firm owns its data and the content it puts into Ross. You grant us only the limited rights needed to operate the service for you. We claim no ownership of your client information or documents. You can export your data, including the audit trail, and the record is always yours. We retain ownership of the Ross software, its templates, interfaces, and underlying technology.

11.Fees & billing

Ross is billed month to month at the platform fee plus a per-active-case fee shown at checkout, with no per-user seats. Payments are handled by Stripe. Billing is based on the active cases your firm covers for the billing month. You can cancel at any time, effective at the end of the current billing period; fees already incurred are non-refundable except where required by law. We may change pricing on reasonable prior notice.

12.Disclaimers & limitation of liability

The service is provided "as is" and "as available," without warranties of any kind, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, non-infringement, or that the service will be uninterrupted or error-free. Ross assists your firm's work; it does not replace professional legal judgment, and you are responsible for reviewing its output.

To the fullest extent permitted by law, Truth Computing will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenues, data, or goodwill, arising out of or relating to the service. Our total aggregate liability arising out of or relating to the service will not exceed the fees your firm paid to us for the service in the twelve (12) months preceding the event giving rise to the claim. Some jurisdictions do not allow certain limitations, so some of the above may not apply to you.

13.Indemnification

Your firm agrees to indemnify and hold harmless Truth Computing from claims, damages, and costs arising out of your firm's data, your use of the service in breach of these terms, your failure to obtain required client consent, or your violation of law or the rights of a third party.

14.Suspension & termination

Either party may terminate for convenience with reasonable notice; you can cancel at any time as described above. We may suspend or terminate access if these terms are breached, if use of the service creates a legal or security risk, or as required by law. On termination you can export your data, and we will delete or return customer data as described in the Privacy Policy.

15.Changes to these terms

We may update this page from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify customers. Continued use of Ross after a change takes effect means the updated terms apply.

16.Governing law

These terms are governed by the laws of {{GOVERNING JURISDICTION, e.g. the State of ___, USA}}, without regard to its conflict-of-laws rules, and the parties submit to the exclusive jurisdiction of the courts located there, except where applicable law provides otherwise.

17.Contact

Questions about privacy, data, or these terms:

↑ Back to top of Terms