The Rag Group LLC ("Company," "we," "us," or "our") operates Case Strategy Services, an AI-powered legal research platform for VA-accredited attorneys, claims agents, and Veterans Service Organization (VSO) representatives. We are a limited liability company organized under the laws of the State of California. Our registered/mailing address is 2108 N Street, Suite N, Sacramento, CA 95816.
Privacy Contact:
Email: clientservices@projectrag.co
Mailing: The Rag Group LLC, 2108 N Street, Suite N, Sacramento, CA 95816
For GDPR/international data inquiries, the same contact applies. We will respond within 30 days.
This Privacy Policy applies to:
This Policy does not apply to:
At Registration / Checkout
During Use
Authentication & Session Data (via Clerk, Inc.)
Usage and Technical Data
Rate Limit and Security Logs
To let you revisit recent work, the Service saves your most recent research sessions in your web browser's local storage (a feature of your browser, on your own device). This includes the queries you submitted and the results and summaries returned to you.
We also store small, non-personal interface preferences locally (such as light/dark theme and text size). These contain no personal or client information.
| Purpose | Legal Basis (GDPR) | Data Used |
|---|---|---|
| Delivering the Service (processing queries, returning results) | Performance of contract | Queries, account credentials, session data |
| Processing payments and managing subscriptions | Performance of contract | Email, organization or practice name; payment data processed by Stripe |
| Authentication and access control | Performance of contract | Email, session tokens, org membership |
| Rate limiting and security enforcement | Legitimate interests | IP address, query timestamps |
| Responding to support requests | Legitimate interests | Email, message content |
| Detecting and preventing fraud, abuse, and security threats | Legitimate interests | IP address, usage patterns, security logs |
| Complying with legal obligations | Legal obligation | As required by applicable law |
| Improving service reliability (aggregated, de-identified analytics only) | Legitimate interests | Anonymized usage metrics - never individual queries |
We do not use your data for:
Every search query you submit passes through the following pipeline. We disclose this in full because VA-accredited professionals have confidentiality and professional obligations regarding claimant and client data.
Optional - Attached Documents. If you attach a document (PDF or TXT) for context or to draft an argument, its text is extracted in your browser where possible. For scanned/image-based PDFs with no selectable text, page images are sent to Anthropic's Claude API for optical character recognition (OCR). Extracted text is used solely as context for your request, is capped to a limited number of characters before being sent to the AI, and is not written to persistent storage by Company. Under Anthropic's standard commercial API terms, API inputs and outputs are not used to train its models, but may be retained by Anthropic for a limited period as described below.
Step 1 - Embedding (OpenAI OpCo, LLC). Your query text is sent to OpenAI's text-embedding-3-large API to generate a vector representation. Under OpenAI's standard Services Agreement, API inputs are not used to train or improve its models unless the customer explicitly agrees to that use. OpenAI's Services Agreement is available at openai.com/policies/services-agreement.
Step 2 - Vector Search (Qdrant). The resulting vector is used to search our case law database hosted on Qdrant Cloud. No identifiable user information is passed to Qdrant at this step - only the query vector.
Step 3 - Summary Generation (Anthropic, PBC). Retrieved document excerpts and your original query are sent to Anthropic's Claude API to generate a summary. Under Anthropic's standard commercial API terms, API inputs and outputs are not used to train its models. Anthropic's privacy practices are available at anthropic.com/legal/privacy.
Conversational Follow-Ups. If you ask a follow-up question about results currently displayed in the active session, the question and relevant displayed result passages are sent through our backend to Anthropic's Claude API to generate the answer. The follow-up uses only that displayed result set; it does not retrieve new sources or create server-side conversation history.
Step 4 - Response Delivery (Vercel / DigitalOcean). Results are returned to your browser via our Vercel-hosted frontend and DigitalOcean-hosted backend.
AI Provider Retention. Under their standard API terms, OpenAI and Anthropic may retain API inputs and outputs for up to approximately 30 days for service delivery, abuse prevention, security, or legal compliance, subject to exceptions in their applicable terms. Company does not use a separately negotiated zero-data-retention arrangement. Neither provider uses API inputs or outputs to train its models by default.
Query Log Retention: Query logs are retained on our backend only for a limited period necessary for security monitoring and service integrity, after which they are deleted. Queries are not linked to individual client matters in our systems.
Professional Recommendation: We recommend anonymizing or generalizing queries wherever possible to avoid including identifying claimant or client information. Consult the rules, standards, and organizational policies applicable to your accreditation or license before submitting matter-specific queries.
| Cookie / Technology | Provider | Purpose | Duration |
|---|---|---|---|
| Session token | Clerk, Inc. | Authentication - maintains your logged-in state | Session / up to 7 days |
| CSRF token | Clerk, Inc. | Security - prevents cross-site request forgery | Session |
| Google Fonts | Google LLC | Typography rendering; your browser requests font files from Google (no advertising or analytics integration) | Browser cache |
| Static script CDN | Cloudflare, Inc. (cdnjs) | Serves the in-browser PDF text-extraction library (pdf.js); your browser requests script files from cdnjs (no advertising or analytics integration) | Browser cache |
We do not use:
You may configure your browser to block or delete cookies and other site data. Blocking session cookies will prevent login and use of the Service. Blocking requests to Google Fonts will cause font fallbacks but will not affect Service functionality.
Because we do not track users across third-party websites or over time, we do not serve targeted advertising, and we treat all users the same regardless of any "Do Not Track" (DNT) browser signal. We do not need to respond to DNT signals differently because we do not engage in the cross-site tracking those signals are designed to limit.
We do not sell personal information. We share information only as follows:
The following vendors process data on our behalf to deliver the Service. Each is bound by the data processing terms of its respective agreement and is prohibited from using your data for its own purposes beyond service delivery.
| Subprocessor | Function | Data Shared | Data Residency |
|---|---|---|---|
| OpenAI OpCo, LLC | Query embedding | Query text | United States |
| Anthropic, PBC | AI summary generation & document OCR | Query text, retrieved excerpts, attached document text | United States |
| Qdrant Solutions GmbH | Vector database (Qdrant Cloud) | Query vectors, document metadata | United States |
| Clerk, Inc. | Identity & access management | Name, email, session credentials | United States |
| Stripe, Inc. | Payment processing | Billing info, email | United States |
| Vercel, Inc. | Frontend hosting & CDN | Browser requests, session tokens | United States / global edge network |
| DigitalOcean, LLC | Backend hosting | Application data, server logs | United States |
| Upstash, Inc. | Rate-limiting datastore (Redis) | IP address, account identifier | United States |
| Plus Five Five, Inc. (Resend) | Transactional welcome-email delivery | Name, email address, and transactional message content | United States |
| Google LLC (Google Workspace) | Business email for support and rights requests | Email address and the content of correspondence you send us | United States / global infrastructure |
| Google LLC (Google Fonts) | Web-font delivery | IP address and font-file request metadata; no query or document content | Global infrastructure |
| Cloudflare, Inc. (cdnjs) | Static script delivery for in-browser PDF extraction | IP address and asset-request metadata; no query or document content | Global edge network |
Locations above describe the known configured region or primary infrastructure for the listed service. A provider may use subprocessors or global infrastructure as described in its own terms and data-processing documentation.
We may disclose information if required by law, court order, or regulatory process. We will provide prompt notice to you before disclosure where legally permitted, so you may seek a protective order.
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred to the successor entity. We will notify you via email and in-app notice before your information becomes subject to a different privacy policy.
We may share information for other purposes with your prior written consent.
| Data Category | Retention Period |
|---|---|
| Account information (name, email, organization or practice) | Duration of subscription; within 30 days after termination we delete or anonymize data accessible through systems and accounts we control and instruct applicable subprocessors to delete it under their terms, except where longer retention is required by law |
| Query logs | A limited period for security and service integrity, then deleted |
| Recent sessions stored locally in your browser (Section 3.4) | Stored only on your device; erased on sign-out, on manual clear, or when the rolling session cap (currently 3) discards older sessions. Never stored on our servers. |
| Payment records | As required by Stripe and applicable tax/financial law (typically 7 years) |
| Security logs (IP, rate limit violations) | A limited period for security purposes, then deleted |
| Support correspondence | 2 years from resolution |
| Aggregated, de-identified analytics | Indefinitely (no personal data retained) |
Upon termination or expiration of your subscription, within 30 days we will delete or anonymize personal data accessible through systems and accounts we control and instruct applicable subprocessors to delete it under their terms, or act sooner upon a verified request, except where longer retention is required by law. Subprocessors may retain limited copies for the periods allowed by their standard terms, backup schedules, security requirements, or legal obligations. You may request written confirmation of the steps taken.
We implement the following technical and organizational measures:
Company intends to pursue SOC 2 Type II certification. We will announce attainment in the Service and via email to subscribers.
No security system is impenetrable. If you believe your account has been compromised, contact clientservices@projectrag.co immediately.
Regardless of location, you may:
To exercise these rights, email clientservices@projectrag.co. We will respond within 30 days.
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we share it.
Right to Delete: You may request deletion of personal information we have collected, subject to certain exceptions (e.g., legal obligations, security purposes).
Right to Correct: You may request correction of inaccurate personal information.
Right to Opt Out of Sale or Sharing: We do not sell personal information and do not share personal information for cross-context behavioral advertising. No opt-out mechanism is required because we do not engage in these activities.
Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for purposes beyond what is necessary to provide the Service.
Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
How to Submit a Request: Email clientservices@projectrag.co with "CCPA Request" in the subject line. We will verify your identity before processing the request and respond within 45 days (extendable by 45 additional days with notice).
Authorized Agent: You may designate an authorized agent to submit a CCPA request on your behalf by providing written authorization and verifying your identity directly with us.
CCPA Categories of Personal Information Collected:
| CCPA Category | Collected | Sold | Shared |
|---|---|---|---|
| Identifiers (name, email, IP) | Yes | No | No (except subprocessors) |
| Commercial information (subscription, billing) | Yes | No | No (except Stripe) |
| Internet/electronic activity (queries, usage) | Yes | No | No (except subprocessors for delivery) |
| Professional/employment information (organization or practice name, accreditation or license status) | Yes | No | No |
| Sensitive personal information | No | N/A | N/A |
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and applicable national law:
Legal Bases for Processing: See the table in Section 4.
Data Transfers: Personal data of EEA/UK/Swiss residents is processed in the United States. Where required for such transfers, we will put in place appropriate safeguards, such as the European Commission's Standard Contractual Clauses. Contact clientservices@projectrag.co regarding international data-transfer terms.
Right to Lodge a Complaint: You have the right to lodge a complaint with your local supervisory authority. A list of EEA supervisory authorities is available at edpb.europa.eu. The UK supervisory authority is the Information Commissioner's Office (ico.org.uk).
All Users remain solely responsible for the confidentiality, competence, verification, and conduct requirements applicable to their VA accreditation, professional license, and organization. Attorneys also remain responsible for compliance with applicable Rules of Professional Conduct, including:
Company processes User Content as a third-party service provider in circumstances intended to preserve applicable legal privileges and protections, consistent with the common-interest doctrine and the functional-equivalent-of-employee doctrine where recognized. However, the applicability of these doctrines and other protections varies by role and jurisdiction and is not guaranteed. Users are advised to consult qualified counsel or the appropriate supervising or compliance authority before submitting protected content to any third-party service.
Company will assert applicable privileges to resist compelled disclosure of User Content in legal proceedings to the extent permitted by law.
The Service is not HIPAA-compliant. Do not submit protected health information (PHI). If you inadvertently submit PHI, notify us immediately at clientservices@projectrag.co.
The Service is intended exclusively for eligible VA-accredited attorneys, claims agents, and VSO representatives, including through eligible subscribing law firms and VA-recognized veterans service organizations. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that a minor has provided personal information, we will delete it promptly.
We may update this Privacy Policy from time to time. For material changes - defined as changes that expand data collection, alter data sharing practices, or materially reduce your rights - we will provide at least 30 days' prior notice via email and in-app notification before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
Prior versions of this Privacy Policy are archived and available upon request at clientservices@projectrag.co.
For privacy questions, rights requests, or data inquiries:
The Rag Group LLC
2108 N Street, Suite N, Sacramento, CA 95816
Email: clientservices@projectrag.co
For DMCA notices: clientservices@projectrag.co
For GDPR/international data requests, include "GDPR Request" in the subject line. Response within 30 days.