← Word Add-in

Privacy Policy

OpenCaseLaw Word Add-in — Effective September 2, 2026

1. Provider

This add-in is provided by OpenCaseLaw, operated by Jonas Hertner.
Website: opencaselaw.ch
Contact: team@jonashertner.com

2. What the add-in does

The OpenCaseLaw Word Add-in lets you look up Swiss court decisions and statute articles and insert citations directly into your Word document. Optional Pro features verify references (Verify), enrich a paragraph with leading cases (Strengthen), find decisions supporting a statement (Ground), check every citation in a document (Audit) and offer a literary reflection on a draft (Mirror). Three of these use AI; see section 4.

3. Data we process

We process data only when you explicitly trigger an action. What leaves your machine depends on the feature:

4. Pro features and AI processing

Three of the Pro features forward text to Anthropic's Claude for analysis. Two do not:

Text sent to Anthropic is processed at the time of the request. We do not store it (see section 10) and we send no IP address, license key or other identifier with it. Anthropic processes the request under its commercial API terms; retention on Anthropic's side is outside our control. Anthropic's privacy policy: anthropic.com/privacy.

5. Redaction of personal data before Pro requests

Law-firm documents routinely contain client names, social-security numbers, bank details and addresses. Before any Pro request leaves Word, the add-in runs a redaction step in your browser. It is always on: there is no setting to disable it, and if the redaction module fails to load the request is refused rather than sent unredacted.

What it does. The redactor is pattern-based (regular expressions), not an AI model. It replaces matches in nine categories with numbered placeholders such as [NAME_1] or [AHV_1]:

The mapping from placeholder to original stays in your browser and is never transmitted; only the placeholders are. Every occurrence is numbered separately, so the same person appearing three times becomes three different placeholders. When the server's answer quotes your text, the add-in restores the original wording locally before displaying it. When anything was redacted, the Verify, Strengthen, Ground and Audit result views show how many items were redacted and of which kind, so you can check what was caught; the Mirror view does not currently show this.

What it does not do. The redactor does not recognise every piece of personal data. In particular it does not catch:

Legal citations (BGE, BGer, docket numbers, statute references) are not targeted by the patterns and normally remain intact, so that verification works.

Server-side check. Our server re-runs the five structural patterns (e-mail, AHV, IBAN, CHE, phone) on every incoming Pro request. If any of them matches, the request is rejected with an error and not processed; the rejection names only the pattern type, never the matched text. Whatever passes is scrubbed once more with the same five patterns before any AI call. The server does not re-check names, addresses or dates of birth.

Redaction reduces the personal data that leaves your machine. It does not eliminate it and is not a guarantee of anonymity. You remain responsible for deciding whether a given document may be processed with the Pro features, and for anonymising it beforehand where your professional-secrecy or data-protection obligations require it.

6. No tracking

The add-in does not use cookies, analytics, tracking pixels, or any form of behavioral monitoring. It sends one optional, anonymous usage signal: a monthly-rotating install-cohort hash used solely to estimate the number of active installations. The hash changes every month and cannot be linked across months or to you; you can disable it at any time under Settings → Anonymous usage signal, and the add-in works identically without it. Details are in the OpenCaseLaw privacy notice.

7. Personal data

We do not collect personal data from free-tier users. For Pro subscribers, we store only the email address provided during checkout. All payment processing is handled by Stripe — we never receive or store credit card numbers or bank details.

8. Third parties

Your data is sent only to our own API server (mcp.opencaselaw.ch). The only third-party sub-processors are:

No data is sold, shared with advertisers, or used for any purpose beyond providing the service.

9. Data location

Our API server is hosted by Hetzner in Germany. Data transmitted to Anthropic is processed according to Anthropic's infrastructure policies.

10. Data retention

Search queries and document text are processed in real time. Document text is never stored on our server, whether redacted or not. Pro usage is recorded as the feature used and the time of use against your license key; further technical logging (cost ledger, daily quotas) is described in the OpenCaseLaw privacy notice linked below. When semantic re-ranking runs, the query text (200 characters at most) is recorded in an internal quality log — with no IP address, no user ID and no session reference, so entries cannot be attributed to you or to one another — and is automatically deleted per the retention period stated in the OpenCaseLaw privacy notice. Pro subscriber email addresses are retained for the duration of the subscription and deleted upon cancellation.

11. Your rights

You may request access to, correction of, or deletion of any personal data we hold by writing to team@jonashertner.com.

12. Changes to this policy

We may update this policy from time to time. The effective date at the top of this page will be revised accordingly. Continued use of the add-in after changes constitutes acceptance of the updated policy.

This policy is written in English. German, French, and Italian versions are available on request at team@jonashertner.com.