Data Retention & Security Policy

B8R Legal — last updated 5 August 2026

What we actually do to protect your data

These are specific, current measures rather than general assurances, because this is the standard we expect to be judged against:

How long we keep things

DataKept for
Your cases, clients, payments, vendors, tasksAs long as your account is active
All of the above, after you delete your accountErased from live systems immediately
Residual copies inside encrypted backupsAged out within 30 days
Wallet and payment records needed for tax and accountingAs long as tax law requires us to keep them
Grievance and support correspondenceAs long as needed to show the complaint was handled

We hold no archive of your data older than 30 days. That is a deliberate limit, not an oversight: we do not want to be sitting on old copies of privileged client information. It also means that once 30 days have passed we cannot restore your records, however good the reason.

You must keep your own copy of anything you need long-term. Your professional obligations may require you to retain case and financial records for years — far longer than we hold anything. Export regularly from Profile → Backup & export.

Exporting your own records

You can export your cases to a CSV file at any time from Profile → Backup & export, choosing active, archived, or all cases. The file is yours to store wherever you keep your practice records.

If you may need to produce app records as evidence, keep the exported file unmodified along with a note of when you exported it. An electronic record produced in court needs a certificate confirming it has not been tampered with, and an untouched export with a known date is far easier to certify than a screenshot.

What we ask of you

Most real-world data loss starts on the user's side. Please:

If there is a breach

If personal data held by us is breached, we will notify the Data Protection Board of India and every affected user without undue delay, describing what happened, what data was involved, what we have done, and what you should do. We will not quietly absorb an incident that affected your data.

To report a vulnerability or a suspected breach, write to support@b8r.in. Reports made in good faith are welcome and we will not pursue action against a researcher who reports one responsibly.