Our role
Neomatter reads the requests that reach a customer’s legal team, gathers relevant context from the systems the customer connects, and prepares analyses, recommendations and draft replies for the customer’s lawyers to review. Customers control their data. When we process customer data in Neomatter, we do so on the customer’s behalf and under our agreement with that customer.
Data we process
We process data submitted to or connected with Neomatter, including:
- Account and team profile information, such as names, work email addresses and roles.
- Requests and the material that comes with them, including messages, emails, attachments, comments and matter records.
- Content from systems the customer chooses to connect, such as documents, agreements, CRM records and tickets, used as context for the work.
- The work Neomatter produces, including analyses, recommendations, citations, playbooks, decisions and draft replies.
- Integration metadata and encrypted connection tokens.
- Operational metadata and audit events.
- Minimized product analytics and diagnostic events used to operate and improve the service, such as opaque session/page/interaction identifiers, screen or view labels, structural control identifiers, timestamps, durations, and request outcomes. These events are designed not to include field values, rendered text, names, email addresses, message bodies, attachment contents, or legal work product.
Neomatter may process legally privileged, confidential, personal, or commercially sensitive information when customers submit it through requests, emails, attachments, or integrations.
When you visit neomatter.com, our hosting provider records standard request logs. The website does not use advertising cookies or load advertising or analytics scripts. If you reach the website by clicking one of our Google ads, Google adds a click reference to the page address. If you then book a demo from that page, the reference is passed to Cal.com with your booking, and we report to Google Ads that a demo was booked from that ad click, along with the booking time. We do not send Google your name, email address, or other booking details. When you book a demo, we receive the details you enter, such as your name and email address; bookings are handled through Cal.com.
How we use data
We use data to:
- Provide Neomatter: open matters from incoming requests, gather context, prepare analyses, recommendations and draft replies, and track matters and decisions.
- Learn and apply a customer’s own positions and playbooks, for that customer only.
- Authenticate users and enforce tenant isolation.
- Maintain audit logs, security logs, backups, and operational reliability.
- Detect abuse, investigate incidents, and comply with legal obligations.
- Improve product quality using aggregated or minimized analytics.
Replies are sent only when an authorized user chooses to send them. We do not sell customer data, and we do not use customer data to train generalized, public, or third‑party AI models.
Google API Limited Use
If a customer connects Gmail or another Google API integration, Lightfield’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When a customer connects Google Workspace, Neomatter receives the Gmail messages, headers, attachments, and mailbox identifiers needed to create matters and apply Neomatter mailbox labels. If the user grants the separate read-only permissions, Neomatter also searches files across the Google Drives the user can access, downloads or exports selected file content for bounded text extraction, and reads Google Calendar event details to add relevant context to the user’s work. Neomatter does not request Google Contacts access and cannot edit, move, share, or delete Drive files.
We share, transfer, or disclose Google user data only as needed to provide this functionality:
- To Render, which hosts the Neomatter API and workers that process the connected data.
- To Supabase, which hosts Neomatter’s tenant-isolated application database and stores the resulting matter records, source references, and encrypted integration-token records.
- To Amazon Web Services and Google Cloud, which store encrypted backups of the application database for recovery.
- To the OpenAI API, which processes the minimum relevant content needed for classification, summarization, routing, preparation, and connected-context features. We configure supported model requests with response storage disabled (
store=false), do not opt Google user data into model-training data sharing, and do not permit Google user data to be used to train generalized or foundational AI models.store=falseis not represented as zero data retention; limited provider security or abuse-monitoring retention may still apply under the provider’s API terms. - To the customer’s authorized Neomatter users, when the data or derived output is displayed as part of the service.
We do not transfer Google user data to advertising platforms, data brokers, or model gateways, and do not sell Google user data. Human access is limited to security, support, legal, or compliance purposes with customer authorization, when required to operate the requested feature, or as required by law.
AI processing
Neomatter uses the OpenAI API directly for its AI features, including classification, summarization, routing, research across connected context, and drafting. We do not route customer or Google user data through an AI gateway or model hub. AI processing is limited to providing Neomatter, and we do not use customer-identifiable content to train generalized, public, or third-party AI models.
Security
We use access controls, audit logging, encryption in transit, encryption at rest, tenant-scoped authorization, session revocation, encrypted backups, and secure development controls to protect customer data. We have completed a SOC 2 Type I examination by an independent CPA firm. Security incidents are handled under our incident response plan.
Retention and deletion
Customer data is retained according to our Data Classification and Retention Policy. Authorized administrators can request or initiate organization export and deletion. Some records may be retained as required for security, legal, audit, backup, or compliance purposes.
Subprocessors
Our core service providers are:
- Render, for application hosting.
- Supabase, for database services.
- Vercel, for web hosting.
- OpenAI, for AI processing.
- WorkOS, for sign-in and authentication.
- Amazon Web Services and Google Cloud, for encrypted backups and key management.
- Stripe, for billing.
- GitHub, for engineering operations.
- Axiom and Better Stack, for redacted operational telemetry.
Optional Google, Microsoft, Slack, Salesforce, Atlassian, Zendesk, ServiceNow, and similar integrations process data only when enabled by the customer. Our logging controls are designed to exclude Google user content, prompts, documents, tokens, and message bodies from operational telemetry.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information. If you use Neomatter through your organization, please contact your organization first, since it controls that data; we will help it respond. You can also contact us directly at the address below.
Changes
We may update this policy as Neomatter changes. We will post the updated version here with a new date, and communicate material changes through the product or customer channels.
Contact
Privacy requests and security reports can be sent to security@neomatter.com.
© 2026 Lightfield, Inc.