Luris LogoLuris

Privacy Policy

Last Updated: 29 June 2026

1. Introduction

This Privacy Policy describes how Lex Coverage and Advisory Private Limited (CIN: U69100DL2025PTC446249, PAN: AAGCL2447K), incorporated under the Companies Act, 2013, with its registered office at H No. 6, LGF, Vikram Vihar Extension, Lajpat Nagar (South Delhi), New Delhi – 110024, Delhi, India (collectively, "Luris", "Company", "we", "us", or "our"), collects, processes, discloses, and protects personal data in connection with www.luris.in and all associated services (collectively, the "Platform").

This Policy is framed with reference to the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, and rules made thereunder. We recommend reading this Policy in full.

2. Definitions

  • "Data Fiduciary": the Company, which determines the purpose and means of processing personal data.
  • "Data Principal": the individual to whom personal data relates.
  • "Data Processor": an entity that processes personal data on behalf of the Company.
  • "Personal Data": any data about an individual who is identifiable by or in relation to such data.
  • "Processing": any operation performed on personal data, including collection, storage, use, sharing, transmission, and erasure.
  • "User Content": case descriptions, documents, agreements, or other material you submit to the Platform.
  • "AI Features": Case Prediction, Agreement Analyzer, Legal Roadmap Generator, the AI Legal Research Assistant, and any successor or additional AI-powered feature on the Platform.

3. Scope and Applicability

This Policy applies to all individuals who visit, register on, or submit information to the Platform in their personal or professional capacity ("Users"). Where the Company in the future enters into enterprise or institutional agreements with law firms, corporate legal departments, or other organizations ("Enterprise Customers"), data submitted by individuals under such an agreement may instead be governed by the terms of that specific agreement, with the Company acting as a Data Processor on the Enterprise Customer's behalf. As of the date of this Policy, the Company offers its Services directly to individual Users on a self-service basis, and this Policy governs accordingly.

4. Personal Data We Collect

4.1 Account Information

Name, email address, phone number, and authentication credentials, collected via Firebase Authentication at registration and account use.

4.2 Payment Information

Transaction metadata (amount, date, status, payment reference ID) for credit purchases. We do not store your card, UPI, or bank account details — these are collected and processed entirely by our payment partner, Razorpay, under its own security and compliance framework (including PCI-DSS).

4.3 Case and Document Information ("User Content")

Case descriptions, uploaded agreements, dispute particulars, and any other material you submit for AI-assisted analysis. This category may include:

  • Sensitive details about your own legal matters;
  • Information about third parties (e.g., opposing parties, witnesses, other individuals named in a dispute) that you submit in the course of describing your matter — see Section 8 for how this is handled.

By submitting User Content, you provide your implied consent for us to use that data solely to generate the specific output you have requested. We do not use User Content for any purpose beyond this, and we do not use User Content to train, fine-tune, or otherwise improve our AI models.

You may delete your submitted User Content from our storage at the end of your session, using the option provided at the end of each results page (for example, following a Case Prediction, Agreement Analysis, or Legal Roadmap output). If you do not use this option, your User Content will be retained in accordance with Section 10. Please note that your account registration information and financial/transaction records are retained separately, as required for legal, regulatory, and accounting purposes, and are not affected by this deletion option.

4.4 Communication Information

Content of messages, support requests, or feedback you send us, together with your name and contact details.

4.5 Usage and Technical Data

IP address, browser and device type, operating system, pages visited, feature usage patterns, query volume, and session duration.

4.6 Cookies and Similar Technologies

See Section 15.

4.7 Information from Third Parties

If you are referred to the Platform by another user, or if we engage marketing or analytics partners in the future, we may receive limited contact or referral information about you from such sources.

4.8 Publicly Available Information

We use publicly available Indian Supreme Court and High Court judgments — sourced from official and public repositories of court records — to build and maintain our proprietary judgment databank. This is addressed specifically in Section 8.

5. How We Use Personal Data

We process personal data to:

  • Create, authenticate, and administer your account;
  • Process payments and maintain transaction and billing records;
  • Generate the specific AI-assisted output you request (case predictions, agreement analyses, roadmaps, research responses);
  • Provide customer support and respond to queries or grievances;
  • Maintain, monitor, and improve the security, stability, and performance of the Platform;
  • Detect, investigate, and prevent fraud, abuse, or violations of our Terms;
  • Comply with applicable law, regulatory requests, or valid legal process;
  • Communicate with you about your account, transactions, or material changes to our Services or policies.

We do not use your personal data for unrelated marketing or advertising purposes without separately obtaining your consent.

6. Legal Basis for Processing

Our basis for processing personal data is your consent, obtained at account creation and/or at the point you submit information for a specific feature. We do not currently rely on any other legal basis (such as a certified legitimate use under the DPDP Act) for processing personal data.

You may withdraw consent at any time per Section 12. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

7. Who We Share Personal Data With

We share personal data with the following categories of recipients, each engaged for the stated purpose only:

  • Google LLC (Gemini API) — processes case descriptions, documents, and queries submitted to AI Features, for the purpose of generating the requested analytical output.
  • Supabase — hosts our structured database, including the judgment databank, user credit balances, and transaction records.
  • Firebase (Google) — manages authentication and account credentials.
  • Razorpay — processes payment transactions.
  • Professional Advisors — our auditors, chartered accountants, and legal counsel may access limited personal data (e.g., transaction records for audit purposes) strictly as necessary for their engagement.
  • Regulators, Courts, and Law Enforcement — where required by valid legal process, statutory obligation, or court order.
  • Business Transferees — in the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the successor entity, subject to equivalent privacy protections.

We do not sell personal data to third parties for advertising or marketing purposes.

8. Personal Data in the Judgment Databank

Our proprietary databank consists of Indian Supreme Court and High Court judgments. These are public judicial records, published by the courts themselves as part of the public record of judicial proceedings, and routinely relied upon by legal researchers, advocates, and citizens under the principle of open justice.

These judgments necessarily contain personal data of the litigants, witnesses, and other individuals named in them — persons who are not Users of the Platform and have not provided consent to us directly. We process this data on the basis that:

  • It originates from and remains part of the public judicial record;
  • Our processing (indexing, search, and AI-assisted analysis for legal research purposes) is consistent with the public and precedential function that published case law already serves;
  • We do not use this data to build profiles of, market to, or take any adverse action against the individuals named in such judgments — our use is confined to legal research and case-law analysis.

If you are an individual named in a judgment within our databank and have concerns about its inclusion, contact our Grievance Officer (Section 16).

9. Cross-Border Data Transfer

Certain processing described in Section 7 — including AI processing via Google's Gemini API — may involve transfer of personal data outside India. Under Section 16 of the DPDP Act, such transfers are permitted except where the Central Government has specifically restricted transfer to a particular country by notification. As of the date of this Policy, no such restriction notification affects our processing. We will update this Policy if that changes.

10. Data Retention

We retain personal data only as long as necessary for the purposes in this Policy, or as required by law:

  • Account information: retained for the duration of your account, and for a limited period thereafter for legal and accounting purposes.
  • Payment and transaction records: retained in accordance with statutory recordkeeping requirements under Indian tax and company law (typically several years).
  • User Content (case data, documents): retained for the duration of your active session and a reasonable follow-up period thereafter to support related features (such as follow-up chat), and in any case no longer than 12 months from submission, unless a longer period is required by law.

Upon expiry of the applicable retention period, we will delete or anonymize the relevant personal data, except where retention is required by law.

11. Data Security

We implement technical and organizational measures appropriate to the risk of processing, including:

  • Encryption of data in transit;
  • Row-level security policies restricting database access by role, including default-deny configurations for sensitive tables such as credit balances and transaction records;
  • Access controls limiting internal access to personal data on a need-to-know basis;
  • Use of a service-role credential, distinct from the publicly exposed client key, for any operation requiring elevated database privileges.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Your Rights as a Data Principal

Under the DPDP Act, you have the right to:

  • Access a summary of personal data we hold about you and the processing activities undertaken;
  • Correction of inaccurate or misleading personal data, and completion of incomplete personal data;
  • Erasure of personal data that is no longer necessary for the purpose it was collected, unless retention is required by law;
  • Grievance redressal through our Grievance Officer (Section 16);
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity;
  • Withdraw consent at any time, without affecting the lawfulness of prior processing.

To exercise these rights, contact us using the details in Section 17.

13. Significant Data Fiduciary Status

The DPDP Act allows the Central Government to designate certain Data Fiduciaries as "Significant Data Fiduciaries" based on factors such as the volume and sensitivity of personal data processed, risk to Data Principals' rights, and use of new technology. As of the date of this Policy, the Company has not been so designated. If designated in the future, we will comply with the additional obligations that apply, including appointing an India-based Data Protection Officer and conducting periodic data protection impact assessments, and will update this Policy accordingly.

14. Children's Privacy

The Platform is intended for individuals 18 years of age or older. We do not knowingly collect personal data from individuals below this age. If we become aware of having done so, we will take steps to delete such data promptly.

15. Cookies and Tracking Technologies

We currently use only essential cookies necessary for authentication and session management. We do not currently use third-party advertising or tracking cookies. This section will be updated if that changes.

16. Grievance Redressal

Grievance Officer: Saurabh Sharma, Legal Director Email: support@luris.in Address: H No. 6, LGF, Vikram Vihar Extension, Lajpat Nagar (South Delhi), New Delhi – 110024, Delhi, India

We will acknowledge grievances within 24 hours and endeavour to resolve them within 15 days.

17. Data Breach Notification

In the event of a personal data breach likely to result in harm to affected Data Principals, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Act and its rules.

18. Relationship with Other Policies

This Policy should be read together with our Terms and Conditions and AI Policy, which together govern your use of the Platform.

19. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified via email or a prominent Platform notice prior to taking effect.

20. Governing Law and Jurisdiction

This Policy is governed by Indian law. The courts at Delhi shall have exclusive jurisdiction over disputes arising in connection with this Policy.

21. Contact Us

Lex Coverage and Advisory Private Limited H No. 6, LGF, Vikram Vihar Extension, Lajpat Nagar (South Delhi), New Delhi – 110024, Delhi, India Email: support@luris.in