Skip to content

Trust

Privacy notice

The short version: this site sets no cookies, runs analytics that never store anything on your device, and collects personal data only when you subscribe, email us, or appear in a public court or regulator record that we report on.

Updated 2026-09-04

1. Who is responsible

SafeLegalAI (safelegalai.com) is published by Cognesio LLP, a limited liability partnership registered in England and Wales. Cognesio LLP is the controller of the personal data described here. Contact: legal@safelegalai.com.

LegalAI Space is an affiliated product (an Omnizio LP product built by the same team at Cognesio LLP). It is a separate service with its own privacy notice; nothing you do on this site is shared with it.

2. Cookies and storage on your device

We set no cookies. The only thing this site ever writes to your browser is a single localStorage entry, theme, and only if you press the light/dark toggle. It holds the word “light” or “dark”, is never sent to us, and is strictly necessary to honour your choice. Clearing site data removes it.

Because nothing is stored on or read from your device for analytics, we do not show a cookie banner. If we ever add technology that needs consent under the Privacy and Electronic Communications Regulations, we will ask first.

3. Analytics (cookieless)

We use PostHog in its cookieless mode to understand which pages are read. PostHog is configured so that:

  • no cookies, local storage or session storage are used, and no identifier is placed on your device;
  • no person profiles are created, no session recordings are made, no surveys are shown, and we never call identify();
  • your browser's “Do Not Track” signal is respected — if it is on, nothing is sent;
  • visitors are counted with a hash computed on PostHog's servers from your IP address, user agent and a salt that changes daily and is then deleted. Your IP address is not stored and, in this mode, is not used for location lookup.

What we see: the page viewed, the referring site, screen size, browser and operating system family, and the time. Autocapture of clicks and form inputs is switched off. PostHog Inc. processes this data for us on PostHog Cloud (US region) under its data processing agreement. Our lawful basis is legitimate interests (understanding what is read so we can keep the record useful); the impact on you is minimal because no identifier persists.

4. Server logs

Like every website, our hosting infrastructure records requests (IP address, user agent, URL, time) so we can keep the site secure and diagnose faults. We do not use these logs for analytics or profiling, and they rotate within 30 days. Lawful basis: legitimate interests (security and reliability).

5. The weekly briefing

If you subscribe, your email address and the date you subscribed are processed by Buttondown, our newsletter processor, on our instructions. Open and click tracking is disabled in our account, so emails contain no tracking pixels. Every email has a one-click unsubscribe; we also delete your address on request. Lawful basis: consent, which you give by subscribing and can withdraw at any time. Buttondown is based in the United States; the transfer is covered by the data processing terms in Buttondown's agreement, including the standard contractual clauses and the UK addendum.

6. When you contact us or report something

Emails to our report and contact addresses — tips, corrections, vendor updates, rights of reply — are read by the Cognesio LLP editorial team. We keep them for as long as the matter is open and for up to two years afterwards so we can show how a record was handled. Reports may be triaged with AI tools for routing and de-duplication; decisions are made by people. Lawful basis: legitimate interests (running an accurate publication and answering you). Please do not send us information about third parties beyond what is needed to make your point.

7. Personal data in our datasets

The Incident Tracker and Regulation Tracker record what courts and regulators have decided. Judgments, orders, disciplinary decisions and official guidance are public documents, and they name lawyers, parties, firms, judges and regulators. We reproduce those names only as they appear in the public record, link the source, and record the outcome. We do not add allegations of our own.

We process this personal data under legitimate interests, for the purposes of journalism and public-interest research into AI in legal practice, and we rely on the journalism and academic/research provisions of the Data Protection Act 2018 where they apply. Where a court has anonymised a judgment, we keep the anonymisation.

If you are named in a record you can ask us to correct an error, add context or a reply, or reconsider inclusion. We correct confirmed errors with a dated note and consider every request on its facts; we do not remove accurate reports of public court or regulator findings simply because they are unwelcome.

8. Links to other sites

External links open in a new tab and take you to sites we do not control; their privacy notices apply. Links to commercial vendors carry referral tags (utm_source and similar) so the vendor can see that traffic came from SafeLegalAI; those tags contain no information about you. Links to courts, regulators and legislation carry nothing.

9. Who we share data with

Only the processors named above — PostHog (analytics), Buttondown (newsletter) and our hosting provider — each under a contract that limits what they may do with the data. We do not sell personal data, run advertising, or share it with LegalAI Space or any other business.

10. Your rights

Under the UK GDPR (and the EU GDPR if you are in the EEA) you can ask for access to the personal data we hold about you, have it corrected or erased, restrict or object to its processing, and receive a copy in a portable form. Some rights are limited where we process public-record data for journalism. Write to legal@safelegalai.com; we respond within one month. You can also complain to the Information Commissioner's Office (ico.org.uk) or, in the EEA, to your local supervisory authority.

11. Retention, security and children

We keep personal data only as long as the purposes above require: analytics events are aggregated by PostHog and raw events expire under its retention settings; newsletter addresses until you unsubscribe; correspondence for up to two years after a matter closes; dataset records for as long as they are part of the public record we maintain. Data is protected with access controls, encryption in transit and the security practices of our processors. This site is not directed at children and we do not knowingly collect data from anyone under 16.

12. Changes

We update this notice when our practices change and show the date at the top. Related pages: disclaimer and terms, editorial standards, about and ownership.