Effective July 27, 2026
Privacy Policy
This Privacy Policy explains how 2dcite (“2dcite,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you use 2dcite.com, related applications, and services (the “Services”). It is designed to address requirements under California law (including the California Consumer Privacy Act as amended by the CPRA, “CCPA”), the EU/UK General Data Protection Regulation (“GDPR”) where applicable, and other applicable privacy laws.
Controller contact for privacy requests: support@2dcite.com. If we appoint an EU/UK representative or DPO, we will update this page.
1. Who we are and what we do
2dcite operates a marketplace that connects licensed attorneys and judges with approved 2L/3L law students for independent, human-in-the-loop citation verification of legal work product. We process account data, eligibility materials, uploaded documents, review findings, payment metadata, certificates, and operational logs to provide that service—not to sell personal information or to provide legal advice.
2. Categories of information we collect
Depending on your role and use of the Services, we may collect:
- Identifiers & account data: name, email address, role (attorney, judge, student, admin), bar or license number (attorneys/judges), organization name if provided.
- Authentication credentials: we store only a one-way password hash (bcrypt). We do not store passwords in plain text and cannot recover your original password.
- Student eligibility data: law school, year (2L/3L), professor name and email, proof documents (enrollment, legal writing, recommendation), and approval status.
- Job & review content: document titles, optional instructions, uploaded PDFs or tables of authorities, citation findings, overall notes, certificates, and related status history.
- Commercial & payment data: fee amounts, membership status, payout hold/release state, and Stripe identifiers. Card numbers and full payment credentials are processed by Stripe; we do not store full card numbers on 2dcite servers.
- Technical & security data: IP address (best-effort from proxies), user agent, session tokens (hashed at rest where applicable), audit logs of security-relevant actions, and diagnostic health metrics.
3. Sources of information
- Directly from you (registration, uploads, reviews, support)
- Automatically from your browser or app (logs, security signals)
- From service providers acting on our instructions (e.g., Stripe payment confirmation webhooks, hosting)
4. How we use information (purposes)
- Create and secure accounts; authenticate sessions
- Verify student eligibility and operate admin approval
- Match jobs under a blind matching model (see §6)
- Deliver documents and findings to authorized parties; generate Certificates of Citation Review
- Process payments, memberships, fund holds, and student-share release
- Sanitize inputs, prevent abuse, detect fraud, rate-limit endpoints, and maintain audit trails
- Comply with law, respond to lawful process, and retain records for court or bar association review when required
- Communicate service, security, and transactional messages
- Improve reliability and product operations (aggregated/metrics where feasible)
5. Legal bases (GDPR / UK GDPR)
Where GDPR applies, we process personal data on one or more of these bases:
- Contract — to provide the Services you request (Art. 6(1)(b))
- Legitimate interests — security, fraud prevention, product integrity, blind-matching protection for students, and internal operations, balanced against your rights (Art. 6(1)(f))
- Legal obligation — tax, accounting, response to valid legal process (Art. 6(1)(c))
- Consent — where we expressly ask for it (and you may withdraw it without affecting prior processing)
Special-category data is not required for 2dcite. Do not upload health, biometric, or other special-category data unless you have a lawful basis and it is strictly necessary for your matter; you remain responsible for such uploads.
6. Blind matching and student identity protection
2dcite uses a blind matching system. Student reviewers are assigned without disclosing the student’s name, contact information, school, or other identifying details to the submitting attorney or judge. Client-facing job records and Certificates of Citation Review identify the reviewer only as an independent, qualified law-student reviewer. This protects students from retaliation after flagging citation errors and is designed so students can be completely candid without fear of retribution.
2dcite retains student identity and review records internally so that, if a court, bar association, or other lawful authority requires production, 2dcite can produce the retained record. Retention for that purpose does not authorize disclosure of student identity to the submitting attorney or judge in the ordinary course of the service.
In ordinary product use, submitting attorneys and judges see that a qualified student was assigned and receive findings and certificates, not the student’s name, email, school, or user id. Platform administrators may access identity as needed to operate, secure, and support the service. Students remain bound by confidentiality toward clients.
Review findings and any certificate are provided only to the submitting party through the platform (and platform administrators as needed to operate the service). Students must not share findings outside the platform.
Student reviewers are bound by confidentiality. Except as required by law, a student may not disclose any non-public information obtained through a review—including the identity of the submitting attorney or judge, the content of submitted materials, review findings, or the fact that a particular review occurred—to any third party.
7. How we share information
We do not sell personal information and we do not “share” it for cross-context behavioral advertising as those terms are defined under the CCPA. We disclose information only as follows:
- Service providers / processors: hosting (e.g. Vercel), database (e.g. Neon/Postgres), object storage, email, and Stripe for payments—under contractual confidentiality and purpose limits.
- Assigned participants: job documents and instructions to the assigned student; findings and certificates to the submitting attorney/judge—under blind matching for student identity.
- Legal & safety: when required by law, court order, bar association process, or to protect rights, safety, and integrity of the Services.
- Business transfers: in connection with a merger, acquisition, or asset sale, subject to continued protection consistent with this Policy.
8. Retention (including court and bar review)
We retain account, job, review, certificate, payment, membership, and audit records for as long as needed to operate the Services, resolve disputes, enforce agreements, secure the platform, and meet legal, tax, and professional-accountability needs.
In particular, we retain job and reviewer linkage records so that if a court, bar association, or other lawful authority requires production or review, 2dcite can produce the retained information. That retention does not mean we disclose student identity to submitting counsel in ordinary product use.
When retention is no longer necessary, we delete or de-identify data subject to backup cycles and legal holds. You may request deletion (see §11–12); we may decline or limit deletion where we must retain records for legal holds, fraud prevention, accounting, or ongoing disputes.
9. Security measures
- TLS encryption in transit for the hosted website and API
- Passwords stored only as bcrypt hashes (not plain text); session tokens handled with secure cookie practices
- Role-based access control (attorney/judge, student, admin) and authorization checks on job endpoints
- Input validation and sanitization (length limits, control-character stripping, schema validation) on user-supplied fields
- Rate limiting on authentication and other abuse-sensitive endpoints
- Audit logging of security-relevant actions
- Payment card data handled by Stripe (PCI DSS–compliant provider); not stored as full PANs on 2dcite
No method of transmission or storage is 100% secure. By uploading materials, you acknowledge that transmission and storage involve residual risk, and that 2dcite’s security measures do not create liability for unauthorized access, disclosure, or loss of confidential information beyond what applicable law non-waivably requires.
2dcite takes no responsibility for confidential, privileged, sealed, or otherwise sensitive documents or information you choose to upload. You are solely responsible for determining what material is appropriate to submit and for complying with court orders, professional obligations, and applicable law. Submissions may be limited to a table of authorities (or a comparable list of citations) solely to confirm the existence and citation form of authorities. You are not required to upload an entire brief or order if a limited submission is sufficient for the review you request.
10. International transfers
We are based in the United States. If you access the Services from the EEA, UK, or other regions, your information may be processed in the United States and other countries where our providers operate. Where required, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses) with processors.
11. Your privacy rights (California — CCPA/CPRA)
If you are a California resident, you may have the right to:
- Know / access categories and specific pieces of personal information we collected about you
- Delete personal information, subject to legal exceptions
- Correct inaccurate personal information
- Opt out of sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising)
- Limit use of sensitive personal information to purposes necessary to perform the Services (we use sensitive data such as account credentials and professional identifiers only as described here)
- Non-discrimination for exercising CCPA rights
Categories collected (for CCPA notice-at-collection style transparency) include identifiers, professional information, internet or electronic activity (logs), commercial information (transactions), and inferences only as needed for matching and fraud prevention—not for advertising profiles.
To exercise rights, email support@2dcite.com with “California Privacy Request” in the subject. We will verify your identity (e.g., account email control) before fulfilling. You may use an authorized agent as permitted by law.
We do not use or disclose sensitive personal information for purposes that require a right-to-limit beyond what is necessary to provide the Services.
12. Your privacy rights (GDPR / UK GDPR)
Where GDPR applies, you may have rights to access, rectification, erasure, restriction, portability, and objection (including to processing based on legitimate interests), and to withdraw consent where processing is consent-based. You may lodge a complaint with your local supervisory authority. Contact support@2dcite.com to exercise rights. We may need to retain certain records as described in §8.
13. Cookies and similar technologies
We use essential cookies and similar storage for authentication (session), security, and load balancing. We do not operate third-party advertising cookies on the core product surfaces described here. Browser controls may block cookies; blocking essential cookies may prevent sign-in.
14. Children
The Services are for adults engaged in legal practice or law study (2L/3L). We do not knowingly collect personal information from children under 16 (or under 13 where COPPA applies). Contact us to request deletion if you believe we have collected such data in error.
15. Intellectual property notice (related to our systems)
The 2dcite software, source code, documentation, branding, and build artifacts are owned by 2dcite LLC and are protected by United States copyright law and other applicable intellectual property laws. © 2026 2dcite LLC. All rights reserved.
No license—express, implied, or statutory—is granted to copy, modify, distribute, reverse engineer, create derivative works of, or commercially exploit the 2dcite code, build, or related materials, except as expressly authorized in a separate written agreement signed by 2dcite LLC. Access to the hosted service under these Terms is a limited, revocable right to use the Platform as an end user, not a software license or transfer of ownership.
This section concerns ownership of our software and materials; it does not transfer ownership of the legal documents you upload. You retain rights in your submissions, subject to the limited license needed for us to host, process, match, and deliver the Services.
16. Changes to this Policy
We may update this Policy from time to time. We will post the revised version with an updated effective date. Material changes may also be communicated by email or in-product notice where appropriate.
17. Contact
Privacy and data-protection requests: support@2dcite.com