Last updated: April 8, 2026
AAI for MerusCase ("AAI", "we", "us") is operated by AAI.dev. This policy describes how we collect, use, and protect information when you use our software.
When you sign up: your name, email, phone number, firm name, MerusCase API token, staff role assignments, and billing information (processed by our payment provider).
AAI accesses your MerusCase data through the MerusCase API using your API token. This includes cases, parties, events, tasks, activities, uploads, injuries, contacts, billing ledger entries, and document content.
Your case data is never stored by AAI. It is fetched live from MerusCase during each session and passes through the AI reasoning engine for processing. When your session ends, the data is not retained.
Query logs and audit logs are stored locally on your machine in ~/.aaicase/ with owner-only file permissions (mode 600). We do not collect or transmit this data.
Your data is transmitted to exactly two destinations: your MerusCase account (via API) and the AI reasoning engine (for query processing). No other destinations. No analytics. No telemetry. No advertising. No data brokers.
A third-party AI service processes your queries. Your data is not used to train AI models under the API terms. The AI service's data retention policy applies to data in transit.
~/.aaicase/ are mode 600 (owner read/write only)Every write operation is logged to ~/.aaicase/audit.log (append-only, never truncated) with timestamp, endpoint, case ID, and API response.
You may request deletion of your account, export your local data from ~/.aaicase/, revoke access by changing your MerusCase API token, or delete all local data by removing the directory.
Email: sean@aai.dev