AAI
AAI for MerusCase
Navigate
Product How It Works Results 28 Skills
Company
About Security AI Safety Blog
Contact sean@aai.dev
← Back to AAI for MerusCase

Privacy Policy

Last updated: April 8, 2026

AAI for MerusCase ("AAI", "we", "us") is operated by AAI.dev. This policy describes how we collect, use, and protect information when you use our software.

1. What We Collect

Account Information

When you sign up: your name, email, phone number, firm name, MerusCase API token, staff role assignments, and billing information (processed by our payment provider).

Case Data

AAI accesses your MerusCase data through the MerusCase API using your API token. This includes cases, parties, events, tasks, activities, uploads, injuries, contacts, billing ledger entries, and document content.

Your case data is never stored by AAI. It is fetched live from MerusCase during each session and passes through the AI reasoning engine for processing. When your session ends, the data is not retained.

Usage Data

Query logs and audit logs are stored locally on your machine in ~/.aaicase/ with owner-only file permissions (mode 600). We do not collect or transmit this data.

2. Where Your Data Goes

Your data is transmitted to exactly two destinations: your MerusCase account (via API) and the AI reasoning engine (for query processing). No other destinations. No analytics. No telemetry. No advertising. No data brokers.

3. AI Processing

A third-party AI service processes your queries. Your data is not used to train AI models under the API terms. The AI service's data retention policy applies to data in transit.

4. Local Data Protection

  • All files in ~/.aaicase/ are mode 600 (owner read/write only)
  • API token never appears in logs or conversation history
  • Temp files use secure random directories and are deleted immediately after use
  • API response cache auto-expires
  • SSRF protection and path traversal protection enabled

5. Audit Trail

Every write operation is logged to ~/.aaicase/audit.log (append-only, never truncated) with timestamp, endpoint, case ID, and API response.

6. What We Do NOT Do

  • We do not sell, share, or disclose your data to third parties
  • We do not use your case data to train AI models
  • We do not store your case data on our servers
  • We do not collect telemetry or analytics
  • We do not access your MerusCase account outside of your active sessions

7. Your Rights

You may request deletion of your account, export your local data from ~/.aaicase/, revoke access by changing your MerusCase API token, or delete all local data by removing the directory.

8. Contact

Email: sean@aai.dev

AAI for MerusCase

AI case intelligence for California Workers' Compensation attorneys. Built by a CIO who has been inside the firms for 20 years.

Product

  • Overview
  • How It Works
  • 28 Skills

Company

  • About
  • Blog
  • Security
  • aai.dev

Contact

  • sean@aai.dev
© 2026 AAI — Augmented Artificial Intelligence.
Privacy Terms