You handle privileged conversations. We built CruxChat so that trusting us requires trusting almost nothing: by default we hold nothing, and what you choose to store can be made unreadable, even to us. This page shows the whole machine.
I.The default
Every conversation follows the same path through our systems, with everything deleted from our servers by default.
II.The choice
Cloud storage is optional, and is a convenient way to move conversations between devices, share conversations with colleagues, or store your conversations for later reference.
Cloud storage offers an optional level of protection. Using a passphrase adds a layer only you can unlock: your conversations are encrypted with a key only you hold, so only you can access them. Passphrase-encrypted conversations cannot be recovered by CruxChat.
| Default | Cloud save | Cloud save + passphrase | |
|---|---|---|---|
| What we hold | Nothing | Your encrypted package | Your package, encrypted on your device before it leaves |
| Who can read it | Nothing to read | You (and we can recover it for you) | Only you. We cannot decrypt it. |
| If you lose your credential | N/A | Standard password recovery | No recovery. Permanently inaccessible by design. |
| If we are subpoenaed | Nothing exists on our servers | Subject to rules governing stored records | We can confirm an account exists, but contents are not readable by us without your passphrase. |
Standard cloud save works the way virtually all professional software does: any provider that can recover your data can, in principle, access it. That is the industry norm, not a gap.
The passphrase option exists for firms that want even that possibility removed. Most firms run the default and save selectively. The passphrase is a separate credential from your password that you maintain. Not being able to recover conversations without a passphrase is the tradeoff of a storage mode with no backdoor and no admin override.
III.The precedent
In United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y. Feb. 17, 2026), a federal court held that a defendant’s use of a public, consumer AI tool to analyze his own case was protected by neither attorney-client privilege nor the work product doctrine. The materials had been seized during the government’s investigation, and the court’s ruling left them available to the prosecution. Many consumer AI products and professional legal tools are built on closely related frontier AI models; the opinion indicates that the court focused less on the AI model itself than on how the service was used, the governing contractual terms, and whether counsel directed the work.
This discussion is provided for informational purposes and is not legal advice. Whether attorney-client privilege applies depends on the facts of a particular matter and the governing law. This comparison describes the considerations discussed in the Heppner opinion and how CruxChat’s design differs in those areas.
| The court’s focus | The consumer tool in Heppner | CruxChat |
|---|---|---|
| Who uses the AI, and at whose direction | The client, acting alone. His attorneys never directed the use. | The attorney. CruxChat documents your client conversations at your direction, inside the representation. |
| What the terms allow | The platform’s consumer terms permitted collection of prompts and outputs, and allowed disclosure under specified circumstances, including to government authorities. | Contractual confidentiality agreements prohibit those uses. Your conversations are never used to train AI models. |
| What happens to the data | User inputs and outputs remained subject to the platform’s standard retention and disclosure policies. | Server data is deleted once processing completes. Storage is optional, and can be made unreadable even to us. |
Heppner did not establish that any particular AI product preserves or defeats privilege. It highlighted that attorney direction, confidentiality obligations, and data handling can matter. CruxChat’s architecture was designed with those considerations in mind: attorney-directed workflows, contractual confidentiality agreements with every processor, limited retention, and deletion once processing completes.
IV.The duties
The ABA’s formal guidance on generative AI maps your professional duties onto AI tools. Here is how CruxChat answers each one.
| Competence Rule 1.1 |
You can verify anything the AI produced. Every point in a summary cites the moment in the recording it came from, and CruxVerify checks any summary, your edits included, against the original conversation. |
|---|---|
| Confidentiality Rule 1.6 |
Client information stays protected at every step. Signed confidentiality agreements with every processor, no AI training on your data, server data deleted after processing, and optional zero-knowledge storage. |
| Supervision Rules 5.1 / 5.3 |
Nothing moves without you. Every summary is reviewed by an attorney before distribution, and all sharing is explicit and attorney-controlled. Nothing is recorded automatically, and nothing is sent automatically. |
| Communication & fees Rules 1.4 / 1.5 |
Clients stay informed, in plain English. Every client leaves every meeting with a clear written summary. The efficiency shows up as capacity, not inflated hours. |
V.The processors
Three named parties. Signed agreements with each. No one else.
| Transcription | One dedicated provider, transcription only. Operates under a signed confidentiality agreement and does not retain your audio. |
|---|---|
| AI summarization | One enterprise AI provider, summarization only. Processes your transcripts under a signed agreement, and your conversations are never used to train AI models. |
| Amazon Web Services | Infrastructure. CruxChat runs on AWS with enterprise security controls. Storage, when you choose it, is encrypted. |
No other third parties touch conversation data. No analytics vendors, no ad networks, no data brokers. A complete subprocessor list (names, roles, and the commitments each operates under) is part of the security documentation we provide during your review.
VI.The controls
| Recording starts with you | There is no bot that joins your meetings, no calendar integration that captures by default, and no ambient listening. Nothing is recorded until you start the recording. |
|---|---|
| Explicit sharing only | Packages and summaries go only where you send them, to registered CruxChat users you choose. Shared content is a copy under the recipient’s control. Nothing is linked back or distributed automatically. |
| Clean distribution | Strip internal document headers and transcript citations with one click before a document leaves your office, so clients receive exactly what they need and nothing more. |
| Two separate credentials | Your account password is recoverable the standard way. Your (optional) zero-knowledge passphrase is not, because a recoverable key would be a backdoor. |
| Manual account approval | Every account is individually reviewed and approved, with email addresses verified against the firm’s domain. There is no self-service signup. |
Put us to the test
Have your IT reviewer, your managing partner, or your most skeptical colleague read this page, then ask us anything it didn’t answer. We’ll walk through the architecture in your demo, step by step.