collins

Privacy Policy

Last updated 6 August 2026

Collins OS is practice management software for law firms. This policy explains what we collect, where it lives, who can reach it, and what we will never do with it. It covers collinsos.com and the Collins OS application at app.collinsos.com.

Two kinds of people are described here, and the difference matters throughout: a firm is our customer, and a client is the firm's client, whose information the firm stores in Collins OS. We hold client information on the firm's behalf and under the firm's direction. The firm, not Collins OS, decides what goes in and who may see it.

The short version We do not sell data, we do not advertise, and we do not train AI models on your matters, your documents, or your clients' information. The AI features in Collins OS run on the same infrastructure as the rest of the product — your drafts are not sent to a third-party model provider.

1. Who we are

Collins OS is operated by Collins Legal, PLC, 4101 Charlotte Avenue, Suite F186, Nashville, TN 37209, United States. Questions about this policy, or any request described below, go to hello@collinsos.com.

2. What we collect

Account information

When a firm signs up we collect the firm name, the name and email address of each user, a hashed password, and role assignments. We never store passwords in a form we can read.

Firm and client data

Whatever your firm puts into the product: contacts, matters, calendar events and deadlines, documents, time entries, expenses, invoices, payments, trust ledgers, and notes. Much of this is information about your clients, and some of it is privileged. We treat all of it as confidential.

Billing information

Subscription payments are processed by Stripe. Card numbers go to Stripe directly and never touch our servers; we retain a customer identifier, the plan, seat count, and payment status.

Technical logs

Server logs record request times, IP addresses, and errors. We use them to keep the service running and to investigate abuse. They are not used to build profiles of anyone.

The website

collinsos.com uses no advertising trackers and sets no cookies for advertising. If you submit the contact form, we receive the email address you typed and whatever you wrote.

3. Where your data lives

Collins OS runs on dedicated infrastructure operated by us in the United States, not on a shared public cloud. Each firm's records live in a separate database; the application binds a signed-in user to their own firm's database and to no other.

Firms on a Private deployment run Collins OS on hardware the firm itself controls. In that arrangement, firm and client data never reaches our systems at all, and the sections below about our storage do not apply to it.

4. Connected accounts (Google and Microsoft)

A firm may choose to connect a Google or Microsoft account so Collins OS can show its calendar and send email as the firm. This is optional, it is off until an administrator turns it on, and it can be disconnected at any time from Settings › Connections.

When connected, we request only the access the feature needs:

What we ask forWhat we do with it
Your name and email address Identify which mailbox is connected, and show it back to you in Settings.
Calendar, read-only Display your existing events alongside matter deadlines in the Collins OS calendar. We do not create, edit, or delete events.
Send mail Send the messages you ask Collins OS to send — an invoice, a portal link, a consult confirmation — from your own address rather than a generic one. We send nothing you did not initiate.
Read mail (separate, additional opt-in) File correspondence with your existing contacts onto the right matter. This is a second, deliberate consent, off by default. Mail from anyone who is not already a contact in your firm is not stored.

We store the resulting access and refresh tokens encrypted, in your firm's own database, and use them for nothing but the features above.

Google API Services User Data Policy Collins OS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models. We do not transfer Google user data to third parties except as necessary to provide or improve the features you enabled, to comply with applicable law, or as part of a merger or acquisition. We do not use Google user data for advertising, and no human reads it except with your explicit permission or where required for security or legal reasons.

5. Artificial intelligence

Collins OS includes AI features: legal research, document drafting, and writing review. These run on infrastructure we operate, using models we host. Your matters, drafts, and client information are not sent to OpenAI, Anthropic, Google, or any other outside model provider, and are not used to train any model — ours or anyone else's.

AI output is a starting point and can be wrong. It is not legal advice and it does not replace a lawyer's review. That obligation stays with the firm.

6. Who else touches your data

We share data with service providers only where a feature requires it, and only the minimum that feature needs:

We do not sell personal information, and we do not share it with advertisers or data brokers. If we are ever compelled by law to produce data, we will tell the affected firm unless we are legally barred from doing so.

7. How long we keep it

Firm and client data is retained for as long as the firm's account is active. On cancellation, the firm may export its data; we delete the firm's database within 30 days of a written deletion request, or within 90 days of account closure, whichever comes first. Backups age out on their own schedule and are overwritten within 90 days. Disconnecting a Google or Microsoft account deletes the stored tokens immediately.

8. Security

Traffic is encrypted in transit. Credentials and connected-account tokens are encrypted at rest. Access within a firm is governed by roles the firm controls, and trust-accounting records are append-only by design — they can be added to, never quietly rewritten. Access to production systems is limited to personnel who need it.

No system is perfectly secure. If a breach affects your data, we will notify the affected firm promptly and tell you what we know.

9. Your rights

A firm may access, correct, export, or delete its data at any time, mostly from inside the product and otherwise by writing to us. If you are a client of a firm that uses Collins OS and you want to see or remove your information, contact that firm — the data is theirs to control, and we will support their instructions. Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA; we honor those requests and do not discriminate against anyone for making one.

10. Children

Collins OS is a business product and is not directed to children. We do not knowingly collect information from anyone under 13.

11. Changes

If we change this policy in a way that matters, we will update the date at the top and tell account administrators by email before it takes effect.

12. Contact

Collins Legal, PLC · 4101 Charlotte Avenue, Suite F186, Nashville, TN 37209 · hello@collinsos.com