Evidence Locker by Matterdesk
Privacy policy
Effective and last updated: 9 September 2026
This policy explains what the invitation-only Evidence Locker pilot collects, why it is used, who can see it, and how to request deletion or withdrawal.
What we collect
- Account and contact details, workspace role, authentication and security records.
- Matter titles, collection terms, date limits, approvals and access assignments supplied by authorised users.
- Files users upload and, only after an explicit connection and confirmation, matching Gmail, Google Drive, Outlook mail, OneDrive or Dropbox records and related metadata.
- SHA-256 digests, source provenance, access/review/disclosure actions and a tamper-evident custody history.
- Operational logs needed for security, reliability, abuse prevention and support.
Selected cloud-file uploads
Where enabled, “Upload from Google Drive”, “Upload from OneDrive” and “Upload from Dropbox” let the owning client choose their own provider account, search filenames and explicitly confirm individual files for one matter. The provider identity, selected metadata, preserved digest and acquisition receipt are recorded. This foreground import does not scan the whole account, collect any mailbox or run background monitoring. Google Drive access is read-only; OneDrive access is read-only files and basic profile for the account signed in with; Dropbox access is read-only file and account information for personal accounts. Individually accessible Shared Drive files may appear, but complete Shared Drive traversal, SharePoint document libraries and Dropbox team spaces need a separate collection process. Provider search is not a guarantee of completeness.
Import sessions last at most 15 minutes and use encrypted short-lived access tokens, not refresh tokens. Ending the session immediately removes its local credential; expiry cleanup removes expired credentials and unselected browsing metadata. Already confirmed manifests and custody receipts remain. Ending a session does not claim to revoke the provider-wide grant; you can remove it in your provider’s connected-app settings.
Persistent connected sources
Google access is limited to read-only Gmail and Drive permissions. Matching Gmail messages may include Spam or Trash and matching Drive files may include Drive Trash. Complete Shared Drive traversal is not supported in this release and requires a separate collection process. Evidence Locker does not send email or create, modify, move or delete Google data.
Microsoft access is limited to read-only Outlook mail and read-only OneDrive for the account that signs in. Matching Outlook messages may include messages currently in Deleted Items or Junk Email and their attachments. Only that account’s own mailbox and own OneDrive are searched: SharePoint document libraries, shared team sites and Teams messages are not collected in this release and require a separate collection process. Microsoft returns ranked indexed matches rather than a complete traversal, so recent or unindexed items may be omitted; use a separate collection process when completeness is required. Evidence Locker does not send mail or create, modify, move or delete Microsoft data. Microsoft publishes no way for an application to revoke its own access, so withdrawal erases every stored credential immediately and records that no provider confirmation exists; remove Evidence Locker in your Microsoft account permissions page or ask your tenant administrator to remove it.
Dropbox access is limited to read-only file and account information for personal Dropbox accounts; Dropbox Business accounts and team spaces are not supported. Evidence Locker queries Dropbox’s active index, then this release collects only candidates whose displayed filename or path contains a complete approved term (case-insensitive); content-only matches are not collected. Trash and deleted items are excluded, new or changed document content may not yet be indexed, identical-content duplicates may not all be returned, and Dropbox limits a match set to 10,000 results. Dropbox search is not guaranteed complete; use a separate collection process when completeness is required. Evidence Locker does not create, modify, move or delete Dropbox data.
Connecting a source allows the service to search within a matter’s approved terms and dates and to copy matching content into its evidence record. The connection belongs to the client workspace and may be selected for more than one matter. Withdrawing it from any matter withdraws it from all matters in that client workspace, cancels pending connection flows and stops future collection. Active collection credentials are removed immediately. Where the provider supports application revocation, one already-encrypted credential may be retained only for revocation retries for up to seven days and is erased when revocation succeeds or retry work reaches a terminal outcome; where it does not, as with Microsoft, every credential is erased at once and none is retained. Material already preserved remains in the evidence record and custody history unless an authorised deletion process can lawfully remove it.
How information is used
Information is used to preserve authorised evidence, verify integrity, support case-specific search and review, create evidence manifests, govern disclosure, secure the service and provide support. Evidence Locker does not sell personal information or use data collected from a connected source for advertising.
Content and metadata derived from any connected source — Gmail, Google Drive, Outlook mail, OneDrive and Dropbox — are excluded from the optional external semantic-embedding job. The deterministic capture, hashing and custody path does not use AI. Limited metadata from other manually supplied records may be processed by a configured semantic-search provider to provide search inside the workspace; original file bytes are not sent for that purpose.
Optional case analysis
Lady J case analysis is separate from preservation, and its availability depends on workspace configuration and an approved processing policy. Where enabled, the owning client must read the applicable processing notice and explicitly consent to the selected evidence and a stated purpose. That notice describes the provider, where processing occurs, and the applicable terms and limits. Uploading or connecting a source does not itself authorise external AI analysis. Generated analysis is a draft for qualified human review, not legal advice, legal representation or a legal determination.
Who can receive information
Information is visible only according to workspace roles and matter assignments. Workspace operators and authorised counsel can administer and review a matter. Counsel can deliberately disclose selected evidence manifests to specifically assigned opposing-counsel or law-enforcement accounts. A source owner’s matching records are not made public merely because a connector is linked.
Service providers may process the minimum information needed to host the application and storage on Microsoft Azure, deliver sign-in email through the configured mail provider, and operate approved search features. They act to support the service, not for their own advertising.
Google API data
Evidence Locker’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used only for the user-facing evidence-preservation feature the user requests and is not used to train or improve a general-purpose AI model.
Retention, security and location
Preserved evidence and custody events are retained for the matter’s evidentiary purpose and according to the controlling firm’s instructions and applicable legal obligations. Authentication, rate-limit and temporary OAuth records have shorter operational lifetimes. On withdrawal, active collection credentials are removed immediately; one encrypted revoke-only credential may remain for provider-revocation retries for no more than seven days and is erased on successful or terminal completion.
Controls include encryption in transit, application-layer envelope encryption for new originals, restricted cloud storage, role-scoped access, immutable custody receipts, integrity verification and protected backups. No internet service can promise absolute security.
Your choices and requests
Source owners can end a selected-file import session or withdraw a persistent connector from a matter page; persistent-connector withdrawal applies to every matter in that client workspace. Users can ask to access, correct or delete account information, or complain about handling. Evidence subject to a legal hold, firm instruction or custody obligation may need to be retained; we will explain the applicable outcome. See the data deletion instructions.
Contact
Questions, privacy requests and complaints can be sent to hello@matterdesk.ai.