Security and data handling

How Demole handles your firm's data, how the AI features work, and what this page does not claim.

This page describes how the software works today. It is not a third-party audit or certification, and it makes no claim about certifications, hosting region or encryption at rest. Ask us for the current position on any of those before you rely on Demole for sensitive work.

Last updated:

Data handling

What is stored, where, and who can reach it.

  • Cases, clients, tasks, calendar entries, invoices, time entries and uploaded documents are stored in the application's PostgreSQL database. Documents live in that database rather than a separate file store, and each upload is capped at 4 MB.
  • Workspace records are filtered to the signed-in user or, on a firm plan, to their firm. A solo account sees only its own records; members of a firm share one workspace.
  • A client can be given a separate portal login. It shows only that client's own matters (title, status, court, case number and next hearing date), read-only. Portal access is off until you enable it for a client, and you can switch it off again.
  • You can delete cases, clients, documents, tasks, invoices and time entries yourself in the app.
  • Subscription payments run on Dodo Payments' hosted checkout. Card numbers never reach Demole or its database; Demole stores only Dodo's customer and subscription IDs.
  • Hosting: the application is built to run as a container on Google Cloud Run, with a managed PostgreSQL database (Neon). This page does not state a hosting region.

Sign-in and access

How accounts are protected, and who inside HERMEiAS can reach them.

  • Passwords must be at least 8 characters and are stored only as bcrypt hashes.
  • Sessions use a signed token in an HttpOnly cookie (not readable by page scripts) with SameSite=Lax, marked Secure in production, and last up to 30 days.
  • Two-factor authentication with an authenticator app is available to every account. Eight single-use backup codes are issued and stored only as hashes.
  • Personal API keys (for the REST API) are stored only as hashes. The full key is shown once, when it is created, and any key can be revoked.
  • There are two roles, lawyer and admin, and admin screens are limited to admin accounts.
  • HERMEiAS administrators can sign in as a user to give support. Signing in as a user, suspending accounts, resetting 2FA and exporting the user list are recorded in an admin audit log.

Confidentiality and privilege

Access to your workspace is limited to your own account, the members of your firm, any client you give portal access to (their own matters only), and HERMEiAS administrators acting under the audit-logged support access described above.

Demole does not decide what is privileged or confidential, and it does not change your professional obligations. Attorneys remain responsible for their own confidentiality, supervision and privilege judgments, including whether to put client information into any third-party tool and what your jurisdiction's rules and your engagement terms require when AI is involved.

How the AI features work

The assistant and the drafting tools call a third-party model. This is what that means for your data.

Provider
Requests go to Google's Gemini API, through Google's official SDK.
What is sent
Demole's own instructions, plus, for the assistant, the conversation so far in that chat and any image, PDF or .txt file you attach (up to 4 MB); for a drafting tool, only what you fill in or paste. Stored cases, clients and documents are never added automatically.
What Demole keeps
Assistant conversations, including attachments, are saved in your account so you can reopen them. Drafting-tool inputs and results are shown to you and are not stored by Demole. Where a plan limits daily AI use, Demole records only which account used which feature and when, not the content.
Training
Demole does not train or fine-tune models on your content, and the product has no training pipeline.
Provider-side handling
What Google retains from API requests, and whether it uses them to improve its products, depends on the terms of the Gemini API plan behind Demole's keys. This page does not assert a position on either. Ask us for the current terms before you submit confidential client material.

Checking AI output

Demole AI is a drafting and research aid. It can produce citations, quotations and statements of law that are wrong or out of date. Before you file or advise:

  1. Check every citation against the primary source (the official code site, the reporter or the court's docket), not against the assistant.
  2. Confirm the authority is still current: amendments, later history and subsequent treatment.
  3. Read any quoted language in the source itself before you rely on it or file it.

The built-in references are curated and limited. The statute-of-limitations pages cover a limited set of states and claim types; each carries an as-of date, and a page whose citations have not been cross-checked against the official code is flagged as unverified. The in-app U.S. Code and Constitution quick reference is a finding aid for a small set of frequently cited provisions, not the authoritative text.

Services Demole relies on

Third-party services that handle data as part of running Demole:

  • Google Gemini APIAI assistant and drafting tools
  • Dodo PaymentsSubscription checkout and billing
  • NeonManaged PostgreSQL database
  • Google Cloud RunApplication hosting
  • Ahrefs Web AnalyticsWebsite analytics

Not legal advice. Demole AI is a practice-management and drafting aid for licensed legal professionals. It does not constitute legal advice and does not replace independent professional judgment. Using this page does not create an attorney-client relationship.

Questions or concerns

Have a security or data-handling question, or want to raise a concern? Include it when you request a demo.

Request a demo