Privacy Policy
Effective: July 1, 2026
MinuteBridge ("we," "us") is a call-to-billing service for law firms, operated by MinuteBridge LLC, based in Missouri, USA. This policy explains what we store, what we deliberately do not store, and who controls what. It is written to be read, not skimmed — it is short because we keep very little.
The design principle: we are a workflow tool, not an archive
Your communications live in RingCentral. Your billing records, notes, and case content live in your practice management system (MyCase, Clio, or a Google Sheet you own). MinuteBridge sits between them for the few moments it takes you to review and confirm an entry. We keep the minimum needed to make that review easy — and it expires on its own.
What we store
- Account data: your name, email, firm name, sign-in credentials (passkeys or a salted password hash), and session records.
- Authorization tokens for the services you connect (RingCentral, MyCase, Clio, Google) — encrypted at rest, scoped to you individually, never shared between users.
- Communication metadata, for 90 days: phone numbers (encrypted and blind-indexed at rest), timestamps, durations, direction, and page counts for calls, texts, and faxes on your connected lines — the data that powers your review queue. A nightly process deletes anything older than 90 days.
- Directory metadata from your practice management system: contact names, phone numbers, matter names and statuses — so incoming calls can be matched to clients and matters. Refreshed from your system; removable at any time with the in-app "clear cached data" control.
- Logging records: pointers (IDs) linking a call to the entry you created in your system, so we can show what's been logged and support corrections.
- Billing account data via Stripe: subscription state and invoice history. We never see or store card numbers — payment details go from your browser directly to Stripe.
- Audit records of administrative actions (sign-ins, connections, deletions) — metadata only.
What we never store
- Call audio and voicemail recordings — streamed from RingCentral to your screen, or into your own system at your instruction, never retained by us.
- Text message content — fetched live for your review; the durable copy is the record you choose to file in your own system.
- Notes, narratives, and case content — written by you, delivered to your system, not persisted or logged here.
- Your hourly rates beyond the moment of use — rates are read live from your system with your token.
Our server logs do not contain request or response bodies, by rule.
Who controls what (the legal frame)
For information about your firm's clients and callers, your firm is the controller and MinuteBridge is a processor: we handle caller metadata only to provide the service to you, on your instructions. Requests from your clients about their data belong with your firm; we support you with tools to purge a caller's metadata immediately (ahead of the automatic 90-day expiry). For your own account data, we are the controller.
How your data is used
Only to provide the service: matching calls to your clients and matters, running your review queue, and writing what you approve into your own system. We do not sell data, share it for advertising, or use your data to train AI models. No analytics beyond aggregate feature-usage counts tied to operating the product.
This website's analytics
The public marketing site (minutebridge.com) counts visits with our own first-party measurement — no third party, no cookies, and no cross-site tracking. We record the page visited, the referring site, a coarse device type (mobile, tablet, or desktop), and whether a visitor opened the early-access form or the demo. To count unique visitors without a cookie, we derive a one-way daily hash from your IP address and browser (the "Plausible" method); it is salted with a secret that rotates every day and is then discarded, so the count cannot be linked across days or traced back to you. We do not store your IP address or user agent, and this data never leaves our own server. Because nothing here identifies you or persists on your device, no consent banner is needed.
Service providers (subprocessors)
- Google Cloud — application hosting and database (USA).
- Stripe — payments and subscription billing.
- Resend — transactional email (verification, receipts, service notices).
RingCentral and your practice management system are your own vendors under your own agreements — we access them only with the authorization you grant and can revoke.
Security
Per-tenant database isolation enforced at the database layer, encryption at rest for tokens and communication metadata, HttpOnly session cookies, passkey and multi-factor sign-in, and an internally maintained security checklist anchored to OWASP ASVS. No security page substitutes for design: the strongest protection is that the sensitive content simply is not here.
Retention and deletion
- Communication metadata: deleted automatically after 90 days.
- Cancellation: export your account data yourself, in-app; after a 14-day grace period your firm's data is deleted entirely. Backups age out within 14 days on rotation.
- Removing a team member immediately revokes their access and deletes their tokens, mirrors, and settings.
- Nothing of yours is stranded here: your communications remain in RingCentral and your records remain in your own system, both untouched by cancellation.
Your rights
Access, correction, export, and deletion are self-serve in the app. For anything else — including rights requests under applicable state privacy laws — reach us through your account in the MinuteBridge app. We respond to verified requests within 30 days.
Changes
We will post changes here and notify account owners by email at least 30 days before material changes take effect.