Nithidesk

Legal

Privacy policy

How Nithidesk handles personal data in its two products — Nithi Desk Diary and LexAI. Both hold material that is frequently privileged, so this document is specific about what happens to it rather than reserving the right to do anything.

Version 1.0 · In effect from 17 August 2026 · how changes are notified

1. Who we are

Nithidesk builds and operates two products for legal practice in Sri Lanka:

  • Nithi Desk Diary — a mobile application giving a set of chambers one shared court diary.
  • LexAI — a web application providing practice management for a law firm, reached at app.lexai.nithidesk.online.

This policy covers both, and also this website. Where something applies to only one product, it says so. We are based in Colombo, Sri Lanka, and can be reached at privacy@nithidesk.online.

Both products are at an early stage — the Diary is in closed testing and LexAI is running a pilot with a small number of firms. We would rather tell you exactly what the software does today than describe an aspiration.

2. Who controls the data

This distinction matters more here than in most privacy policies, because most of what these products hold is not your personal data — it is your clients’.

Your own account
We decide how your account data is handled — your name, email, password and sign-in records. For that data we are the controller.
Your clients and matters
Your chamber or firm decides what to record about its clients, why, and for how long. We only hold and process it on your instructions. For that data your chamber or firm is the controller and we are a processor. We do not use it for our own purposes, and we do not decide when it is deleted — you do.

In practice this means that if a client of your firm asks what is held about them, the obligation to answer is your firm’s, not ours. We will help you answer it.

3. What Nithi Desk Diary collects

About you

  • Your name, email address and, if you provide it, your telephone number.
  • The chamber you belong to and your role within it.
  • A cryptographic hash of your password — never the password itself, which we cannot read or recover.
  • Sign-in and session records, kept so that a compromised account can be investigated.

What you enter about matters

  • Case titles, numbers, courts and districts.
  • Party names, and the names of counsel appearing.
  • Hearing dates, sessions, outcomes, the next step directed, and the bench’s remarks where you record them.
  • Attendance, and each member’s listings and availability.
  • Leave and unavailability that members enter.

Technical data

  • Device model and operating system version, and the application version — used to reproduce faults.
  • Entries you create with no connectivity, held on your own device in a pending queue until they can be sent.

The application contains no advertising identifiers, no behavioural analytics and no third-party tracking software.

4. What LexAI collects

About you

  • Your name, email address, telephone number and role in the firm.
  • A cryptographic hash of your password, and — if you enable it — a secret used for multi-factor authentication.
  • Professional details your firm chooses to record: Bar Association enrolment number and date, practising certificate expiry, continuing professional development points, and the courts where you regularly appear.
  • Sign-in records, failed sign-in counts and account lockout state, kept to resist password guessing.
  • An audit record of actions you take in the system, attributed to you and retained so the firm can account for what was done to a file.

What your firm enters

  • Client records: names, contact details, identifiers your firm records, and the results of any conflict or know-your-client checks it performs.
  • Matters: case numbers, courts, categories, parties, opposing counsel and timelines.
  • Documents your firm uploads, and text extracted from them for searching.
  • Hearings, deadlines, tasks, reminders and diary entries.
  • Time entries, fee agreements and invoices.
  • Questions your users ask the assistant, and the answers and drafts it returns.

Documents are uploaded from your browser directly to object storage using a short-lived signed URL, so a scanned bundle does not pass through the application servers.

Technical data

  • One cookie, used to hold your signed session. It is HttpOnly, Secure and restricted to our own site. It is necessary to keep you signed in and is not used to track you.
  • Server logs containing IP address, request path and timing, kept on the server for a short period to diagnose faults and abuse.

This marketing website — the pages at nithidesk.online — sets no cookies at all, runs no analytics, and loads nothing from any other company’s servers, including its typeface.

5. Why we process it

To provide the service
Performance of our contract with your chamber or firm. Without the case, hearing and client records there is no product.
To keep accounts secure
Our legitimate interest, and yours, in preventing unauthorised access to privileged material. This covers password hashing, multi-factor authentication, lockouts and sign-in records.
To maintain an audit trail
Your firm’s professional and regulatory obligation to account for what was done to a client file, which we support on its instructions.
To fix faults
Our legitimate interest in a working product. We look at logs and crash data, not at your case files, to do it.
To bill you
Performance of contract, and our legal obligation to keep accounting records.

What we never do: we do not sell personal data, we do not share it for advertising, we do not build profiles of you, and we do not use your case files or client data to train artificial intelligence models — ours or anyone else’s.

6. Artificial intelligence

LexAI includes an assistant that answers questions about your matters and drafts documents. It works by sending text to a large language model operated by Google (the Gemini API). This is the part of the system that sends your content outside our own infrastructure, so it is worth reading carefully.

Names are masked before the model sees them

Every request passes through a redaction step first. Personal names, National Identity Card numbers, passport numbers, telephone numbers, email addresses, payment card numbers and similar identifiers are detected and replaced with placeholders such as [PERSON_1] before the text leaves our server. The mapping between a placeholder and the real value is held only in memory for the life of that single request, is never written to disk or sent anywhere, and is used to restore the real values in the answer on our side.

We should be straightforward about the limits of this. Detection is automated and is not perfect: an unusual name, or a name embedded in an unusual way, can be missed. Masking substantially reduces what is disclosed to Google — it does not reduce it to nothing. The surrounding facts of a matter are, necessarily, sent.

What Google does with it

We use the paid Gemini API. Google states that content submitted through it is not used to train its models. Google processes it to return a response and retains it briefly for abuse monitoring. Google’s terms govern that processing, and they may be changed by Google.

If you would rather not use it

The assistant is a feature, not a requirement. A firm that does not want any content sent to a language model can ask us to disable it for their tenancy, and the rest of the product continues to work. Write to privacy@nithidesk.online.

Do not rely on it as legal advice

The assistant produces drafts and summaries. It can be confidently wrong. Statutory periods and filing windows shown in either product are scheduling aids, not a substitute for checking the current statute. A qualified person must review anything before it is filed or relied upon.

7. Who else processes it

We keep this list short deliberately. Each of these has access only to what its function requires.

Amazon Web Services
Hosting, storage, backups and email delivery. All application data and all documents sit on infrastructure we operate within AWS.
Google
The Gemini API, for the LexAI assistant only, and only after the masking described in section 6. Nothing from the Diary is sent to a language model.
Meta Platforms
The WhatsApp Business API, only where a firm chooses to enable WhatsApp notifications. Where enabled, the message content and the recipient’s number are processed by Meta to deliver it. This channel is not active by default.
Stripe
Subscription payments, where billing is enabled. Card details are entered with Stripe and never reach our servers. Not active during the pilot.
Google Play · Apple
Distribution of the Diary application. They tell us aggregate install and crash figures; they do not receive your case data from us.

8. Where it is stored

Your data is stored in Amazon Web Services’ Asia Pacific (Mumbai) region, in India. Backups stay in the same region. We chose Mumbai because it is the closest AWS region to Sri Lanka, which keeps the application responsive from Colombo.

This means your data leaves Sri Lanka. If your chamber or firm has an obligation — under client instructions, professional rules, or a court order — to keep particular material inside Sri Lanka, tell us before you put it in either product, because at present we cannot offer in-country hosting.

Requests to the Gemini API are processed by Google, which may process them outside India and outside Sri Lanka.

9. How long we keep it

Case and client records
For as long as your chamber or firm keeps them. You decide; we do not delete a matter on our own initiative.
Your account
Until it is deleted, by you or by your firm’s administrator. See section 12.
Audit records
Retained for the life of the tenancy. An audit trail that could be trimmed would not be worth keeping.
Backups
Database backups and storage snapshots are retained on a rolling basis for up to 14 days, then destroyed. Deleted data can therefore persist in a backup for up to a fortnight after deletion.
Server logs
Rotated continuously and held for days, not months.
After a tenancy ends
We will keep the data for 30 days so that you can export it, then delete it. Tell us if you want it deleted sooner.

10. Security

What is actually in place today:

  • All traffic is encrypted in transit with TLS. The site is served over HTTPS only, with HTTP redirected.
  • Storage volumes holding the database and documents are encrypted at rest.
  • Passwords are stored as bcrypt hashes. Accounts lock after repeated failed sign-ins.
  • Multi-factor authentication is available on LexAI accounts.
  • In LexAI, each firm’s records live in a separate database schema, chosen from your signed session rather than from anything the browser sends — so a request cannot ask for another firm’s data by changing a value.
  • In the Diary, separation between chambers is enforced by row-level security in the database itself, so it does not depend on the application remembering to filter.
  • Audit exports are cryptographically signed, so a copy can be shown to be the copy that was produced.
  • Administrative access to servers is through short-lived, logged sessions. No password-based remote shell is exposed to the internet.
  • Backups are automated daily and held outside the running instance.

No system is impossible to breach. If a breach affects your personal data we will notify the affected chambers and firms without undue delay, describe what happened and what we are doing, and make the report the law requires.

11. Your rights

Sri Lanka’s Personal Data Protection Act No. 9 of 2022 gives you rights over your personal data. Depending on the circumstances you may ask to:

  • be told what we hold about you, and get a copy of it;
  • have inaccurate data corrected;
  • have data erased, where we are not required to keep it;
  • object to processing, or ask that it be restricted;
  • withdraw consent where processing rests on consent.

Write to privacy@nithidesk.online. We will respond within 30 days. We may need to verify who you are first — we are not going to hand a lawyer’s case data to whoever asks for it.

If you are a client of a firm that uses LexAI, ask the firm rather than us. The firm decides what is held about you and is the right party to answer; we hold it on their instructions and will support them in responding.

12. Deleting your data

Nithi Desk Diary

You can delete your own account from inside the application: open Profile and choose Delete account. It takes effect immediately and needs no email exchange with us. Your account, your personal details and your membership of the chamber are removed.

If you are the only member of a chamber, the chamber and its diary are deleted with you. If there are other members, the chamber’s shared records remain with them — a hearing you logged stays in the chamber diary, because it belongs to the chamber’s practice rather than to you, and removing it would leave the diary wrong.

LexAI

Your firm’s administrator can deactivate and delete a user account. To delete an entire firm tenancy, an authorised person at the firm should write to privacy@nithidesk.online. We will confirm the request, give you the chance to export first, and then delete the tenancy — its schema, its documents and its stored objects.

Either product

If you cannot reach the in-app option, write to privacy@nithidesk.online and we will do it for you. Two things to be aware of in both products: deleted data can persist in backups for up to 14 days before those backups expire, and entries that are part of a firm’s audit trail or its accounting records may be retained where the firm is required to keep them.

13. Children

Neither product is intended for children, and neither is offered to them. Accounts are for legal practitioners and their staff. We do not knowingly collect personal data from a child as an account holder. Case records may of course concern a child — a custody or maintenance matter, for instance — and that data is handled as your firm’s data under this policy, with the same protections as everything else.

14. Changes

When this policy changes we update the version and date at the top of the page. For a change that materially affects how we handle your data — a new processor, a new purpose, a new location — we will tell the chambers and firms using the products by email before it takes effect, and not rely on you noticing a new date.

15. Contact

For anything in this policy, including requests about your data:

Nithidesk, Colombo, Sri Lanka.

Note on this document

This policy describes what the software does, written against the system as it is built. It is not legal advice and has not been reviewed by a lawyer in practice. If you are relying on it to meet an obligation under the Personal Data Protection Act, or to satisfy a Google Play or App Store review, have a practitioner read it against your own circumstances first.