Last updated: July 2026

Privacy Policy

ECFiler ("we," "us," or "our") operates the ecfiler.com website and the ECFiler platform (the "Service"). This Privacy Policy explains how we collect, use, store, and protect information when you use the Service. ECFiler is designed for licensed attorneys and legal professionals who file documents on the federal CM/ECF system. We take the confidentiality of legal data seriously.

1. Information We Collect

We collect the following categories of information:

Account Information

  • Email address and name — collected during account registration through our authentication provider, Clerk.
  • Bar admission and attorney identifiers — if you choose to provide them in your profile.

Court Credentials

  • None. We do not collect your PACER or CM/ECF username or password. Filing credentials remain in the operating-system keyring on your own machine and never reach our servers. See Section 2.

Filing Data

  • PDF documents you upload for filing, including main documents and attachments.
  • Case information — case numbers, court identifiers, party names, and event codes associated with your filings.
  • AI-generated metadata — docket text suggestions, event code predictions, and document analysis results produced by our AI systems during the filing workflow.
  • Filing history — records of filings prepared and staged through the Service, including timestamps, courts, and status.

Usage Information

  • Anonymous page-view and performance metrics collected through Vercel Analytics and Speed Insights (see Section 6).
  • Browser type, operating system, and screen resolution for compatibility purposes.

2. Court Credentials

We do not collect, store, transmit, or have access to your PACER or CM/ECF credentials. This is an architectural guarantee, not just a policy:

  • The hosted Service never asks for a court password. It prepares, validates, and stages filings; you submit them on CM/ECF yourself.
  • When you file through the local ECFiler CLI, your credentials are read from the operating-system keyring on your own machine (macOS Keychain, Windows Credential Manager, or Linux Secret Service) and are used only for the session you initiate. They are never sent to ECFiler servers, logged, or cached remotely.
  • Because no credential ever reaches our infrastructure, a breach of ECFiler's servers cannot expose a court password.
  • Legacy note: an earlier version of the Service offered server-side credential storage. That capability was removed from the code in July 2026 — before any filing path ever used it — and the hosting environment that held the legacy store has since been decommissioned. No ECFiler server stores court credentials today.

3. Filing Document Retention

Documents you upload to ECFiler are stored on a per-user basis and are accessible only to your account. Our retention practices are as follows:

  • Active documents (uploaded within the last 30 days) are stored in their original form to support your filing history and any resubmission needs.
  • After 30 days, documents are compressed and moved to archival storage. Compressed documents remain accessible through your filing history but may take slightly longer to retrieve.
  • Sealed or restricted documents are never accepted by the hosted Service and therefore are never stored in any form (see Section 4).
  • You may delete your entire filing history and all stored documents at any time from your account settings (Settings → Delete My Data).
  • Deletion takes effect immediately when you request it (see Section 11).

4. Sealed Documents

The hosted Service does not accept sealed or restricted documents at all. If a document is marked sealed, subject to a protective order, or otherwise restricted from public filing, ECFiler refuses the upload before any content is stored. There is no sealed-handling mode on our servers: no sealed content is ever received, stored, logged, or backed up. This refusal is a deliberate architectural decision documented in our sealed-document policy. Sealed material must be filed through the court's own procedures; the local ECFiler CLI likewise hard-fails rather than ever filing sealed content publicly.

5. Authentication

ECFiler uses Clerk as our authentication and user-management provider. When you sign up or sign in, Clerk processes your email address, name, and authentication tokens. Clerk may also collect device and browser information for security purposes (e.g., detecting suspicious login attempts). ECFiler does not store your password for your ECFiler account — that is managed entirely by Clerk. Please review Clerk's Privacy Policy for full details on their data practices.

6. Analytics & Performance

We use Vercel Analytics and Vercel Speed Insights to collect anonymous, aggregated usage metrics. These tools help us understand page performance, load times, and general usage patterns. Specifically:

  • Vercel Analytics collects anonymous page-view data. It does not use cookies and does not track individual users across sessions.
  • Vercel Speed Insights measures real-user performance metrics (e.g., page load time, time to interactive) to help us optimize the application.
  • Neither tool collects personally identifiable information, filing content, or case data.

We do not use Google Analytics, Facebook Pixel, or any advertising-related tracking on the Service.

7. Infrastructure & Data Storage

ECFiler's infrastructure is hosted by two providers:

  • Vercel — hosts the frontend application (the website and user interface you interact with). Vercel operates data centers in the United States and complies with SOC 2 Type II standards.
  • Self-hosted backend — the backend API server, database, and document storage run on infrastructure we operate directly (a dedicated virtual private server), not on a third-party application platform.

All data transmitted between your browser and ECFiler is encrypted in transit using TLS 1.2 or higher, and data at rest is encrypted with industry-standard encryption. ECFiler's servers do not communicate with CM/ECF and never hold court credentials (see Section 2).

8. Third-Party Data Sharing

We do not sell, rent, or trade your personal information or filing data to any third party.

We share data with third parties only in the following limited circumstances:

  • Clerk (authentication) — email and account data as described in Section 5.
  • Vercel and our hosting provider — as infrastructure providers, these companies process data on our behalf under their standard data processing terms.
  • Legal compliance — we may disclose information if required by law, subpoena, court order, or government request. We will notify you of such requests to the extent legally permitted.

9. Your Data Rights

Regardless of your location, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate personal data.
  • Delete your account and all associated data (see Section 11).
  • Export your filing history in a machine-readable format.
  • Withdraw consent for optional data processing (e.g., analytics) at any time.

To exercise any of these rights, contact us at privacy@ecfiler.com. We will respond within 30 days.

10. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights regarding your personal information:

  • Right to know — you may request a detailed disclosure of the categories and specific pieces of personal information we have collected about you in the preceding 12 months.
  • Right to delete — you may request deletion of your personal information, subject to certain exceptions (e.g., data required for completing a transaction you initiated).
  • Right to non-discrimination — we will not discriminate against you for exercising your CCPA rights. You will not receive different pricing or service levels.
  • No sale of personal information — ECFiler does not sell personal information as defined under the CCPA. We have not sold personal information in the preceding 12 months.

To submit a CCPA request, email privacy@ecfiler.com with the subject line "CCPA Request." We will verify your identity before processing your request and respond within 45 days as required by law.

11. Account & Data Deletion

You may delete your ECFiler data at any time from your account settings page (Settings → Delete My Data). Upon deletion:

  • No court credentials need to be deleted — we never had them (see Section 2).
  • Your filing history, uploaded documents, staged filing packages, and all associated case data are permanently deleted immediately — not queued.
  • Attestation integrity records are the one narrow exception. ECFiler keeps an append-only, hash-chained log proving that each staged filing was attested by a named person at a specific time. When you delete your data, the case data behind your attestation records (and the cryptographic salt that could link the remaining hashes to it) is deleted with everything else. What remains is the attestation record itself: the attestor name you typed, the attestation language you saw, timestamps, an internal account identifier, and content-free hashes. These records cannot be linked back to any case or document and exist solely so the integrity of the log can be proven; they are retained indefinitely.
  • Your login account (including your email) is managed by our authentication provider and can be deleted from the account menu (Manage account → Delete account).
  • Anonymous, aggregated analytics data (which cannot be linked back to you) may be retained.

If you need assistance with account deletion, contact privacy@ecfiler.com.

12. Children's Privacy

ECFiler is intended for use by licensed attorneys and legal professionals. We do not knowingly collect personal information from individuals under the age of 18. If we learn that we have collected information from a minor, we will promptly delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes, we will notify you by email (using the address associated with your account) or by posting a prominent notice within the Service at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact

If you have questions about this Privacy Policy or our data practices, contact us at:

ECFiler Privacy

Email: privacy@ecfiler.com

ECFiler is a filing tool, not a legal advisor.