Privacy policy
In short: we collect only what you send us through this site's forms and tools, we use it to respond and to do the work you ask for, we never sell it, and you can have it deleted by sending one email. The detail is below.
Last updated: 25 August 2026
Who we are
Lawyerd ("we", "us") is a counsel-led content-removal practice operating at lawyerd.net. For personal data collected through this website, Lawyerd is the data controller. Contact for anything in this policy: dmca@lawyerd.net.
When we handle removal matters for clients, we act on the instructions of the rights holder who engages us. Data inside those matters — evidence, reported URLs, correspondence with platforms and hosts — is processed for the client under the engagement terms and professional confidentiality, in addition to this policy.
What we collect
Intake and contact forms. Name or company, work email address, and the matter description you choose to submit. Submissions are delivered to counsel through a private Telegram channel and recorded in our own infrastructure (Cloudflare D1) so enquiries are not lost. They are never published or placed in any public-facing database.
Evidence Snapshot tool (/evidence/). Your email address and the URL you ask us to preserve. The capture report is delivered to that address by email. Submitted URLs are rendered and screenshotted by our capture pipeline and may also be submitted to the Internet Archive's Wayback Machine — a public archive — so submit only URLs of publicly accessible web pages, not private content.
Abuse-contact lookup (/abuse-contact/). Name, company and work email address, collected before full lookup results are shown.
Newsletter. Email address, processed by Buttondown on our behalf. Please note: submitting any email-bearing form on this site also subscribes that address to our enforcement newsletter (single opt-in). Every issue contains a one-click unsubscribe link, and unsubscribing is immediate.
Technical data. Standard server logs and short-lived rate-limiting records (IP address and email hash) used only to keep the free tools available and abuse-free. We do not build visitor profiles from this data.
Cookies and analytics
Our primary analytics is Plausible — cookieless, aggregate and privacy-preserving; it does not track individuals across sites and does not use IP addresses to identify visitors. Where Google Analytics is enabled, it sets its own cookies under Google's terms; we use it for the same aggregate purpose only. The site itself sets no advertising or cross-site tracking cookies, and we run no ad pixels.
Platform applications, including Meta apps
We operate applications on third-party platforms — including apps that use Meta's intellectual-property reporting tools — solely to prepare, submit and track IP reports on behalf of the rights holders who instruct us. Through those applications we process only the data those reports require: the reporting rights holder's identity and rights documentation, references to the reported content, and the platform's responses to our filings.
Platform data is handled in accordance with the relevant platform's terms (for Meta apps, Meta's Platform Terms and Developer Policies). We do not sell it, do not use it for advertising, profiling or any purpose beyond the report it was collected for, and do not share it with anyone except the instructing rights holder, the platform itself, and authorities where a filing legally requires it. It is deleted when it is no longer needed for the matter, when the engagement ends, or on a valid request — see our data deletion instructions.
Why we process it — legal bases
We process personal data to respond to enquiries and perform engagements (contract, and steps taken at your request before a contract); to meet professional and statutory obligations of a legal practice (legal obligation); and to operate, secure and improve the site and its tools, including the newsletter for people who have contacted us (legitimate interest, which you may object to at any time). Client matter data is additionally protected by professional confidentiality and, where agreed, NDA.
How long we keep it
Intake correspondence is kept for the duration of the engagement discussion and as required by professional-records obligations. Newsletter data is kept until you unsubscribe. Evidence Snapshot records are kept so that delivered reports remain verifiable, or until you ask us to delete them. Rate-limiting records expire automatically within hours. Matter files follow the retention terms of the engagement. Anything not covered by a legal or professional retention duty is deleted on request — see data deletion.
Who we share it with
We do not sell personal data, and we do not share it for advertising. Data is disclosed only to the service providers needed to run the practice, each acting on our instructions:
- Cloudflare — website hosting and the storage behind our forms and tools (D1, KV, R2);
- Telegram — delivery of form submissions to counsel's private intake channel;
- Buttondown — newsletter delivery and subscription management;
- Amazon Web Services (SES) — transactional email sent from our own backend (for example, Evidence Snapshot reports);
- Plausible — cookieless aggregate analytics; Google Analytics where enabled;
- Scrapfly and the Internet Archive — rendering, screenshotting and public archiving of URLs submitted to the Evidence Snapshot tool (the URL you submit, not your identity).
Beyond processors, data leaves our hands only where the work itself requires it: filings made with platforms, hosts and authorities on a client's instructions, and disclosures required by law.
International transfers
The providers above operate globally, so data may be processed in the EU/EEA, the United Kingdom and the United States. Where data of EU/EEA or UK residents is transferred outside those regions, we rely on the safeguards those providers offer — standard contractual clauses or an equivalent recognised transfer mechanism.
Security
All traffic to the site is encrypted in transit (TLS). Form submissions travel over authenticated channels to systems only counsel and the small operating team can access, on a need-to-know basis. Client matter data is segregated from the public website. No system is perfectly secure; if a breach ever affects your personal data, we will notify you and the competent authority as the law requires.
Your rights
Under the GDPR, the UK GDPR and equivalent laws you may request access to, correction, deletion, restriction or portability of your personal data, object to processing based on legitimate interest, and withdraw consent where processing is based on it. Write to dmca@lawyerd.net — we respond within one business day and act within the statutory deadline. You also have the right to lodge a complaint with your local data-protection supervisory authority. Step-by-step deletion instructions: lawyerd.net/data-deletion.
Children
This site is a professional service directed at businesses and rights holders. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, tell us and we will delete it.
Changes to this policy
Material changes are published on this page with an updated date at the top. Questions about this policy: dmca@lawyerd.net.