atorni ← Back to home

Privacy Policy

Effective date: May 26, 2026

1. Introduction

Atorni is a Philippine-focused legal AI assistant. It is operated by Karl Gabriel M. Anciro (the “operator,” “we,” “us”), a sole proprietor based at 2F Unit 3, 34 Matias St., Brgy. Paltok, Quezon City, Philippines 1105. This Privacy Policy explains what personal information we collect, how we use it, and the choices you have, in line with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173, the “DPA”) and its Implementing Rules and Regulations.

This policy applies to:

  • the public marketing site at atorni.ph, including the waitlist sign-up;
  • the chat application, where authenticated users interact with the AI assistant; and
  • the administration interface used internally to manage accounts.

By using any part of Atorni, you confirm that you have read and understood this policy.

2. Information we collect

We collect only what we need to operate Atorni.

Account information. When you create a chat account, we collect your full name, email address, and a password. Passwords are hashed before storage — we never see or store your plain-text password.

Waitlist information. When you join the waitlist from the marketing site, we collect your email address.

Chat content. When you use the chat assistant, we store the messages you send, the AI’s responses, the source citations returned by retrieval, and any feedback you choose to submit through the in-app feedback dialog.

Sign-in session. When you sign in, we create a session so you can stay signed in across visits. The session credentials are kept by your browser.

Technical information. Our servers record standard request data — IP address, user-agent string, and timestamps — in application logs. The IP address of waitlist submissions is held briefly to rate-limit abuse.

We do not knowingly collect sensitive personal information as defined under the DPA (e.g., government IDs, health, religion, ethnic origin), and we do not ask you to provide any in your chats. Please refrain from sharing such information in chat content; treat chats as content visible to operators of the third-party AI providers listed below.

3. How we use your information

We use the information above to:

  • provide the AI chat service, including retrieving relevant cases and statutes and generating an answer;
  • authenticate you and keep your session active;
  • rate-limit abuse and protect the service;
  • contact waitlist subscribers about the launch and major service updates;
  • respond to feedback and support requests;
  • comply with our legal obligations.

We do not sell your personal information. We do not share it with advertisers or use it to build advertising profiles.

4. Legal basis for processing

Under DPA Sections 12 and 13, we rely on the following bases:

  • Consent — when you sign up for the waitlist or create an account.
  • Performance of a contract — when we process your data to deliver the chat service you have asked for.
  • Legitimate interest — for security, abuse prevention, server logging, and product improvement, provided your rights and freedoms are not overridden by these interests.

5. Third parties and cross-border transfers

Atorni uses a small number of third-party processors. Where these processors are located outside the Philippines, the DPA’s rules on cross-border transfer apply, and we have selected providers with comparable data protection commitments.

OpenRouter (United States). When you send a chat message, it is forwarded to OpenRouter, which routes it to the AI model provider you have selected for that conversation (such as Anthropic, OpenAI, Google, and other model providers). This is a cross-border transfer of your message content.

Microsoft Azure. We host the application and store your data on Microsoft Azure. Your account data, chat history, and waitlist record reside on Microsoft-managed servers.

Local search model. Before sending your question to the AI, we convert it into a numerical form so we can match it against our library of cases and statutes. This step runs locally on our servers using an open-source model — your messages are not sent to any outside party for this step.

Source materials we cite from. The legal materials surfaced as citations in chat are taken from public sources (lawphil.net and elibrary.judiciary.gov.ph). No personal data is sent to those sources at runtime.

6. Data retention

We keep your information only as long as needed:

  • Account data — for as long as your account is active. You may request deletion at any time using the contact details below.
  • Chat history — retained so you can continue past conversations. Deletable on request.
  • Waitlist — kept until launch and a reasonable period after, or until you unsubscribe.
  • Server logs — typically rotated within 30 to 90 days.

When you ask us to delete your data, we remove it from our active records promptly. Copies may persist in backups for a short period before being overwritten on schedule.

7. Security

We implement reasonable organizational, physical, and technical safeguards as required by DPA Section 20:

  • passwords hashed using industry-standard algorithms;
  • sign-in sessions cryptographically protected so they cannot be forged;
  • industry-standard encryption (HTTPS) for traffic between your device and our servers;
  • role-based access controls separating regular accounts from administrator accounts;
  • data access restricted to the operator;
  • automatic account lockout after repeated failed sign-in attempts.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the National Privacy Commission as required by law.

8. Your rights under the Data Privacy Act

As a data subject, you have the rights listed in DPA Section 16, including:

  • Right to be informed of how your personal data is being processed.
  • Right to access the personal data we hold about you.
  • Right to correct inaccurate or outdated information.
  • Right to object to processing, including processing for direct marketing.
  • Right to erasure or blocking of your data when there is a valid reason.
  • Right to damages if you have been harmed by inaccurate or unlawful processing.
  • Right to data portability — receive your data in a structured, commonly used format.
  • Right to file a complaint with the National Privacy Commission at privacy.gov.ph if you believe your rights have been violated.

To exercise any of these rights, contact us at the address below. We will respond within a reasonable time, typically within thirty (30) days.

9. Cookies and tracking

The marketing site is static and does not set cookies or use third-party analytics.

The chat and admin applications use your browser’s built-in storage to keep you signed in. This is strictly necessary for the service to work — it is not used for tracking, profiling, or advertising. Clearing your browser’s site data will sign you out.

If we add analytics or any other tracking in the future, we will update this policy and, where consent is required, request it explicitly.

10. Children’s privacy

Atorni is intended for adults — typically legal professionals, students, and researchers. We do not knowingly collect personal data from children under fifteen (15) years of age, and the DPA’s heightened-protection rules for sensitive personal information of minors apply where relevant. If you believe a child has provided us personal information, please contact us so we can delete it.

11. Changes to this policy

We may update this Privacy Policy from time to time. The “Effective date” at the top will reflect when the latest version took effect. Material changes will be communicated through the chat application and, where applicable, by email to waitlist subscribers.

12. Disclaimer

Atorni provides legal information, not legal advice. The AI’s responses may contain errors, omissions, or outdated information, and they do not create a lawyer-client relationship. Always verify outputs against primary sources before relying on them for any legal decision, filing, or transaction.

13. Contact

For any question about this policy, or to exercise any of the rights described above:

  • Email: privacy@atorni.ph
  • Operator: Karl Gabriel M. Anciro
  • Address: 2F Unit 3, 34 Matias St., Brgy. Paltok, Quezon City, Philippines 1105

To file a complaint with the supervising regulator: