Privacy policy
Five Point Four Technologies, Inc. ("5point4", "we", "us") builds and operates L/UX™ HQ Control
Tower (the "Service"), a case-management, status-update and client-reporting application for law firms.
Each firm (our "customer") gets its own private deployment, for example yourfirm.luxhq.app. This policy
explains what information the Service handles, how we use it and the choices you have.
1. Who is responsible for what
Your firm decides who can use its deployment and what matter information is entered. For that matter information we act as a service provider (a "processor") on your firm's instructions. For account and sign-in information we act on our own behalf, as described here. If you are a client of a firm that uses the Service, your relationship is with that firm; please contact them first.
2. What information the Service handles
Account and sign-in
- From Google Sign-In: your Google account email, name and profile identifier, used to confirm who you are.
- Your firm's own record of you: your display name, title, role and which matters you are assigned to.
Firm matter information
- Information your firm and its users enter: matter numbers and names, clients, team assignments, critical dates, assignments between colleagues, status updates and briefs.
Google Calendar access (only if your firm uses calendar sync)
- With your permission, we receive an authorization token that lets the Service create, update and delete calendar events for critical dates on matters you work on.
- We read your upcoming calendar entries to suggest which matter they belong to. We store the title, start time and length only of entries you act on; entries you don't act on, and the notes or description field of any entry, are not stored.
Technical and security information
- An access log of actions in the Service (for example, viewing a matter or confirming a date), with time and user, which your firm can use for audit purposes.
- Standard server logs kept by our hosting providers (IP address, browser type, timestamps) for security and troubleshooting.
3. How we use Google user data
| Google data | What we do with it |
|---|---|
| Basic profile (email, name) | Sign you in and match you to the person record your firm created. Your email domain must be one your firm has approved. |
Google Calendar events (calendar.events scope) | Create an event for each confirmed critical date on a matter you work on, with the other people chosen for that date as guests; update it when the date changes; delete it when the date is done or vacated. We only act on events the Service itself created, identified by a private marker we set on them. We do not copy, export or analyze your other calendar events, and we do not store their contents. |
What those events contain. Each firm chooses how much detail its calendar entries and service emails carry. By default an entry names what the date is, the matter and the client (for example, "Reply brief due — M-04218 Northgate Mill Partners"), because a date nobody recognizes is a date nobody acts on. Email subject lines carry counts only, never a client name. A firm can ask us to reduce calendar entries to the matter number and the type of date.
Limited Use. L/UX HQ Control Tower's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features described above.
- We do not transfer Google user data to others except as needed to provide those features, to comply with law, or as part of a merger or acquisition with notice to users.
- We do not use Google user data for advertising, and we do not sell it.
- We do not use Google user data to develop, improve or train generalized artificial intelligence or machine learning models.
- No person at 5point4 reads your Google user data unless you give us permission for a specific purpose (for example, a support request), it is necessary for security, or it is required by law.
4. AI features
If your firm enables the Claude connection, an authorized user can ask questions about their matters and have drafts prepared. Those requests run with that user's own permissions: the AI can read only what that person could read in the Service, and anything it writes into the record is logged as having come from Claude. We do not use firm matter information, or Google user data, to train AI models, and our AI provider is contractually prohibited from doing so with information sent through the Service.
5. How we use other information
- To provide the Service to your firm: showing matters, dates, assignments and updates; sending the daily critical-dates email; producing reports.
- To keep the Service secure: access control, audit logs, abuse prevention and troubleshooting.
- To communicate with your firm about the Service (for example, maintenance notices or a change of sending domain).
We do not use firm matter information for any purpose other than providing the Service to that firm.
6. How information is stored and protected
- Each firm's data is stored in its own database, hosted in the United States. Access is enforced in the database itself (row-level security): users see only the matters their firm has given them access to, on every screen, in every export and in the AI features.
- Google authorization tokens are stored encrypted and are readable only by the server-side job that syncs calendars.
- All connections use HTTPS. Sign-in uses Google's own authentication, including whatever multi-factor requirement your firm has set on its Google accounts.
7. Service providers we use
We share information only with providers that help us run the Service, under agreements that limit their use of it:
- Supabase — database and authentication.
- Vercel — application hosting.
- Resend — sending service email (invitations and the daily critical-dates email).
- Google — sign-in and calendar.
- Anthropic — the AI features, where your firm has enabled them.
We may also disclose information if required by law or valid legal process, to protect the rights and safety of users or others, or on your firm's instruction. Where a legal demand reaches us for a firm's matter information, we will notify that firm unless we are prohibited from doing so.
8. Retention and deletion
- Matter information is kept for as long as your firm's agreement with us requires, then deleted or returned as that agreement provides.
- You can revoke the Service's access to your Google account at any time at myaccount.google.com/permissions. Calendar sync stops immediately.
- You can ask us to delete your stored Google token and sign-in data by writing to the address below. We will do so within 30 days, unless your firm requires us to keep audit records.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, export or delete personal information. Because your firm controls its deployment, please contact your firm first; we will help them respond. You can also contact us directly at the address below.
10. Children
The Service is for law-firm professionals and is not directed to children under 16.
11. Changes
We will post changes on this page and update the effective date. If a change materially affects how we use Google user data, we will notify affected firms before it takes effect.
12. Contact
Five Point Four Technologies, Inc.
Austin, Texas
Email: connect@5point4.com