EntificLabs.

Entific Labs is a brand of TSV Studios Inc., incorporated in British Columbia, Canada.

Documents

  • Terms of Use
  • Privacy Policy
  • Data Processing Addendum

Version 1.0
Last updated August 21, 2026

Privacy Policy

How TSV Studios Inc., trading as Entific Labs, handles personal information.

The short version. We collect what we need to run the Service and bill for it. We never sell personal information. We never use your files or your clients' information to train AI models. Most of the sensitive data in the Service belongs to your clients, not to us — for that data you are the controller and we act only on your instructions.

1. Two different roles

This distinction runs through everything below, so it comes first.

Account data — we are the controller

Information about you as a user: your name, email address, organisation, billing details, and how you use the Service. We decide why and how this is processed, and this Policy governs it.

Customer Content — we are a processor

The documents you upload and the case records you create, including personal information about your own clients — names, contact details, UCI numbers, immigration history, and the contents of the documents themselves. We hold this on your behalf and act on your instructions. Your organisation is the controller. Our obligations are set out in the Data Processing Addendum.

If you are an individual whose lawyer or consultant uses Entific and you want to exercise a privacy right over your own information, please contact them directly — they control that data and we cannot lawfully act on it without their instruction. We will assist them promptly.

2. Personal information we collect

2.1 Information you provide

  • Account information — name, email address, and the organisation you belong to, collected when you register.
  • Billing information — plan, subscription status, and transaction history. Card details are collected and stored by Stripe; we never receive or store your full card number.
  • Communications — messages you send us for support or enquiries, and their contents.
  • Customer Content — documents, prompts, and case records you submit. Handled as described in Section 1.

2.2 Information collected automatically

  • Usage data — pages visited, features used, timestamps, and approximate location derived from IP address.
  • Device data — browser type, operating system, and device identifiers.
  • Session recordings — we use PostHog to record how the interface is used. Form inputs are masked before capture, so text you type into the Service is not recorded. We do this specifically because inputs here carry privileged facts.

2.3 Public sources

The Service includes a corpus of court decisions published by the Federal Court of Canada and other tribunals. Those decisions are public records and may contain personal information about the parties to them. We reproduce them under the Reproduction of Federal Law Order (SI/97-5) as unofficial copies, and we link to the official version of each.

3. How we use personal information

  • To provide the Service — authenticate you, process your requests, and store your work.
  • To bill you — process payments, manage subscriptions, and maintain records.
  • To improve the Service — understand which features are used and where the interface fails, using aggregated usage data. See the limits in Section 4.
  • To communicate — service notices, security alerts, and support responses.
  • To keep the Service secure — detect and prevent fraud, abuse, and unauthorised access.
  • To comply with law — meet legal, accounting, and reporting obligations.

4. Artificial intelligence and your data

We do not use Customer Content to train AI models. Not your uploaded documents, not your prompts, not the outputs generated for you, and not your case records. We contractually require our model providers not to train on it either.

Our systems improve by ingesting published court decisions and other public legal sources — never the files you entrust to us.

To generate an output, the Service sends the relevant part of your content to a model provider listed in Section 6. That content is processed to answer your request and is not retained by the provider for training. Aggregate operational metrics — request counts, latency, error rates, token usage — are used to run and improve the Service; the content itself is not.

Outputs are generated automatically and may be inaccurate. We do not use automated decision-making that produces legal effects about you.

5. How we share personal information

We share personal information only as described here. We do not sell it.

  • Service providers — the vendors in Section 6, who process data on our behalf under contract.
  • Within your organisation — administrators and collaborators on a case can see content shared with them.
  • Legal and safety — where required by law, court order, or to protect rights and safety. Where we are permitted to notify you of a legally compelled disclosure, we will.
  • Corporate transactions — in a merger, acquisition, or sale of assets, subject to this Policy continuing to apply.

6. Service providers

These vendors process data on our behalf. The final column marks those that may handle Customer Content — the ones that matter most in a security review.

ProviderPurposeLocationCustomer Content
Vercel Inc.Application hosting and content deliveryUnited StatesYes
Supabase Inc.Database and file storageCanadaYes
Clerk Inc.Authentication and account identityUnited StatesNo
Stripe, Inc.Payment processing and billingUnited StatesNo
Algolia SASSearch infrastructure for published court decisionsUnited States / European UnionNo
PostHog Inc.Product analytics and session replay. Form inputs are masked before captureUnited StatesNo
Railway Corp.Application hostingCanadaYes
Google LLCAI model processingUnited StatesYes
OpenAI, L.L.C.Language model processingUnited StatesYes
NVIDIA CorporationLanguage model processingUnited StatesYes

7. International transfers

Entific is based in British Columbia, Canada. Most of our service providers are located in the United States, so personal information is transferred to, stored in, and processed in the United States and may be subject to lawful access requests by authorities there.

Where required, we rely on contractual protections including standard contractual clauses. If data residency is a requirement for your organisation, contact us at legal@thestarkventures.com before uploading content.

8. Retention

We keep account data for as long as your account is active and for a reasonable period afterwards to meet legal, accounting, and audit obligations. Customer Content is retained while your account is active; on termination we make it available for export for 30 days and then delete it, as described in the Data Processing Addendum. Backups are purged on a rolling cycle.

9. Security

We use technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit and at rest, role-based access controls, and restricted administrative access. No system is perfectly secure, and we cannot guarantee absolute security. If you believe you have found a vulnerability, please report it to legal@thestarkventures.com.

10. Your rights

Under Canadian federal law (PIPEDA) and, where applicable, the BC Personal Information Protection Act, you have the right to:

  • access the personal information we hold about you;
  • ask us to correct information that is inaccurate or incomplete;
  • withdraw consent, subject to legal and contractual restrictions;
  • ask us to delete information we no longer need; and
  • make a complaint about our handling of your information.

To exercise any of these, contact legal@thestarkventures.com. We will respond within 30 days. We may need to verify your identity first.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada or, in British Columbia, to the Office of the Information and Privacy Commissioner for BC.

11. Cookies and similar technologies

We use a small number of cookies and similar technologies:

  • Strictly necessary — authentication and session management, via Clerk. The Service cannot function without these.
  • Analytics — PostHog, to understand product usage. Form inputs are masked.

We do not use advertising cookies, and we do not participate in interest-based advertising networks. Most browsers let you block or delete cookies; blocking strictly necessary cookies will prevent you from signing in.

12. Children

The Service is intended for use by professionals and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact legal@thestarkventures.com and we will delete it.

13. Changes to this Policy

We may update this Policy. If we make material changes we will notify you by email or by a prominent notice in the Service before they take effect. The “last updated” date at the left shows when this version was published.

14. Contact

For any privacy question, or to exercise a right, contact our privacy contact:

TSV Studios Inc. (trading as Entific Labs)
555 Burrard Street, Vancouver, British Columbia V7X 1M8, Canada
legal@thestarkventures.com

© 2026 TSV Studios Inc. All rights reserved.

entific.ai