Mylo Prime — Privacy Policy
Version: 1.1 Effective Date: August 2, 2026 Last Updated: August 2, 2026 — v1.1 supersedes v1.0 (effective February 1, 2026). Added the QuickBooks (Intuit) integration disclosure; removed a web-form contact channel that was never launched; stated plainly that no Art. 27 GDPR representative is designated because the Service is not offered in the EEA, UK, or Switzerland; carried forward the text-messaging opt-in non-sharing statement from the superseded web version. Prior versions are available on request from [email protected].
This Privacy Policy describes how Mylo Prime LLC, a Utah limited liability company (“Mylo Prime,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information in connection with the Mylo Prime websites, applications, APIs, AI agents, and related services (collectively, the “Service”).
This Policy applies to:
- Visitors to our public marketing websites (e.g., myloprime.com).
- Account holders and authorized users of the Service.
- Job applicants, partners, and others who interact with us.
It does not apply to personal information that our customers (such as law firms) submit to the Service about their own clients or matters. For that data, our customer is the controller and Mylo Prime is the processor acting on the customer’s behalf under the customer’s privacy policy and our Data Processing Addendum. If you are a customer’s client and have questions about how a law firm uses Mylo Prime, contact that firm directly.
Quick links: Categories of personal data · How we use it · How we share it · Your rights · California (CCPA / CPRA) · Utah (UCPA) · Other state rights · GDPR / UK / EEA · Contact us
1. Controller and Contact
The controller of personal information described in this Policy is Mylo Prime LLC, 320 W 500 S, Suite 200, Bountiful, UT 84010.
For privacy questions or to exercise your rights:
- Email: [email protected]
- Mail: Mylo Prime LLC, Attn: Privacy, 320 W 500 S, Suite 200, Bountiful, UT 84010
2. Categories of Personal Data We Collect
We collect the following categories of personal information.
2.1 Information you provide
- Identifiers and contact data: name, business email address, business phone number, job title, employer/firm, billing address.
- Account credentials: username, password (hashed), multi-factor-authentication tokens, SSO identifiers (e.g., Google OAuth subject, Microsoft Entra object ID).
- Payment data: for paid accounts, payment-card or ACH details, processed by our payment processors (we do not store full card numbers).
- Communications: messages you send us by email, contact form, or chat; support tickets; customer references and testimonials you provide.
- Marketing preferences: subscription elections, event registrations.
- Job-applicant data: if you apply for a job, the information in your application, resume, and interview notes.
2.2 Information collected automatically
- Device and connection data: IP address, device identifiers, browser type and version, operating system, time zone, language preferences.
- Usage data: pages and features viewed, links clicked, referring/exit pages, session duration, timestamps, click paths, search queries inside the Service.
- Telemetry: error logs, performance metrics, feature flag exposure, crash reports.
- Cookies and similar technologies: see Section 7.
2.3 Service-use data (when you use the Service as an authorized user)
When an authorized user of a customer account uses the Service, we process data the user submits or that the Service generates on the user’s behalf, including:
- Prompts and instructions the user enters.
- Content the user uploads or links (documents, audio, images, transcripts, contacts, calendar events, email content) where the customer has connected those sources.
- Outputs generated by AI models in response to user input.
- Activity logs showing which user took which action and when, for audit and security purposes.
This data is Customer Data and is processed under our Terms of Service and Data Processing Addendum on behalf of the customer.
2.4 Information from third parties
- Single sign-on providers (Google, Microsoft) when you use SSO: profile, email, organization affiliation, OAuth tokens for the scopes you authorize.
- Connected services you authorize, such as Gmail, Google Calendar, Google Drive, Airtable, Stripe, LawPay, Twilio, calendaring tools, and document management systems: data within the scopes you authorize.
- Identity verification, anti-fraud, and credit-check vendors (for high-risk or high-value transactions).
- Marketing partners and data providers (firmographic data, intent data — limited to business contact information).
- Public sources for sales-prospecting (LinkedIn, bar association directories, court records).
2.5 Sensitive personal information
In limited cases the Service may process information that some laws classify as “sensitive” or “special category” data, including:
- Account credentials.
- Precise geolocation (rare; only if a feature requires it and only after notice).
- Voice recordings and voiceprints (for the deposition-recording and call-transcription features) — see Section 14.
- Information revealing race, ethnicity, religious beliefs, health, sexual orientation, citizenship, or union membership only to the extent it appears in Customer Data uploaded to the Service (e.g., a deposition transcript or pleading).
- Children’s data — see Section 17.
We do not collect Social Security numbers, driver’s license numbers, financial-account numbers, or government-issued IDs from visitors except as needed for billing or anti-fraud, and we do not sell sensitive personal information.
2.6 No collection from children
The Service is not directed to children under 16 (or under 13 in the United States), and we do not knowingly collect personal information from them. See Section 17.
3. How We Collect Personal Data
We collect personal data:
- Directly from you, when you register, place an order, contact us, or submit data into the Service.
- Automatically, through cookies, tags, pixels, SDKs, server logs, and similar technologies when you visit our sites or use the Service.
- From your organization, if your employer or firm provisions an account for you.
- From third parties identified in Section 2.4.
4. How We Use Personal Data
We use personal data for the following purposes.
| Purpose | Description |
|---|---|
| Provide the Service | Authenticate users, deliver features, route requests to AI models, store and retrieve Customer Data, generate Outputs, integrate with connected services. |
| Operate and secure | Detect and prevent fraud, abuse, malware, account takeover; enforce our Terms and AUP; maintain backups and disaster-recovery; debug; monitor performance. |
| Improve the Service | Analyze aggregated and de-identified usage, A/B test features, evaluate model quality, generate Service Data. We do not use Customer Data to train our or any third-party foundation models without express written consent. |
| Customer support | Respond to inquiries, troubleshoot, train support staff (using redacted excerpts as needed). |
| Billing and account administration | Invoice, collect payment, recover bad debt, perform tax and accounting functions. |
| Communications | Send transactional emails, security alerts, product updates, and (with your opt-in or where permitted) marketing communications. |
| Compliance | Meet legal obligations, respond to lawful requests from authorities, enforce contracts, protect rights and safety. |
| Corporate transactions | Evaluate and effect mergers, acquisitions, financings, and asset sales. |
| Hiring | Evaluate job applicants and manage employment relationships. |
5. How We Share Personal Data
We share personal data with the following categories of recipients.
5.1 Sub-processors and service providers
Vendors that process data on our behalf to provide the Service, including:
- AI model providers (Anthropic, xAI, OpenAI, Google) for inference. We negotiate “no training on Customer Data” / zero-data-retention terms where available. The current list is published at /legal/subprocessors.
- Cloud infrastructure (Google Cloud Platform, including Cloud Run, Cloud SQL, Cloud Storage, Secret Manager).
- Telephony / messaging (Twilio).
- Payments (Stripe, LawPay).
- Email and productivity (Google Workspace).
- Analytics and observability (e.g., logging, error reporting, product analytics).
- Customer support tooling, CRM, and billing.
We require sub-processors to (a) process data only on our instructions, (b) implement appropriate security, (c) keep data confidential, (d) flow obligations to their own subcontractors, and (e) cooperate with audits and data-subject requests.
5.2 Connected services you authorize
When you connect a third-party service (e.g., Gmail), we share data with that service as needed for the integration to work. Those services have their own privacy policies.
QuickBooks (Intuit) integration
If your firm connects Mylo Prime to Intuit QuickBooks Online, we access your QuickBooks company through Intuit’s OAuth 2.0 authorization: we never see or store your Intuit password, and access continues only until you disconnect the integration or revoke the authorization in Intuit. We access accounting records needed to keep billing and trust accounting in agreement, including customers, invoices, payments, credit memos, chart of accounts, and trust-liability balances. We use that data only to synchronize your firm’s billing, invoicing, payment, and trust-reconciliation records inside Mylo Prime. We do not sell it, do not use it for advertising, and do not use it to train AI models. QuickBooks data is retained for the periods described in Section 8 and deleted on request as described in Section 9. Intuit’s own handling of your data is governed by Intuit’s privacy policy.
5.3 Within your organization
If your employer or firm administers your account, we share data with administrators (account usage, audit logs, billing).
5.4 Compliance and protection
We may disclose personal data to: (a) comply with law, legal process, or lawful government request, including subpoenas, court orders, and national-security letters; (b) enforce our agreements; (c) protect the rights, property, or safety of Mylo Prime, our customers, our users, or the public; (d) detect, prevent, or address fraud, security, or technical issues. Where permitted, we will give the affected customer notice and an opportunity to challenge.
5.5 Corporate transactions
In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, personal data may be transferred to the relevant party, subject to commercially reasonable confidentiality protections.
5.6 With consent
We share with other third parties when you direct us to or with your consent.
5.7 De-identified and aggregated data
We may share de-identified or aggregated information that does not reasonably identify any individual.
5.8 No sale of personal information
Mylo Prime does not sell personal information for monetary consideration. Whether some online-advertising activity may constitute “sharing” or “sale” under California, Colorado, or similar laws is addressed in Sections 7 and 10.
6. Artificial Intelligence Disclosures
6.1 The Service uses generative AI
The Service uses third-party large language models and generative-AI systems (provided by Anthropic, xAI, OpenAI, Google, and others) to generate Outputs. We disclose this consistent with the Utah Artificial Intelligence Policy Act, Utah Code Ann. §13-2-12 et seq., and similar laws.
6.2 What we send to AI providers
When an authorized user submits a prompt or request, we send the prompt, relevant context (which may include Customer Data the user has explicitly attached or referenced), and system instructions to one or more model providers to generate an Output. We send only the data necessary to generate the requested Output.
6.3 No training on Customer Data
We do not permit third-party AI providers to use Customer Data to train their foundation models. Where the provider supports it, we use API endpoints that contractually exclude training (e.g., zero-data-retention or no-training tiers). If a provider’s standard policy does not exclude training, we either negotiate an exclusion or we do not route Customer Data to that provider for production use.
6.4 Provider data retention
AI providers may retain prompts and outputs briefly (typically up to 30 days) for abuse monitoring, debugging, and compliance. We work to minimize this retention. Current provider-specific terms and retention periods are summarized at /legal/subprocessors.
6.5 Logging by Mylo Prime
We log prompts, Outputs, and metadata (user, timestamp, model used, tokens, latency, errors) for the purposes of operating, securing, debugging, and improving the Service, billing, and detecting abuse. Logs are retained per Section 8.
6.6 Outputs are not legal advice
Outputs are tools to assist licensed professionals; they are not legal advice and do not create an attorney-client relationship with Mylo Prime. Customer Data submitted by a law firm is processed by Mylo Prime as the firm’s agent, and the firm remains responsible for client confidentiality and the attorney-client privilege.
6.7 Automated decision-making
We do not use personal information for automated decision-making that produces legal or similarly significant effects on you without meaningful human involvement. When the Service classifies, scores, or recommends content for our customer’s review, the customer’s authorized user remains the decision-maker.
6.8 Hallucinations and errors
Generative AI may produce inaccurate, incomplete, or fabricated content. The Service includes prompts and Output review to mitigate, but Outputs must be independently verified before use. See Section 12 of the Terms of Service for the full disclosure.
7. Cookies, Tracking, and Online Advertising
7.1 What we use
We use cookies, web beacons, pixels, local storage, and SDKs (collectively, “Cookies”) for the following purposes.
| Category | Purpose | Disable? |
|---|---|---|
| Strictly necessary | Authentication, session management, security, load balancing. | No (required for the Service to function). |
| Functional | Preferences, language, accessibility settings. | Yes, via browser or in-product controls. |
| Performance / analytics | Usage measurement, A/B testing, error tracking. | Yes, via consent banner where required and via the cookie-preferences page. |
| Marketing | Measuring marketing effectiveness on our public sites; we do not target ads inside the authenticated Service. | Yes, via consent banner where required. |
7.2 Do Not Track and Global Privacy Control
We honor the Global Privacy Control (GPC) signal as a request to opt out of any “sharing” or “sale” under applicable laws. Most browsers’ “Do Not Track” signals are not standardized; we treat GPC as the controlling signal.
7.3 Cookie controls
You can manage Cookies via: (a) the consent banner on first visit (where required); (b) the “Cookie preferences” link in our website footer; (c) your browser settings. Disabling Cookies may impair functionality.
8. Retention
We retain personal data only as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, and reporting requirements. General periods (subject to longer retention if required by law or for dispute defense):
| Data | Retention |
|---|---|
| Account records | Term of account + 7 years (limitations periods, tax). |
| Customer Data inside the Service | Per customer’s settings; on termination, retained for up to 30 days for export, then deleted within 60 days, except as required by law or for backups/audit. |
| Server logs, security logs | 12-24 months. |
| Prompt/Output logs | 12 months by default; shorter for customers under contractual restrictions. |
| Marketing data | Until you opt out + 24 months. |
| Job-applicant data | 1 year for non-hires unless you consent to longer. |
| Billing and tax records | 7 years. |
| Backups | Cycled within 90 days. |
When data is no longer needed, we delete or de-identify it. Backups are deleted in the ordinary course of backup rotation.
9. Your Privacy Rights
Subject to applicable law and verification, you may have the following rights regarding personal information about you:
- Access — receive a copy of personal data we hold about you.
- Correction — request that we correct inaccurate or incomplete data.
- Deletion — request that we delete personal data, subject to exceptions.
- Portability — request a copy in a structured, machine-readable format.
- Restriction — restrict our processing in certain circumstances.
- Objection — object to processing based on legitimate interests, including for profiling or marketing.
- Opt out of “sale” or “sharing” — see Section 10 for California; Section 11 for Utah; Section 12 for other states.
- Limit use of sensitive personal information — see Section 10.
- Withdraw consent — where processing is based on consent, you may withdraw at any time without affecting prior processing.
- No discrimination — we will not discriminate against you for exercising your rights.
- Lodge a complaint with a supervisory authority (if you are in the EEA, UK, or Switzerland) or the relevant state attorney general.
9.1 How to exercise your rights
Submit a request by:
- Web form: myloprime.com/privacy/request
- Email: [email protected]
- Phone: 801-693-9999
We will verify your identity using information you have on file with us, with reasonable additional steps for sensitive requests. We will respond within the timeframes required by applicable law (generally 45 days for U.S. state laws, with one 45-day extension on notice; one month for GDPR/UK GDPR with a 2-month extension where complex).
9.2 Authorized agents
You may use an authorized agent to submit a request on your behalf. We may require written authorization and verification of the agent’s authority.
9.3 If we deny a request
We will tell you why. You may appeal a denial by replying to our response with the words “appeal” in the subject line; we will respond within the time required by applicable law (e.g., 45 days under VCDPA, CPA, CTDPA, UCPA).
9.4 Customer Data
If your personal information is held in the Service as Customer Data submitted by a Mylo Prime customer (such as a law firm), please direct your request to that customer. We will assist the customer in responding consistent with our Data Processing Addendum.
10. California Residents (CCPA / CPRA) Disclosures
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”), gives you the rights described in Section 9 plus the disclosures below. The CCPA does not apply to personal information we process on behalf of customers as a service provider.
10.1 Categories of personal information collected (last 12 months)
| CCPA category | Collected | Examples |
|---|---|---|
| Identifiers | Yes | Name, email, IP, account ID. |
| California Customer Records (Cal. Civ. Code §1798.80(e)) | Yes | Name, contact info, billing address. |
| Protected classifications | Limited | Only as appears in Customer Data submitted to the Service. |
| Commercial information | Yes | Subscription plan, transaction history. |
| Internet/network activity | Yes | Cookies, usage telemetry. |
| Geolocation (general) | Yes | Inferred from IP. |
| Geolocation (precise) | Limited | Only if a feature requires it and you authorize. |
| Audio/visual | Yes | Voice recordings (e.g., deposition feature) when used. |
| Professional/employment | Yes | Job title, employer, job-applicant data. |
| Education | Limited | Only if provided by job applicants. |
| Inferences | Yes | Product-engagement inferences, prospect scoring. |
| Sensitive personal information | Limited | Account credentials; voiceprints (deposition feature); other categories only as appears in Customer Data. |
10.2 Sources, business purposes, recipients
See Sections 3, 4, and 5 above. We use the categories above for the business purposes listed in Section 4.
10.3 “Sale” and “sharing”
We do not sell personal information for monetary consideration. We may “share” personal information for cross-context behavioral advertising on our public marketing sites (not inside the authenticated Service) where consent is given. You can opt out via the “Do Not Sell or Share My Personal Information” link in our footer or by sending the GPC signal.
10.4 Sensitive personal information
We use sensitive personal information only for the purposes permitted by Cal. Civ. Code §1798.121(a) and identified in this Policy. You can request that we limit the use of sensitive personal information via the “Limit the Use of My Sensitive Personal Information” link in our footer or by emailing [email protected].
10.5 Retention
See Section 8.
10.6 Shine-the-Light
California residents may request information once per year about disclosures of personal information to third parties for direct-marketing purposes. Email [email protected] with “Shine the Light Request” in the subject line.
10.7 No discrimination
We will not discriminate against you for exercising your CCPA rights.
11. Utah Residents (UCPA) Disclosures
If you are a Utah consumer, the Utah Consumer Privacy Act (Utah Code Ann. §13-61-101 et seq.) gives you the rights to (a) confirm whether we process your personal data; (b) access it; (c) delete it; (d) obtain a copy in a portable format; (e) opt out of targeted advertising; and (f) opt out of the sale of your personal data.
You may exercise these rights as described in Section 9.1. Utah does not currently provide a right to correct or to appeal a denial; we will nonetheless honor reasonable correction requests and offer the appeal process described in Section 9.3 as a courtesy.
12. Other US State Privacy Rights
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), Oregon, Montana, Iowa, Tennessee, Indiana, New Hampshire, Delaware, New Jersey, Florida, and other states with comprehensive privacy laws have rights similar to those in Sections 9-11, including access, correction, deletion, portability, and opt-out of targeted advertising / sale / profiling. Use the procedure in Section 9.1.
If you are a Nevada resident, you may opt out of the sale of certain “covered information” by emailing [email protected].
If you are a Washington resident and your data falls within the My Health My Data Act, contact [email protected] to exercise the rights under that statute.
If you are an Illinois resident and the Service collects biometric identifiers (e.g., voiceprints from deposition recordings), Section 14 describes our practices under the Illinois Biometric Information Privacy Act (BIPA).
13. European Economic Area, United Kingdom, and Switzerland
If you are in the EEA, UK, or Switzerland, this Section provides the disclosures required by the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and the Swiss Federal Act on Data Protection.
13.1 Controller
For personal data described in this Policy, the controller is Mylo Prime LLC. For Customer Data we process for a customer, the customer is the controller and Mylo Prime is the processor.
13.2 Legal bases
We process personal data on one or more of the following legal bases:
- Contract (Art. 6(1)(b)) — to provide the Service to you or your organization.
- Legitimate interests (Art. 6(1)(f)) — to operate, secure, and improve the Service; to communicate with customers and prospects about goods and services they have shown interest in; to defend legal claims; to manage corporate transactions. Where we rely on legitimate interests, we have considered the impact on you and your rights.
- Consent (Art. 6(1)(a)) — for marketing emails to non-business contacts, optional Cookies, and certain integrations. You can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) — for tax, accounting, or to respond to lawful requests.
For special-category data (Art. 9), we rely on explicit consent or other applicable conditions, such as the data subject having manifestly made the data public, or processing necessary for the establishment, exercise, or defense of legal claims.
13.3 International transfers
We are based in the United States. When we transfer personal data from the EEA, UK, or Switzerland to the U.S. or other third countries, we use appropriate safeguards, including the European Commission’s Standard Contractual Clauses (SCCs), the UK Addendum, and the Swiss Addendum, supplemented by transfer-impact assessments and additional measures (encryption in transit and at rest, access controls, audit) as appropriate.
13.4 Your rights
You have the rights of access, rectification, erasure, restriction, objection (including for direct marketing), portability, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not engage in such automated decision-making). You may withdraw consent at any time.
13.5 Complaints
You may lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concerns first; please email [email protected].
13.6 EU/UK representative
Mylo Prime does not currently offer the Service to data subjects in the EEA, the UK, or Switzerland and has not designated a representative under Art. 27 GDPR or UK GDPR. If we become required to designate one, we will name the representative in this Policy and update the “Last Updated” date above.
14. Voice, Audio, and Biometric Information
The Service includes features that record audio (such as deposition recording, call transcription, and voice agents). When these features are used:
- We disclose the use of recording and require the user to confirm consent and any required notice to other participants.
- Recordings and derived transcripts are stored as Customer Data per the customer’s account settings.
- We use recordings to generate transcripts and Outputs and to improve quality and accuracy. We do not use recordings to identify a specific natural person except as necessary to provide the requested feature.
- Where features may create biometric identifiers (e.g., a voiceprint to identify a speaker), we obtain written consent before doing so and provide the disclosures required by laws such as the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), the Washington Biometric Privacy Act, and similar laws.
- Retention of biometric identifiers follows our written biometric retention schedule, available on request, and in any event not longer than the lesser of (a) the period required for the purpose and (b) three years after the last interaction.
15. Security
We maintain administrative, technical, and physical safeguards designed to protect personal data, including:
- Encryption in transit (TLS 1.2+) and at rest.
- Role-based access controls and the principle of least privilege.
- Multi-factor authentication for administrative access.
- Audit logging and monitoring.
- Vendor risk management.
- Incident-response procedures.
- Regular vulnerability scanning and penetration testing.
- Secure software-development lifecycle practices.
No system is perfectly secure. If you suspect a security issue, contact [email protected].
We will notify customers of security incidents affecting their data without undue delay and within seventy-two (72) hours of confirmation, consistent with our Terms of Service and DPA. We will notify individuals of breaches of their personal data as required by applicable law.
16. Marketing Communications
We may send marketing communications to business contacts where permitted by law. You can opt out at any time by clicking “unsubscribe” in any marketing email or emailing [email protected]. We will continue to send transactional and security-related communications.
For SMS marketing where applicable, we comply with TCPA, CAN-SPAM, and the Utah Telephone Fraud Prevention Act, and we obtain prior express written consent where required. STOP / HELP commands are honored.
16.1 Text messaging
Law firms using the Service may send transactional and informational text messages to clients and prospective clients who have opted in. Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the text message services necessary to deliver the messages. For how phone numbers, message content, and opt-in and opt-out records are handled, see the SMS Privacy Policy and the SMS Terms.
17. Children’s Privacy
The Service is not directed to children under 16 (or under 13 in the United States), and we do not knowingly collect personal information from them. If you believe a child under 13 has provided us personal information, contact [email protected] and we will delete it promptly.
18. Changes to This Policy
We may update this Policy from time to time. The “Last Updated” date at the top reflects the most recent change. For material changes, we will notify you by email or in-product notice and, where required by law, obtain consent. Prior versions are retained and are available on request from [email protected].
19. Contact Us
Mylo Prime LLC 320 W 500 S, Suite 200, Bountiful, UT 84010 [email protected] 801-693-9999
Registered Agent for Service of Process: Hepworth Legal, 320 W 500 S, Suite 200, Bountiful, UT 84010.
For Terms of Service, see /legal/terms. For our Data Processing Addendum, see /legal/dpa. For our Sub-processor List, see /legal/subprocessors.