Legal

Privacy Policy

Last updated 30 August 2026 · WakilFlow

This Privacy Policy explains how WakilFlow (“we”, “us”) collects, uses, stores, and shares information when you use our website, web app, and mobile applications. It is written for advocates and law firms in Nepal and for Google Play listing requirements. It is not legal advice.

1. Who we are

WakilFlow is practice-management software for law firms, independent advocates, and their staff. The service includes a public website, a web application, and iOS/Android apps.

Questions: [email protected]. Account and data deletion: https://wakilflow.com/delete-account

2. Scope

This policy covers personal data we process as a service provider to your firm (account data, usage of the product) and limited public-site data (for example, if you contact us from the marketing site).

Your firm remains responsible for client files it stores in the workspace under professional secrecy and applicable court rules. We process that content to host and display it for authorised members of that workspace.

3. Information we collect

Account and profile: name, username, email, phone, bar council number, firm or practice name, address, language and display preferences, role in a workspace.

Practice content you enter: cases, clients, opponents, hearings, diary, tasks, leads, payments, notes, documents, voice notes, and activity history.

Workspace and billing: organisation name, plan, trial dates, invoices/subscription records, team memberships and invitations.

Technical and security: IP address, browser/device type, timestamps, authentication tokens, and logs needed to operate and secure the service.

Optional integrations: if you connect Google Drive, we store OAuth tokens and file metadata/links so documents can be shown against a case. File bytes remain in your Google account unless you also upload a copy to our servers.

We do not require government ID numbers beyond what you choose to type into case forms. We do not sell mailing lists.

4. Data stored on your phone (mobile app)

To work online and offline, the Android/iOS app stores data on the device, including: access and refresh tokens; a cached copy of cases, hearings, documents metadata, diary, and related records (Hive); your last-used server URL; language preference; and (if you enable it) biometric enrolment that unlocks a stored session — we do not collect fingerprints or Face ID images; the operating system performs the biometric check.

If you enable daily reminders, the app schedules local notifications on the device (a dedicated notification channel). Reminder times you choose stay on the device.

Signing out, uninstalling the app, or deleting your account (below) is how you remove this device copy. Uninstall does not by itself delete your cloud account.

5. How we use information

To create and authenticate accounts, run workspaces, sync the mobile app, send transactional email (invites, password reset, account deletion confirmation, important security mail), process subscription status, provide support, improve reliability and security, and meet legal obligations.

We do not use your case files to train public AI models. Optional product features that call third-party AI, if ever enabled, will be described in-product before use.

7. Who we share data with (processors)

We do not sell personal data. We use service providers who process data on our instructions:

Amazon Web Services (AWS) — application hosting, databases, and file storage. Default region for object storage in our configuration is ap-south-1 (Mumbai); compute may run in other AWS regions we operate (currently including the United States for the production app server unless we notify you of a change).

Google — Google Drive and Google APIs if you connect Drive; Google Fonts may load in the web app. Google’s terms apply to those services.

Email delivery — transactional mail is sent through the SMTP provider configured for the deployment (for example a business mailbox). Password reset and deletion links go to the address on the account.

Payment processors, if/when card billing is enabled, receive only what is needed to collect fees. We may disclose information if required by a competent Nepal court or regulator, or to protect the security of the service.

8. International transfers

Your data may be stored or processed outside Nepal, including on AWS and Google infrastructure. We use these providers so the product can run with reasonable uptime and security. By creating an account you understand that practice data may leave Nepal. We apply encryption in transit (HTTPS/TLS) and restrict administrative access.

9. Security

Workspaces are isolated by organisation. Access inside a firm follows roles and capabilities your administrators set. Passwords are hashed; sessions use short-lived access tokens and rotating refresh tokens. Connections use TLS. No system is perfectly secure — use strong unique passwords, limit staff roles, and treat confidential filings accordingly.

10. Cookies and analytics

The website and the logged-in product use essential cookies or local storage for your session and display preferences (for example theme and language). The product stores an authentication token in the browser.

We use Google Analytics 4 across the site and the web app to understand traffic and how the product is used. It sets its own cookies and receives the page address, device and browser type, and an approximate location derived from your IP address. We do not send it your name, email, or any case, client, or document content. Advertising and personalisation signals are switched off, so this data is not used to build ad profiles.

Google Consent Mode is enabled and scoped by region. Visitors from the European Economic Area, the United Kingdom, and Switzerland are measured without analytics cookies unless they consent, so no identifier is stored on their device. Elsewhere, including Nepal, analytics cookies are set without a banner.

You can clear site data in your browser at any time; that also signs you out. Browser tracking protection and the Google Analytics opt-out add-on will stop this measurement.

11. Children

WakilFlow is built for legal professionals and firm staff. It is not directed at children under 13 (or under 18 where local law treats the user as a minor for this type of service). We do not knowingly collect personal data from children. If you believe a child has created an account, contact [email protected] and we will close it.

12. Retention

We keep account and workspace data while the account or firm subscription is active. After you delete your account we close the login immediately (see §13). Content that still belongs to other members of a firm is kept for that firm. If you were the last remaining member of a workspace, we deactivate that workspace and aim to erase or anonymise remaining practice content within 30 days, unless a longer period is required by law or an ongoing dispute.

Security logs are kept for a limited operational period. Backups roll off on a schedule and may contain copies until those backups expire.

13. Deleting your account and data (Play Store)

You can request deletion of your account and associated personal data in any of these ways:

In the web app: Settings → Security → Delete account (you must confirm your password and type DELETE).

In the mobile app: Settings → Delete my account (password confirmation).

Without signing in (including if you already uninstalled the app): open https://wakilflow.com/delete-account, enter the email on the account, and confirm using the link we send. You may also email [email protected] from that address.

When deletion completes we deactivate the login, revoke sessions, discard Google Drive tokens we stored for you, and anonymise your profile (name, email, phone, and similar). This is not a temporary freeze or disable — that login cannot be used again. Firm files remain if other people still use that workspace. This is the same deletion path listed in Google Play’s Data deletion URL.

14. Your rights

You may ask us to access, correct, or delete personal data we hold about you, or to export workspace data where the product provides it. Send requests to [email protected]. We may need to verify that the request comes from the account holder or a firm administrator. Some records cannot be erased where law or a remaining firm workspace still requires them.

16. Changes

We will update this page when our practices change and adjust the “Last updated” date. Material changes may also be noted in the product. Continued use after an update means you accept the revised policy.