1. Confidential legal work and AI processing
Talden is a hosted AI workspace for professional legal work. It processes the material and context selected for a task, including confidential client material when that material is permitted under the Agreement. The Data Addendum supplies the binding confidentiality and processing commitments for individual as well as organization subscriptions. It covers nonpersonal confidential information, not only Personal Data.
Talden does not use Customer Content to train shared models. Its contractual processing arrangements prohibit its approved subprocessors from using that content to train or improve shared models or for unrelated purposes. Task-specific generation, internal review of the requested draft, source checking, user-approved memory and authorized support are different operations, described in the Data Addendum. This statement is not a promise of zero retention or no human access under all circumstances. Authorized support, a genuine security investigation and binding legal requirements have narrowly defined treatment.
The Subprocessor and Recipient Register explains model routing and the other providers that operate the Service. Anthropic ordinarily supplies chat, drafting and review through Vercel AI Gateway. Optional OpenAI functions include speech and scanned-page processing. Perplexity receives reduced research queries and named public targets, not uploaded files or full matter context. Talden does not promise U.S.-only processing, a customer-selectable residency region, or end-to-end encryption that prevents every processing provider from accessing material needed to perform the task.
2. Access and security boundaries
The standard sign-in uses a password and an emailed device code; session revocation is available. Optional Microsoft Entra sign-in does not automatically transfer an individual workspace to an employer. The individual beta has one private workspace per User. Talden uses tenant-separation controls, encrypted connector tokens, restricted personnel access, rate and run limits, signed-webhook checks, HTTPS source fetching with anti-SSRF checks, and redacted telemetry. The contractual security baseline is Data Addendum Annex 2.
The Service is not represented as SOC 2 audited, ISO certified or HIPAA-enabled. No uptime, support-response, recovery-time or recovery-point service level is included. Scheduled work is best effort, not deadline monitoring or a substitute for a lawyer's docketing and records systems. Users should retain independent copies of work they must preserve. A hash-chained audit trail records events; it does not prove legal correctness or cure an unauthorized act.
Microsoft 365 is read-only at launch. All external writes, including messages, provider-side drafts, file writes and calendar creation, remain disabled until separately activated. Google, Clio and messaging integrations are not offered merely because their names appear in a roadmap or dormant permission list. Users can stop ongoing tasks and disconnect accounts. Disconnecting Talden does not itself revoke the source provider's account grant; the connection screen provides the separate revocation route.
3. Retention, deletion and incident contact
Ordinary uploaded originals are removed after extraction unless Keep is selected. Extracted text, generated work and approved memories are separate retained records. Moving material to Trash is not permanent erasure. Permanent deletion, matter purge, account closure, backup expiry and limited legal/billing retention follow Data Addendum Annex 3. Those are different events. A subscription cancellation stops renewal; it does not instruct deletion of a client's work.
The Service supports exports of the practice archive, available documents, audit records and usage data. Account closure is handled through Support and verified before export or purge. The standard closure process provides a 30-day export opportunity followed by production deletion within 30 days, unless immediate deletion is requested. Deleted material in backups expires or is rendered unrecoverable within 90 days after production deletion, subject to narrowly lawful holds. Content-bearing audit fields follow content deletion; minimal contract and billing evidence does not carry full matter records forward indefinitely.
Report a suspected security issue through the Security contact in the Contact Directory. Do not put confidential documents into an ordinary support or security message; Talden will arrange a protected channel when needed. Talden provides Customer incident notice under the Data Addendum and cooperates with applicable legal duties. Neither this overview nor the Agreement guarantees preservation of attorney-client privilege, work-product protection or the admissibility of an audit record; those depend on the facts and applicable law.