AI Disclosure — Legal Ops Maestro
Effective date: 2026-05-08 Version: 2.1
You are interacting with an AI system. Legal Ops Maestro uses AI to generate polished impact narratives, resume bullets, work-pattern insights, and character archetype narratives from your tracked legal-ops work. Output is generated by artificial-intelligence models, not by human reviewers, and is labeled “AI-generated” in the product interface.
This disclosure is provided to satisfy our transparency obligations under Article 50 of the EU AI Act (Regulation (EU) 2024/1689) and comparable US state laws (including Colorado SB24-205 and Utah SB 149), as well as under GDPR Articles 13 and 14.
1. Where We Use AI
AI is used in the Services to:
- Compose polished impact narratives in your voice from your Core 12 tracking data and free-text highlights (paid Show Off Your Work Bundle);
- Generate resume-ready bullet points from the same inputs (paid Show Off Your Work Bundle);
- Produce work-pattern insights describing how you spend your time across the Core 12 (paid Show Off Your Work Bundle);
- Produce one-sentence character archetype narratives describing your work persona (free feature);
- Generate personalized quick-log button labels during onboarding (free feature).
AI is not used to make hiring, credit, licensure, disciplinary, performance evaluation, or any other automated decision that produces legal or similarly significant effects concerning you within the meaning of GDPR Article 22. All AI output is suggestive content for you to review, edit, and use at your discretion.
2. Data-Flow Chain
When you use a paid AI feature:
- The extension or web wizard composes a structured payload from only the fields you consent to send — typically your archetype, top Core 12 categories, tracked hours, and optional highlights you type.
- Your browser transmits the payload over TLS to our Cloudflare Worker backend at
legalopsmaestro.com/api/ai/*. - The Worker scans the input for credential and identifier patterns (see Section 5) and rejects any that match before any token is spent.
- The Worker assembles a server-side prompt and forwards it to Cloudflare AI Gateway under Unified Billing with Zero Data Retention (ZDR).
- The Gateway routes directly to one of two upstream model providers — Anthropic or OpenAI — on each provider’s standard API tier. ZDR ensures Cloudflare does not retain prompts or responses; standard API tiers do not train on API traffic.
- The provider returns the generated content. The Worker validates the output (length, format, refusal sentinel) and relays it to you.
- Prompts and responses are not persisted on Legal Ops Maestro servers. We log only metadata about the call (model used, token counts, cost in cents, gateway cache status, timestamp, SKU attribution) for operational accounting. Our
ai_usagetable contains no prompt or response columns.
For the free archetype-narrative feature and free onboarding-button feature, the same flow applies but the call routes to Cloudflare Workers AI (inference on Cloudflare’s global network) instead of a Unified Billing upstream. Cloudflare does not train models on Workers AI inputs.
No third-party multi-provider routers in the paid path. Cloudflare AI Gateway’s Unified Billing routes for Anthropic and OpenAI are ZDR-eligible end-to-end. Paid traffic goes Worker → Cloudflare AI Gateway → Anthropic or OpenAI directly; no aggregator sits in the middle.
Transfer note. Cloudflare Workers, Cloudflare AI Gateway, Anthropic, and OpenAI are United-States-hosted. Submissions from EEA users transfer to the US under Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. Please see our Privacy Policy §7 for details.
3. Model Providers
We may route AI requests to one or more of the following:
- Anthropic, PBC — paid AI features in the Show Off Your Work Bundle (polished impact narrative, resume bullets, work insights). Accessed via Cloudflare AI Gateway Unified Billing on the standard API tier. ZDR-composite by default. Anthropic does not train on API traffic.
- OpenAI, L.L.C. — paid AI features and Anthropic-fallback routing. Accessed via Cloudflare AI Gateway Unified Billing on the standard API tier. ZDR-composite by default. OpenAI does not train on API traffic.
- Cloudflare Workers AI — free features (archetype narrative, onboarding personalized buttons) and degraded-fallback for short-form paid features when the gateway is fully unreachable. Cloudflare neither creates nor trains the AI models made available on Workers AI, and does not use your inputs to train Cloudflare products. See Workers AI data usage.
We do not route paid traffic to Google Gemini, OpenRouter, or any other multi-provider router or aggregator.
4. Training Disclaimer
Neither Legal Ops Maestro, Cloudflare AI Gateway, Cloudflare Workers AI, Anthropic (standard API tier), nor OpenAI (standard API tier) trains AI models on your prompts or responses. Cloudflare confirmed 2026-04-28 that ZDR + no-training is a composite guarantee for Unified Billing routes to Anthropic and OpenAI; standard API tiers default to no-training without separate enterprise agreements.
5. Confidentiality — Do Not Submit Privileged or Client Data
Once you buy a paid product, any data you provide is sent through an LLM API under Zero Data Retention. The provider does not retain it and we do not log it, but you are responsible for ensuring there is no confidential data in what you submit.
Text you submit into AI-assisted features is transmitted to third-party AI providers via Cloudflare AI Gateway. You must not submit:
- information subject to the attorney-client privilege, whether your own, your firm’s, or a client’s;
- attorney work product, including mental impressions, legal strategy, draft pleadings, or memoranda prepared in anticipation of litigation;
- information you are obliged to keep confidential under ABA Model Rule 1.6 (or the analogous rule of your licensing jurisdiction), including information relating to the representation of a client, regardless of whether otherwise privileged;
- personally identifiable information of clients, opposing parties, witnesses, or third parties, unless fully de-identified;
- trade secrets, sealed court filings, grand jury material, data subject to a protective order, or material subject to export controls (ITAR/EAR);
- any information whose disclosure would breach a non-disclosure agreement, professional duty, regulatory obligation, or court order.
Use hypothetical facts, sanitized examples, or your own non-confidential career narrative when describing matter context. If in doubt, do not submit. We display a persistent reminder next to AI-feature inputs.
The Worker enforces a credential pre-scan that blocks API keys, AWS credentials, OAuth tokens, GitHub/Stripe/Slack tokens, JWT-shaped bearer tokens, and PEM-formatted private keys before any prompt reaches the AI Gateway. Cloudflare DLP additionally blocks Social Security numbers, financial identifiers, insurance and tax numbers, and government-issued ID numbers at the gateway layer. These guardrails catch obvious patterns; they do not substitute for human judgment about matter content.
Email addresses, phone numbers, and similar contact details are not blocked, because they legitimately belong in resumes and similar career artifacts.
6. Output Validation
Every AI response is validated server-side before relay:
- Refusal-sentinel detection. Each system prompt instructs the model to emit a single sentinel token (
__LOM_OUT_OF_SCOPE__) if the input falls outside the requested task. We detect that token and return a specific error rather than the model’s text. - Format and length checks. Each feature has expected shape constraints (e.g., resume bullets between 3 and 10 lines, each under 24 words; work insights with three named Markdown sections). Outputs that fail these checks return an error, and the budget is not decremented.
- Guardrails. Cloudflare AI Gateway Guardrails are enabled on both inbound and outbound traffic, blocking violence, hate, sexual, and self-harm content categories.
7. Human Review Requirement
AI outputs can be inaccurate, incomplete, or outdated. You must independently review and validate all outputs before relying on them in any career, employment, or business context. AI-generated bullets, intros, narratives, and summaries are coaching content only — not legal advice, employment endorsements, or character assessments. Final responsibility for what you publish or submit rests with you.
8. No Automated Decision-Making with Legal Effect
We do not use AI to make hiring, credit, licensure, disciplinary, performance evaluation, or any other automated decision that produces legal or similarly significant effects concerning you within the meaning of GDPR Article 22. If you believe a Legal Ops Maestro AI output has been applied to you incorrectly (e.g., by an employer using it as part of a review), contact support@legalopsmaestro.com — though our role ends at delivering the output to you.
9. AI Literacy Statement (AI Act Article 4)
OrchestrateIQ, LLC staff who deal with the operation and use of the AI systems on our behalf receive documented training appropriate to their role, technical knowledge, and the context of use, consistent with Article 4 of the EU AI Act.
10. US State Disclosures
For users in the United States, this disclosure also serves the AI interaction-notice requirements of the Colorado Artificial Intelligence Act (SB24-205, as amended by SB25B-004) and the Utah Artificial Intelligence Policy Act (SB 149). Because Legal Ops Maestro AI outputs are career-documentation content and not automated consequential decisions, the additional deployer obligations that apply to “high-risk AI systems” under those laws do not apply to the Services.
11. Logging Posture
Cloudflare AI Gateway is configured to log metadata only — model slug, upstream provider, token counts, request status, timestamp, and SKU attribution. Prompt and response bodies are not persisted at the gateway. The Worker’s ai_usage table contains the same metadata; no prompt or response columns exist on the schema.
If we ever need to inspect a specific prompt or response for incident debugging, we will follow the operational runbook (notify, toggle, reproduce, inspect, toggle off, document) — and only with the affected user’s explicit per-incident consent.
12. Changes to AI Processing
We may update AI providers, model versions, retention defaults, and related controls over time. Material updates will be reflected in this disclosure and, where required, in our Privacy Policy, with a new effective date and version number.
13. Questions or Concerns
For AI-processing questions, contact support@legalopsmaestro.com. You also have the right to lodge a complaint with your local data protection authority under GDPR, and to submit AI-related complaints to your national AI Act market-surveillance authority where such a body has been designated.