IRONSTICKIRONSTICK← Home

IRONSTICK — GDPR Data-Flow Declaration
Relations with External Large Language Models

Factual, code-derived description of every path on which data leaves IRONSTICK towards an external LLM, what exactly is transmitted, in which form, and where the pseudonymization layer applies. Windows desktop edition. This document describes IRONSTICK's behaviour only — what the AI provider does with received data is governed exclusively by the provider's own terms (the terms and privacy policies of the providers the user has set up — Google, Alibaba Cloud, Moonshot AI, OpenAI and/or Anthropic), which the user must review separately.

1. Scope and endpoints

AI API, AI desktop app and MCP server on the left, the IRONSTICK Client in the middle, data vault with AES-256, IRONSTICK Server and scan app on the right

In-app external AI calls go to the provider the automatic cascade is using at that moment. The user can set up up to five providers; every provider that is set up is used automatically in this fixed, cost-saving order: Gemini (Google) → Qwen (Alibaba Cloud) → Kimi (Moonshot AI) → ChatGPT (OpenAI) → Claude (Anthropic). At every program start IRONSTICK checks which of them respond; if a quota or credit runs out during the day, or a provider stops answering, the very same request is repeated with the next provider, which is then used for the rest of the day. The content transmitted is identical on every provider (section 3 onwards: pseudonymized by the router, consent, audit log). The endpoints are:

Gemini through a Google account is a consumer service, not a commissioned-processing channel. According to the Google Antigravity terms, Google may use interactions to improve its products and machine-learning technologies, and Google staff may review them, unless the user switches this off in the Google Antigravity settings; there is no data-processing agreement for this path. IRONSTICK transmits the same pseudonymized content as on the API paths, but a practice whose professional rules require a data-processing agreement for every processor should not set up Gemini — a provider that is not set up is never used by the cascade.

Three configurable model tiers are used per provider (small / medium / large). A separate, optional channel is the desktop connector (section 4.9): there, data flows into the user's own local desktop AI (Claude Desktop / Claude Code, ChatGPT Desktop, Qwen Desktop or Kimi Desktop), i.e. to that AI's provider (Anthropic, OpenAI, Alibaba Cloud/Qwen or Moonshot AI/Kimi) under the user's own subscription/account with that provider. The bridges may run in parallel — the same local MCP server can be registered with Claude, ChatGPT, Qwen and Kimi at once, and they can work on the same case simultaneously. IRONSTICK operates no server of its own; no data ever flows to the software vendor. The optional office LAN server (IRONSTICK SERVER, section 9) does not change this: it is operated by the law firm itself, on the firm's own hardware, inside the firm's own network — it never contacts the vendor and never contacts any AI provider.

The master switch is the user's own access. In-app external AI processing exists only if the user has opened their own account with an AI provider and entered their own access key in the configuration (for Gemini: signed in with their Google account). Without any provider set up, no in-app external AI call can occur at all — every feature described in section 4 then stays local or is simply unavailable. That account is a direct contract between the user and the provider; IRONSTICK is not a party to it. The same applies to the desktop connector, which requires the user's own subscription/account with the chosen desktop AI provider (Anthropic, OpenAI, Alibaba Cloud/Qwen or Moonshot AI/Kimi). Documents marked secret are excluded from the connector's and the chat's tools, from the AI instruction package and from every generated output (attachments, dossiers, exports); their processing during capture follows the user's deliberate choice at capture time (section 4.1).

Fully local (nothing leaves the machine): text extraction and OCR, the deterministic local chat layer, global search, relevance radar, letter-chain analysis, dossier/PDF generation, the redaction finder's local pass, and the building of the AI instruction package.

2. The pseudonymization layer

Every in-app agent run can carry a pseudonymizer that tokenizes outgoing text, translates tool arguments back for local execution, re-tokenizes tool results, and de-tokenizes the final answer locally. The mapping lives only in memory, one fresh mapping per operation; it is never persisted.

Top: IRONSTICK Client, anonymized figure with gears, AI API; bottom: IRONSTICK Client, user, AI desktop app

2.1 What is replaced

SourceFieldsToken
Client recordsname, CNP, phone, e-mail, address+city $PARTEI_A$, $CNP_A$, $TEL_A$, $MAIL_A$, $ADRESSE_A$
Persons / entitiesfull name (person or company), CNP $PARTEI_B$ / $FIRMA_A$, $CNP_B$
Casescase number, opponent, claimant $FALL_A$, $PARTEI_C$…
Pattern layer (unknown values in free text) court file numbers (n/nnn/yyyy), 13-digit CNPs, IBANs, e-mail addresses, plausible phone numberssame token families

2.2 What deliberately stays real

2.3 Deliberate clear-name exceptions

3. Consent moments and the audit log

Calls routed through the central router are consent-gated and logged: each model round writes a row to the local audit table (T0_AiExtLog) with the complete request and response in the tokenized form that actually left the machine; refused/blocked attempts are logged without payload. The consent dialog states model tier and approximate request size, and one approval covers the current screen session (for document capture: the current program run).

Flows with automatic consent (no dialog): background e-mail triage (continuous operation), the data consistency monitor's analysis run, and the redaction AI finder (enabling its toggle is the consent). These are still pseudonymized (except the redaction finder's intended clear-name answers) and still audited.
Flows that bypass the router: the word processor's AI functions, read-aloud preprocessing and the File→Markdown AI correction call the API directly. They are pseudonymized (exception: read-aloud), but they show no consent dialog of their own and write no audit-log rows. The user's operation of these features (pressing the AI button, starting a generation, starting read-aloud with the AI toggle on) is the consent moment.

4. The data flows, use case by use case

4.1 Document capture

Text extraction and OCR are local. If an API key is configured, IRONSTICK asks once per program run, then up to four call types run (all pseudonymized, all audited):

4.2 E-mail monitor (triage)

Case assignment is deterministic first (case number or known registry number found in subject/snippet — no AI call). Otherwise one small-tier call per e-mail with exactly: sender name and address, subject, and the stored preview snippet (hard-capped at 1,500 characters) — never the full body — plus the complete case list (tokenized) as matching context. Answer: priority + case number. In the e-mail screen this is consent-gated once per session; in background operation it runs without a dialog (enabling the monitor is the consent). Pseudonymized and audited in both modes.

No tracking pixels. Opening a mail in the monitor never contacts the sender's server: images referenced by an internet address (including invisible tracking pixels) are not loaded and appear as placeholders with a notice, so the sender cannot learn when, how often or from which address a mail was read. Only images embedded in the mail itself are displayed.

4.3 Person analysis (web research)

Three stages after a one-per-session consent:

The result is stored locally with reliability "unconfirmed". The related autofill buttons on the person/institution forms likewise send the typed name in clear text (documented exception).

4.3a OSINT party check (osint_entity)

The OSINT check of a party is a fixed procedure the application runs itself when a connected AI calls it with name, city, district, country and natural/juristic person:

The result is returned to the calling AI as a prepared, unverified profile. Nothing is written into the master data: every finding passes the review gate of the data consistency monitor (section 4.5) and is adopted only when the user accepts it. Only publicly accessible sources are evaluated.

4.4 Daily protocol

The screen itself is local. Importing free-form text runs a local parser first; only when no protocol format marker is found does an AI fallback normalize the raw text: the pasted text is sent completely (abort above 200,000 characters), small tier, consent-gated, pseudonymized, audited. Stored protocols leave the machine only as tool results of the chat/connector (capped excerpts) or inside the AI instruction package (section 5).

4.5 Data consistency monitor

Phase 1 (e-mail ↔ master data) is fully deterministic. Phase 2 sends one small-tier call (pseudonymized, audited, no dialog, throttled to new inbound documents) containing: all stored institution and person/entity master records of the owner (IDs, names, contact data, CNP — tokenized where in the dictionary; institution names clear), all party names from cases, and de-duplicated contact-region snippets (±~100 characters around address/phone/tax markers) from inbound document full texts, capped at 130,000 characters in total. The answer only ever becomes a suggestion that the user must accept in the monitor.

4.6 Word processor (AI assistance in the text)

None of the word-processor calls show a separate consent dialog or write audit-log rows (router bypass, see section 3).

4.7 Red/Blue Team review and dialogue summary (API)

Two further API flows belong to drafting. Red/Blue Team: if the user has switched it on for the active provider (switch next to the API key; a saved key is required), every formal document handed over via deliver_file — from the in-app chat and from the desktop connector alike — is read once more by the same provider as opposing counsel (medium tier). Transmitted: the draft text, the date and the case's jurisdiction; pseudonymized through the router and audited like every router call; no separate dialog — the switch is the consent; at most two rounds per file, after the second round the file is handed over regardless, with the reviewer's report attached for the user. Dialogue summary: in long chat sessions the older part of the dialogue (only the user's questions and the model's final answers, never tool results) is condensed by the active provider (small tier, background) into a 2,000-character summary that replaces the raw history; it is stored encrypted in the scratch store and overwritten each time.

4.8 AI chat (external, API)

Consent once per chat session; medium tier with automatic escalation to the large tier (the whole context is then sent again); pseudonymized; every round audited. Each turn transmits: the system prompt (static rules), the live GUI context (current screen, open case/client incl. client name — tokenized), up to 10 AI-memory entries of the open client, the most recent dialogue capped at 6,000 characters plus a 2,000-character summary of older turns (4.7) and the list of the chat's scratch files. Every tool the model calls returns its result into the API conversation — including document full texts (capped at 10,000 characters per item; larger results are written to the encrypted scratch store and read in portions), e-mail bodies and daily-protocol excerpts. Since September 2026 the chat uses the same tool layer and the same delivery gates as the desktop connector (4.9): pleading verification, Red/Blue Team (4.7) and hand-over through the export dialog — what leaves the system is a submission-ready template. The local chat layer answers routine requests without any transmission.

Two convenience tools deserve explicit mention. get_weather fetches current weather data for a named place from the non-LLM service Open-Meteo (section 7) — only the place name / its coordinates are transmitted to that service, never case or person data. get_my_location answers exclusively from the most recent locally stored security snapshot (section 8): the AI's request triggers no new external lookup — it only reads what is already on disk. As with every tool, what these tools return flows back into the AI conversation, i.e. to the AI provider.

4.9 Bridge to a local desktop AI (Claude Desktop / Claude Code / ChatGPT Desktop / Qwen Desktop / Kimi Desktop) — OPTIONAL add-on modules

Each desktop-AI access is an optional module, purchased separately. It exists only where the practice has acquired and installed the respective bridge module; without any module, the connector section stays locked in the configuration, the local endpoint never starts, and none of the flows described in this section can occur. The same local STDIO MCP server can be registered with Claude Desktop/Claude Code, ChatGPT Desktop, Qwen Desktop and/or Kimi Desktop — the mechanics below are identical for all; only the receiving provider differs.

This channel transmits raw, unpseudonymized case data. That is its purpose: the user's own desktop-AI session drafts submission-ready templates and therefore needs real names and numbers.

5. The AI instruction package (export ZIP)

IRONSTICK Client, user with MD files and ZIP archive, AI web app

Building the package is local and involves no AI call. It produces clear-text Markdown (no pseudonymization) intended to be uploaded by the user to an external LLM of their choice. Content:

FileContent
Casesall cases of the selected client with parties, status and evidence-ID index (no full texts)
Entitiesall persons/entities of the entire practice (not only this client) incl. CNP/CUI, birth date, full contact data, profession, vehicle — plus the stored analysis blocks (assessment, vulnerabilities, residences, finances, social environment, sources)
Institutions, Deadlinesall institutions; active deadlines with case numbers and client name
Mailthe 100 most recent e-mails practice-wide: sender, recipient, subject, attachment file names, snippet ≤500 characters (no full bodies)
Daily protocollast 10 days, practice-wide, incl. case chronology of that window
Per caseone dossier per case: the complete chronicle with document full texts (budget ~170 KB per file, then compact form), client and party identifiers incl. CNP; plus all case background notes uncapped
Instruction filesfive working-rule documents — no personal data
What happens when this ZIP is fed to a foreign LLM: the user personally transfers, in clear text, substantial parts of the entire practice — client identities with national ID numbers, third-party profiles including sensitive assessments, practice-wide correspondence metadata and case files — to that provider. From that moment the data is processed under the foreign provider's terms (training use, retention, jurisdiction) entirely outside IRONSTICK's control. IRONSTICK shows a privacy warning before the export (once per program run) and offers the export also to Google Drive, which additionally places the files with Google. The user acts as the transmitting controller under GDPR and must ensure a legal basis (e.g. Art. 6, professional secrecy rules) before uploading.

Documents marked secret are excluded from deadlines, daily protocols and case dossiers.

6. Summary matrix

FlowWhat leaves (form)PseudonymizedOwn consent dialogAudit log
Document capture (4 calls)OCR/document text ≤30k, case/name listsyesyes — once per program runyes
E-mail triage (screen)From/Subject/Snippet ≤1.5k + case listyesyes — once per sessionyes
E-mail triage (background)sameyesno (monitor switch = consent)yes
Person research st. 1real name (web search)no — by designyes — once per sessionyes (clear)
Person research st. 2/3page texts ≤8k / ≤6k per sourceyessame consentyes
Person/institution autofilltyped name (web search)no — by designyes — once per sessionyes (clear)
Daily-protocol AI importpasted raw text ≤200kyesyesyes
Consistency monitormaster records + contact regions ≤130kyes (instit. names clear)no (throttled background)yes
Word processor: revise / structureselection + 6k context / doc lines ≤40kyesno (button = consent)no
Read-aloud preprocessingeach sentence, clear textnono (start = consent)no
Red/Blue Team review (API)draft text + date + jurisdiction, per round (max 2)yesno (switch = consent)yes
Dialogue summary (API)older dialogue turns (user/assistant only)yesno (part of the chat consent)yes
File→Markdown AI correctionconverted textyesnono
Redaction AI finderalready-redacted text; answers contain third-party clear namesoff — by designtoggle = consentyes
AI chat (external)prompt + GUI ctx + memory + 6k tail + 2k summary + tool results ≤10k/itemyesyes — once per sessionyes
Desktop-AI bridge (Claude Desktop/Code, ChatGPT Desktop, Qwen Desktop, Kimi Desktop)raw tool results (full case data)no — by designyes — once per program run, 10-min block on refusalno (app side)
AI instruction ZIPclear-text practice export (user-initiated upload)nowarning once per program runn/a

7. Non-LLM external services (for completeness)

IRONSTICK Client, internet, location symbol and weather symbol

Independent of any LLM, the following features contact external services with the minimum data needed: number validation (EU VIES, EORI, GLEIF, business registers — the number being checked), geocoding of addresses (OpenStreetMap Nominatim — the address), the person search's direct web queries (the name), IMAP (your mail server), and optional exports to Google Drive (the exported files). None of these involve the AI provider.

Two further services receive equally minimal data:

Neither of these services involves the AI provider.

8. Local storage, integrity and user control

IRONSTICK Client with TOTP access lock; documents, scratch store and database encrypted with AES-256

Independent of the AI channels above, the following applies to all data IRONSTICK holds:

Allocation of responsibility. Because IRONSTICK stores everything locally and transmits data only on the paths documented in sections 1–7 — each of them either pseudonymized, consent-gated, or triggered by a deliberate user action — the operator of the practice is the sole data controller: they choose the storage medium and its encryption, manage and retain backups, decide which AI functions are enabled, give or withhold each consent, and alone decide what is done with every document, export or backup the software produces. AI-generated content — drafts, summaries, assessments, classifications — is always a proposal that the user must professionally review before relying on or dispatching it. This document exists so that every one of those decisions can be made on full knowledge of the actual data flows.

9. The optional office LAN server (IRONSTICK SERVER)

IRONSTICK Server and IRONSTICK Client connected over the LAN; the server has no connection to the internet

Practices with several IRONSTICK workstations can operate the optional IRONSTICK SERVER — a coordination service running on the firm's own Synology NAS, inside the firm's own local network. For the purposes of this declaration the decisive facts are:

Annex — Model clause for your client privacy notice (proposal)

The following text is a drafting proposal that a law practice using IRONSTICK can copy into its own client privacy notice. It is written to be accurate to the data flows described above — it promises no more protection than the software actually provides. It deliberately avoids citations of statutory articles so it can be pasted into notices of any structure.

Before you paste this — checklist for the lawyer:
  1. Have the data-processing agreement of every AI provider you have set up in place, name in the clause only the providers you actually use, and check the sentence on training and retention against the terms you actually signed. The clause below does not cover Gemini through a Google account (a consumer service without such an agreement, section 1) — if you set that path up, it needs its own wording and normally the client's explicit consent.
  2. Keep the bracketed sentence about the AI workspace only if you really use the desktop-AI connector (Claude Desktop/Code, ChatGPT Desktop, Qwen Desktop or Kimi Desktop); delete it otherwise.
  3. This clause covers the in-app flows described in this document. It does not cover the AI instruction package (section 5) — uploading that export to any AI service is a separate decision and will normally require the client's explicit consent.
  4. If you have disabled individual AI functions in the configurator, shorten the list of purposes accordingly — describe exactly what you use, no more.
  5. This is a drafting proposal, not legal advice. Have it reviewed against your bar's professional rules and local data-protection practice before use.

English (master)

AI-assisted case processing. Our practice uses the case-management software IRONSTICK, which includes AI-assisted functions. For these functions, selected data from your file may be transmitted to an external AI service provider (depending on availability: Alibaba Cloud, Moonshot AI, OpenAI or Anthropic, via their programming interfaces), which processes it on our behalf under a data-processing agreement. We use these functions for: classifying and registering incoming documents, prioritising incoming e-mail, checking our records for inconsistencies, drafting and reviewing legal documents, and legal analysis and research.

Protective measures. Before anything is transmitted, the software replaces the direct identifiers stored in our system — names, personal identification numbers, telephone numbers, e-mail addresses, postal addresses, case numbers and bank details — with neutral placeholders on our own computer. The table linking placeholders to real data never leaves our office, and the provider's answers are translated back locally. Only what the specific function requires is transmitted, within fixed size limits. A small number of functions technically require real data — for example public web research on a person's name, or the read-aloud function; we use these only through a deliberate individual action. [Optional — delete if not used: For drafting court documents we additionally use an AI workspace in which case data is processed without placeholder replacement; this channel is only ever used under our direct supervision.]

The provider. Under the provider's terms applicable to us, content transmitted through the programming interface is not used to train AI models and is stored only for a limited period. Processing may take place outside the European Economic Area; in that case the transfer is protected by the safeguards agreed in our data-processing agreement with the provider. What the provider may do with the data is governed by that agreement — not by the AI's own discretion.

Your choice. Our professional duty of confidentiality remains unaffected: beyond what is described here, no data leaves our practice. The processing rests on the mandate you have given us and on our legitimate interest in handling your case efficiently and accurately. You may object to the use of the AI-assisted functions at any time; where feasible, we will then handle your file without them. You also retain all your statutory data-protection rights, including access, correction, deletion and complaint to the supervisory authority.

This declaration was derived from the application source code (pseudonymizer, external router, audit log, and each feature's transmission path) and reflects the shipped behaviour of the described version. Processing by the AI provider itself — retention, training use, sub-processors, jurisdiction — is governed solely by the provider's terms — the links to each provider's terms and privacy policy are in the corresponding section of the AI configuration (Google Antigravity: antigravity.google/terms; Alibaba Cloud: alibabacloud.com/help/en/legal; Moonshot AI: platform.kimi.ai/docs/agreement; OpenAI: openai.com/policies). For Anthropic services consult, in their current versions: the Commercial Terms of Service (anthropic.com/legal/commercial-terms), the Usage Policy (anthropic.com/legal/aup) and the Privacy Policy (anthropic.com/legal/privacy).