What Happens to Client Data When a NJ Solo Attorney Cancels an AI Subscription
Photo by Tyler on Unsplash
6 min readSeptember 10, 2026

What Happens to Client Data When a NJ Solo Attorney Cancels an AI Subscription

NJ RPC 1.6AI data retentionlaw firm data security

AI-assisted, reviewed by Adam Elias. This post was drafted with AI under Adam's editorial rules and published under his name. It is commentary, not legal advice. Verify any rule or citation against the primary source before you rely on it. Published September 10, 2026. Reviewed September 10, 2026.

You cancel your subscription to an AI legal research or drafting tool. Maybe a better option came along, maybe the pricing jumped, maybe you just didn't use it enough to justify the line item. You click cancel, get a confirmation email, and move on.

Here's the part most NJ solo attorneys skip entirely: your client data is probably still sitting on that vendor's servers. And under New Jersey's Rules of Professional Conduct, that's your problem, not theirs.

The Offboarding Gap Nobody Talks About

AI legal tools compete aggressively for your signup. The onboarding flow is frictionless by design. The offboarding flow almost never is. Read the data retention section of any major legal AI vendor's terms of service and you'll typically find language like "we retain your data for up to 90 days following termination" or "user-uploaded content may be retained in backup systems for up to 12 months."

That's not fine print designed to be malicious. It's standard infrastructure practice. But it creates a direct tension with NJ RPC 1.6, which requires attorneys to make reasonable efforts to prevent unauthorized disclosure of client information. Your obligation doesn't pause because you've stopped paying.

The practical problem: you may have uploaded client intake documents, contract drafts with identifying terms, deposition summaries, or case memos into these tools over months or years. Some attorneys don't realize how much accumulates until they actually try to audit it before canceling.

What to Do Before You Cancel

Before you hit that button, spend thirty minutes doing what most attorneys skip.

Request a data inventory. Most enterprise-tier legal AI vendors will respond to a written request itemizing what data they hold associated with your account. Some tools have a self-service export function. Use it. Download everything and confirm what's there.

Read the deletion clause, not just the privacy policy. These are often in different documents. The privacy policy describes how data is used while you're a customer. The deletion clause, buried in the terms of service or a data processing addendum, describes what happens after termination. You want a clause that says data is deleted (not just "de-identified" or "anonymized") within a defined, short timeframe.

Submit a written deletion request on the same day you cancel. Don't assume cancellation triggers deletion. Send a separate email to the vendor's privacy or support contact, citing your account ID and requesting confirmation that all uploaded content and derived model data is deleted within a specific window. Keep that email and any response.

Check whether a BAA governs the relationship. If you signed a Business Associate Agreement because any of your clients' matters touched health information, the HIPAA-side deletion obligations may be stricter and more clearly documented than the general terms. If you never signed a BAA and health data was involved, you have a different, larger problem to address.

What NJ RPC 1.6 Actually Demands Here

NJ RPC 1.6 requires "reasonable efforts" to prevent unauthorized access to or disclosure of client information. That standard is not infinite, but it's also not passive. The New Jersey Supreme Court's guidance on electronic communications has consistently treated "reasonable efforts" as something that scales with the sensitivity of the data and the ease of the precaution.

Sending a deletion request costs you nothing. Confirming you received an acknowledgment costs you five minutes. Given how easy these steps are, failing to take them is hard to defend as "reasonable" if client data from a canceled vendor account later surfaces in a breach.

The more nuanced issue is training data. Some AI vendors, particularly those not built specifically for legal use, reserve the right to use uploaded content to improve their models. If your terms of service didn't include an explicit carve-out prohibiting use of your uploads for model training, you have a legitimate question about whether your client matter summaries or contracts contributed to a vendor's AI improvements. That's not a hypothetical exposure. It's one reason why legal-specific vendors with explicit no-training clauses command a premium worth paying.

Building a Short Offboarding Checklist Into Your Practice

Solo attorneys should treat every AI tool subscription the way they treat any third-party vendor holding client data: with a documented intake and a documented exit. That doesn't require a 20-page policy. It requires a short checklist you actually use.

At minimum, that checklist should cover: what data was uploaded to this tool, whether you have a copy, what the deletion clause says, whether you've submitted a written deletion request, and whether you've received written confirmation. Add it to your docket system as a recurring task triggered whenever a software subscription is canceled.

If you're currently using two or three AI tools and you've never reviewed what data they hold or what their offboarding terms say, that's the first thing to fix this week. Pull up each vendor's terms of service, find the data retention and deletion sections, and note the timelines. Then decide whether you're comfortable with what you find.

Most attorneys aren't, once they actually look.

Get the weekly roundup

New AI Sidebar articles delivered to your inbox. No spam, unsubscribe anytime.