Why On-Device Case Management Protects Attorney–Client Privilege

Every case management platform that stores data in the cloud introduces a third party with access to privileged case information — and with it, a potential waiver of attorney–client privilege. On-device architecture eliminates that exposure at the architectural level.

Corrections and updates — 2026-07-12

Cloud vendor access and privilege waiver: Updated to clarify that cloud vendor access to case data does not automatically waive attorney–client privilege. Whether access constitutes waiver depends on a fact-specific analysis under United States v. Kovel, 296 F.2d 918 (2d Cir. 1961), and analogous state law — including whether the vendor's role is necessary to the representation. See ABA Model Rule 1.6.

Subpoena risk: Corrected language to reflect that on-device architecture eliminates the vendor subpoena vector but does not make all legal process "impossible" — the attorney's own device remains subject to lawful process.

Backup clarification: Added distinction between the app's own architecture (no sync) and OS-level backup mechanisms (iCloud Backup and encrypted local backups), which are user-managed and architecturally separate.

The attorney–client privilege is the oldest known privilege in Anglo-American law. It protects confidential communications between attorney and client from compelled disclosure, and it is the foundation upon which the legal profession's duty of confidentiality — codified in ABA Model Rule 1.6 — rests. Yet every year, attorneys risk inadvertent waiver of privilege by using third-party services that have access to their case data, often without realizing that the privilege analysis turns on whether the third party was "necessary" to the representation.

The core doctrinal question is straightforward under federal common law and most state evidence codes: when a client communication is shared with a third party who is not essential to the legal representation, the privilege is waived. The seminal case is United States v. Kovel, 296 F.2d 918 (2d Cir. 1961), which held that communications made through an accountant — when the accountant was "necessary" to enable the attorney to understand the client's financial circumstances — remained privileged. The Kovel extension applies only when the third party's role is functionally equivalent to that of an interpreter or translator of client information that the attorney needs to provide legal advice.

The Cloud Case Management Problem

Cloud-based case management platforms store case data on servers operated by the platform vendor. That means the vendor's employees, contractors, and infrastructure have — at minimum — technical access to the data. Some vendors encrypt data at rest and in transit, but the vendor holds the encryption keys or can re-encrypt data under government request. Whether that technical access constitutes a privilege waiver depends on a fact-specific analysis that few attorneys have performed for their case management vendor.

The Kovel Analysis for Cloud Case Management

Under Kovel, a third party's access to privileged client information is permitted only when the third party is "necessary" to enable the attorney to provide legal services. Is a cloud case management vendor necessary to the representation? The answer will depend on the specific facts — including what data the vendor can access, the vendor's contractual obligations, and whether the vendor's role is integral to the legal services the attorney provides. In many circumstances a purely administrative case management vendor may not be "necessary," but courts have not squarely addressed this question, and the analysis must be made on the specific facts of each engagement. The privilege analysis therefore turns on the specific facts: what data is stored, who at the vendor can access it, and whether the attorney had a reasonable expectation of confidentiality given the vendor's terms of service and data practices.

Several state bar ethics opinions have addressed this question for cloud-based practice management tools. The general consensus is that attorneys may use cloud services if they exercise reasonable care in selecting the vendor — including reviewing the vendor's privacy policy, data encryption practices, and contractual terms. But "reasonable care" is a floor, not a guarantee. A vendor's data breach, a government subpoena directed at the vendor, or a change in the vendor's terms of service can all create privilege complications that the attorney cannot control.

How On-Device Architecture Eliminates the Problem

On-device case management solves the third-party access problem by eliminating the third party. When case data is stored exclusively on the attorney's own device using a local persistence framework like SwiftData, there is no vendor server holding the data, no vendor employee who can access it, and no cloud infrastructure that can be subpoenaed. The attorney–client privilege analysis becomes simpler because the question of third-party access never arises.

The key architectural distinction is between data that is processed on-device and data that is transmitted to a server. Many apps marketed as "on-device" or "local-first" still transmit data to a server for backup, sync, or analytics. True on-device case management — where the persistence layer is local-only, no sync service is involved, and no data leaves the device — is architecturally distinct from the "cloud-first-with-offline-mode" approach that most case management platforms take.

Privilege Protection Comparison

Cloud case management (e.g., Clio, MyCase): Case data stored on vendor servers. Vendor has technical access. Attorney must analyze whether vendor is "necessary" under Kovel. Data subject to vendor's security posture, government subpoenas directed at vendor, and vendor's terms of service changes.

On-device case management (e.g., Docketloom): Case data stored on attorney's device only. No vendor server involved. No third-party access. No Kovel analysis required. Data protected by device-level security (passcode, Face ID / Touch ID, iOS Data Protection).

The Subpoena Risk

Consider the following scenario: An attorney uses a cloud case management platform. A litigant in a related matter serves a subpoena on the platform vendor for all data relating to the attorney's cases. The vendor must respond — it has a legal obligation to comply with valid legal process. The attorney may be able to assert privilege or move to quash, but the burden shifts to the attorney to intervene, and the vendor may disclose data before the attorney has an opportunity to object.

With on-device architecture, this scenario is architecturally eliminated. There is no vendor to subpoena. The data exists only on the attorney's device. Any legal process seeking the data must be directed at the attorney, who can assert privilege directly in response to the subpoena or discovery request. The attorney controls the data, not a third-party vendor. (The attorney's own device remains subject to lawful process, but the attorney — not a third party — controls the response.)

Practical Considerations

On-device case management is not without tradeoffs. The primary consideration is data backup: because the app does not sync data to any cloud service, the attorney must implement their own backup strategy. iOS device backups — including encrypted local backups to a computer and encrypted iCloud backups (both operating-system-level features managed through iOS Settings, not app-level sync) — provide the necessary redundancy. The attorney should verify that backups are occurring regularly and should test restoration periodically.

The second consideration is device availability: case data is only accessible on the device where it was entered. Attorneys who work across multiple devices may find this limiting. For solo practitioners and small firms who primarily work from a single iPhone or iPad, however, the tradeoff is well worth the privacy and privilege protection that on-device architecture provides.

This content is legal information, not legal advice. It does not create an attorney–client relationship and cannot substitute for consultation with a licensed attorney about your specific circumstances.

Enjoyed this post?