Firm policy comes before product choice
Professional obligations around client confidentiality, privilege, retention, and legal hold are not satisfied by choosing a well-designed app. Firm-approved and documented systems are necessary context, but they do not by themselves guarantee every legal or professional obligation is met.
Start there. A personally selected tool that conflicts with firm policy creates a problem regardless of how good its encryption is.
What a consumer vault does not provide
Encryption addresses confidentiality at rest. It does not establish access logging, retention schedules, legal-hold compliance, matter-based organisation, conflict checking, or a defensible chain of custody.
Those are the properties professional obligations actually turn on, and an app that does not claim them should not be assumed to deliver them.
When mobile capture is genuinely necessary
Sometimes a photograph has to be taken on a phone. The principle then is transit rather than storage: capture, transfer to authorised systems promptly, verify the transfer, and remove the temporary copy per policy.
The phone is a capture device in that workflow, not a repository.
Practical requirements
- Confirm device and application approval with the firm before using either.
- Keep personal and client material in genuinely separate storage.
- Document retention, export, backup, and incident-response responsibilities.
- Verify each transfer to authorised storage before deleting the mobile copy.
- Know the firm's process for a suspected loss or disclosure before one occurs.
Two serious errors
- Using a personal cloud photo library for client intake material.
- Deleting material that is subject to a legal hold.
Scope of this guide
This describes general information-handling practice. It is not legal advice and does not address the rules of any particular jurisdiction or bar association.
Your professional conduct rules govern, and where this guidance conflicts with them, they win.
A fictional example
Jonas starts with a non-sensitive test: “Confirm device and app approval with the firm.” Next, Jonas follows the second check: “Separate personal and client storage.” This fictional scenario demonstrates the decision process; it is not a report of product testing.
Common mistakes
- Using a personal cloud library for client intake
- Deleting material subject to legal hold
What this workflow does not change
- Using a personal cloud library for client intake
- Deleting material subject to legal hold
Questions people ask
Does encryption make an app legally compliant?
No. Compliance depends on the full organizational, contractual, technical, and jurisdictional context.