Get Receipts
Legal · Privacy

Privacy Policy

What We Collect

When you use a ZIP or county lookup, that location is sent to our server and Supabase so we can resolve the jurisdiction and return the relevant official-source directory. We do not intentionally attach those lookups to a named subject unless you choose a cloud-synced project or an AI assist.

If you join the soft-launch list, send a correction, or contact us, we store the information you submit so we can follow up and improve the directory.

Payments are not active during soft launch. If paid products are introduced later, payment information will be processed by a payment provider and disclosed before checkout.

Browser-Local by Default

A new case file is stored in your browser using localStorage and IndexedDB. This can include subject details, locations, saved sources, notes, receipts, and evidence files. The application reads this local data to render and update your workspace. Clearing browser storage can delete it.

Local evidence files remain on the device unless you explicitly use an AI-assisted artifact-reading action. Creating or loading a project file is a separate action that syncs the project workspace to Supabase so it can persist beyond that browser.

AI Processing You Choose

The Guide uses OpenAI when you submit a message. We send the message and the structured case context needed to answer it, which can include subject details, locations, research steps, and saved-receipt context. We store the interaction, response, model metadata, and safety evaluation in Supabase for product quality, abuse prevention, and auditability.

Source explanation and artifact reading use Anthropic when you explicitly invoke those tools. Depending on the action, we send the selected screenshot, PDF, or text together with relevant subject, jurisdiction, station, and source context. We log the generated explanation and operational metadata in Supabase, but the application does not store the uploaded artifact bytes in that interaction log.

OpenAI states that API data is not used to train its models by default and that standard abuse-monitoring logs may be retained for up to 30 days. Anthropic states that commercial API inputs and outputs are not used for training by default and are ordinarily deleted from its systems within 30 days, subject to its stated exceptions and contract settings. Review the providers' current policies before submitting sensitive material: OpenAI API data controls and Anthropic commercial data retention.

Analytics and Service Events

We use Vercel Web Analytics for aggregate page and device information such as routes, referrers, browser or device category, and approximate geography. Vercel describes this product as avoiding permanent cross-site identifiers. We also record limited funnel events in Supabase, such as whether intake or a case step was reached. Those events are designed not to include the subject name or typed location and respect supported Do Not Track and Global Privacy Control signals. We do not use Google Analytics.

Processors and Sharing

We do not sell personal data. We disclose data to service providers only as needed to operate the product: Vercel for hosting and analytics, Supabase for database and optional project persistence, OpenAI for Guide requests, and Anthropic for explicitly requested source or artifact assistance. We may also disclose information when legally required or necessary to protect the service and its users.

Your Rights

You may request deletion of any personal data we hold by contacting us. We will respond within 30 days.

Last updated: July 9, 2026. Pending attorney review.