Privacy Policy
1. Who We Are
ReportMax is operated by ReportShield LLC ("we," "us," or "our"), a law enforcement technology company. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the ReportMax platform ("Service"). Contact us at admin@reportmax.support.
2. Information We Collect
Account Information
When you register, we collect your name, email address, badge number, agency name, and password (stored as a one-way hash). We also store your subscription status and report usage count.
Report Generation Data
When you generate a report, we receive the tokenized version of your input — meaning subject names, addresses, dates of birth, phone numbers, and license plate numbers have already been replaced with opaque tokens on your device before transmission. The AI subprocessor receives only the tokenized text. We do not receive or store the raw identifying information you type.
We store metadata about generation events in our audit log, including: timestamp, officer ID, report type, character count of output, and whether generation succeeded. We do not log the raw content of reports.
Authentication and Session Data
We collect device identifiers (hashed), IP addresses, and user-agent strings when you log in, to support multi-factor authentication and device trust. Session tokens are stored in secure, HTTP-only cookies.
Usage and Technical Data
We collect standard server logs including request timestamps, response codes, and error information for reliability and security monitoring. These logs are retained for 90 days.
3. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Providing and maintaining the Service | Contract performance |
| Authentication and account security (MFA, device trust) | Contract performance / Legitimate interest |
| Processing subscription payments | Contract performance |
| Sending transactional emails (MFA codes, password resets, device alerts) | Contract performance |
| Audit logging for accountability and tamper-evidence | Legitimate interest / Legal obligation |
| Security monitoring and fraud prevention | Legitimate interest |
| Responding to your support requests | Contract performance |
We do not use your data for advertising, behavioral profiling, or sale to third parties. We do not use report content to train, fine-tune, or benchmark any AI model.
4. Tokenization and AI Processing
ReportMax employs client-side tokenization before AI processing:
- When you type a report, your browser automatically detects and replaces PII — including full names, street addresses, dates of birth, phone numbers, and license plate numbers — with opaque placeholder tokens (e.g., [NAME_1], [ADDR_1])
- Only the tokenized text is transmitted to our servers and onward to the AI API
- The token-to-value mapping exists only in your browser session memory and is discarded when you close or reset the report
- After the AI generates a draft, rehydration occurs in your browser — the AI's response is never stored with real subject values on our servers
- The final rehydrated draft (with real values restored) appears only in your browser
5. Information Sharing and Disclosure
We share information only as described below:
Service Providers (Subprocessors)
| Subprocessor | Function | Data Shared |
|---|---|---|
| Anthropic | AI narrative generation | Tokenized report text only — no raw PII |
| Replit | Cloud hosting and database | Account data, audit logs, encrypted at rest |
| Stripe | Payment processing | Payment information only — no report content |
| Resend | Transactional email | Email address and message content for auth emails only |
Legal Requirements
We may disclose information if required by law, subpoena, court order, or to protect the rights, property, or safety of ReportMax, our users, or the public. We will notify you of such requests to the extent permitted by law.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections described here.
6. Data Retention
- Draft content: Never stored server-side. Drafts exist only in your browser's localStorage and are auto-deleted after 24 hours.
- Audit log entries: Retained for the duration of your account plus 7 years for accountability purposes.
- Account data: Retained until account deletion plus 30 days.
- MFA codes and session tokens: Purged upon expiration (codes expire in 10 minutes; sessions after inactivity).
- Server logs: Retained for 90 days.
7. Security
We implement technical and organizational measures to protect your information, including TLS 1.2+ for data in transit, AES-256 encryption for data at rest, MFA for all accounts, and a tamper-evident audit trail. See our Security Practices page for details.
8. Cookies and Local Storage
We use strictly necessary cookies for session management (HTTP-only, secure in production). We use browser localStorage to store your in-progress draft (auto-deleted after 24 hours). We do not use tracking cookies, advertising cookies, or third-party analytics.
9. Your Rights
Depending on your location, you may have the right to access, correct, delete, or port your personal data, or to object to or restrict certain processing. To exercise these rights, contact us at admin@reportmax.support. We will respond within 30 days.
To delete your account and associated data, contact us directly. Note that audit log entries may be retained beyond account deletion as required by law enforcement accountability standards.
10. Children's Privacy
ReportMax is intended exclusively for sworn law enforcement officers and authorized agency personnel. We do not knowingly collect information from minors. If you believe a minor has registered, contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact Us
Privacy questions or requests: admin@reportmax.support