Built for law enforcement privacy: ReportMax's tokenization architecture replaces subject names and identifying details with opaque tokens on your device before any data leaves your browser. Our AI subprocessor never receives raw subject-identifying information. We do not sell your data or use report content to train AI models.

1. Who We Are

ReportMax is operated by ReportShield LLC ("we," "us," or "our"), a law enforcement technology company. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the ReportMax platform ("Service"). Contact us at admin@reportmax.support.

2. Information We Collect

Account Information

When you register, we collect your name, email address, badge number, agency name, and password (stored as a one-way hash). We also store your subscription status and report usage count.

Report Generation Data

When you generate a report, we receive the tokenized version of your input — meaning subject names, addresses, dates of birth, phone numbers, and license plate numbers have already been replaced with opaque tokens on your device before transmission. The AI subprocessor receives only the tokenized text. We do not receive or store the raw identifying information you type.

We store metadata about generation events in our audit log, including: timestamp, officer ID, report type, character count of output, and whether generation succeeded. We do not log the raw content of reports.

Authentication and Session Data

We collect device identifiers (hashed), IP addresses, and user-agent strings when you log in, to support multi-factor authentication and device trust. Session tokens are stored in secure, HTTP-only cookies.

Usage and Technical Data

We collect standard server logs including request timestamps, response codes, and error information for reliability and security monitoring. These logs are retained for 90 days.

3. How We Use Your Information

PurposeLegal Basis
Providing and maintaining the ServiceContract performance
Authentication and account security (MFA, device trust)Contract performance / Legitimate interest
Processing subscription paymentsContract performance
Sending transactional emails (MFA codes, password resets, device alerts)Contract performance
Audit logging for accountability and tamper-evidenceLegitimate interest / Legal obligation
Security monitoring and fraud preventionLegitimate interest
Responding to your support requestsContract performance

We do not use your data for advertising, behavioral profiling, or sale to third parties. We do not use report content to train, fine-tune, or benchmark any AI model.

4. Tokenization and AI Processing

ReportMax employs client-side tokenization before AI processing:

5. Information Sharing and Disclosure

We share information only as described below:

Service Providers (Subprocessors)

SubprocessorFunctionData Shared
AnthropicAI narrative generationTokenized report text only — no raw PII
ReplitCloud hosting and databaseAccount data, audit logs, encrypted at rest
StripePayment processingPayment information only — no report content
ResendTransactional emailEmail address and message content for auth emails only

Legal Requirements

We may disclose information if required by law, subpoena, court order, or to protect the rights, property, or safety of ReportMax, our users, or the public. We will notify you of such requests to the extent permitted by law.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections described here.

6. Data Retention

7. Security

We implement technical and organizational measures to protect your information, including TLS 1.2+ for data in transit, AES-256 encryption for data at rest, MFA for all accounts, and a tamper-evident audit trail. See our Security Practices page for details.

8. Cookies and Local Storage

We use strictly necessary cookies for session management (HTTP-only, secure in production). We use browser localStorage to store your in-progress draft (auto-deleted after 24 hours). We do not use tracking cookies, advertising cookies, or third-party analytics.

9. Your Rights

Depending on your location, you may have the right to access, correct, delete, or port your personal data, or to object to or restrict certain processing. To exercise these rights, contact us at admin@reportmax.support. We will respond within 30 days.

To delete your account and associated data, contact us directly. Note that audit log entries may be retained beyond account deletion as required by law enforcement accountability standards.

10. Children's Privacy

ReportMax is intended exclusively for sworn law enforcement officers and authorized agency personnel. We do not knowingly collect information from minors. If you believe a minor has registered, contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

12. Contact Us

Privacy questions or requests: admin@reportmax.support