Privacy
Privacy without fairy tales.
Last updated: September 15, 2026
This website is designed to collect as little personal information as reasonably possible. It does not require a public user account. That said, no public website can promise perfect anonymity, and your hosting provider, network provider, browser, external websites, or an AI provider may process technical information outside this website’s direct control.
Anonymous community posts
Community posts are public after moderation. Do not submit names, addresses, emails, phone numbers, Social Security numbers, account numbers, payment-card numbers, court case numbers, children’s identities, medical details that identify a person, or confidential documents.
The website automatically attempts to remove common email addresses, phone numbers, Social Security numbers, payment-number patterns, and case-number patterns. Automatic redaction is imperfect. A moderator should review posts, but moderation also cannot guarantee that every identifying fact will be caught.
The website does not store a raw IP address inside the community-post record. For rate limiting and duplicate-report control, it creates a one-way HMAC fingerprint from the connection address and browser user agent. The fingerprint rotates monthly. The hosting server may separately retain ordinary access logs, which can include IP addresses and request details.
Resource database searches
Resource searches are processed against the website’s SQL knowledge database or its generated read-only fallback. The application does not intentionally save search terms. A hosting provider, database server, security service, or access log may still record request metadata. Resource entries are public-source research and do not contain community-post or document-generator submissions.
AI resource guide
Chat messages are not intentionally saved by this website. In guided mode, the question is processed locally by the website’s rule-based resource matcher. In full AI mode, the website removes several common identifiers and sends the question, a short recent conversation history, and relevant resource links to the configured AI provider. Redaction is not foolproof, so keep questions general.
The AI provider may process data under its own terms, privacy policy, retention controls, and account settings. The site owner should review and configure those provider settings before enabling full AI mode.
Document generator
Document-generator fields are processed to create a preview or downloadable file. They are not intentionally written to the website’s JSON storage. Your browser, server logs, backups, security tools, or network infrastructure may still temporarily process request data. Avoid using the generator on an untrusted or shared device.
Navigator Suite and browser-local case workspace
The private case workspace, evidence organizer, and FOIA request tracker use your browser’s local storage. The website does not intentionally transmit those workspace records to the server. They remain available to anyone using the same browser profile until you export them, clear them inside the tool, clear browser storage, or the browser removes the storage.
Do not use the local workspace on a shared or otherwise untrusted device, including a monitored, employer-controlled, school-controlled, library, or shelter computer. Browser-local storage is convenient, but it is not privileged or encrypted legal-file storage. Exported backups are ordinary JSON or text files and should be protected like any other sensitive case record.
Screeners, deadline estimates, and court routing
The benefits screener, legal-issue classifier, deadline estimator, court finder, complaint navigator, and appeal navigator process answers in the browser or through the site’s structured navigation database. The application does not intentionally create a user profile from those answers. The server and hosting provider may still log ordinary request metadata when a server API is used.
Donations and external links
Donation payments are handled by the external donation service selected by the site owner. This website should not collect payment-card information directly. Every external court, agency, nonprofit, payment provider, and resource site has its own privacy practices.
Cookies
The website uses a session cookie for security features such as CSRF protection and administrator authentication. It does not include advertising trackers or analytics scripts by default. A future site owner who adds analytics or other services should update this notice.
Deletion and corrections
A moderator can hide or permanently delete community posts through the private moderation page. Public posts also include a report button for privacy and safety concerns. Because no public account is attached to a post, the website may not be able to verify that a person requesting removal authored it.
Children
This website is not designed to collect personal information from children. Do not identify a child in a community post or AI question. Suspected child abuse in Arkansas should be reported through the official hotline at 1-800-482-5964; call 911 for immediate danger.
Security limits
The website includes security headers, CSRF protection, server-side secrets, moderation, rate limits, output escaping, and restricted storage directories. These reduce risk but do not make the system invulnerable. Keep PHP and the hosting environment updated, use HTTPS, back up carefully, and review server logs and permissions.