Effective September 5, 2026
Privacy Policy
Blue Notice is designed to collect only the information needed to screen and research a homeowner’s assessment question.
Information we collect
When you submit the intake, we may collect:
- Your name and email address.
- Your property address, township, and filing deadline.
- Assessment-notice files and the property details, ownership confirmations, and context you choose to provide.
- Referral source and campaign parameters such as UTM tags.
- Your required acknowledgments of the intake terms and service limits.
How we use information
We use intake information to determine eligibility, research the property, prepare and deliver the requested verdict, respond to questions, maintain service security, and meet legal obligations. We do not sell personal information.
Service providers
Supabase
Supabase stores intake records and private documents and provides email-code sign-in. Reviewers use an authenticated operator workspace with multi-factor authentication. Customers can access only their own cases and purchased, approved package files.
Vercel
Vercel hosts the website and provides aggregated, cookie-free web analytics. We record anonymous funnel events on public pages only. We do not attach names, emails, addresses, property index numbers, deadlines, submission IDs, uploaded documents, or form answers to analytics events.
Resend and business email
Resend sends sign-in codes, intake receipts, results notices, and purchase confirmations. Our domain mailbox handles replies and refund requests. Application notifications exclude property details, case identifiers, document links, and attachments; they link to your account.
Stripe
Stripe processes payments through its hosted checkout. We store payment references, amounts, and payment/refund status. Card details are handled by Stripe and are not stored in the Blue Notice application.
Cloudflare and GitHub
Cloudflare Turnstile helps protect sign-in against abuse. Private file snapshots are stored in Cloudflare R2 using scheduled GitHub Actions jobs with restricted access.
Retention and deletion
Access to results ends 90 days after the first results publication, on the date shown in your account. Purchasing a package or receiving a correction does not restart this window. We delete active source uploads, deliverables, intake records, and working notes through daily cleanup after that period. Unfinished uploads become eligible for cleanup after 24 hours; abandoned, unpublished cases are deleted after 90 days of inactivity.
Our application file snapshots and daily database recovery copies follow a seven-day retention schedule; expiry jobs and provider processing may not remove every backup copy at the exact moment active access ends. Deletion records are reapplied during restoration. Minimal transaction records may be retained separately for accounting, refunds, and legal obligations. Payment and email providers also maintain records under their own policies. Your account email remains available for returning sign-in until you request account deletion, subject to records we must retain.
Security and your choices
No online service can guarantee absolute security. We limit document access to the people performing the review and use authenticated provider accounts. You may ask to access, correct, or delete your intake, subject to records we must retain by law.
A privacy contact address will be published with the production domain before launch.
Changes
We may update this policy as the service changes. The effective date at the top identifies the current version.