Privacy policy
Last updated July 24, 2026
1. Overview
This Privacy Policy ("Policy") describes how Report960 ("Report960," "we," "us," or "our") collects, uses, discloses, retains, and protects information in connection with the Report960 web application, APIs, and related services (collectively, the "Service"). The Service is offered exclusively to sworn law enforcement personnel, authorized civilian support staff, and the agencies that employ them ("you" or "User"). By accessing or using the Service, you acknowledge that you have read, understood, and agree to this Policy and to our Terms of Service and Acceptable Use Policy.
The Service uses artificial intelligence. Its outputs are probabilistic, may contain errors, omissions, or inaccuracies, and must never be relied upon as a substitute for independent professional judgment, supervisor review, agency policy, or legal counsel. See Section 9 for the full AI disclaimer.
2. Controller and processor roles
Where the Service is used pursuant to an agreement with a law enforcement agency ("Agency"), the Agency is the controller, custodian, and owner of the report content and case data submitted to the Service, and Report960 acts as a service provider and processor operating on the Agency's documented instructions. Where an individual officer uses the Service under an individual or trial subscription, that officer is responsible for confirming that their use complies with their employing agency's policies and with applicable law.
3. Information we collect
3.1 Account information
- Name, work email address, badge or employee identifier, rank, unit, and Agency affiliation.
- Authentication credentials, including hashed passwords and multi-factor authentication factors.
- Role and permission assignments provisioned by you or your Agency.
3.2 Report and case content ("Customer Content")
- Report narratives, uploaded documents, attachments, metadata, edits, comments, and analysis outputs you or your Agency submit to or generate within the Service.
- You must not submit information you are not authorized to process, including but not limited to sealed records, juvenile records restricted under Welfare & Institutions Code § 827, medical information restricted under HIPAA, CJIS-restricted material outside authorized channels, or classified national-security information.
3.3 Session and device information
- IP address, approximate geolocation derived from IP, browser type, operating system, device fingerprint, and language.
- Session identifiers, sign-in and sign-out timestamps, and events used to enforce one active session per badge.
3.4 Usage and diagnostic information
- Feature usage counts, page navigations, error traces, latency measurements, and AI token counts.
- Cost and billing metadata associated with your seat or your Agency's account.
3.5 Communications
- Messages you send to support, security, or sales, including their contents and attachments.
We do not knowingly collect information from anyone under the age of eighteen (18). The Service is not directed to children.
4. How we use information
- To provide, operate, maintain, secure, and improve the Service.
- To authenticate Users and enforce single-session-per-badge integrity.
- To detect, investigate, and prevent fraud, abuse, credential sharing, and security incidents.
- To generate audit logs required for evidentiary and accountability purposes.
- To provide support, respond to inquiries, and communicate service or security notices.
- To bill Agencies and reconcile seat and usage-based charges.
- To comply with legal obligations, enforce our agreements, and exercise or defend legal claims.
We do not sell Customer Content. We do not use Customer Content to train, fine-tune, or improve any generalized artificial-intelligence model, whether operated by us or by any third party. We do not use Customer Content for advertising.
5. Legal bases and authority to process
We process personal information as necessary to perform our contract with you or your Agency, to comply with legal obligations, and where we have a legitimate interest in operating and securing the Service that is not overridden by your rights. For Users subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, the "CCPA"), we process personal information as a service provider on behalf of your Agency and subject to the restrictions in the CCPA and applicable Data Processing Addendum.
6. Disclosure of information
We disclose information only in the categories described below and only as necessary:
- Sub-processors. Vetted vendors that host infrastructure, provide database and storage services, deliver email, or perform model inference under written data-processing terms that prohibit any use of Customer Content other than to provide their service to us. Current categories: cloud hosting and edge compute, managed database and authentication, transactional email, and AI model inference through a first-party model gateway.
- Your Agency. Agency administrators can access accounts, activity, and Customer Content within their tenant, including audit logs of your activity.
- Legal process. When required by a valid subpoena, court order, warrant, or other legal obligation, or where we reasonably believe disclosure is necessary to prevent imminent harm, fraud, or a violation of our Terms. Where legally permitted, we will attempt to notify the Agency before disclosing Customer Content.
- Corporate transactions. In connection with a merger, acquisition, financing, or asset sale, subject to confidentiality obligations and continued application of this Policy.
We do not share Customer Content with law enforcement (other than the Agency that owns it) or any third party except as described above.
7. Retention
- Customer Content is retained for the life of the Agency's or User's account and for up to ninety (90) days after termination for recovery, after which it is deleted or irreversibly de-identified.
- Audit logs and evidentiary records are retained for seven (7) years or the period required by the Agency's records-retention schedule, whichever is longer.
- Session, sign-in, and security-event logs are retained for up to eighteen (18) months.
- Backups are retained on a rolling thirty-five (35) day schedule and then overwritten.
Deletion timelines may be extended where required by law, legal hold, or an active investigation into misuse of the Service.
8. Security
We maintain administrative, technical, and physical safeguards designed to protect the Service and the information we process, including transport encryption (TLS 1.2 or higher), encryption at rest for managed databases and storage, role-based access controls, row-level security, least-privilege access for personnel, mandatory single-session enforcement, and continuous logging and monitoring.
No method of electronic transmission or storage is one-hundred-percent secure, and we cannot and do not guarantee absolute security. You are responsible for safeguarding your credentials, keeping your device up-to-date, and promptly notifying us of any suspected compromise at security@report960.com.
9. Artificial intelligence — no guarantee of accuracy
The Service uses generative artificial-intelligence models to review, score, cite, and comment on police-report content. AI outputs are inherently probabilistic and may:
- Contain factual errors, misquotations, omissions, or fabricated ("hallucinated") citations;
- Reference statutes, cases, or regulations that have been amended, repealed, or superseded;
- Reach different conclusions on the same input from run to run;
- Fail to identify legally significant issues in a report; and
- Produce output that is inaccurate, incomplete, biased, or otherwise unfit for a particular purpose.
Report960 makes no representation or warranty, express or implied, that any AI output is accurate, complete, current, admissible, legally sufficient, or fit for any use. AI outputs are editorial suggestions only. They are not legal advice, not policy guidance, and not a substitute for the User's independent professional judgment, supervisor review, agency policy, legal counsel, or the plain text of the applicable statute. The User remains solely and fully responsible for every report they file and every action they take.
10. International transfers
The Service is operated and hosted in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, which may have data-protection laws that differ from those of your jurisdiction.
11. Your rights
Subject to applicable law and to your Agency's ownership of Customer Content, you may request access, correction, deletion, or portability of your personal information by emailing privacy@report960.com. Agencies may exercise these rights for their tenants through the Settings screen or by contacting us. We will respond within the period required by applicable law.
12. Do Not Track
The Service does not respond to browser "Do Not Track" signals because there is no accepted industry standard for how to interpret them.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced in-product and by email to Agency administrators at least thirty (30) days before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
14. Contact
Privacy inquiries: privacy@report960.com
Security disclosures: security@report960.com
Legal notices: legal@report960.com
