Legal
Privacy policy
Effective date:
Leer en españolThe Spanish version is a translation. If the versions differ, the English version controls, subject to applicable law.
1. Who we are and what this policy covers
FOIA Warfare LLC, a Nevada single-member limited liability company, operates foiawarfare.com. This policy covers our website, accounts, request tools, correspondence handling, mailing lists and support. Feature availability can be limited during early access.
Our tools help prepare government-record requests and manage related cases. We are a private company, not a government agency or law firm, and we give no legal advice. Planned authorized filing is described as a future feature in our terms.
2. Information we collect and why
Accounts and profiles: email, account identifiers, sign-in and session information, name, language, requester category, preferences and information you provide about your organization or contact details. We use these to authenticate you, personalize drafts, route mail and manage your account. Email links and codes, and Google or Apple sign-in when available, support account access.
Requests and cases: chat messages and history, records sought, agency, personal identifiers you enter, generated letters, fee-waiver and expedite explanations, PDFs, tracking numbers, status and deadline information. We use these to draft and score documents, resume conversations, track cases, prepare replies and appeals, and explain correspondence. Information derived from requests can also be retained in internal agency-reference and diagnostic records.
Correspondence: sender and recipient addresses, subjects, message bodies, headers, timestamps and attachments from agency mail, plus your outgoing replies. We store raw messages and files, check senders and attachments, extract text and case details, and provide case notifications. Documents can contain immigration, medical, financial, family or criminal-record information about you or other people. Provide only what your request needs; sensitive information is not automatically removed from every copy.
Billing: Stripe processes payment details through its hosted checkout. Our checkout does not collect full card-number fields. We retain customer and subscription identifiers, plan and billing-period information, payment-event references, refund amounts and references, and dispute information to manage access and billing.
Public and support submissions: mailing-list email, language and optional message; Wire comment name, email and body; issue reports, corrections and optional contact details. We use these for requested communications, moderation and support. Approved comments and display names are public. Avoid putting private case details in public comments or unnecessary sensitive details in support reports. Mailing-list capture stores new entries as unconfirmed and suppressed pending confirmation; supplying an email address is not itself confirmed marketing permission.
Technical information: IP addresses, some hashed IP references, device and browser information, paths, referrers, approximate country or state from request headers, session identifiers, interactions, error logs and operational events. We use these for abuse prevention, diagnostics, analytics and service operation. Some controls store raw IP addresses. Account, case and session identifiers can link activity to you; a hash or identifier is not necessarily anonymous.
3. Where information comes from
Information comes from you, your browser, sign-in and payment providers, agencies and other correspondents, and our own generated documents and processing results. Agency directories and public reference sources support routing and citation checks. If a connected Gmail sending feature is available and you choose it, we receive the connection details and sending authorization; that connection is not an inbox-import service.
4. Providers and other recipients
Vercel hosts the application and processes web requests and runtime information. Supabase provides account authentication, database and file storage. Stripe handles payments and billing. Resend handles outgoing email and incoming agency mail, including message contents and attachments.
Anthropic processes AI inputs described below. Cloudmersive receives attachment files for malware scanning when scanning is enabled. PostHog receives analytics events and session replay when active. Sentry receives error diagnostics with application filters intended to remove personal and record content.
Cloudflare Turnstile processes challenge and verification information for abuse prevention, including IP information in some verification flows. Google and Apple process sign-in information when you use those options. Google processes connected Gmail sending when that feature is available and chosen. The Coming Soon page loads Google Fonts, which causes requests from your browser to Google. Stripe, Cloudflare and Google may also set their own cookies or collect browser information under their own policies when their hosted checkout, challenge or font services load, including across other sites that use them. PostHog is used for our own analytics only.
Linear receives qualifying support and issue-report content for triage; that text may include information you provide. FOIA.gov directory and eCFR reference lookups send agency filters or citation queries, rather than whole request letters in those lookup flows. This provider list describes integrations; some depend on the feature and configuration in use.
User-approved agency replies transmit their contents to the addressed agency. When authorized initial filing becomes available, the selected agency will receive the request and required identity and authorization information. This can include USCIS, ICE or CBP if that is the agency you select. An account deletion does not erase an agency copy. We may also disclose information when required by applicable law or to address a justified security, fraud or legal-protection need. We do not promise advance notice of every legal demand.
No public archive export is currently offered. A future public-record archive option would require a partner agreement and your separate choice for that request. First-party FOIA and Privacy Act records are excluded from that archive-sharing plan.
We have not implemented an advertising network or a service for selling your request records. Analytics disclosures here still apply. We do not represent that every vendor arrangement falls outside state-law definitions of sale or sharing. Contact legal@foiawarfare.com about any applicable sale, sharing or targeted-advertising opt-out right.
5. AI processing
We send chat and request context, conversation history, correspondence, reply and appeal context, extracted document text and some support reports to Anthropic to generate drafts, classify content and explain records. Some scanned PDFs are sent as complete files for text extraction. Processing can include sensitive information contained in those inputs.
Some text classification replaces patterns such as Social Security numbers and A-numbers before sending text. This is not comprehensive redaction and does not remove sensitive content from every prompt, original message or full PDF. Provider retention and use depend on the applicable provider terms and account arrangements. This policy does not promise zero retention or exclusion from model training. Review AI output for errors before relying on it.
7. Retention and deletion limits
We retain information to provide the service, maintain cases, address abuse and billing, and meet applicable legal duties. We do not currently have an enforced fixed deletion period for all case text, chat history, correspondence, files, billing or support records. Expiration of a link or access token does not mean its underlying information has been erased.
Current cleanup jobs target limited copies: diagnostic copies of chat content are set to expire after seven days; one issue-report contact-email field after 90 days; and unused automatic reply drafts after 72 hours. These do not delete the main chat history, report body, case documents or all copies. Planned broader retention periods are not current deletion guarantees.
Settings offers account deletion. A successful request removes the profile, sign-in account and certain related records, but deletion can fail. Case text, generated letters, internal reference information, email logs, public comments, support reports and billing records can remain, sometimes with the account link removed. Stored files, browser storage, vendor copies and backups are not comprehensively erased by this action. Text may still identify you after its account link is removed.
Archiving a case hides it rather than erasing it. Before deleting an account with a linked Stripe customer, we expire every open Stripe Checkout session for that customer and cancel every subscription that is not already canceled or incomplete_expired. If billing cleanup fails, we return a retryable error and do not delete the account. Account deletion does not issue a refund or remove information held by government agencies. Contact legal@foiawarfare.com to request deletion of remaining information. An account-delete confirmation does not establish provider or backup retention windows; we cannot promise complete or immediate erasure.
8. Access, correction and privacy requests
Where available, sign in to view case information, download documents, edit your name and use account deletion. These controls are not a complete account export or a way to correct every stored field. You can ask legal@foiawarfare.com for access, correction, deletion, a copy of information, restriction, objection or an appeal of a privacy decision, as applicable to your location and circumstances.
We may need information to verify your identity and authority before acting. We handle requests under applicable legal requirements, including any required response period, appeal process and protection against discrimination for exercising rights. There is no universal promised 30-day response or 48-hour deletion period. Exceptions can apply to records needed for lawful billing, security or legal obligations, and we will explain the applicable disposition of your request.
We have not determined whether FOIA Warfare is subject to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). California residents can send requests to legal@foiawarfare.com, including requests for access, correction, deletion or an opt-out of sale, sharing or targeted advertising. We will review requests under applicable law; this policy does not claim verified CCPA/CPRA compliance or verified sale, sharing or Global Privacy Control handling.
9. Security and processing locations
Our application uses account and ownership checks, database access policies, administrative access controls, secure production-cookie settings and attachment scan restrictions. Some service workers and authorized administrators process information to operate the service. These measures reduce risk but do not guarantee security. Our app does not encrypt all request text and files at the individual-record level or provide end-to-end encryption.
The service concerns U.S. government records and can receive visits from outside the United States. We do not promise that every provider processes or stores information only in the United States. Contact legal@foiawarfare.com about processing-location or transfer questions. Report suspected account compromise to support@foiawarfare.com and privacy concerns to legal@foiawarfare.com. Any legally required incident notices remain subject to applicable law.
10. Children
The service is intended for adults age 18 or older, not for accounts belonging to children or marketing directed to children. This is an eligibility rule, not a claim that signup verifies age. Records provided by an adult can contain information about a minor; that does not establish a guardian filing or parental-consent feature. If you believe a child has provided information directly, contact legal@foiawarfare.com so we can review the situation and any required action.
11. Changes to this policy
We will post revisions here with a new effective date and provide additional notice or obtain consent when applicable law requires it. We do not promise a fixed advance-email schedule. This policy describes data practices; reading it does not authorize us to file a request, sign a declaration or receive records on your behalf. Any required filing or release authorization is separate.
Contact and notices
- Legal and privacy requests: legal@foiawarfare.com
- Account help: support@foiawarfare.com
- Billing: billing@foiawarfare.com
Mailing address for notices:
FOIA Warfare LLCPO Box 213, Minden, NV 89423