Skip to content
Tailboard

Privacy

What we collect. And what we don't.

Last updated 2026-09-03. Plain-English privacy policy for the Tailboard policy library.

The short version

Tailboard is a free, public library of policy templates. We don't require accounts and we never sell or share visitor data. We use Google Analytics to count visits. Two things do leave your browser and you should know about both: what you type into the Policy Builder is sent to Anthropic to generate your draft, and we store a one-way hash of your IP address and browser to enforce the Builder's daily usage limit. Details below.

What we collect

When you visit Tailboard, our hosting provider (Firebase Hosting, a Google service) automatically receives standard web request information — your IP address, browser user-agent, and the page you requested. This is the same information any web server receives.

We use Google Analytics 4 to count page views, referrers, approximate location (country / region), and the path users take through the site. Analytics is initialized client-side via gtag.js.

If you contact us via the email addresses listed on the site, we receive whatever you send us. We use that information to respond to your question and nothing else.

What we don't collect

  • We don't require an account, login, or any identifying information to browse the site.
  • We do not store your Policy Builder answers or generated drafts in any Tailboard database. They are held in your browser for the session and sent to Anthropic to produce the draft — see “The Policy Builder” below.
  • We don't accept Protected Health Information (PHI), Personally Identifiable Information of third parties, criminal-justice information (CJI), or any patient or case-specific data. If you enter such information, we do not retain it.
  • We run no third-party advertising trackers and set no cookies beyond those described under “Cookies” below. We do compute a one-way hash of your IP address and browser user-agent solely to enforce the Policy Builder's usage limit — described under “The Policy Builder”. We do not use it to profile, track across sites, or identify you.

The Policy Builder

The Policy Builder is the one part of Tailboard that sends your input off your device. Here is exactly what happens.

What is sent. Your structured answers (agency type, size, jurisdiction, apparatus, staffing, and any free-text notes you add) plus the topic you chose are sent to a Tailboard server function, which forwards them to Anthropic to generate the draft. Anthropic is our sub-processor for this feature. The generated draft is streamed back to your browser.

What is not stored. Tailboard does not write your answers or your generated draft to any database. They live in your browser for the session and are gone when you close the tab or hit restart. We do not email them to ourselves, log them, or review them.

What is stored.To stop one person from consuming the whole community's daily allowance, we keep a rate-limit counter. The record contains a truncated one-way SHA-256 hash of your IP address and browser user-agent, combined with a secret key held in Google Secret Manager, plus a request count and a date. It contains no message content. The hash cannot practically be reversed to your IP without that secret. These records are deleted automatically after one week by a Firestore time-to-live policy.

Don't paste sensitive material. Do not enter Protected Health Information, patient or case details, personal information about third parties, or law-enforcement-sensitive information into the Builder. It is a drafting aid for generic agency policy, and it is not an appropriate destination for any of that.

Cookies

We use one cookie: _ga (and related GA4 cookies) — set by Google Analytics to distinguish users for aggregate measurement. This cookie expires automatically after 2 years.

We may also store a small tb_discipline preference cookie (fire / EMS / police) so the site remembers your discipline filter between visits. This is set only after you actively choose a discipline in the switcher.

Who else touches this data

We use three service providers. We have no others.

  • Google (Firebase Hosting, Cloud Functions, Firestore, Secret Manager) — serves the site, runs the Policy Builder function, and stores the rate-limit counters.
  • Anthropic — generates Policy Builder drafts from the answers you submit. Used only for that feature.
  • Google Analytics — aggregate visit measurement.

Your choices

  • Most browsers let you block cookies or third-party scripts. Tailboard works fully if you block Google Analytics — we just won't see your visit in the aggregate count.
  • To opt out of Google Analytics across all sites, install the official Google Analytics Opt-out Browser Add-on.
  • If you'd like a copy of any information we hold about you, or want us to delete information you have sent us, email privacy@tailboard.org.

Children

Tailboard is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us at privacy@tailboard.org and we will delete it.

Changes

If we change this policy, we'll update the date at the top of the page. Material changes will be noted in the site's news section.

Contact

Questions? Email privacy@tailboard.org.