Privacy Policy
Effective: August 28, 2026
CLERS ("we", "the service") is operated as an Echo911 service. This policy describes what we collect and why.
What we collect
- Officer submissions: name, agency, ORI, agency email, badge number, supervisor contact, case identifiers, request narratives, and uploaded documents.
- Company accounts: names, work emails, phone numbers, company contact and legal-service details, and published request policies.
- Operational records: IP addresses, timestamps, user agents, and a complete audit trail of actions taken on requests. This logging is a core feature of an evidence-custody system and cannot be disabled.
How it is used
Data is used solely to operate the request workflow: routing requests, verifying identities, notifying parties, and preserving chain of custody. We do not sell data, run advertising, or share request contents with anyone other than the requesting parties, the responding company, and participants they explicitly add.
Retention
Evidence files are retained per each company's retention policy (default 90 days after completion) unless a legal hold applies. Audit records are retained indefinitely as part of the custody record. Verification codes expire within minutes and are stored only as hashes.
Security
All traffic is encrypted in transit. Evidence files are stored outside the web root, virus-scanned, hashed with SHA-256, and served only through expiring, access-logged links. Officer access uses per-session one-time codes; company staff use Argon2id-hashed passwords with optional TOTP two-factor authentication.
Contact
Questions about this policy: support@clers.com.