Privacy policy
Privacy policy
1. Who we are
This site is operated by a U.S. LLC (the "Operator") whose formation is currently in progress. The registered entity name will be published here once formation completes; this policy applies to the operator of this domain regardless of the legal-entity name update. A public contact email and mailing address for privacy and legal matters will be added here at that time.
2. What this site does
IRSnoticeDecoder is an information hub for IRS CP and Letter notices. The decoder runs in your browser. There is no account creation, no login, no payment processing, no phone form, no "callback" collection.
3. What we collect
Notice content: nothing. When you use the decoder — picking from the list or pasting notice text — the content stays in your browser. We do not log, store, transmit, or analyze pasted text on our servers. The decoder's lookup logic runs in the JavaScript that already loaded with the page.
Server logs: technical only. Standard web-server logs (IP address, request URL, user-agent, timestamp) are kept for security and operational purposes. These are not tied to notice content because we do not receive notice content.
Analytics: none today. As of the effective date above, no analytics SDK is loaded on this site. The page's Content Security Policy permits same-origin scripts only. There is no Google Analytics, no Google Tag Manager, no Meta Pixel, no third-party tag.
Analytics: future state. If we add Google Analytics 4 later for aggregate page-view counts, the analytics_storageconsent default will be "granted" (not opt-in), consistent with the EU/UK Consent Mode v2 framework for analytics that does not target advertising. ad_storage and ad_user_data would remain denied by default — no remarketing, no behavioral profiling, no user-level identifiers leaving the analytics layer. We will update this policy and the Content Security Policy together if and when that change ships.
Cookies: minimal. We do not use third-party advertising cookies. Functional cookies that the framework sets for performance and CSRF protection are first-party only.
4. What we don't do
- We do not sell, lease, or share user data with third parties.
- We do not provide notice content (because we don't have it) to tax-resolution-mill operators, lead-generation services, or any other third party.
- We do not run remarketing, behavioral targeting, or ad-network pixel collection.
- We do not collect phone numbers or run outbound dialers.
5. Future upload-decoder path (not yet live)
We are designing a future browser-side OCR + redaction path that would let users upload a PDF or photo of their notice. That path is not yet live. When it ships, it will be governed by the architecture described on how our decoder works: OCR runs in the browser, a redaction pipeline removes SSN, EIN, names, addresses, phone numbers, and account numbers before any text leaves the browser, and the only data that transits the network is the redacted notice-type extraction request. Server-side logs for that path will record only aggregate counts: { site, notice_code, success_bool, timestamp } — never redacted content, never PII residue. We will update this policy before that path ships.
6. Children
This site is not directed at children under 13 and does not knowingly collect data from them.
7. Your rights
Because we collect minimal personal data and no notice content, the practical scope of data-subject rights (access, deletion, portability) under U.S. state privacy laws (CCPA, CPRA, VCDPA, others) is limited. A published contact channel for exercising any right or asking a privacy question will be added here once the operating entity's formation completes.
8. Changes
We may update this policy as the decoder evolves (most notably when the v2 upload path ships). The effective date at the top of the page reflects the most recent revision. Material changes will be flagged on the homepage for at least 14 days before they take effect.
9. Contact
A published email address for questions about this policy or about data handling on this site, and a mailing address for legal notices, will be added here once the U.S. legal entity completes formation. We will not list a contact channel that does not yet exist.