← Back to the address check
Pilot data handling

Privacy

The 2025 check and 2026 preview work without an account, contact form, or payment. This page describes the behavior visible in the current code and separates it from future checkout behavior.

Address lookup

Your browser normalizes the address you enter and requests matching static address and property-data files from the site. The pilot does not submit the typed address to an Appeal Prepper application database, and its database schema and production database binding are currently empty.

Those file requests still travel through the site host, CDN, and network providers. As with ordinary website traffic, those providers may retain request metadata such as IP address, requested file path, browser information, timestamps, referrer, and security or error logs under their own configurations and policies. This page does not promise that infrastructure access logs never exist.

Downloads and property research

CSV, XLSX, and City worksheet PDF exports are assembled in your browser and downloaded to your device. The pilot does not upload the generated file back to an Appeal Prepper application endpoint.

The PDF exporter retrieves a blank worksheet template from this site. ZIP-code enrichment calls the City's DataSF API using the property parcel number, and links for official guidance or property research send you to the linked third-party site when you choose them. Those third parties receive ordinary request information and apply their own privacy practices.

Product measurement

Appeal Prepper is configured to use PostHog for anonymous website analytics, product measurement, and copy experiments when analytics is enabled. PostHog then receives ordinary analytics context such as a randomly assigned browser identifier, page URL, referrer, device and browser information, experiment assignment, and the non-identifying product events described below. Appeal Prepper does not create a PostHog person profile for visitors to the free lookup.

The allowed product-event fields are limited to non-identifying context such as result state, property segment, roll year, evidence tier, failure reason, and export format. Automatic click and form capture, session recording, heatmaps, exception capture, and no-code page rewriting are disabled in the site integration.

Sensitive fields are excluded from analytics: the typed or selected address, APN, owner name, phone number, email, signature, and downloaded worksheet contents are not allowed measurement fields and are not sent to PostHog by the product measurement code.

Accounts, contact details, and payments

The current free homeowner flow does not require an Appeal Prepper account and does not ask for a phone number, email address, owner name, payment method, signature, or current assessment notice. The 2026 preview starts with a provisional estimate derived from the public 2025 closed-roll value.

Before paid ordering launches, this notice must be updated to explain the checkout provider, order information, retention, and report-delivery behavior.

The repository includes an unused hosting helper capable of reading platform-provided authentication headers in other contexts. The homeowner page does not call that helper, and identity is not required for lookup, evidence review, or downloads.

Your choices

  • Do not enter an address if you do not want it reflected in ordinary website requests.
  • Block or clear the PostHog analytics cookie and browser storage using your browser controls if you do not want the anonymous experiment identifier retained between visits.
  • Delete downloaded worksheets from your device when you no longer need them.
  • Avoid entering owner names or contact details; the lookup does not need them.
  • Review the privacy terms of DataSF, search engines, and official City sites before following external links.