Privacy Policy
Effective Date: September 1, 2026
OpenRecords Desk is an independent, noncommercial public-interest project designed to support government transparency, public records research, civic engagement, and accountability.
This Privacy Policy explains the types of information OpenRecords Desk may collect, how that information may be used, and circumstances in which information may be processed or disclosed.
1. Scope
This Privacy Policy applies to information collected through OpenRecordsDesk.com and the OpenRecords Desk application.
Because OpenRecords Desk is a records-management and public-records research tool, users may intentionally enter or upload substantial amounts of information concerning records requests, public bodies, government correspondence, PAC proceedings, and responsive government records.
2. Information You Provide
Depending upon the features you use, OpenRecords Desk may collect or store information you provide, including:
- account and login information;
- your name, email address, or other account information;
- records-request information;
- names and information concerning public bodies and government agencies;
- FOIA or other public records request text;
- government responses and correspondence;
- Public Access Counselor review information;
- PAC case numbers, correspondence, events, notes, determinations, and related materials;
- documents and files uploaded to the service;
- internal notes and research;
- legal research and citations; and
- other information you choose to enter into the application.
3. Information Contained in Public Records
Documents obtained from government agencies may contain information concerning third parties. Depending upon the particular records, this could include names, addresses, email addresses, telephone numbers, photographs, government correspondence, identifiers, allegations, opinions, employment information, or other personal information.
OpenRecords Desk does not control what information government agencies include in records they release.
Users are responsible for determining whether information contained in public records should be uploaded, stored, disclosed, reproduced, or published.
4. Automatically Collected Technical Information
When you access OpenRecords Desk, the website or its service providers may automatically receive technical information associated with your visit. This may include:
- IP address;
- browser type and version;
- device and operating-system information;
- date and time of access;
- pages or features accessed;
- referring pages or websites;
- server and security logs;
- authentication and session information; and
- information used to detect errors, abuse, attacks, or unauthorized access.
5. Cookies and Similar Technologies
OpenRecords Desk may use cookies, browser storage, session identifiers, and similar technologies necessary for authentication, security, preferences, application functionality, and website operation.
Third-party infrastructure or analytics services used by the website may also use cookies or similar technologies subject to their own policies.
6. How Information Is Used
Information may be used to:
- operate and maintain OpenRecords Desk;
- authenticate users and maintain account sessions;
- store and organize records requests and PAC matters;
- provide document-management and research features;
- maintain application functionality;
- respond to user questions or support requests;
- diagnose technical problems;
- maintain backups and recover from failures;
- protect the website, users, and systems from abuse, fraud, attacks, or unauthorized access;
- enforce the Terms of Use;
- improve the application and understand how it is used; and
- comply with applicable legal obligations.
7. Third-Party Service Providers
OpenRecords Desk may use third-party providers to operate or support the website. These providers may include web-hosting companies, email providers, security services, backup providers, analytics services, content-delivery networks, anti-spam or anti-abuse services, and other technical infrastructure providers.
Those providers may process information as necessary to perform their services and may maintain their own logs or technical records in accordance with their respective privacy policies and legal obligations.
The particular providers used by OpenRecords Desk may change as the project develops.
8. No Sale of Personal Information
OpenRecords Desk does not sell personal information.
OpenRecords Desk is a noncommercial public-interest project and does not operate as a data broker.
9. Disclosure of Information
Information may be disclosed when reasonably necessary:
- to operate the website through service providers;
- at your direction or with your consent;
- to investigate or prevent fraud, abuse, attacks, or unauthorized access;
- to protect the rights, safety, security, or integrity of OpenRecords Desk, its users, or others;
- to enforce applicable Terms of Use; or
- when required by applicable law, legal process, subpoena, court order, or other lawful governmental demand.
OpenRecords Desk does not promise that information stored through the service is immune from lawful legal process.
10. Security
Reasonable administrative and technical measures may be used to protect information stored through OpenRecords Desk.
However, no website, server, database, network, or method of electronic storage or transmission can be guaranteed to be completely secure.
You should not upload information for which the consequences of unauthorized disclosure would be unacceptable unless you have independently evaluated the risks.
11. Your Responsibility for Sensitive Information
OpenRecords Desk is designed primarily for public records and government-transparency work. It is not intended to function as a secure repository for passwords, financial account credentials, Social Security numbers, medical records, private authentication credentials, or other highly sensitive information unrelated to legitimate public-records work.
If responsive government records contain sensitive information, you should consider whether that information needs to be stored in OpenRecords Desk and whether redaction or other precautions are appropriate.
12. Data Retention
Information may be retained for as long as reasonably necessary to provide the service, maintain records and backups, preserve the integrity of records-request or PAC histories, protect the service, resolve disputes, enforce applicable terms, or comply with legal obligations.
Backup copies or technical logs may remain for a period of time after information is removed from the active application.
13. Account and Data Requests
You may contact OpenRecords Desk regarding access to, correction of, or deletion of information associated with your account.
Requests will be evaluated in light of the information available, technical feasibility, legitimate security and recordkeeping needs, and applicable law.
To make a privacy request, contact:
Email: soxside@gmail.com
14. Adults Only
OpenRecords Desk is intended for adults who are at least 18 years old.
The service is not directed to children, and individuals under 18 should not create accounts or use the interactive features of OpenRecords Desk.
If information is received indicating that an account belongs to a person under 18, appropriate action may be taken to restrict or remove the account.
15. External Websites
OpenRecords Desk may link to government websites, statutes, court resources, public bodies, legal materials, and other external websites.
This Privacy Policy does not govern those external websites. Their collection and use of information are governed by their own policies and practices.
16. Public Records Are Not Necessarily OpenRecords Desk’s Public Content
Information stored in a user’s OpenRecords Desk account is not automatically made public merely because the underlying material originated from a public body or was obtained through a public records request.
Whether particular information is displayed publicly depends upon the functionality of the service and actions taken by authorized users.
17. Changes to This Privacy Policy
This Privacy Policy may be updated as OpenRecords Desk develops, as third-party services change, or as legal and operational requirements evolve.
The current version will be posted on this website with its effective date.
18. Illinois and United States Operations
OpenRecords Desk is operated from Illinois, United States. Information processed through the service may be stored or processed in the United States by OpenRecords Desk or its service providers.
19. Contact
Questions, concerns, or requests regarding this Privacy Policy may be sent to:
Email: soxside@gmail.com
OpenRecords Desk is an independent, noncommercial public-interest project dedicated to government transparency and accountability.