← Back to the address check
Pilot data handling

Privacy

The free 2025 check and paid 2026 report work without an Appeal Prepper account or login. This page explains address lookup, Stripe checkout, entitlement storage, analytics, and browser-generated downloads.

Address lookup

Your browser normalizes the address you enter and requests public address and 2025 property-data files from the site. For a 2026 request, the server checks the property's payment entitlement before returning comparison data. Protected 2026 comparison shards are not publicly downloadable.

Those file requests still travel through the site host, CDN, and network providers. As with ordinary website traffic, those providers may retain request metadata such as IP address, requested file path, browser information, timestamps, referrer, and security or error logs under their own configurations and policies. This page does not promise that infrastructure access logs never exist.

Downloads and property research

CSV, XLSX, and City worksheet PDF exports are assembled in your browser and downloaded to your device. The pilot does not upload the generated file back to an Appeal Prepper application endpoint.

The PDF exporter retrieves a blank worksheet template from this site. ZIP-code enrichment calls the City's DataSF API using the property parcel number, and links for official guidance or property research send you to the linked third-party site when you choose them. Those third parties receive ordinary request information and apply their own privacy practices.

Product measurement

Appeal Prepper is configured to use PostHog for anonymous website analytics, product measurement, and copy experiments when analytics is enabled. PostHog then receives ordinary analytics context such as a randomly assigned browser identifier, page URL, referrer, device and browser information, experiment assignment, and the non-identifying product events described below. Appeal Prepper does not create a PostHog person profile for visitors to the free lookup.

The allowed product-event fields are limited to non-identifying context such as result state, property segment, roll year, evidence tier, failure reason, and export format. Automatic click and form capture, session recording, heatmaps, exception capture, and no-code page rewriting are disabled in the site integration.

Sensitive fields are excluded from analytics: the typed or selected address, APN, owner name, phone number, email, signature, and downloaded worksheet contents are not allowed measurement fields and are not sent to PostHog by the product measurement code.

Accounts, contact details, and payments

Appeal Prepper does not require an account, phone number, owner name, signature, or current assessment notice. Stripe collects and processes the payment information required for Checkout under Stripe's own privacy practices; Appeal Prepper does not receive card numbers.

Appeal Prepper stores an opaque order identifier, canonical property reference, product and price contract, Stripe payment identifiers, payment status, the purchased comparison snapshot, and refund evidence. Access attaches to the property, not to a customer identity or browser token.

Anyone searching an actively paid property can see its 2026 report. A full refund revokes future website access, but cannot recall PDF, CSV, XLSX, or other data already downloaded.

Your choices

  • Do not enter an address if you do not want it reflected in ordinary website requests.
  • Block or clear the PostHog analytics cookie and browser storage using your browser controls if you do not want the anonymous experiment identifier retained between visits.
  • Delete downloaded worksheets from your device when you no longer need them.
  • Avoid entering owner names or contact details; the lookup does not need them.
  • Review the privacy terms of DataSF, search engines, and official City sites before following external links.