Skip to main content

Privacy Policy

Last updated: 2026-08-26

This page describes how Tenant Wiki handles information that you provide.

What we ask you for

You can search and read public legal sources without an account. If you sign in, we ask for your email address. Some private services can also ask for:

  • Facts about your housing situation, such as dates, addresses, and party names
  • Documents that you choose to upload
  • An optional organization code from a tenant union or legal-services partner

Do not submit information that is not needed for the service you are using.

How we store email

Your email address is converted to a one-way HMAC fingerprint as soon as it arrives. The fingerprint is what the database stores. The original email address is only held in server memory long enough to send your sign-in link, then discarded.

We cannot reverse the fingerprint to recover your email address.

How we store information you enter

Information that you enter is used only to provide the service that you request. We do not retain raw names, addresses, or dollar amounts in the primary database after the service completes. Download files are removed after 30 days.

Server logs

The web server logs IP addresses, request paths, and timestamps for routine diagnostics. These logs are retained for 30 days. Error logs are retained for the same period.

What we don't do

  • We do not share your information with landlords, courts, or third parties.
  • We do not sell or rent your data.
  • We do not use the facts you submit to train machine-learning systems.
  • We do not run third-party advertising trackers or analytics SDKs.

Browsing the database

Searching the site and reading legal sources requires no account and writes nothing about you to the application database. The only record is the standard server log described above.

Cookies

After you sign in, a session cookie keeps you signed in across pages. The cookie holds only an opaque session identifier — no personal data. Sessions expire after 7 days of absence or 24 hours of inactivity, whichever comes first. Logging out deletes the session immediately.

Deleting your data

Signed-in users can delete every record tied to their account at any time, including saved work, uploaded-document data, active sessions, and the email-to-user mapping. Visit Delete My Data from any signed-in page. You retype the email tied to your account as a confirmation step. The deletion runs immediately and cannot be reversed. You are then signed out.

Changes to this policy

If our services change in a way that affects what we collect or how we store it, this page will be updated. The "Last updated" date at the top reflects the most recent revision.