Privacy policy
CJIS Policy Companion, published by CJIS360 LLC. Effective September 29, 2026. Last updated October 4, 2026 (voice input; age confirmation; agencies and administrator roles; keep me signed in; CJIS roles; account deletion by email; problem reports).
This policy describes what the CJIS Policy Companion app and its server collect, why, where it goes, and how long it is kept. The app has no advertising and no analytics or tracking software. We do not sell or share data for advertising.
Do not enter Criminal Justice Information
The app answers questions about the published FBI CJIS Security Policy. It is not designed to receive Criminal Justice Information (CJI), case details, or personal information, and you must not enter them. The server screens each question for patterns that look like CJI or personal identifiers, such as Social Security numbers, vehicle identification numbers, case or warrant numbers, and named suspects or victims. A question that matches is refused. Its text is not stored and is not sent to any other service; only the category of the match and the time are recorded.
What the server receives and keeps
- Your account. Your email address, display name, and an account identifier, kept until you delete the account. Sign-up and sign-in are handled by Microsoft Entra, which emails you a one-time code each time you sign in; there is no password. If your account belongs to an agency, we keep which agency and your role (user or agency administrator) with the account. If an administrator sets your CJIS roles (for example General User, or TAC), we keep them with the account and use them only to put the controls for your job first in answers.
- What your agency's administrators see. If you joined through an agency, that agency's administrators can see your email address, display name, join and last-seen dates, how many answers you have on the server, and when you confirmed your age, and can disable your account or sign you out. They cannot see your questions or answers.
- Invitations. If an administrator invites you by email, your email address is kept with the invitation until you activate your account or the invitation expires after 30 days.
- Administrator activity record. Actions administrators take on accounts (for example disabling an account or signing it out), and your own Sign out on all devices, are recorded with the date and the accounts involved, kept for one year, then deleted. Invitations appear in this record with a shortened email address only.
- Your questions and the answers. Each question, its answer, the policy passages used, and technical details needed to review answer quality (such as the model and data versions) are stored with your account for 30 days, then deleted.
- Feedback. Ratings you give an answer, and any comment, are stored with that answer and deleted with it. Comments pass through the same CJI screening as questions.
- Problem reports. If you choose to report a problem with an answer, you describe it, confirm it contains no CJI or personal information, and send it as a numbered report (for example CJISCP_IC_0001). The report keeps your description, a copy of the question and answer it is about, which screen you were on, your device type (iPhone, Android or web) and the app version, and the messages between you and the CJIS360 team. Only CJIS360's own administrators can see reports; your agency's administrators cannot. Reports are kept while they are open and for one year after they are resolved or closed, then deleted; they are deleted with your account if you delete it. Report text passes through the same CJI screening as questions.
- Network address. Your IP address is held in server memory for no more than two minutes to limit how many requests one device can make. It is not written to storage.
- Voice audio. When you play Talon's voice, the generated audio is held in server memory for five minutes so it can be replayed, then discarded.
The server does not receive your contacts, location, or device identifiers.
Service providers
- Anthropic generates answers. Your question, and any earlier question and answer you follow up on, are sent to Anthropic together with the relevant policy text.
- Google Cloud Text-to-Speech produces Talon's voice. Only the answer text is sent, and only when you play it.
- Microsoft Azure hosts the server and its storage in the United States.
- Microsoft Entra External ID runs account sign-up and sign-in, sends the one-time sign-in codes, and holds your email address and display name on our behalf.
Each provider processes this data under its own commercial terms to perform the service for us. As of the effective date, their published terms state:
- Anthropic does not use API inputs or outputs to train its models by default, and generally deletes them within 30 days, subject to legal, contractual, or abuse-monitoring exceptions.
- Google states that it does not log any customer Cloud Text-to-Speech text or audio data.
- Microsoft Azure stores the server's data on our behalf; we set how long it is kept, as described above.
What stays on your device
- Your last 25 questions and answers, so you can reopen them. Clear them at any time from Question history. They are not synced anywhere.
- Your voice, if you choose Ask by voice on iPhone or Android. Speech is turned into text by the phone's own on-device speech recognition: no audio is sent to CJIS Policy Companion, CJIS360 LLC, or any of our service providers, and no recording is kept. The button appears only on phones that support on-device recognition. The text goes into the question box for you to review, and is sent only when you choose Ask Talon, like a typed question. The web version has no voice button.
- Your sign-in session, in the device's secure storage (Keychain on iOS, Keystore on Android). In a web browser, it lasts until the tab is closed, unless you tick "Keep me signed in on this device"; then it stays in that browser's storage until you sign out.
Children and age
The app is for criminal justice and public safety professionals aged 18 or older. It is not directed to children or teens, and we do not knowingly collect personal information from anyone under 18. Account holders confirm they are 18 or older when they activate their account; we keep the date of that confirmation and the wording confirmed with the account until it is deleted. If we learn that an account belongs to someone under 18, we delete it.
Your choices
You can clear on-device history at any time, choose not to play voice audio, and turn off microphone and speech recognition access for the app in your phone's settings. Delete your account from the Account screen in the app: that deletes your account, your sign-in, and the questions and answers stored for it. If you cannot sign in, delete your account by email. To ask about data held on the server, contact us at the address below.
Changes
We will post changes on this page and update the effective date.
Contact
CJIS360 LLC, a Florida limited liability company, 7590 Via Luria, Lake Worth, FL 33467. Email: privacy@cjis360.app.