ReporterFlow is a secure, cloud-based business management platform built for federal court reporters, with an optional state-edition workflow for state and county court reporters ("we," "us," "our," or "ReporterFlow").
This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have over your data. By using ReporterFlow you agree to the practices described here.
Questions about this policy? Email support@reporterflow.com.
When you create an account we collect your name and email address. Authentication is handled by Supabase Auth and (optionally) Google OAuth. We never see or store your Google password.
To generate invoices, AO compliance forms, and reports, we store information you voluntarily provide in your profile, including: full name, business address, phone number, federal district, certifications, signature image, and identifiers required for federal billing forms (e.g., Tax ID last 4, vendor numbers).
We store the transcript orders, invoices, payment records, and the AO compliance forms you generate (AO-44, AO-40A, AO-40B, AO-37, AO-38, AO-39, AO-35, and ST-39D). This may include case captions, docket numbers, attorney and judge names, hearing dates, page counts, billing rates, deposits, and totals. This data is required to deliver the core functionality of the app.
If you upload a finished transcript file through the Delivery tab on an order, we store the file in a private storage bucket scoped to your account, encrypted at rest. The file is served to your paying client through the Payment Portal via a short-lived signed URL after you unlock the order. Transcript delivery files are subject to an automatic 30-day retention window — see Section 7 (Data Retention) for details. Using the upload is optional; you can always continue to share a hosted link (Google Drive, etc.) instead.
We store attendance events (court sessions, hearings, voucher entries) including dates, hours, locations, judges, and proceeding types. This data powers your AO-38 attendance ledger and other compliance reports.
We store expense entries you record, including dates, amounts, categories, payees, descriptions, and depreciation schedules used for AO-40B vouchers. If you attach a receipt image to an expense, we store that file in a private, account-scoped storage bucket alongside the expense record. We do not perform any text extraction (OCR) on your receipts.
We store the attorney, firm, judge, payee, and requesting-party records you enter into the app, including names, firm names, email addresses, phone numbers, and mailing addresses. This data is used solely to populate your invoices and forms; it is never shared with third parties for marketing.
If you use the email features, we store the parsed email content you import, drafts you compose, and the recipients of transactional emails you send (e.g., invoice deliveries, transcript-ready notifications). Email is sent on your behalf via Resend; we do not connect to your inbox or read your existing mail.
If you open a support thread with the ReporterFlow team, we store the messages you exchange with us so we can help you and keep a record of the conversation. Support messages are visible only to you and the ReporterFlow admin team; they are never shown to other users.
If you submit product feedback through the in-app Feedback button, we store the feedback text, the page you were on when you submitted it, and your email address (so we can respond). Feedback is visible only to the ReporterFlow team.
Your subscription to ReporterFlow itself is billed through Stripe; we store only your Stripe customer ID and the subscription event history (renewal dates, refunds), never your card details. We do not process card payments between you and your clients on your behalf — if you record payments you have taken (check, wire, card, PayPal, Zelle, Venmo) we store only the amount, date, and the reference text you enter. If that ever changes, we will update this policy before storing any processor data.
Separately, if you choose to display payment-acceptance details to your clients on the Payment Portal — such as a PayPal email, Zelle information, a Venmo handle, or check instructions — we store those details so they can be shown to the clients you invoice. You provide them voluntarily, and they are visible by design to the clients you send a payment link.
If you use AI features (calendar parsing, order extraction, chat assistant), the inputs you submit are sent to our backend and forwarded to large-language-model providers solely to fulfill the request. Outputs are returned to you and stored alongside the order or task you were working on. We do not use your data to train models, and we do not allow our model providers to either.
Our hosting provider (Cloudflare) may automatically collect standard server log data, including IP addresses, request paths, browser type, and timing. This data is used for security monitoring, rate limiting, and reliability — never for marketing.
We do not sell your personal information. We do not use your data for advertising or behavioral profiling. We do not allow third parties to use it for those purposes either.
ReporterFlow relies on the following third-party services. Each operates under its own privacy policy and data processing terms:
| Service | Purpose |
|---|---|
| Supabase | Database (PostgreSQL), authentication, and file storage. All user data is row-level-security isolated. |
| Cloudflare | Web hosting, edge compute (Workers), and content delivery. |
| Stripe | Subscription billing — processes your annual ReporterFlow subscription charge. PCI-DSS compliant; handles all cardholder data. |
| Resend | Transactional email delivery (invoices, transcript notifications). We do not access your inbox. |
| Google OAuth | Optional sign-in. We receive only your name and email address; we never read your Google data. |
| Anthropic | Large-language-model provider used for AI features (Claude). No training on your data. |
ReporterFlow includes AI-assisted features (calendar parsing, order extraction from email, transcript notice parsing, chat assistant). Our use of these features is limited to the following:
All data is stored in Supabase's managed PostgreSQL infrastructure hosted in the United States. We implement the following security measures:
While we take reasonable steps to protect your information, no method of transmission over the internet is 100% secure. We encourage you to use a strong, unique password and enable two-factor authentication on your Google account if you sign in with Google.
We retain your data for as long as your account is active or as needed to provide the service. Cancelled accounts retain read-only access to historical records; we delete personal data from active databases approximately 365 days after subscription end, subject to any legal obligations that require longer retention.
Transcript delivery files uploaded through the Delivery tab on an order have a separate, shorter retention window: they are kept for 30 days from upload and then automatically deleted by a scheduled daily cleanup. The pasted Transcript Link URL on the order (if you also provided one) is retained indefinitely as a fallback for the client; only the uploaded file itself is purged.
You can export your data at any time from Settings → Data → Import & Export. To request immediate deletion, email support@reporterflow.com — we will delete your data within 30 days of a verified request.
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, email support@reporterflow.com. We will respond within 30 days.
ReporterFlow is offered only to professionals who are at least 18 years old, consistent with our Terms of Service. It is not directed at children, and we do not knowingly collect personal information from anyone under the age of 13. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you via the app or email. Your continued use of ReporterFlow after changes are posted constitutes your acceptance of the revised policy.
This Privacy Policy is governed by the laws of the United States and the state in which the operator of ReporterFlow is domiciled, without regard to conflict-of-law provisions.
If you have any questions about this Privacy Policy or your personal data, please email us at support@reporterflow.com. We respond to privacy requests within 30 days.