Privacy policy
Effective September 9, 2026 · RadioPaperwork, a Sparkgap LLC product
What we hold about you
An account is an email address, a password (stored only as a hash, which we cannot read), an organization name, and the list of stations your organization watches. Alongside that we keep the scan results we produce, alert history, an audit log of changes made in your organization, and our billing records: your Stripe customer and subscription identifiers (your card stays with Stripe and never reaches us). If you set up filing, we also hold each station's OPIF API access token, encrypted, never displayed back to anyone, and sent only with documents you have approved; the documents we draft and file for you are kept as your filing record. Those are the customer records we hold in the service. Optional public-site analytics is described below.
Station data is public record
Everything we report about a station, call signs, facility records, public-file folder contents and upload timestamps, comes from the FCC's own public systems (publicfiles.fcc.gov and the FCC's licensing database). It is public before we read it and stays public regardless of us. Scanning a station creates no relationship between that station and any account.
Payments
Payments are processed by Stripe. Your card number never reaches our servers; we hold only Stripe's identifiers for your subscription and its status. Stripe's handling of your payment details is described in Stripe's own privacy policy.
Cookies
The required cookie signs you in. When you arrive through a link in an email we sent, the link carries
a short campaign code (such as ?r=rp1) naming that email; your browser keeps
it for ninety days and we store it with the free check you run and with the account you
buy, so we know which note was worth writing. It identifies the email, not you. Your
optional analytics choice is also stored in local storage. If you allow analytics, Google
Analytics may set first-party measurement cookies on measured public pages.
Optional public-site analytics
Google Analytics does not load unless you choose Allow analytics. If you opt in, it receives the public page URL without its query string or fragment, a sanitized referrer, and browser and device information. Google may derive approximate location from the request address. It runs only on the home, guide, privacy, and terms pages. We do not send station or call-sign pages, checker activity, form values, campaign codes, sign-in pages, or account and dashboard activity. Google signals and advertising personalization are disabled.
Use Analytics settings in the footer of a measured page to change your choice. Turning analytics off disables collection, removes Google Analytics cookies this site can access, and reloads the page without the tag.
We send the email the product is for: gap alerts, the weekly summary, and account messages like password resets. Stop them by removing stations from your watch list or closing your account. Write to us and we delete it.
What we don't do
We don't sell or share your information with anyone, we don't advertise to you, and we don't tell anyone, including the FCC, what your organization watches. Service providers that touch data (hosting, email delivery, Stripe, and optional Google Analytics) process it only to run or measure the service. We do not use Google Analytics for advertising.
Access and deletion
Ask and we'll send you what we hold, correct it, or delete your account and its data. Write to [email protected] from your account email; we answer within 30 days.
Changes
If this policy changes in a way that matters, account holders get an email before it takes effect. The date at the top is the version.