Version 2.0 · Effective September 12, 2026 · Supersedes v1.0 (August 21, 2026, updated August 30, 2026) — read the previous version
Privacy Policy — Officer One
Officer One is built by bigBespoke LLC for working law-enforcement officers. You extend trust for a living. This page is where we earn it: what we collect, why, what we never do, and the controls you keep.
The whole policy in four sentences. Your drafts, questions, photos, and records belong to you and are used to run the app for you — never sold, never used for advertising, never used to train public AI models. Your department can see that you hold a seat; it can never see what you write. We keep a record of what you do inside the app so support can help you and so your work has an audit trail — it is yours, and it dies with your account. Deleting your account erases your work immediately, from inside the app, with no ticket and no waiting period.
Contents
- Who we are, and who this covers
- What we collect — the full table
- What we never do
- AI processing
- Dictation and your voice
- The camera and your photos
- Location
- The usage trail
- Notifications
- Signing in on another device
- Looking around without an account
- When you write to support
- The record we keep about you as a customer
- Departments and seats
- Referrals
- Information about other people that you enter
- People we contact who are not users
- Our website, cookies, and advertising
- Service providers
- Security
- How long we keep things
- Deleting your account — what goes, what stays, and what you must do yourself
- Your rights, and how to use them
- Legal demands for your data
- Where we operate
- Children
- Changes to this policy
- Contact
1. Who we are, and who this covers
Officer One is published by bigBespoke LLC, a United States limited liability company. The product launched as PocketCop and was renamed Officer One in August 2026 — same company, same accounts, same commitments. We operate the website officerone.app, the administrative console at admin.officerone.app, and the Officer One apps for iOS and Android. For everything in this policy, bigBespoke LLC is the controller of your information.
This policy covers three groups of people, and says so plainly because the rules differ:
- Officers and other users of the app and website — sections 2 through 16 and 18 through 28.
- Department administrators who buy and manage seats — the same, plus section 14.
- People we contact who have never used the product — chiefs, agency contacts, and anyone who fills in a form on our site. Section 17 is yours, and sections 18 through 28 apply to you too.
When your agency buys the seats. Your agency pays. It does not become the owner of your work, and it does not become the controller of your personal information. We deal with you directly, on the terms in this policy, whoever pays the bill. Section 14 is the whole of what an agency can see.
2. What we collect — the full table
In plain terms: your account details, the work you create on purpose, a technical trail of taps and versions so we can support you, and billing status. No contact scraping, no background collection, nothing runs while the app is closed.
| Category | What it is | Where it comes from | Why we have it | Sensitive under state law? |
|---|---|---|---|---|
| Account | Email, name, password (stored only as a cryptographic hash we cannot reverse), and — if you add them — rank, agency, and state | You | To give you an account and keep your work attached to it | Login credentials are treated as sensitive |
| Your work product | Warrant drafts and their underlying facts, report narratives, questions you ask and answers you receive, charge inquiries, FTO trainees and daily observation reports, department forms you upload as templates, bookmarks and highlights, and the PDFs the app builds for you | You | To run the tools you opened | This is the most sensitive data we hold, and every rule below is written with it in mind |
| Usage trail | Which tool you opened, when, on which app version — an event log under your account | The app, as you use it | Support, your own audit trail, and knowing which tools earn their place | No |
| Device and technical | App version, platform, OS version, device model, language, and an installation identifier | The app | To make the right build work on the right phone and to diagnose faults | No |
| Crash reports | What failed and where in the code, the device model, the OS and app version, and a short trail of the screens you visited just before. Not configured to carry what you typed; your name and email are never sent to it | The app, only when something fails | To fix what broke | No |
| Billing | Subscription status, plan, price, renewal date, receipt and transaction identifiers, the last four digits and brand of your card | Stripe, or Apple if you subscribed in the App Store | To know whether your subscription is active and to answer billing questions | No — and we never hold your full card number |
| Location | The state and county you confirm | Your device, only when you allow it and only at the moment you ask for a jurisdiction | To put the right state's law and the right court's form in front of you | Precise location is sensitive; see section 7 for why we do not keep it |
| Voice | Nothing. We receive text, never audio | — | — | See section 5 |
| Photos | A photo of a pill you choose to submit, held only for the seconds it takes to read it | You | To read an imprint, colour, and shape into the search | See section 6 |
| Where your account came from | What the link that brought you said — a colleague's share code, a source word like facebook, a campaign word, and the time. Written once, never a name and never a lookup | The link you tapped; on Android, once, from Google Play | To know which doors and which campaigns actually bring officers in | No |
| Notification token | A push token issued by Apple or Google through Expo | Your device, if you allow notifications | To send the few notifications described in section 9 | No |
| Information about other people | Whatever you type into a draft, a narrative, an inquiry, or an FTO record about a suspect, victim, witness, or trainee | You | It is part of your work product; section 16 is the whole of how we treat it | Treated at the same level as your work product |
| Support | What you write to us, what we write back, and the account context beside it | You | To answer you | Can contain anything you choose to include |
| Customer record | Our own notes about how you are doing as a customer — stage, what you have used, what we have said, and our conclusions about what would help | Us, from the data above | To treat you like a person instead of a row | Section 13 says what it is and is not |
| Website visit | Pages viewed, referring link, approximate region from your IP, browser type, and — on our marketing pages only — the advertising cookie in section 18 | Your browser | To run the site and to measure our own advertising | Section 18 is the whole story |
| Anti-abuse | A one-way hash of the network address a website form was submitted from, and the browser string | Your browser | To stop a bot filling our forms a thousand times; the hash cannot be turned back into an address | No |
What we do not collect, and could: your contacts, your calendar, your photo library beyond the single picture you hand us, your other apps, your movements, your fingerprints or face, your device advertising identifier, or anything at all while the app is closed. There is no code in the app that does any of those things.
3. What we never do
- We never sell your personal information, rent it, or give it to a data broker. Not at any price, and no change to this policy will ever make that untrue.
- We never show advertising inside the app, and the app carries no advertising or cross-app tracking software of any kind. Our marketing website is a separate thing and section 18 tells you exactly what runs there.
- We never use your drafts, questions, photos, or records to train public AI models, and we do not let our providers do it either (section 4).
- We never give your department, your chain of command, or anyone else access to your individual work product. A department administrator sees seats, not substance (section 14).
- We never browse your work for entertainment or curiosity. Section 20 says exactly who can reach it and on what grounds.
- We never collect in the background. The app works when you open it and stops when you close it.
- We never publish, quote, or repeat what you wrote — not in marketing, not in a case study, not in a screenshot — without asking you first and getting a yes.
4. AI processing
In plain terms: when you use an AI feature, the text or photo you provided goes from our servers to our AI provider, a result comes back, and that content is not used to train anybody's model.
The warrant builder, the narrative tools, the charge inquiry, the pill reader, and Ask send what the feature needs — and only that — from our servers to our AI infrastructure provider (currently xAI) to produce your draft, reading, or answer. The exchange is server to server and encrypted. Your device never talks to the AI provider directly, and your identity is not sent with the request.
On training. We do not consent to our content being used to train models, we have not enabled any setting that would allow it, and we use the provider under business terms rather than consumer terms for exactly this reason. If a provider ever changed its terms so that our officers' content could be used for training, we would move providers or stop using the feature before that took effect — we would not update this page to make it acceptable.
What we keep about an AI call. Timing, size, model identifier, and the version of the prompt that produced it — no content. Your draft, the original AI proposal, and the record of what you accepted, rejected, or rewrote live under your account, because that trail is yours and it is what makes the work defensible.
You control what goes in. Enter the facts your case and your agency's policy allow, the same judgment you apply to any drafting tool. What comes back is a draft for your review — you remain the author and the affiant.
5. Dictation and your voice
Speech to text uses your phone's own recognition — Apple's or Google's. Depending on your device, its settings, and the language, the operating system may process the audio on the device or on Apple's or Google's servers under their terms. That path belongs to your phone, not to us.
We receive the text, never the audio. Officer One does not record, store, or transmit voice recordings. The microphone is live only while you are holding or have toggled a capture control that is visible on screen, and it stops when you let go or leave the screen.
6. The camera and your photos
The pill reader is the only feature that uses a camera or a photo, and only when you tap to use it. You either take one picture or pick one picture. That single image goes to our server and straight on to the AI provider, which reads the imprint, colour, and shape. The reading comes back; the photo is not saved to your account, to our database, or to our file storage. It exists in memory for the seconds the reading takes.
The app never scans, indexes, or reads your photo library. It sees the one picture you hand it.
7. Location
Location is optional. When you allow it, the app asks your device for a position once, at the moment you ask for a jurisdiction, and turns it into a state and county. You can deny the permission and type a zip code instead — every feature still works.
We store the jurisdiction you confirm — state and county — and never the coordinates. We do not track movement, keep a location history, or learn where you patrol. Because we never retain precise geolocation, the "sensitive personal information" rules in several state privacy laws have nothing of yours to reach.
8. The usage trail
In plain terms: the app keeps a first-party log of which tools you used and when. It is your audit trail and our support record. It is deleted with your account.
Officer One records feature events under your account: a door opened, a draft begun, a PDF built, a question asked — with a timestamp and the app version. Each event may carry a few flat facts about the work: which warrant kind, which statute, which state, how many. Never the facts you typed, never a sentence of yours, never a coordinate, and never your device's name. We built it deliberately, for three reasons: support can diagnose a problem from evidence instead of guesswork; your usage has a factual record if you ever need one; and we learn which tools earn their place.
The trail is first-party. It lives in our database, it feeds no advertising ecosystem, it is never sold or shared, it is never shown to your department, and it is deleted with your account like everything else. It records that you used a tool, and what kind of work it was — not the words you put into it.
9. Notifications
If you allow notifications, your device gives us a push token, which we store under your account and delete with it. We use Expo's push service to deliver messages to Apple's and Google's push systems.
We send few of them, and each one is tied to something that actually happened: support wrote back, a payment needs attention, your referral reward landed. Every kind can be turned off individually in the app, and turning off the permission at the operating-system level stops all of them. We do not send marketing pushes, and the text of a notification never contains your work.
We do not send text messages. There is no SMS in this product, and we do not ask for your phone number.
The email we send you is transactional: a receipt, a password reset, a support reply, a notice about your subscription, or an announcement of a change to these documents. We do not run a marketing list, and we will not add you to one. If we ever send you anything promotional, it will say who it is from, carry our postal address, and carry a one-click way to stop — and stopping will never affect your service.
10. Signing in on another device
You can sign in on a computer by showing a code to your phone. When you do, we hold a short-lived record linking the browser session to your approval — it expires two minutes after it is created, is single use, and carries no personal information beyond what completing the sign-in needs. Approving a browser is an account action, and we log it so you and we can see that it happened.
11. Looking around without an account
You can use the app before you make an account — the law shelf, the scripts, the walkthroughs, the aid cards, and the prices. While you are in that state we hold an anonymous identifier for your device and the usage trail attached to it, and nothing that identifies you: no email, no name, no phone number.
Two consequences, plainly. We have no way to reach you and no way to prove who you are, so an anonymous session cannot be recovered if the app is deleted, cannot be opened on a second device, and cannot be the basis of a data request we can verify. And subscribing creates an account — you see the plans and the prices first, and picking one asks for an email address and a password before any money moves — because the account is where the work lives and what carries it to your next phone.
12. When you write to support
When you open a support thread, the person answering sees your message, your account record, and a summary of your usage trail — versions running, features used, work counts — so the first reply can be an informed one. That context is there to help you, never to quote back at you.
If a problem cannot be diagnosed from the trail, we may need to look at a specific document you are asking about. We ask you first, we look at that document only, and the access is logged. When you send feedback from inside a tool, the work itself is attached only if you tick the box for it, and that box is off until you tick it — your words come to us either way, the document does not.
Support transcripts stay in your inbox. Closing a thread archives it; writing again reopens it. Mail we send you leaves through Zoho ZeptoMail; mail you send to support@officerone.app arrives in a Zoho mailbox. Both are covered in section 19.
13. The record we keep about you as a customer
We keep a record about you as a customer: what stage you are at, what you have used, what we have said to you and when, and our own conclusions about what would make the product better for you. Some of that is fact and some of it is inference — and an inference about you is still information about you, so we are telling you it exists rather than leaving it off the list.
Three rules govern it. It is written as though you will read it, because you can ask for it and we will hand it over. It is built only from data you gave us — what you typed, tapped, paid, or wrote to us — never from a search of you, a purchased list, or anything outside this relationship. And it is deleted with your account.
14. Departments and seats
In plain terms: your agency can pay for your seat. It cannot read your work.
When an agency covers its roster with a department plan, the department administrator sees membership facts: who holds a seat (name and email), invite status, seat count, and the plan's billing state. The administrator does not see — and there is no toggle, tier, price, or request path that reveals — any member's drafts, questions, law lookups, charge inquiries, FTO records, uploaded templates, support conversations, or usage trail.
Your work product stays yours whether you pay or your department does. If an agency requires visibility into work product as a condition of coverage, that arrangement happens inside the agency's own systems — its records management system, its supervisors, its policies — and never through us.
And if your agency asks us directly — we say no. A chief, a supervisor, an internal-affairs investigator, or a records officer who asks us for an officer's drafts, questions, or usage is told no, whether that officer still works there or not. The only thing that changes that answer is valid legal process, and section 24 says exactly what we do then — including telling you first.
When someone is invited. A department administrator enters a colleague's work email to send an invitation. Until that person creates an account, we hold the address and the invitation's status and nothing else, and we use it for nothing but the invitation. A pending invitation can be withdrawn by the administrator, which deletes it. Once the person joins, the record stays with the department as its own roster record — that this address was invited, and when it joined — and it is deleted if that officer later deletes their account.
When someone leaves. Leaving a roster, being removed from it, or the department closing ends the seat — never your access on the spot: a removed member keeps fourteen days of personal grace, and their work is theirs forever either way. You keep your account, you keep everything in it, and you can subscribe individually. Your former administrator stops seeing you in the roster. A closed department leaves behind a record that it existed — its name, its seat count, and the date it closed — with every member detached from it.
15. Referrals
Every officer gets a share code. When a colleague signs up with your code, we record that they joined with it, so the reward in the Terms can be paid.
You see a count, never a list. Your referrals screen tells you how many colleagues joined with your code. It never names them, and a colleague is never told who did or did not refer them. If your reward is delivered as an App Store code, that code is yours and appears in your app.
Where your account came from. When you arrive from a link — a colleague's share link, an advertisement, a search result — we write on your own account what that link said: a share code, a source word, a campaign word, and the time. On Android, Google Play passes it to the app once, on first launch. It is written once and never overwritten, it is never a name and never a lookup, and we use it to know which doors and which campaigns actually bring officers in. It stays in our database — no advertising platform receives it, ever — and it is deleted with your account.
16. Information about other people that you enter
Most of what an officer types into this app is about somebody else — a suspect, a victim, a witness, a complainant, a driver, a trainee. That person never signed up here, and this section is how we treat them.
Whose information it is. It is part of your work product. We hold it for you, under your account, to run the tool you opened, and for nothing else. We do not analyse it, profile the people in it, sell it, share it, use it to train models, or build any picture of any person named in it. It is protected exactly like the rest of your work: readable by your account and by nobody else's, invisible to your department, and deleted when you delete your account.
FTO records. A trainee's daily observation reports are about a real colleague. The same rules apply: your trainee's records are your work product, your trainee's chain of command does not get them from us, and they die with your account. Your agency's own policy governs what a DOR must contain and where the official copy lives.
Your responsibility, and ours. You are the one with the legal authority to record information about the people in your cases, and you are responsible for exercising it inside your agency's policy and your state's law — including what may and may not be entered into a third-party tool (Terms, section 4). We are responsible for holding it the way this policy says.
If one of those people asks us for their data, we will not hand it over, and we will not confirm or deny that it exists. We are not the custodian of your agency's records and we will not become a back door into an investigation. We point them to the agency, and where the law compels us to do more, section 24 governs. The one thing we will do is tell you, so that you and your agency can respond properly.
17. People we contact who are not users
Some of the people in our records have never used Officer One: a chief we wrote to, an agency's published contact, or someone who filled in the department-enquiry form on our website. This section is yours.
What we hold. Your name, your rank or title, your agency, your work email and work phone, your agency's address, the public source we took it from and the date, and a record of what we sent you and what you said back. If you filled in our form, we also hold what you typed in it.
Where it comes from — public sources only. Your agency's own website or published staff page, a state or association directory, a published roster, a public-records response, a public procurement listing, or your own message to us. Each record carries the source we took it from and the date we read it, so we can show our work if you ask. We do not buy contact lists, we do not use a data broker, we do not scrape anything behind a login, and we do not enrich a record from outside those sources. And we never want or keep your home address, your personal phone, your photograph, or anything about your family — several states exempt exactly those from public records for good reason, and we treat that as our rule in every state.
What we do with it, and nothing else. We write to you about Officer One, and we keep a record of what we sent so that we do not write twice. Every message identifies itself as coming from us, identifies itself as commercial, carries a valid postal address for bigBespoke LLC, and tells you how to stop — the four things federal law requires of a commercial message, in every message, without exception. Each one is written by a person here. We do not sell or rent your details, we do not give them to an advertising platform or a data broker, we do not use them to build an audience, and we make no automated decision about you.
How to stop, and what else you can ask for. Reply "no thanks" to any message, or write to support@officerone.app. The law gives us ten business days; we do it the same day. After that we keep one thing and one thing only — your address on a do-not-contact list, so the stop is permanent — and we delete the rest.
You have the same rights here as a user does: ask us what we hold about you and we will tell you, ask us to correct it and we will, ask us to delete it and we will. No account, no form, no fee. If we ever refuse a request, you can appeal by replying, and a person will reconsider it and answer you in writing.
If you work for a public agency, be aware that in many states the message we send you and your reply become public records of your agency the moment they arrive. That is your state's law, not our choice, and we write every message as though it will be published.
18. Our website, cookies, and advertising
Nothing in this section happens inside the app. The Officer One app carries no advertising software, no analytics suite, no advertising identifier, and no pixel of any kind. Nothing you do in it is ever shared with an advertiser — not a draft, not a question, not a tool you opened, not your account, not your usage trail. There is no code in the app that could.
Our marketing website is a different thing, and this is the whole of it. If you came to officerone.app from an advertisement, the platform that showed you that advertisement can tell that you arrived, and our site confirms it when a visitor reaches an app store from our page or completes a purchase. We use Meta's pixel for that. It is how we learn whether an advertisement worked at all, and it is the only measurement on the site — no advertising network, no session recorder, no third-party analytics suite, and nothing beyond the storage the pages need to work.
And it stops at the website. The moment you are in the app, the connection ends. We never join what you do in the app to the advertisement that brought you, because the app has nothing to join it with. If you would rather the website did not measure your visit either, a browser that blocks trackers or sends a Global Privacy Control signal stops the pixel loading, and we do not work around it.
Audiences. We advertise to people who work in law enforcement using the ordinary interest and job-title categories the advertising platform sells to everyone. We have never uploaded, and will never upload, a list of our officers, their email addresses, or their phone numbers to an advertising platform to build an audience.
19. Service providers
We use a short list of processors, each bound by contract to use your information only to provide their service to us:
| Provider | What it does | What it touches |
|---|---|---|
| Google Firebase (Google Cloud), United States region | Authentication, database, file storage, hosting, functions, crash-free operation of the backend | Account data, work product, usage trail |
| Stripe | Payments and subscriptions bought on our website, and from the Android app | Payment details (card data stays with Stripe), billing status |
| Apple | App distribution; subscriptions bought inside the iPhone app; on-device or OS dictation; push delivery | Store account and purchase under Apple's terms; the subscription status Apple reports to us |
| App distribution through Google Play; on-device or OS dictation; push delivery | Your Play account under Google's terms; dictation per section 5 | |
| xAI | AI drafting, answers, and the pill reading | The text or photo you submit to an AI feature; not used for training |
| Sentry | Crash and error monitoring | Crash reports, device, OS, and app version |
| Zoho (ZeptoMail and Mail) | Sending transactional email; receiving mail to our addresses | Your email address and the content of messages between us |
| Expo (EAS) | App builds, over-the-air updates, push delivery | Update bundles; your push token if you allow notifications |
| Meta | Advertising measurement on the marketing website only | Website visit events described in section 18 — never account data |
We do not use processors outside this list for your personal information. When this list changes in a way that matters, we update this page, bump its version, and say so in the app's What changed log.
20. Security
Your data is encrypted in transit with TLS and encrypted at rest on Google Cloud infrastructure. Access rules are enforced at the database layer: your documents are readable by your authenticated account and by no other user, and several collections — the ones holding our own counters and administrative records — are closed to every client and reachable only by our server.
Passwords are stored as cryptographic hashes we cannot reverse. Secrets and API keys live in managed secret storage and never ship inside the app you install. Payment credentials are handled entirely by Stripe, or by Apple if you subscribed in the App Store; we never see a full card number.
Who at bigBespoke LLC can reach your work, and when. Administrative access is limited to a small number of named people, each using their own credentials so every access is attributable and logged. They may reach your work product for four reasons and no others:
- a support request you opened, or a fault you reported;
- a legal obligation we are required to meet;
- an investigation into abuse, fraud, or a threat to someone's safety;
- reviewing content for field accuracy and product quality — by a person bound in writing to the confidentiality obligations in this policy, who may never use what they see for any police purpose, their own or anyone else's, and may never pass it to an agency, a colleague, or a prosecutor.
That fourth reason is stated because it is true: the reference content in this app is checked by working officers, and telling you so is better than a comfortable sentence that leaves it out. It does not permit browsing, and it does not permit anything in reasons one through three to happen without a reason.
On your phone. Copies of your recent work are cached on your device so the app works without signal. That cache is protected by your device's own security and is removed when you delete the app. Lock your phone.
Criminal justice information. Officer One is not a criminal-justice agency system and is not certified under the FBI's CJIS Security Policy. We do not connect to NCIC, a state criminal history system, or any CJIS-governed source, and we never receive data from one. What you type into a draft is what you type; your agency's policy governs what may be typed into a third-party tool, and section 4 of the Terms puts that responsibility where it belongs.
If something goes wrong. Nobody can honestly promise zero risk. If a breach affects your personal information we will notify you without undue delay and within the time any applicable law requires, tell you what we know as we learn it, and say plainly what we are doing about it. We will not wait for certainty to tell you something happened.
21. How long we keep things
| What | How long |
|---|---|
| Your account, work product, and usage trail | While your account exists. Deleted immediately when you delete it |
| Crash reports | Up to 90 days at our error-monitoring provider, then automatically dropped |
| AI call metrics (timings and sizes, no content) | While your account exists; deleted with it |
| Information about other people inside your work (section 16) | Exactly as long as the work it sits in — deleted with it, and with your account |
| Support conversations | Kept as ordinary business records for up to 3 years after the conversation ends, then deleted |
| Billing and transaction records | 7 years, because tax and accounting law requires it. Held by us and by Stripe or Apple |
| Website visit records | The advertising platform's own retention applies to the pixel; our server logs are kept 30 days |
| Records about people we contact who are not users (section 17) | Until you ask us to stop, plus the minimum needed to honour that — your address on a do-not-contact list, and nothing else |
| Operational backups | A copy of the database taken for disaster recovery expires on its own cycle within 30 days of the deletion |
22. Deleting your account — what goes, what stays, and what you must do yourself
In plain terms: You → Delete account erases your work on the spot. Self-serve, immediate, no ticket, no waiting period. Two things are on you: export anything your agency needs to keep, and cancel an App Store subscription in the App Store.
What happens the moment you tap it. Any subscription we bill ends first — so a deleted account can never be charged again — and then our servers permanently delete your warrants and their audit trails, narratives, chats and answers, charge inquiries, FTO trainees and observation reports, your usage trail, your uploaded templates, every generated file, your bookmarks and highlights, your customer record, your notification token, your profile, and your login. This is a hard delete of live records, not a deactivation. If your phone loses signal mid-way, a server process finishes the job.
What is left afterwards. Three things, and nothing else:
- Billing and transaction records, because tax and accounting law requires them. They live with us and with Stripe or Apple, and contain no work product.
- Support correspondence, as an ordinary business record — so a refund or a dispute can be answered later. It contains whatever you chose to put in it.
- A marker that an account with that internal identifier was deleted, carrying no name, no email, and no content. It exists so our own accounting can never double-count you.
Two things only you can do.
- Export first if your agency needs the record. We are not your records system. Some states require an agency to retain the original AI-assisted draft of a report for as long as the report itself is retained — deleting your account here destroys our copy of it. Export what your agency's policy requires before you delete.
- Cancel an App Store subscription with Apple yourself. A subscription we bill ends before anything is erased — we do that for you. An App Store subscription we cannot touch: it is an agreement between you and Apple, Apple lets us read its status and nothing more, and nobody but the subscriber can end it. So deleting your account does not cancel it, and Apple will keep charging you until you do. You → Billing → Manage subscription takes you straight to Apple's screen for it. The delete card says this too; we are saying it twice because this is the way people lose money.
This cannot be undone. There is no trash can, no thirty-day window, and no copy we can restore for you afterwards. That is the promise, and it is also the warning.
You can also ask us to delete your account by writing to support@officerone.app, and we will do it for you.
If an account holder dies. An executor or a next of kin can ask us to close and erase the account, and we will, on reasonable proof. We will not release the work product to anyone but the account holder — a request for the contents of a deceased officer's drafts goes through the agency or through legal process, not through us.
23. Your rights, and how to use them
We extend the same rights to every person, in every state, whether or not your state has a privacy law:
- Know and access — ask what we hold about you and we will tell you, including the customer record in section 13 and the categories in section 2.
- Portability — ask for a copy of your data in a portable format.
- Correct — your profile is editable in the app; anything else, ask.
- Delete — self-serve in the app, as section 22 describes, or by asking us.
- No sale, and nothing to opt out of in the app — we do not sell personal information, and the app runs no advertising or tracking software at all. Section 18 is the website's whole story and how to stop it there.
- No profiling with legal effect — we make no automated decision about you that produces a legal or similarly significant effect, so there is nothing to opt out of.
- Nothing is used for anything else — what you give us runs the service you asked for, and that is the whole of it.
- No retaliation — using any right here never degrades your service, your price, or the way we treat you.
- Appeal — if we refuse a request, you may appeal by replying to our refusal. A person will reconsider it and give you a written answer with reasons within 45 days. If we refuse again, you may complain to your state attorney general, and we will tell you how.
To use a right: You → Support in the app, or email support@officerone.app. We verify a request against your signed-in account or your email of record, and we honour an authorised agent where the law provides for one. We answer within 45 days, and usually much faster. There is no charge, and there is no form — a person reads your message and answers it.
24. Legal demands for your data
You know how this works from the other side, so here is our posture, plainly.
We require valid legal process before disclosing user data — a subpoena, a court order, or a warrant, as the law requires for the kind of data sought. We read demands narrowly and produce the minimum they lawfully compel. We push back on demands that are overbroad, defective, or fishing. We notify you before disclosure so you have a chance to object, unless the law forbids it — and if we are ordered to stay silent, we tell you when the order lifts. In an emergency involving a genuine risk of death or serious injury, we may act faster and tell you afterwards.
We never volunteer user data to anyone, including to law enforcement, including to officers who use this product. A person who works with us does not get a shortcut around this page.
Understand what exists to be demanded. Your drafts, the original AI proposal, and the record of what you accepted or changed are retained on purpose, because that trail is what makes your work defensible. It can also be sought by a party in litigation. That is the same as every other document you create in the course of your work, and it is why the Terms ask you to treat what you type here as a record, not as a private notebook.
25. Where we operate
Officer One is built and sold for law-enforcement professionals in the United States. Our infrastructure runs in United States regions, and we do not offer the service to people in the European Economic Area, the United Kingdom, or Switzerland. If you use it from outside the United States, your information is processed in the United States.
26. Children
Officer One is a professional tool for adults. It is not directed at children, we do not knowingly collect personal information from anyone under 18, and nobody under 18 may have an account. If you believe a minor has created one, tell us and we will delete it.
27. Changes to this policy
Every version of this policy carries a version number and an effective date, and we keep the previous versions.
- A material change — a new kind of information collected, a new provider that touches your data, a new purpose, a change to who can see your work, or a change to your rights — is announced in the app before it takes effect, and we ask you to accept it — a full screen you cannot tap past, with the change in plain language and both documents readable right there. We do not mail you about it; the notice is where you already are. Where a law requires direct notice of a particular change — a price increase, or a breach — you get that by email as well.
- An editorial change — a clearer sentence, a corrected typo, a renamed screen — updates the date and appears in the app's What changed log without interrupting you.
Two things will never change by a policy update: we will never start selling your personal information, and we will never start using your work to train public AI models. If a future owner of this company wanted to do either, they would have to obtain your consent, not publish a new page.
28. Contact
bigBespoke LLC · support@officerone.app · or You → Support inside the app, where a person answers.
Postal address for privacy requests and legal notices: bigBespoke LLC, 609 Smith Vasser Rd, Harvest, AL 35749.