Privacy policy
Last updated: 1 September 2026.
This policy covers the Section iOS app, Section Pro tools and the Section website. Section is an independent UK police reference project and is not an official police or government service.
Core iOS app
The core reference library works offline. Bookmarks, preferences, disclaimer acceptance and the local offence database stay on your device. Section has no user accounts, advertising SDKs or cross-app tracking.
Pro AI tools
When you use an online Pro tool, the text you enter, Apple's signed subscription evidence and, where available, an Apple device-verification identifier are sent over encrypted connections to Section's Cloudflare-hosted service. The service uses these to provide the feature, verify Pro access, prevent abuse and apply daily usage limits.
- Statement Writer keeps your working input and generated draft in the running app's memory until one hour after your last change. It does not save that content to an on-device file or database. Copy and Share are separate actions you control.
- Section's service does not write Statement Writer prompts or outputs to its application database or usage records. Section cannot retrieve a statement from those records.
- The usage database stores an opaque one-way subscription-derived quota key, UTC day, count and update time. It does not store the raw StoreKit proof, Apple device identifier or statement text.
- Cloudflare processes the request and network, routing, security and invocation metadata needed to deliver and protect the endpoint. Section's application error logs record bounded error codes or upstream status values, not prompt or output bodies.
- Statement Writer sends the constructed prompt to Anthropic's commercial Messages API and returns Anthropic's output to the app. It does not use OpenAI or Cloudflare Workers AI.
Anthropic's current standard commercial API policy says it deletes API inputs and outputs from its backend within 30 days, except where a different retention arrangement or a longer-retention feature applies, where content must be retained for Usage Policy enforcement, or where law requires retention. Content flagged for a Usage Policy violation may be retained for up to two years and safety classification scores for up to seven years. Statement Writer uses the Messages API and does not use the Files API. Anthropic's Commercial Terms say it may not train models on customer content. See Anthropic API retention, Anthropic Commercial Terms and Anthropic's Data Processing Addendum.
For Statement Writer, use placeholders only. Do not enter names, addresses, identifiers, or personal, sensitive or operational information. The app does not use a personal-information detector and cannot reliably identify every name or identifier. It does not reject ordinary wording merely because it resembles a name or uses a particular format. See the Statement Writer Terms of Use.
Section does not use Pro input for advertising or tracking. Cloudflare Web Analytics applies to public website pages for aggregate measurement; it is not embedded in the iOS Statement Writer request flow.
Subscriptions
Section Pro subscriptions are purchased through Apple. Apple processes payment details and controls trial eligibility, renewals, cancellation and refunds. Section receives StoreKit entitlement information needed to unlock Pro; it does not receive your card or bank details.
Website and waitlist
If you join the website waitlist, we collect your email address, optional role/context text and basic request information needed to protect the form from abuse. We use it for Section access and product updates, not unrelated marketing.
The website uses Cloudflare hosting and may use cookieless Cloudflare Web Analytics for aggregate traffic measurement. It does not use advertising pixels.
In-app feedback
When you send feedback, Section stores the category and message, the related offence when applicable, and any contact email you choose to provide. You can also choose whether to include the app version, build, iOS version and device type. Section does not include a device identifier in feedback reports. Cloudflare processes the request and a daily one-way network fingerprint is used only to limit abuse; the raw network address is not retained in the feedback record.
Do not include names, addresses, crime references or other sensitive operational information. Feedback is used to investigate faults, correct content, provide support and plan product improvements.
Sharing and retention
Data is shared only with service providers needed to deliver Section, including Apple, Cloudflare, Anthropic and, for Pro tools other than Statement Writer where configured, OpenAI. Statement Writer itself is Anthropic-only. We do not sell personal data. Waitlist, feedback, quota and service records are retained only while needed for access, support, security, accounting or legal obligations.
Your choices
You can avoid all online Pro processing by using the offline reference features only. You can manage or cancel a subscription in your Apple Account subscription settings. To ask about Section's processing, access, correction or deletion, use the in-app feedback form or the Section support form. Do not include statement content or operational personal data in the request.
Changes
If Section adds accounts, advertising, new analytics, or materially different data use, this policy and the App Store privacy answers will be updated before that change ships.