Privacy policy
- Effective date
- October 6, 2026
- Applies to
- Personal information TakePublic processes
- Contact
- hello@takepublic.com
- Version
- Current
This privacy policy describes how TakePublic, Inc., a Delaware corporation ("TakePublic", "we", "us") collects, uses, and shares personal information in connection with the TakePublic platform, the takepublic.com marketing site, and the free compliance scanner (together, the "Service").
TakePublic is a technology platform, not a law firm, broker-dealer, or auditor. Forms 3, 4 and 5 prepared in TakePublic file only after the reviewer the company designates, such as its securities counsel, signs off; any other filing prepared in TakePublic files only after a licensed securities attorney signs off.
Two roles matter here. For the content a customer company puts into the platform (filing drafts, accounting data, insider and questionnaire information), we process that data on the customer's behalf under our agreement with them, and the customer decides how it is used. This policy governs the personal information we control directly: accounts, scanner leads, site visits, and support.
This policy does not cover personal information about TakePublic's own employees, contractors, or job applicants; we provide separate notices to them.
1. Information we collect
In the categories used by state privacy laws such as the California Consumer Privacy Act, the information we collect consists of identifiers, professional information, commercial information, and internet or other network activity. Specifically, we collect the following, directly from you or from your company:
- Account information: name, email address, and an optional mobile number for the text messages you choose.
- Company profile: legal name, CIK, ticker, fiscal calendar, filer status, and onboarding questionnaire answers.
- Customer content processed for your company: filing drafts and sections, trial balance and accounting data, Section 16 insider information, and director and officer questionnaire responses.
- Text message choices: when a person opts in to or out of text messages, the mobile number, the time, and the version of the words shown; for a request notice opt-in, also the page it was given on and the request it named.
- Credentials and connection data: EDGAR filer codes and access tokens your company provides for filing, and OAuth tokens for accounting connections your company authorizes. These are encrypted at rest with AES-256-GCM.
- Scanner leads and waitlists: the email address you give us to receive a free compliance report, to join a waitlist, or to request access to a plan, and the company it concerns.
- Sanctions screening: the names of companies that sign up and of the people a workspace adds or renames, the lists any name matched, and our staff's decision on a match.
- Usage and log data: IP address, browser type, pages viewed, error reports, and timestamps, collected automatically to operate and secure the Service.
2. How we use information
We use personal information to provide and secure the Service, compute and send deadline alerts, process payments, respond to support requests, and send the reports and communications you ask for. Administrative messages about your account and deadlines are part of the Service. We send text messages through Twilio: one-time security codes on signing, sign-off and response pages; a notice when a company emails a person a request, or changes their mobile number while a request for their signature is open, only after that person opts in on one of those pages; the deadline reminders a person chose; and service status updates when turned on. Two-step sign-in codes are sent by Google Cloud Identity Platform. A notice or reminder goes only to a number whose owner has opted in, and we keep a record of each opt-in, with the version of the words shown (the current versions are dated September 29, 2026), and of each opt-out. Reply STOP to any text to opt out, or HELP for help. Message frequency varies, and message and data rates may apply. Marketing email is optional and every marketing message includes an unsubscribe link. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
We also use names to comply with sanctions and export control laws: we screen companies and the people a workspace adds or renames against the United States, United Kingdom, European Union, and United Nations sanctions lists, which we download from the governments that publish them; no personal information is sent to them. A possible match pauses the sign-up or the change until a member of our staff reviews it and decides; no one is refused by the screening alone.
We do not use personal information for advertising, profiling, or automated decisions that produce legal effects.
3. AI processing
When you ask the support assistant a question, your question and, once your company is set up, a snapshot of its filings, deadlines and plan are sent to our AI model providers solely to answer it. When you drop or paste a broker confirmation, grant notice, statement or description to record an insider's transaction or holdings, its text is sent to them solely to propose the values you then check. When your company requests an AI-generated draft or enables retrieval features, relevant content is sent to them solely to produce that output. We do not use your content to train AI models, and our agreements with these providers prohibit them from using it to train theirs.
4. How we share information
We do not sell personal information, we do not share it for targeted advertising, and we do not run advertising trackers.
We share information only with the service providers that run the platform, with the government systems you file to, and as the law requires, including reports sanctions laws require. The current subprocessor list is published at /legal/subprocessors and mirrored below. We keep the list current and will notify account owners before a new subprocessor processes customer content.
Connected services work in the other direction and are not subprocessors: when your company connects QuickBooks Online or imports a Google Sheet, those providers send us your data at your direction under your agreements with them, and filings you submit to SEC EDGAR become public government records.
- Google Cloud: application hosting, database, file storage, and Google Cloud Identity Platform authentication.
- Google Analytics: consent-governed usage analytics for the marketing site, the scanner, and the application's onboarding flow.
- Sentry (Functional Software, Inc.): application error monitoring; receives error reports, stack traces, and pseudonymous internal account and workspace identifiers, which are random IDs, never names, email addresses, filing content, or session recordings.
- Cloudflare: website and application delivery, the status page and its email subscriptions, and offsite backup storage of filing artifacts and of the contact details (names, email addresses and phone numbers) used to reach customers with a filing due during an outage.
- Anthropic: reading a broker confirmation, grant notice, statement or description your company drops or pastes to record an insider's transaction or holdings, AI drafting, filing chat, document explanations, and support chat when OpenAI is unavailable (including images and PDFs you attach in the help chat, once they are checked for viruses), when your company uses them; the same Anthropic models may be served through Google Cloud's Vertex AI when Anthropic is unavailable.
- OpenAI: the support chat assistant (your question, a snapshot of your account's filings, deadlines and plan, and images and PDFs you attach in the help chat, once they are checked for viruses), filing chat when Anthropic is unavailable, and text embeddings for retrieval, when enabled.
- Stripe: payment processing.
- Postmark: transactional and alert email.
- Twilio: text messages: one-time codes on signing, sign-off and response pages; notices that a request was emailed, or that a company replaced their mobile number while a request for their signature was open, to people who opt in on a request's page; and deadline alerts and service status updates to people who opt in.
- Slack: internal operational alerts about the Service, which can include the recipient email address of a failed delivery.
- Cursor (Anysphere, Inc.): AI-assisted software development; may process production logs and data visible in development sessions, in the United States.
5. Legal requests and business transfers
If a government or law enforcement agency demands customer information from us, we will direct the agency to the customer and notify the customer before disclosing, unless the law prohibits it. We may share information as part of a merger, acquisition, financing, or sale of assets, subject to confidentiality protections and this policy.
6. Cookies, analytics, and error monitoring
The marketing site and scanner use Google Analytics to understand site usage. How it starts depends on where you are. In the European Economic Area, the United Kingdom, and Switzerland, analytics stays off until you accept the consent banner. Everywhere else, analytics runs by default and you can turn it off at any time by declining the consent banner. Sending a Global Privacy Control signal from your browser turns analytics off automatically in every region, and we honor that choice.
A strictly necessary tp_consent cookie remembers your analytics choice across takepublic.com and its subdomains. When analytics is on, a first-party tp_attrib cookie remembers which page, referrer, or campaign first brought you to the site, so we can tell which channels work. That cookie is sent only to our own systems, never to Google, and declining analytics removes it. Advertising storage is disabled in every region regardless of your choice.
We do not send company identifiers such as tickers to Google, and we do not use advertising or cross-site tracking cookies. We do not sell or share personal information for advertising, so browser opt-out preference signals such as Global Privacy Control are honored.
Inside the application, the onboarding flow uses the same consent-governed Google Analytics to measure signup completion, and when you arrive from the marketing site analytics connects the visit as one session across takepublic.com and app.takepublic.com. The signed-in product screens set no analytics or tracking cookies. The application stores your session in your browser's local storage, and product usage events are recorded in our own systems only.
We use Sentry (Functional Software, Inc.) for error monitoring, so we can find and fix failures. When an error occurs, Sentry receives the error details and stack trace, your browser and operating system type, the page address with query parameters removed, and pseudonymous internal identifiers: the random IDs we assign to your account and your company's workspace, so we can tell how many customers an error affects. These identifiers are never your name or email address. Sentry does not record your screen or session, receives no filing content, and processes this data in the United States.
Our websites and the application may link to third-party sites, such as the SEC's EDGAR system. Those sites have their own privacy practices, and this policy does not apply to them.
7. Security
We protect personal information with encryption in transit, encryption of stored credentials and tokens, role-based least-privilege access, multi-factor authentication for privileged roles in production, and an append-only audit log of material actions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we confirm a security incident affecting your data, we will notify affected customers without undue delay, and in any case within 72 hours of confirming the incident, with a summary of what happened and the steps we are taking.
8. Retention
We keep personal information while your account is active and as needed to provide the Service, meet legal and regulatory obligations, resolve disputes, and enforce agreements. When information is no longer needed, we delete or de-identify it, except signed records, which we keep as described below. Retention varies by category:
- Account information: kept while your account is active, and deleted on request after account closure, subject to legal holds.
- Filing records and artifacts: retained at least seven years in versioned storage with soft delete, protected from deletion by a retention policy TakePublic administers, and for the life of the customer relationship, because they document a regulatory compliance record.
- Signature, certification and Rule 302(b) attestation records, and the audit trail: kept for as long as TakePublic provides the Service and at least seven years, surviving account closure and requests to delete personal information, because they are the evidence of who signed each SEC filing and approval. Regulation S-T requires the filer to keep each authentication document five years and each attestation seven years after the signer's last electronic signature; we keep them longer.
- Credentials and connection tokens: kept while the connection is active and revoked or deleted when you disconnect or close your account. A company's stored EDGAR codes and connection tokens are also cleared 30 days after its plan ends, and a departed insider's EDGAR code 30 days after their last Section 16 obligation.
- Scanner leads and waitlists: kept until you ask us to delete them. Unsubscribing stops our emails to that address.
- Sanctions screening records: kept for as long as sanctions laws require us to be able to show how we screened, and at least ten years, including after an account closes.
- Usage and log data: kept per our operational log retention schedule, then deleted or de-identified.
9. Where information is processed
TakePublic is a US company serving US SEC-reporting companies. Personal information is processed and stored in the United States.
10. Your privacy rights
The only sensitive personal information we hold is the credentials and connection tokens described above, which are stored encrypted and used solely to provide the Service. We do not use or disclose sensitive personal information for any other purpose, and we do not use it to infer characteristics about anyone. Insider and questionnaire information provided by a customer company is processed on that company's behalf, and requests about it should go to that company; we will support the company in honoring them.
The following rights are available to all users in the United States, including residents of California (under the CCPA as amended by the CPRA), Virginia, Colorado, Connecticut, Texas, and other states with consumer privacy laws:
- know and access the personal information we hold about you;
- correct inaccurate personal information;
- delete personal information, subject to legal retention requirements and the signed-record retention in section 8;
- receive a portable copy of personal information you provided;
- opt out of the sale of personal information or its use for targeted advertising (we do neither);
- not be discriminated against for exercising these rights.
11. How to exercise your rights
Email hello@takepublic.com, or if you have an account, update your information in Settings. We will verify your request using the email associated with your account and respond within 45 days; if we need more time, we will tell you and may take up to 45 additional days. You may authorize an agent to submit a request for you; we may ask for proof of authorization and verify your identity directly.
If we decline a request, we will explain why, and you may appeal by replying to our response. We will answer the appeal within 60 days. If the appeal is denied, you may contact your state attorney general.
12. Children
The Service is for business use by adults. We do not knowingly collect personal information from anyone under 18, and we delete it if we learn we have.
13. Changes to this policy
We may update this policy. We will post changes here with a new date, and for material changes we will give prominent notice, such as email to account holders or a notice in the application, before they take effect.
14. Contact
Privacy questions and requests: hello@takepublic.com. TakePublic, Inc., a Delaware corporation.
Questions? Contact hello@takepublic.com.