Privacy Policy
Effective date: August 21, 2026
1. Who we are
This site is operated by Earlville Media LLC, New York, USA. Contact: hello@iepfieldmanual.com, 200 West Main Street, Earlville, NY 13332.
2. What we collect
- When you subscribe: your email address and the service-use address you enter. We use that address to determine the correct sales-tax jurisdiction. For New York addresses, the full address you enter is sent to a geocoding service operated by the U.S. Census Bureau to resolve the exact local tax jurisdiction; for addresses outside New York, we determine the jurisdiction from the state you enter (we record the state and ZIP code as the basis for that determination) and the full street address is not sent to the geocoder. The Census Bureau handles what it receives under its own privacy policy (census.gov/privacy); its web logs may be retained by the government, so do not assume the geocoder discards what it processes. We retain the address you provided, the jurisdiction it resolved to, and a record of your consent to the itemized total (including the date, time, and the IP address the consent came from) as the record behind each charge. We are the seller of record, so we hold billing records directly and use them to operate your membership and honor refunds. When you begin a card payment, we also pass the address you entered to our payment processor as the suggested billing address for your card; you can review and edit it in the payment window before you pay. Card payments are handled by our payment processor, Elavon, in its own secure hosted window: we never receive or store your full card number or card security code.
- When you request the free chapter: your email address.
- When you are a member: your email address (which is your sign-in), your plan and billing status, and your billing history (amounts, dates, and transaction references). Card payments are handled by Elavon in its hosted window; for renewals we store only a token reference to your card issued by the processor, plus the card brand and last four digits so you can recognize it, never the card number. We also keep a ledger of the editable letters you download (which letter, when), because each download is watermarked to your account. If you bookmark a tool or letter, we store only your account email, the published content reference, product, title, link, and save time. If you open a member page, your private reading history stores only your account email, product, published content reference, first and last open times, and an open count. You can clear that history inside the app. Product-level timestamps let the dashboard show what changed since your last visit. The annual value report calculates product-level counts from these records and the update log; it creates no child-data record. If you choose to add a display name to your account (used only to greet you inside the app), we store that name until you change or clear it; it is optional and you can leave it blank. The state you pin, the current task you choose during onboarding, and your one-page reading position remain in cookies on your device, not in your account record.
- When you search inside the member app: we do not write your search terms to your account or our application database, and we do not create search-history profiles. Search terms are processed only to return results. When a search returns no result, the app maps it in memory to a source-controlled generic task category, such as “meeting” or “evaluation,” and increments an anonymous daily category count. That count has no query text, account, IP address, state, browser identifier, or child information. Do not enter a child's name, school, diagnosis, or records; general terms find the same tools.
- When you opt in to member reminders: we store your account email, a source-controlled generic task category, whether you requested a deadline check-in or published-update reminder, your cadence, and delivery timestamps. We do not ask for or store an individualized deadline, state, free-text note, or child fact. Deadline check-ins tell you to review dates in your own records; they do not calculate legal deadlines. You can turn off one category or all optional reminders inside the app.
- When you visit: standard server logs (IP address, page requested, timestamp) retained for 30 days. Our product analytics reject HEAD requests, verified bots, common crawler and monitoring agents, prefetches, and low-confidence bot traffic. For eligible requests, the application creates a daily one-way HMAC token from limited request signals solely to suppress repeated counts for the same approved event and page. The token rotates each day and expires within 48 hours. We keep only daily aggregate counts for allowlisted actions, such as opening a task path, opening or printing a free tool, or completing first-session onboarding. The aggregate table contains a date, event name, approved page or task key, and count. It contains no event-level rows, raw IP address, user agent, email, account, cookie, persistent visitor identifier, search text, field value, state-task combination, or child information. Browser session-storage flags also prevent obvious duplicate client submissions without sending the flags to us. To limit abuse, we keep short-lived rate counters. The application hashes the IP address before it writes a route class, hash, request count, and one-minute window to the limiter table. For signed-in members, we keep a per-account hourly count of pages opened, tied to the account email as a bare number, never which pages. The automatic daily sweep normally removes both kinds of counters.
- When you use a free planning tool: the meeting plan, evaluation request builder, and removal-day tracker run in your browser. We do not receive, store, or analyze what you type. The tools do not use local storage or save your entries. Closing or refreshing the page clears them unless your browser preserves an unfinished form. If you print, copy, or save a PDF, that copy stays where you put it.
- When you report a correction: we store the public page path, issue category, public source URL if you provide one, your note, a one-way hash of a random receipt code, the report status, and review or publication information. We do not ask for an email address and do not attach an IP address or browser details to the report. Do not include a child’s name, school, diagnosis, records, or case facts.
- When you use a protected form: we use Cloudflare Turnstile to protect sign-in and email forms from automated abuse. Turnstile processes security signals such as IP address, browser and device characteristics, site key and origin, and a short-lived verification token. Our server may send the token and IP address to Cloudflare for verification. Cloudflare handles those signals under its Turnstile Privacy Addendum.
- When your browser reports a security-policy violation: the application reduces the report to a directive name, a broad blocked-resource class, a date, and a count. It does not store the full document URL, source URL, line number, code sample, IP address, user agent, or report body in the application database.
What we deliberately do not collect: we never receive or store your full card number or card security code (our payment processor handles card entry), and we do not ask for, and ask you not to send, direct identifiers about your child: no names, ages, diagnoses, evaluations, or school records. We do not intentionally retain child identifiers; be aware that your own choices, such as which letters you download, which tools you save, or what you write in a support email, can reveal that a child-related topic concerns you, and those records are protected like all member data. If you include child information in an email to us, we will not retain it beyond answering your message except where a record must be kept for billing or legal reasons.
3. How we use information
To deliver your purchase, provide the free chapter, send edition updates you are entitled to, answer support requests, process refunds, and, only if you opt in, send occasional emails about the Manual. Every marketing email includes a working unsubscribe link, honored promptly.
For members, we additionally use your information to operate the membership itself: to email you one-time sign-in links (we use no passwords), to charge your card each billing period exactly as you consented at sign-up, to watermark your letter downloads and enforce the weekly download allotment, and to send the transactional notices the law requires for an auto-renewing subscription: your sign-up confirmation, renewal reminders before each charge, receipts, and failed-payment notices. These transactional emails form part of the service and remain separate from marketing preferences while your membership is active. We send generic task reminders only after you opt in, and the app gives you a direct settings link in each reminder.
4. Sharing
We share data only with the service providers needed to run this product: Elavon, our payment processor (to charge your card, under its own privacy policy); Resend, our email service (to deliver sign-in links, receipts, notices, updates, and the free chapter, under its own privacy policy); Cloudflare, which hosts this site and provides the Turnstile bot check described above; and the U.S. Census Bureau geocoding service (to resolve the sales-tax jurisdiction for New York service-use addresses, as described above). We calculate and remit sales tax ourselves from published rate tables; we do not use a third-party tax vendor. We do not sell or rent personal information, and we do not use advertising or social-media tracking pixels.
This product uses the Census Bureau Data API but is not endorsed or certified by the Census Bureau.
5. Cookies and analytics
This site does not use advertising cookies or cross-site tracking, and analytics remain aggregate and cookieless. On the public site, session-storage flags, not cookies, remember whether you dismissed the free-chapter dialog and whether the current browser session already counted a qualified homepage or free-tool opening. Those flags never leave your device. The short-lived server deduplication token cannot follow a visitor across days and does not enter a visitor profile.
The member app sets four first-party cookies, all functional, none used for tracking: a signed session cookie that keeps you signed in (HttpOnly, so scripts cannot read it), a your-state cookie that remembers which state's page you pinned, a current-task cookie that remembers the task path you selected during onboarding, and a resume-reading cookie that remembers the last page you were reading. The your-state, current-task, and resume-reading cookies live only on your device and are never stored in your account record; only the session cookie corresponds to a record on our servers.
6. Retention
Billing records are kept as long as needed to honor refunds and legal obligations. Free-chapter emails are kept until you unsubscribe. Server logs are retained for 30 days and then deleted. Per-IP rate counters are normally removed by the next daily sweep. Anonymous analytics deduplication tokens expire within 48 hours and the daily sweep removes expired rows. Aggregate event and security-report counts contain no visitor identity.
Membership billing records (plans, charges, consents, and the download ledger) are kept while your membership is active and afterward as long as tax, accounting, and dispute obligations require. The consent record behind each charge (the exact accepted text, timestamp, account email, amount, tax, interval, and the IP address the consent came from) is kept separately from ordinary logs for the life of your membership plus six years, matching the period during which a billing or contract dispute may arise. Copies of legally required transactional emails follow the billing-record retention rule. Delivered or terminal member-requested task-reminder messages leave the delivery queue after one year. Reading history keeps no more than 200 published content references and automatically removes entries older than 365 days; you can clear it sooner. Bookmarks remain until you remove them or delete your account. Turning off optional reminders deletes the related preference rows. Anonymous daily content-gap category counts remain for up to two years. One-time sign-in links are stored only as expiring one-way hashes and become useless within minutes of issue. If you ask us to delete your account (Section 7), we delete or de-identify everything not legally required to be kept.
7. Your rights
Email hello@iepfieldmanual.com to access, correct, or delete your personal information, or to opt out of marketing. We honor access, correction, and deletion requests for all users regardless of where you live, subject to records we are legally required to keep (such as billing and tax records); where a legal exception applies, we will tell you.
8. Adults only
The site and member app are intended only for adults age 18 or older. We do not knowingly permit accounts for minors. Parents and caregivers may use the materials for their children, but children should not use the account.
9. Security
The site is served over HTTPS; card entry is handled entirely by our payment processor in its own hosted fields; access to order data is limited to those who need it to run the product.
10. Changes
If this policy changes, the new version will be posted here with a new effective date. Material changes affecting existing purchasers will be announced by email.