Privacy
On a legal-research site, who is watching what is itself sensitive information. Docket Yard is built so that it cannot know — not so that it promises not to look. Data that is never collected cannot be subpoenaed, breached, sold, or misused, including by us.
Reading is anonymous
- No account is needed to read anything. There is one sign-in on this site, at
/review, and it is for the handful of people the operator has asked to check the machine's work — see below. Nothing you can read is behind it. - No cookie is set on any page of the record. Display preferences (compact rows, record ids, theme) live in your own browser and are never sent to the server. The one cookie this site can set belongs to
/review, is scoped to that path, and is therefore never sent when you read anything. - The web server's access log does not record your address, your browser, any identifier, or what you searched for. It records the page and the time, for keeping the site up. Logs are kept for days, not months.
- The site keeps hourly counts of requests by kind of page, response code, size and speed, and whether the visitor looked like a crawler — numbers only, with no address, browser, page or identifier of any sort, kept for 90 days by the hour and indefinitely by the day.
- There are no analytics scripts, no third-party fonts or assets, and no tracking of any kind. Every request the page makes goes to this site.
Following a docket
To email you, Docket Yard has to hold your address. That is the only case in which it holds anything about you, and it holds the minimum:
- What is stored: your email address, the docket you follow, whether you chose as-it-happens or daily, when you confirmed, and a record of which entries were sent to you (so nothing is sent twice). Nothing else — no name, no organisation, no profile.
- The address is stored encrypted. The record holds a keyed hash of it (to match it) and an encrypted copy (to mail it); the key is kept only on the serving machine and in the operator's own safekeeping, never in the record, its backups, or any copy. A backup or a copy of the record cannot be read back into addresses without that key. The operator can decrypt, because sending mail requires it.
- Nothing is sent until you confirm. A request to follow a docket sits unconfirmed for at most 48 hours and is then deleted; a fetch of the confirmation link by a mail scanner does not count, because confirming is a button you press.
- Emails carry no tracking — no images that report being opened, no links that identify you when clicked. They are plain text. The one link that identifies your subscription is the one that stops it.
- A webhook URL is treated as an address. If you ask for deliveries to a URL instead of an inbox, the URL is stored the same way — hashed and encrypted — and its signing secret encrypted; both are confirmed before anything is sent, and deleted when you unsubscribe.
- Unsubscribing deletes. The address, the docket, and the record of what was sent are removed, not flagged. There is no "cancelled" list.
- Nobody sees counts. How many people follow a docket is not published, and is not kept in any form beyond the subscription rows themselves.
- Emails are sent through Amazon Simple Email Service. If your mail server rejects a message or reports it as unwanted, the address is added to a stop list so it is never mailed again.
Reviewers
A few people check the machine's work — whether a citation the software found really points where it says. That is writing to the record, not reading it, so it carries a name: a reviewer chooses how they are credited, and the credit appears beside what they decided. There is no anonymous review, and there is no sign-up; the operator grants access by hand and can withdraw it.
A reviewer account is the same thing as a subscription: an email address, held as ciphertext under the operator's key, with no password. Signing in is a link in the post. What is stored is the decisions — what was reviewed, what was decided, why, and when — and nothing about what a reviewer reads: no page views, no timing beyond the decision's own timestamp, and no address joined to any of it. Their session cookie is scoped to /review, so it is not sent when they read the record, and their reading is as anonymous as yours.
People named in the record
A person who writes to the Board appears here as the Board publishes them: the name, organisation and place it prints beside the comment, and the text of the file they attached, read by machine and shown beside the comment with email addresses and telephone numbers omitted where a pattern finds them; nothing else is withheld, and the Board's own file carries everything.
What can be produced under legal process
Only what exists: the subscription rows above, and the reviewer rows, for addresses that are currently following a docket or hold a grant — and producing them in readable form would take the operator's key, since the record itself holds only ciphertext. There is no reading history, no visitor log with identities in it, and no record of past subscriptions. Emails are sent through Amazon Simple Email Service, which necessarily sees the addresses it delivers to. Docket Yard will not volunteer anything, will insist that any demand be lawful and specific, and will tell the affected person unless a court forbids it.
The operator
Docket Yard is operated by RMI Valuation, LLC, which works in this industry. The architecture above is the answer to the obvious question: the operator cannot see who reads what, because no such record exists; it could see who follows a docket only by deliberately decrypting the subscription rows with the key, and this page says so rather than pretending otherwise.