Civic Tracker · Legal
Privacy
What Civic Tracker collects when you read, sign in or subscribe, what we do with it, and how we handle the public records we publish.
Who we are and what this covers
Civic Tracker is operated by [operator legal name to be added] ("Civic Tracker", "we", "us"). This policy covers civictracker.app, every city site under it (for example culvercity.civictracker.app), the front door at civictrackerapp.com, the email we send, and our API and command-line tools. Test copies of the site (such as staging.civictracker.app) follow the same policy; where they behave differently, this page says so.
Civic Tracker is a sunshine machine for public records. We surface what’s already been filed, connect the data, and make the record usable for humans and agents. This page explains what we collect from you when you use the site, and separately how we handle the public records we publish, which name people because the law requires those records to be public.
What we collect, at a glance
| What | When | Where it is kept |
|---|---|---|
| A count of the pages you have read (as short one-way codes, not addresses) | Only where the free-page limit is switched on | A signed cookie on your device. Not on our servers. |
| Your email address, and the name, city and reason you choose to give | When you request access or sign in | Our database (Cloudflare D1) |
| Sign-in link and session records (one-way hashes, times, your email or account) | When you ask for a link or sign in | Our database |
| Newsletter address, consent record and chosen places | Only if you subscribe and confirm | Our database |
| Correction or redaction requests you send | When you write to us | Our database or mailbox; never published |
| Ordinary request data (IP address, browser, time, page requested) | Every visit, as on any website | Cloudflare's network and short-lived server logs |
We do not ask for your phone number, street address, date of birth, payment details or government ID, and we do not collect precise location. We do not run ads, and we do not load third-party analytics, advertising, social-media or session-replay scripts. We do not use web beacons or pixels.
The free-page limit (the access meter)
Where it is switched on, anyone can read 10 pages without an account in a rolling 30-day window. After that we ask you to become a Civic Tracker (request access) or sign in. Approved members read without a limit.
How pages are counted
- Each distinct page counts once. Reading the same page again is free, and the same page with or without sharing or campaign parameters (such as
utm_source,fbclid,gclid) is one page. - Never counted: the civictracker.app home page, the civictrackerapp.com front door, the about, privacy, terms, legal, accessibility and newsletter pages, files such as images and scripts, and the data requests the app makes for itself.
- A link someone shares with you (one carrying
utm_source,utm_mediumorutm_campaign) always opens and does not use a free page. - Verified search-engine crawlers and link-preview bots see the same page any reader sees, without being counted, so search results and share cards match the page.
What is stored
The count lives only in a cookie named ct_meter on your device. It holds the day your window started and up to 10 short codes, each the first 48 bits of a one-way SHA-256 hash of a page address, plus up to 6 codes for shared links you opened. It is signed so it cannot be edited, and it is HttpOnly, Secure and SameSite=Lax. It expires after 30 days. The cookie belongs to the address you are reading (each city site keeps its own count).
We do not keep a server-side list of visitors, do not store IP addresses for the meter, and do not record your reading history. Clearing your cookies resets the count.
Telling real search crawlers from impostors
When a request claims to come from a search engine, we check it using Cloudflare's verified-bot signal, or by looking up the connecting IP address in public DNS (through Cloudflare's 1.1.1.1 resolver) and confirming it belongs to that search engine. The result is cached briefly in memory and is not stored.
Accounts and sign-in links
Civic Tracker has no passwords. You sign in with a one-time link we email you.
- Requesting access. We store your email address and, if you give them, your name, city and why you want in (up to 1,000 characters), with the date. We use these only to review your request and run your account.
- Manual approval. While Civic Tracker is new, a small number of Civic Tracker administrators read each request and approve or decline it by hand. Administrators can see your email, name, city, reason, request date and whether you confirmed your email. We email you when you are approved.
- Sign-in links. Each link carries a random 32-byte token. We store only a one-way SHA-256 hash of it, with your email and the time. A link works once and expires after 20 minutes. We send at most 4 links per address per hour. Opening a link shows a button; you are signed in only when you press it, so email security scanners that open links cannot sign you in.
- Sessions. Signing in creates a session that lasts 30 days. We store a hash of the session token, your account, and when it was created, expires and was last used. Signing out deletes the session.
- The sign-in cookie is named
ct_sessionon civictracker.app andct_stg_sessionon our staging site. It is set for the main site and all city sites (Domain=.civictracker.app, or.staging.civictracker.appon staging) so one sign-in works everywhere, and it isHttpOnly,SecureandSameSite=Lax. The two names are different so a production sign-in and a staging sign-in never mix. - Account status. We keep whether your account is pending, approved, declined or suspended, your role (member or administrator), when you were approved and by whom, and when you last signed in.
To protect against abuse, sign-in forms are rate-limited. The limiter keys on a one-way hash of your IP address, held briefly in the memory of a single server and never written to our database.
Email we send
- Sign-in and account email (sign-in links, confirmation, approval notices) comes from
mail.civictrackerapp.com. It is sent because you asked for it and cannot be switched off while you have an account, but we send nothing else from this address. - Newsletter email comes only from
news.civictrackerapp.com, only after you confirm, and every issue has an unsubscribe link (see the next section). - Our email has no open pixels or beacons and no click-redirect links: every link goes straight to the page it names. The one image, the Civic Tracker logo, loads from our site at the same address for everyone, so it cannot tell us who opened a message. Your mail app requesting it is an ordinary web request (see Service providers).
- Email is delivered through Cloudflare Email Sending. We keep a per-day count of messages sent (not who they went to) to stay under a fixed daily cap.
- On our staging (test) site only, if email delivery fails, a sign-in link may be written to our private server logs so we can debug delivery. This never happens on civictracker.app.
Newsletter: double opt-in and unsubscribe
When the newsletter is available, signing up works like this:
- You enter your email and, optionally, the places you care about.
- We send one confirmation email. Nothing else is sent until you click it (double opt-in). Unconfirmed sign-ups expire.
- We store your address, status (pending, confirmed or unsubscribed), the places you chose, your language if you chose one, and a consent record: when you agreed, on which form, and which version of the wording you saw. Confirmation and unsubscribe links use random tokens stored only as one-way hashes.
- Every issue carries a one-click unsubscribe link. Unsubscribing takes effect right away.
When you unsubscribe, or an address bounces or reports spam, we add it to a suppression list so we never mail it again on any stream, and we keep the unsubscribed record as proof of your choice. We do not share, rent or sell the list, and campaigns built on Civic Tracker never send email from our servers.
Cookies and browser storage
Civic Tracker uses only first-party cookies, all strictly needed for the feature named. There are no third-party cookies, advertising cookies or analytics cookies.
| Name | Purpose | Lasts |
|---|---|---|
ct_meter | Counts your free pages (signed; page codes only). Only where the limit is on. | 30 days |
ct_session | Keeps you signed in on civictracker.app and its city sites. | 30 days, or until you sign out |
ct_stg_session | The same, on our staging (test) site only. | 30 days, or until you sign out |
ct_preview_jurisdiction | Remembers which place you are previewing, on test and preview addresses only. | 1 day |
The site also remembers which navigation menus you opened, in your browser's local storage under civic-tracker.nav.v3. It never leaves your device. Our pages use your device's own fonts; we load no fonts, scripts or styles from other companies.
Because we do not sell or share personal information or use cross-site advertising, there is nothing to opt out of; we honor Global Privacy Control signals anyway.
How we use information
- To show you pages, run the free-page limit, and keep you signed in.
- To review access requests and send sign-in, approval and (if you subscribe) newsletter email.
- To keep the service secure: rate limits, abuse prevention, telling real crawlers from fakes, and fixing errors.
- To review and act on correction and redaction requests.
- To meet legal obligations and enforce our terms.
We do not use your information for advertising, we do not build profiles of readers, and we do not make automated decisions with legal or similarly significant effects about you. Access requests are decided by people.
No selling, no sharing, no ads
No ads. No third-party cookies or analytics scripts. We do not sell personal information and we do not "share" it for cross-context behavioral advertising, as those terms are defined in the California Consumer Privacy Act. We do not give or rent our member or newsletter lists to anyone, and we do not disclose personal information to third parties for their direct marketing (California Civil Code §1798.83).
We disclose personal information only to the service providers below, when the law requires it (for example a valid subpoena or court order), or to protect people's safety or the security of the service. If Civic Tracker were ever reorganized or transferred, this policy would continue to apply to the information collected under it.
Service providers (Cloudflare)
Civic Tracker runs on Cloudflare, which processes data on our behalf under its customer terms and data processing addendum:
- Cloudflare Workers serve every page and API response.
- Cloudflare D1 is our database: accounts, sessions, sign-in link records, newsletter records and the public-record data.
- Cloudflare R2 stores source documents: original filings privately, and reviewed public copies.
- Cloudflare Email Sending delivers our email.
- Cloudflare's network, security and bot management see each request's IP address, browser details and the page asked for, to deliver the site and block attacks, and give us a verified-bot signal for search crawlers.
- Workers Logs keep short-lived request and error logs (time, address requested, status, and error details) for operating the service. Cloudflare sets how long they are kept; we do not copy them elsewhere or use them to identify readers.
Cloudflare's own privacy policy is published on cloudflare.com. Links on our pages to government systems and other sources take you to those sites, which have their own policies.
Public records we publish
Most of Civic Tracker is public records: campaign finance statements, filings, agendas, contracts, votes and similar documents produced by or filed with governments. Those records name people because the law makes them public.
Campaign finance records
California's Political Reform Act (Government Code §81000 and following) requires campaign committees to report each contributor who gives $100 or more in a reporting period, with their name, address, occupation and employer, along with payments, loans and debts. Those statements are public records open to anyone (Government Code §81008), and local filing officers publish them, often through e-filing systems such as NetFile. Civic Tracker republishes what was filed, linked to the source filing, so the public can follow the money. Names appear as filed, including spelling variations; where we group variants we say so.
What we hide even when the record shows it
Some details are never needed to understand a record. These are always removed from our public pages:
- Minors (any record about a person flagged as under 18). Children are not public figures; no civic purpose outweighs the harm.
- Victims and people not charged (public safety and court records). Being in a police log is not wrongdoing.
- SSNs, driver's license, bank and card numbers (any text). Never needed to understand a record; filers sometimes include them by mistake.
- Signatures (document images). Identity-theft risk; the signed fact is shown without the image.
By default we also limit:
- Home addresses of private individuals: city and ZIP only on our pages (donors, Form 700 filers' residences, property owners who are private people). California campaign filings make contributor addresses public as filed, and that stays true in the source. On our pages a private donor's street line adds little and invites doorstep harassment, so the default shows city and ZIP. Candidates, officials, committees and businesses are shown as filed.
- Private phone numbers and personal email: hidden on our pages (private individuals in any record). Not needed to follow the money; officials' published office contacts are not affected.
Candidates, elected officials, committees and businesses are shown as filed.
Originals stay private, public copies are redacted
We keep each source document exactly as we received it, in private storage that the public cannot reach, so we can always prove what the record said (we call this the Glassbox). Redaction happens only on the public copy, and every redaction we apply is logged. The original government record is unchanged at its source; our redactions affect only Civic Tracker's pages.
Asking for a correction or redaction
If something on Civic Tracker is wrong, or you believe a detail about you should be hidden under the rules above, write to us at [contact email to be added] with the page address, what is wrong, and (for corrections) the record that shows the right information. We review every request. Requests are private and never published; when we correct a page we may add a short public note saying what changed. We cannot remove information that the law requires to be public, but we will apply our redaction rules to it, and we will correct anything we got wrong. If the error is in the original filing, the filer can amend it with the filing officer, and we will pick up the amendment.
How long we keep information
- Meter cookie: on your device only, up to 30 days.
- Account and access request: while your account exists. Ask us and we will delete it (see Your rights).
- Sign-in link records: usable for 20 minutes and only once. Used and expired records stay in the database, unusable, until we clear them; they hold only a hash, your email and times.
- Sessions: 30 days, or until you sign out. Expired sessions cannot be used and are cleared in the same way.
- Newsletter: while you are subscribed. After you unsubscribe we keep your address on the suppression list and the record of your choice, so we never mail you again.
- Correction requests: as long as needed to handle them and keep a record of what we changed and why.
- Server logs: short-lived, as set by Cloudflare.
- Public records: kept as an archive, because the public record is cumulative; amendments and corrections are added rather than silently overwriting history.
Your privacy rights (including California)
Wherever you live, you can ask us to:
- Know and access the personal information we hold about you, and get a copy.
- Delete your account, access request, sessions and newsletter record.
- Correct information about you that is wrong.
- Opt out of the sale or sharing of personal information. We do neither, so this is already the case for everyone.
- Limit the use of sensitive personal information. We do not collect it from readers.
California residents have these rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). In the last 12 months we collected the categories in What we collect: identifiers (email address; name and city if given), internet activity limited to the pages-read count and ordinary request logs, and the content of messages you send us. We collected them from you and your browser, for the purposes in How we use information, and disclosed them only to the service providers in Service providers. We did not sell or share any.
To make a request, email [contact email to be added] from the address on your account (or the address you subscribed with). We verify requests by confirming you control that address, and we respond within 45 days. You may use an authorized agent; we may ask the agent for proof of authority and ask you to confirm. We will not treat you differently for using any of these rights.
Deleting your personal information does not remove public records that name you; for those, see Public records we publish.
Children
Civic Tracker is for a general audience and is not directed to children under 13. We do not knowingly collect personal information from children under 13, and we do not sell or share anyone's information, including teenagers'. If you believe a child has given us personal information, write to [contact email to be added] and we will delete it. Records about people flagged as under 18 are removed from our public pages (see Public records we publish).
Security
- Every page is served over HTTPS. Sign-in and session cookies are
HttpOnly,SecureandSameSite=Lax. - We store sign-in, session, confirmation and unsubscribe tokens only as one-way hashes, so a database copy could not be used to sign in.
- Forms accept submissions only from our own pages; administrator actions also require a per-session security token.
- Sign-in requests and verification attempts are rate-limited.
- Source originals are kept in private storage; only reviewed, redacted copies are public.
No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you as the law requires. To report a security problem, write to [contact email to be added].
International visitors
Civic Tracker is run from the United States and focuses on United States local governments. Cloudflare's network has data centers around the world, so requests may be handled outside your country. By using the site from outside the United States you understand that your information will be processed in the United States and wherever Cloudflare operates, under this policy.
Changes to this policy
When the code changes what we collect, this page changes with it: the policy is built from the same settings the site runs on. We post every change here with a new effective date. If a change is material (for example a new kind of data or a new provider), we will say so at the top of this page and, if you have an account, email you before it takes effect.
Contact
Questions, requests and complaints about privacy: [contact email to be added].
Postal mail: [operator legal name to be added], [mailing address to be added].