Privacy Policy
What we collect, what we never keep, and why — in plain language.
Draft — effective date not yet set. This page takes effect when a date is published here.
The short version
CivicSeat is a public-records reference site. Almost everything on it is about elected officials and candidates, drawn from official government documents — not about you. From you, we collect only: an optional account (a display name, an email address, and a password), whatever you type into the corrections form, ordinary web-server logs, and anonymous-to-us visit counts via Google Analytics. If you use the address lookup, your address is used once to find your districts and is never stored or logged. We run no ads, and we do not sell or share personal information with anyone.
Data about officials is not data about you
The votes, motions, attendance figures, and campaign-finance filings published here are public records about people holding or seeking public office, parsed from official documents with a link back to every source. That is the product of the site, not personal data collected from visitors, and this policy is not about it. If you are an official and believe something is wrong, use the corrections process — a human reads every report.
Reading the site
You can read everything without an account. Visiting sets two first-party cookies: a session cookie and a security (CSRF) cookie. They are technical plumbing, not tracking — they are not used to follow you across other sites. Your light/dark theme choice is saved in your own browser and never sent to us.
In production the site loads Google Analytics to count visits and see which pages get read. Google processes this on our behalf and sets its own cookies; blocking it with your browser or an ad blocker changes nothing about how the site works. This is the only third-party analytics on the site — there is no other tracking, advertising, or fingerprinting of any kind.
Like nearly every website, our web server keeps standard access logs — IP address, page requested, time, and browser identification — used for security and keeping the site running, not for profiling. Public pages are also served through Cloudflare and cached copies on our own server; Cloudflare handles site traffic (including IP addresses) as our infrastructure provider.
The address lookup
The “who represents me” and “development near an address” lookups need your address for exactly one step: turning it into map coordinates. The address is sent to the U.S. Census Bureau’s public geocoding service for that conversion, we match the returned coordinates to districts on our own server, and then the address is discarded. It is never stored — not in a database, not in your session — and never written to a log, even when the lookup fails. This is a hard requirement enforced in the code, not a courtesy.
If you create an account
An account exists so you can follow members, topics, and decisions, and get notified when they move. We store the minimum that makes that work: a public display name, your email address, a password (stored only as a secure hash — we cannot read it), your notification preference, and the usual account timestamps. That is the complete list. Accounts are used for nothing else: no ads, no sale of data, no sharing.
Email from us is limited to what you asked for and what the account needs: address verification, password resets, and — only if you choose them — immediate alerts or a weekly digest of activity on things you follow. Every digest and alert email carries a one-click unsubscribe link that works without signing in, and the same switch lives on your account page.
You can delete your account yourself at any time from the account page. Deletion is immediate and permanent: the account row, your follows, and your saved searches are erased. Corrections you submitted while signed in are kept for the record but detached from you.
The corrections form
When you report bad data we store what you typed — the problem description, any suggested correction, and any source link — along with the page you reported from, your browser identification, and, if you chose to leave one, your email address so we can follow up. Contact information is optional; anonymous reports are welcome. To catch duplicates and abuse we store a one-way cryptographic hash of your IP address — the raw IP is never saved and cannot be recovered from the hash. Each report is also emailed to our corrections inbox for a human to read.
Who touches this data
No one buys it, and no one gets it for marketing. The services that process data to run the site: the U.S. Census Bureau geocoder (address lookup only), Google Analytics (visit counting), Cloudflare (serving and caching pages), our hosting provider (running the servers), and an email delivery provider (sending the email described above). We would disclose personal data beyond that only if the law required it.
Children
CivicSeat is a civic reference work, not a service directed at children, and we do not knowingly collect personal information from children.
Changes to this policy
If what we collect changes, this page changes first — with a new effective date at the top. We hold this page to the same standard as the record: it must describe what the site actually does, not what a template says.
Contact
Questions about privacy, your data, or this policy: [email protected]. A human reads every message.