Version 2026-08-02
Civic Ledger privacy notice
This notice describes the data controls implemented by Civic Ledger. It is a product transparency record, not a substitute for jurisdiction-specific legal advice.
What we process
We receive your authenticated email and optional display name from ChatGPT sign-in. Civic Ledger stores your chosen locale and time zone, explicit governed roles, civic cases and contributions, confidential safety reports and review outcomes, consent records, notifications, opt-in browser push subscription credentials, evidence metadata and files you upload, privacy requests, and pseudonymised security events. For time-bounded access passes, we store a one-way code fingerprint, its validity window, participant record, status, and issuance or verification actors and times; the readable code is shown only once. Civic records are private by default. If you choose case-peer visibility, authenticated people who share a case with you can see aggregate participation counts, roles held, and only the case names you share; they cannot see your email, evidence, private notes, or unrelated case names. Signed-in watchlists store the identifiers and save times of verified spaces you choose. They are private account preferences, included in your access export, removed during erasure, and never used as authority or a trust score. Civic Ledger does not continuously track location or collect GPS, Wi-Fi, or nearby-device identifiers. Place information is limited to locations and map coordinates deliberately supplied for spaces, proposals, or evidence. Do not use access passes, records, or identity checks to rank people beyond the specific civic purpose for which they were issued. Your reflection and recommendation may be sent to OpenRouter with other post-use reviews for private, AI-assisted pattern detection. Space managers review every suggestion; AI cannot change a rule.
Why we process it
- Provide identity, access control, governance, negotiation, agreement, proof, and learning workflows.
- Preserve accountable civic records and independently review evidence.
- Protect the service from abuse and explain rejected write attempts.
- Produce aggregate learning only after privacy thresholds are satisfied and according to your aggregation choice.
- Answer access and erasure requests.
Public and private information
Space facts, adopted rules, and rule consultations are public service records. Case content, evidence files, personal exports, and participant emails are access-controlled. Rule reviewers choose anonymous or named public attribution. Stewards may hide their public display name. AI supports risk review and high-risk deliberation, but people remain responsible for conditions, endorsements, agreements, evidence decisions, mediation, and appeals. Personal, sensitive civic, non-public authority, payment, credential, and raw security data are not sold or published. Public learning uses non-identifying, thresholded aggregates.
AI-assisted deliberation
Proposal facts, published space conditions, and your messages are sent to OpenRouter and the selected model provider for contextual risk assessment, follow-up questions, and reviewable options. Draft chats remain private to their steward; completed records and synthesis are visible to case participants. Model outputs, scores, model identity, and human decisions are logged. AI cannot lower the rules-based score, approve a proposal, or replace human, legal, safeguarding, or emergency judgment. Do not enter unnecessary sensitive personal data.
Access export scope
Your portable export inventories identity, consent, settings, cases you created or joined, conditions, responses, peer decisions, signed agreements, mediation, proof decisions, outcomes, incidents, reviews, space and organisation authority, rule governance, communications, subject requests, and security events. Push endpoints and encryption keys, invitation tokens, storage object keys, and other people’s invitation addresses are withheld. Active files you uploaded remain available through authenticated evidence download paths. Record counts and a delivery checksum make the export independently checkable. The export includes access-pass lifecycle records but never the secret code fingerprint. The export includes your civic-record visibility choice and the underlying participation records.
Retention and deletion
You choose a one, two, or seven-year retention period for future evidence uploads. Expired evidence is removed automatically at or after its recorded retention deadline unless a visible legal or governance hold applies. A personal access export is kept in private object storage for seven days, and generating a new export replaces the former download. Erasure first restricts new writes, provides a seven-day cooling-off period, and requires active civic authority to be handed off. Final erasure anonymises the identity, removes notifications, browser push subscriptions, and eligible personal-data evidence, and preserves pseudonymised shared governance records where deletion would destroy the rights or audit history of others.
Security data
Write requests are rate-limited in durable windows. Security events store a pseudonymous subject identifier, normalised route, outcome, country when supplied by the network, a keyed user-agent hash, and an integrity hash. Civic Ledger does not store raw IP addresses in this application audit table.
Your controls
The privacy centre lets you review consent, change public attribution and future retention, opt out of aggregate research use, generate a private machine-readable export, start or cancel erasure, and inspect recent protected write events.