Skip to main content

Privacy

What we collect, what we never collect.

A civic-trust product cannot survive surveillance practices. This is what we do and what we will not do.

What we store

  • Place cookie (btpftp-place): your ZIP and the derived state, congressional district, city, county, and council district. First-party, lax SameSite, set when you click Set your place. You can clear it any time from the place picker.
  • Watchlist (browser first): the records you mark to watch are stored in your browser's localStorage under btpftp-watchlist. They stay on your device unless you subscribe to the email digest, which saves a copy of your ZIP and causes server-side so the digest can be personalized (see below).
  • Correction submissions: if you submit a correction with an optional email, we store the email server-side only to notify you when the fix lands. Never sold, never shared.
  • Email subscriptions (opt-in): if you subscribe to the digest, we store your email, your chosen cadence (daily or weekly), a snapshot of your ZIP and causes so the digest can be personalized, and the name of the surface you arrived from (for example “receipt” or “digest”). Stored in a managed Redis store, used only to send the digest you asked for. Double opt-in: nothing is sent until you click the confirmation link. One-click unsubscribe in every email deletes all of it. Never sold, never shared.

What we do not store

  • No third-party advertising trackers.
  • No fingerprinting libraries.
  • No social-media login pixels.
  • No session recording, no heatmaps, no mouse tracking.

Analytics

Two things count traffic here. Both are aggregate-only: neither assigns you an identifier, sets an analytics cookie, or records the path you personally took through the site.

  • Vercel Web Analytics: page-view counts, served first-party from this domain (/_vercel/insights) by our host. Cookieless, no persistent visitor id, no cross-site tracking, no data sold or shared for advertising.
  • Referral counter (ours): when you arrive on a link tagged ?ref=receipt, ?ref=digest, ?ref=embed and the like, we add one to a daily tally for that surface, for example “receipt: 24 visits on 2026-07-25.” We store the tag and the date. We do not store your IP, your user agent, a visitor id, or which page you landed on. If you later subscribe in the same browser session, we save that same surface name on your subscription so we can tell which surfaces bring people in; it is a surface name, never anything about you.

Plausible remains supported as an alternative and stays dormant unless NEXT_PUBLIC_PLAUSIBLE_DOMAIN is set.

Data residency

The site is hosted on Vercel. Server-side requests run in the closest Vercel edge region to your browser. Source records and indexed metadata are public; user-specific state lives only in your browser plus the optional correction-submission server queue.

Requests, deletion, contact

Email privacy@bythepeopleforthepeople.com with any request to delete a correction submission you sent, or to ask what we know about you. Default position: we know your ZIP if you set it (visible to you in your own browser), an optional email if you gave one on a correction submission, and your email plus your cadence (daily or weekly) and a ZIP/causes snapshot if you subscribed to the digest. Unsubscribe from any digest email to erase the subscription record entirely.

Last updated 2026-06-02. Material changes will be logged in the corrections log.

Privacy | By The People, For The People