Effective August 4, 2026 · Policy 2026-08-03

Privacy, in plain language.

What we collect

If you join Civic Compute, we store your email address, signup and confirmation timestamps, subscription status, email-delivery state, and any optional community response you submit. Confirmation, unsubscribe, verification, and export links are stored as one-way token digests. Delivery payloads are encrypted while queued and removed after delivery reaches a terminal state.

We record first-party page-view and story-completion events using a short-lived browser-session identifier, plus security and rate-limit records needed to protect the service. We do not use advertising cookies, third-party tracking pixels, or email tracking pixels.

Confirmation and project email

Submitting an address creates a pending record and a confirmation email. Cloudflare processes that email for delivery. We do not enrich the address or include it in project updates until you deliberately confirm. Confirmation links expire after 24 hours, unsubscribe links remain available, and repeated requests are rate-limited. Unsubscribing immediately suppresses future outreach and enrichment.

Limited professional enrichment

After confirmation, Civic Compute may use OpenAI to research public professional information about the organization represented by an email domain and decide whether person-level enrichment would materially improve human review. For a human-readable address, we may locally derive a possible contact-name hint without sharing the complete address or raw local-part. We treat the hint as unverified and retain a contact identity only when public professional sources corroborate it.

When recommended, People Data Labs may look for a professional profile associated with a one-way hash of the submitted email. We request and retain only a name, current title, organization name and website, industry, organization size range, business geography, provider record identifier, and match confidence. We do not request or retain phone numbers, residential addresses, secondary email addresses, or the provider's raw profile response.

AI-assisted classification

Civic Compute may send the normalized professional facts above and your optional community response to OpenAI to classify potential stakeholder type, strategic contribution, geography, expressed priority, and an appropriate human follow-up lane. OpenAI may use web search for organization-domain research, and our administrative record retains supporting source links. Your complete email address is not included in an OpenAI request, and API response storage is disabled where the API supports that setting. These classifications support human review; they do not make legal or similarly significant decisions or trigger automatic outreach.

Why we use information

We use information to provide requested updates and participation opportunities, understand interest in Civic Compute, respond to privacy and support requests, secure and improve the service, and comply with law. Depending on the activity and law that applies, our basis is your consent or request, our legitimate interest in operating and understanding the project, performance of a service you requested, or a legal obligation. We do not sell or share personal information for cross-context behavioral advertising.

Processors, location, and transfers

Subscriber records, normalized professional facts, classifications, compact public-source dossiers, modeled provider costs, privacy records, and first-party analytics are stored in Cloudflare's managed infrastructure. Cloudflare, OpenAI, and People Data Labs process only the bounded inputs needed for their roles under their respective service terms. This early system does not promise a particular country of storage; information may be processed in the United States or other places where a provider operates, subject to applicable safeguards.

How long we keep it

We use documented retention rules rather than keeping everything indefinitely. Pending, unconfirmed signups are removed after seven days. After unsubscribe, future processing stops immediately and remaining local subscriber and enrichment data is removed within 30 days, while a minimized suppression digest remains. First-party analytics are kept for 30 days; rate-limit records for no more than 48 hours; and completed delivery, enrichment-job, and classification metadata for 30 days.

Privacy-request records and linked correspondence are normally kept for 24 months so we can demonstrate what was requested and done. Verification and delivery artifacts are minimized or removed after their shorter operational windows. A scoped legal hold or legal duty may require selected records to be kept longer; holds require an operator reason, review date, and explicit release.

We delete OpenAI Batch input, output, and error files after terminal reconciliation and cancel an active batch if it no longer has an eligible request. Provider-controlled job metadata may remain under the provider's own retention terms. Cloudflare Workflow history is operational, not our compliance record, and is configured for short retention after completion.

Deletion, providers, and recovery copies

A deletion removes Civic Compute's local subscriber, enrichment, classification, and linked operational data, suppresses future lookups and outreach, cancels eligible queued work, and cleans up provider files we control. We cannot change or promise deletion of a People Data Labs source record; a person may separately exercise rights with that provider.

Cloudflare's managed database recovery history may retain older database states for up to 30 days. If a recovery is ever performed, processing remains paused while Civic Compute reapplies active deletion and suppression tombstones and removes restored matches before normal processing resumes.

Your choices and rights

The community question is optional. Civic Compute offers everyone, regardless of jurisdiction, the same baseline ability to access, receive, correct, delete, restrict, object to, or opt out of processing. We do not discriminate because someone exercises a privacy right. You may use an authorized agent; proportionate verification of both the requester and agent may be required.

We verify control of the relevant address and may request stronger evidence when disclosing a specific enrichment dossier, when identity is reasonably in doubt, or when an agent acts for someone else. Routine verified requests target completion within one hour; verified exceptions target 24 hours. Statutory periods still run from receipt. If we extend, partially fulfill, or deny a request, we explain why and how to ask us to review the decision or contact an applicable regulator.

Submit a privacy request, use the unsubscribe link in any project email, or contact hello@civiccompute.build. We acknowledge requests without revealing whether an address has a matching record.

Questions

Contact hello@civiccompute.build, or write to Fauntleroy Partners, LLC, 1522 Western Ave STE 24229, Seattle, WA 98101.