We collect as little as we can.
Last updated October 11, 2026. This page explains what CivicGrid collects when you browse the site, sign in, or call the API, and what we do with it.
Who we are
CivicGrid (civicgrid.org) is an independent project operated by Mayowa Babatola ("Kwami") in Maryland, United States. Questions about this policy or your data go to hello@civicgrid.org.
What we collect
- Account details. When you sign in we receive your email address. If you sign in with Google or GitHub, that provider also shares your name and profile picture with us.
- API keys and usage. For each key we store a one way hash of the key (never the key itself), its first few characters so you can recognize it, its label and tier, when it was created, when it was last used, and how many requests it has made. We use this to enforce rate limits and to spot problems such as a stuck script.
- Server logs. Like most web services, our servers briefly log requests (the address requested, the time, and the response code) to keep the service running and secure. Our network provider, Cloudflare, sees your IP address when you connect.
- Email you send us. If you email us, for example to report a correction, we keep the message so we can reply and act on it.
We do not run advertising, we do not use third party analytics or tracking scripts, and we do not sell or rent personal information to anyone.
Cookies
The site uses cookies only to keep you signed in. Cloudflare may set a short lived security cookie to tell people from bots. There are no advertising or tracking cookies.
How we use it
- To sign you in, issue and check API keys, and apply your tier's limits.
- To send account emails, such as sign-in links.
- To contact you about your account or API usage, for example if a script is overloading the service or a change affects you.
- To keep the service secure and fix problems.
We will not add you to a marketing list without asking first.
Who processes it for us
We use a small number of providers to run CivicGrid. Each handles data only to provide its service:
- Supabase: database and sign-in.
- Vercel: hosting for this website.
- DigitalOcean: hosting for the API.
- Cloudflare: domain, network security, and incoming email.
- Resend: sending account emails.
- Google and GitHub: only if you choose to sign in with them.
We may also disclose information if the law requires it.
How long we keep it
Account and key records are kept while your account exists. Server logs are kept for a short period for operations and security. Backups of the database are kept in private storage for up to 60 days, so deleted data can remain in a backup until it ages out.
Your choices
You can revoke your API keys at any time from your dashboard. To get a copy of your data, correct it, or delete your account, email hello@civicgrid.org from the address on your account. We will respond within 30 days.
Information about public officials
CivicGrid publishes the names and titles of elected and appointed city officials, taken from official public sources. This is public record information about people in public roles, not information about our users. If you are an official and a record about you is wrong, please report a correction.
Children
CivicGrid is not directed at children under 13, and we do not knowingly collect their information.
Changes to this policy
If we change this policy we will update the date at the top of this page. For significant changes we will also email account holders.