Public beta: advisory demonstration only — not a City service, official vote, scientific poll, or final legal design. Read the beta notice.

Data minimization

Privacy

Question, feedback and structured-contribution forms do not request a name, email, account, exact address or file upload. A 120-bit random tracking code is shown at receipt and is not stored. The database retains only a keyed verifier under a separate secret.

Tracking and appeal records

Code lookup accepts the bearer code through a rate-limited POST and returns only fixed safe status descriptions and an applicable reviewed service route. It does not return or echo the raw code, private wording, identity, internal IDs, restricted appeal reason, actor or reviewer note. Invalid and unknown codes receive the same response. A code holder may request another review only from eligible statuses; that reason stays restricted.

Structured contribution records

An exact-version contribution preserves its private wording, classifications, disclosure and source snapshot. Human source review and moderation may create a separate immutable public item; the private original and restricted review notes do not appear in tracking or public output. Corrections and responses create links rather than overwrites.

Moderation privacy

Report evidence, complainant details, restricted reasons, private-intake linkage and internal actor IDs stay restricted. Public actions show only the rule, action, redacted public reason, accountable label and time. Exact category, outcome and appeal counts are completely withheld whenever any nonzero cell is smaller than five. A routine restriction changes display but preserves the underlying record; restoration appends history rather than erasing it.

Identity separation

The active open-beta tier has no identity verification. Synthetic provider fixtures exist only for automated tests. Future eligibility records use separate identity/verification tables and are not linked to the advisory-choice table. The beta does not collect or retain identity-document images.

Advisory voting cookie

When you open a proposal, the server may set a random, HttpOnly beta-voter cookie. The database stores only a salted hash, the exact immutable proposal-version reference and your selected response. The cookie is used to let the same browser update rather than add a response to that version while its window is open. It does not prove identity and should not be used for profiling.

Technical data

The application does not store raw IP addresses in its database. A salted in-memory key is temporarily used for abuse-rate limiting. Hosting and network providers may process ordinary technical logs under their own terms. Participant source links are never crawled by the server.

Retention

Unpublished questions, feedback, verifier records and status/appeal history are scheduled for deletion 90 days after the latest status activity. Published civic, source/version, moderation/correction and audit history may be retained under rules that must be adopted before launch. Questions, correction or deletion requests can be sent to scottgilbertvan@gmail.com.

Do not submit sensitive data

Do not include health or personal records, payment information, passwords, exact addresses, private communications, threats, allegations about private people, or information you do not have permission to share.