Last updated: 10 August 2026 · Status: Phase 0 draft for staging
Who we are
CivicVoice is a moderated, jurisdiction-aware platform for reporting local public issues with evidence, following progress, and (where coverage exists) routing cases to verified officials. Access requires authentication; this is not an open public complaint board.
Data we collect
Depending on how you use the service, we may process:
- Account details — username, display name, email, optional mobile number, password (stored hashed), language preference, and home country / administrative location.
- Verification & security — email and mobile one-time codes (hashed at rest, short TTL), session and device records, login lockout and CAPTCHA risk signals, and related audit events.
- Issue content — titles, descriptions, categories, severity, location lineage, media you upload, identity-visibility choice (default: anonymous to other users), follow relationships, and comments you post.
- Moderation & operations — raw vs moderated text versions, abuse reports, merge/follow history, official portal actions, and social-draft publish metadata when admins post to configured networks.
- Technical telemetry — application logs and optional error monitoring (for example Sentry when configured), with hot-path destination redaction and PII scrubbing that continues to expand.
How we use data
- Create and secure your account; send verification and notification messages.
- Display moderated issues to authenticated users; hide reporter identity from others when you choose anonymous (the platform still retains identity for trust and safety).
- Route approved issues to verified officials where jurisdiction coverage exists; otherwise hold cases in uncovered-jurisdiction workflows.
- Detect abuse, enforce rate limits, investigate reports, and maintain audit trails.
- Improve reliability and security of the service.
Retention
Retention periods below are operational drafts aligned with current product practice and deployment docs. Final schedules require counsel and ops sign-off.
- Account & profile — retained while the account is active; soft-delete / deactivation patterns apply where modeled.
- OTP & ephemeral auth — short-lived (OTP TTL on the order of minutes); expired OTP and session material is purged by scheduled maintenance commands.
- Issues, media, and timelines — retained for the life of the case and community follow history unless removed under moderation, legal hold, or a documented deletion process.
- Audit & abuse records — retained for integrity and safety (draft target ≥ 1 year for core audit); legal holds may extend retention.
- Backups — encrypted dump / PITR procedures are documented for operators; restore windows follow the ops runbook, not this page alone.
Your rights and choices
- Update display name, language, mobile, and home location from your profile; revoke sessions from account session management.
- Choose reporter visibility per issue (anonymous by default to other users).
- Report content that violates safety or privacy norms via the in-product abuse form.
- Request access, correction, or deletion of personal data by contacting us (see below). Response timelines and exceptions (for example legal hold, active investigations, or mandatory audit retention) will be finalized with counsel for the jurisdiction of launch.
Sharing
We do not sell personal data. We share information only as needed to operate the product: with verified officials assigned to a jurisdiction, with moderators and admins performing trust & safety work, with email/SMS/CAPTCHA/error-monitoring providers you configure for a deployment, and when required by law. Social network posts happen only through an explicit admin Post action on a reviewed draft — never as a silent auto-post on approve alone.
Open data & geography attribution
CivicVoice uses open administrative boundary datasets to power country hierarchies and location pickers. Primary layers include geoBoundaries (gbOpen ADM levels). Licenses are typically CC BY 4.0 and/or ODbL depending on the release — operators must retain version, download date, and attribution per docs/14-geography-ingestion.md. Supplemental sources (for example national open-data directories or census place layers) carry their own license notes in fixture metadata.
Contact
Privacy questions for this draft deployment: privacy@civicvoice.example (placeholder address — replace before public launch). Related policies: Terms of Service and Acceptable Use & Moderation.