Privacy
The short version, because it is the question a cautious firm actually asks: to derive anything at all, this software sends your site boundary to public data services run by the United States government, and it sends an address you type into the search box to the United States Census Bureau. Section 3 says exactly which, and exactly what goes to each one.
One recipient in section 3 is not a government service. If the optional assistant is switched on for the deployment you are using, your questions and your site's record go to a commercial language model vendor. It is switched off by default, the tool tells you which state it is in, and section 3, the assistant says exactly what is sent and what is not.
1 Who is responsible for your data
[LEGAL ENTITY NAME] of [REGISTERED ADDRESS] is responsible for the personal data described here. If you have a question about it, write to [PRIVACY CONTACT EMAIL].
[CONFIRM WHICH PRIVACY LAWS APPLY, FOR EXAMPLE A STATE LAW SUCH AS THE CALIFORNIA CONSUMER PRIVACY ACT, OR THE UK AND EU GDPR IF ANY USER IS THERE, AND ADD THE SPECIFIC DISCLOSURES EACH ONE REQUIRES.]
2 What we collect
Only what the service needs to work. There is no tracking, no advertising and no analytics on this website or in the tool.
3 What is sent to third parties
This is the part worth reading properly. CurveNumber derives its inputs from public datasets, and there is no way to do that without asking those services about your site. The first six services below are run by agencies of the United States government; the three after them are commercial and are labelled as what they are. We have no agreement with any of the public ones, we do not control them, and what they do with a request is governed by their own policies, not ours.
One further recipient is a commercial company rather than a public dataset, it receives much more than geometry, and it only exists when the optional assistant is switched on. It has its own part of this section, below the list.
Three things follow from this that are worth stating plainly:
- A site boundary sent to those services is a statement that somebody is interested in that piece of ground. If the existence of your interest in a parcel is itself confidential, that is a reason to think before deriving it here, and we would rather you knew that before you started than afterwards.
- We cache the responses those services return, keyed on the request. That is partly speed and partly manners, since several of them are unfunded public endpoints. A cached response is data about your site sitting on our server, and it is deleted with the rest of your data.
- We do not send your name, your email address, your client's name or your project name to any of those services. They receive geometry, or an address, and nothing that identifies you. The assistant, below, is the one recipient that receives your project name, and it is the reason that sentence now says "those services" rather than "anyone".
The assistant, and the model vendor behind it
The tool has an optional assistant: you type a question about one of your sites and a language model answers it, using your site's record. It is switched off by default, and on a deployment where it is off there is no model, no vendor and no request: the assistant screen is not there, the routes answer "not enabled on this deployment", and the warnings the tool raises about your site are produced by the engine with no model involved at all. If it is on, you will see the assistant in the tool, and every question you ask it sends a request to a vendor.
api.anthropic.com, which is the only vendor this software knows
how to call; which model, and in which region the account calls it, are set by whoever
runs the deployment. [NAME THE MODEL AND THE REGION IN FORCE ON THIS
DEPLOYMENT.]person-abcdef, so the assistant can say that two changes were made by the
same person without being told who that person is. That replacement runs over
everything this software puts in a request on your behalf, on every route that sends
anything — the record, the change log, an override or waiver reason you typed, and the
text of a document you attached — and not only over the parts the assistant looks up
while answering. The one thing it does not rewrite is the question itself, which is
sent as you typed it; see the row below. Also not sent: the site
address you entered in the address field, the client name you entered
in the client field, your own name and organisation, your API key, your
account id, and the drawn boundary itself — the polygon never goes to the vendor, only
the acreages and the values computed from it. There is no user identifier attached to
the request.Two honest notes about the assistant, in the same spirit as the rest of this page. The first is that an answer it gives is checked by the software before you see it — every figure has to be one the record holds, every citation has to be something retrieved in that turn — and that check is ours, it is not the vendor's, and it is not a guarantee that the answer is right. The second is that we cannot see what the vendor does with a request after it arrives, any more than we can see what the federal services do with a boundary. What we control is what leaves this server, which is what the two rows above describe.
4 What we do not do
- We do not sell your data, and we do not share it for anyone else's marketing.
- We do not run analytics, advertising or third party tracking on this website or in the tool. There are no tracking cookies, because there are no cookies.
- We do not take card details.
- We do not use your site data to train anything, and we never will. Nothing you put in this product is used to train or tune a model by us.
- No number in this product is produced by a model. Every figure comes out of the engine: published tables, published methods, and arithmetic. That is true whether or not the assistant is switched on, and it is enforced rather than intended — the assistant can read every value and explain it, and a response containing a figure the record does not hold is blocked before it reaches you. What the assistant is, and what it sends where, is in section 3.
5 Where it is stored, and for how long
Your data is stored on our own servers in [HOSTING REGION]. We keep it while your account is open, because the point of the audit trail is that it is still there when a reviewer asks about a report two years later.
When an account closes, we delete the account and its projects, sites, runs, reports and audit records from the live service after the export window in the terms, and they age out of backups within [BACKUP RETENTION PERIOD]. Server logs are kept for [LOG RETENTION PERIOD]. Billing records are kept for [PERIOD REQUIRED BY TAX AND ACCOUNTING RULES], because we are required to keep them.
Deleting a project or a site deletes what hangs off it, including its audit records. That is irreversible, and it is your decision to make.
An assistant conversation is stored against its site and goes when the site goes. You can also delete one on its own without deleting anything else, and section 6 says what that does and does not remove. A request already sent to the model vendor is out of our hands in the same way a report already sent to a reviewer is: deleting the conversation here does not reach their copy, and their retention is governed by their terms.
6 Your choices and your rights
You can see everything on your account from inside the tool, and you can export your reports and your audit trail at any time. You can ask us to correct something, to delete your account and its data, or to send you a copy of it, by writing to [PRIVACY CONTACT EMAIL]. We will respond within [RESPONSE PERIOD].
If you have used the assistant, there is a delete control on the assistant screen for each site. It removes that site's conversation and everything remembered from it: the messages, the statements the assistant kept from them, anything you told it about the site, the documents you attached, the dismissed warnings, and the log of each turn including any response that was blocked before you saw it. Three things survive it, and the tool says so rather than leaving you to assume: the operator's cost ledger, which holds a model name, a token count and a cost and no site data; the count of how much of your monthly allowance you have used, because an allowance you could reset by deleting a conversation would not be an allowance; and the site's own change log, which is the audit trail of the site rather than of the conversation, and which goes when the site goes.
Two honest limits. A report you have already sent to a client or a reviewing authority is out of our hands, and deleting your account here does not reach it. And an override record inside a report is part of the document's meaning, so we will not edit one in place; the remedy for a record you disagree with is to supersede it, which the software supports and which leaves both entries visible.
[ADD THE SPECIFIC RIGHTS AND THE COMPLAINT ROUTE REQUIRED BY WHICHEVER PRIVACY LAWS APPLY, INCLUDING THE SUPERVISORY AUTHORITY OR ATTORNEY GENERAL A USER MAY COMPLAIN TO.]
7 Security
Traffic to the service is encrypted in transit. Your API key is stored only as a hash, so a copy of our database does not yield working keys. Access to the server is limited to the people who operate it.
We will not claim more than that. This is a small pre-launch product and it has not been through an independent security audit. If you find a problem, write to [SECURITY CONTACT EMAIL] and we will take it seriously.
[ADD THE BREACH NOTIFICATION COMMITMENT REQUIRED BY THE APPLICABLE LAW.]
8 Children
This is professional engineering software. It is not for children and we do not knowingly collect data about anyone under [AGE, AS REQUIRED BY THE APPLICABLE LAW].
9 Changes, and how to reach us
If we change this notice in a way that materially affects you, we will email the address on your account before the change takes effect and keep the previous version available.
Write to [PRIVACY CONTACT EMAIL], or to [POSTAL NOTICE ADDRESS].
Blanks a lawyer or the owner has to fill in
- Legal entity name and registered address, and the privacy and security contact addresses.
- Which privacy laws apply, and the specific disclosures, rights and complaint routes each one requires, in sections 1, 6 and 7.
- Hosting provider and region, in sections 3 and 5.
- The invoicing or payment provider, in section 2.
- Retention periods for backups, server logs and billing records, and the response period for a request, in sections 5 and 6.
- The minimum age, in section 8.
- The model vendor's name, the region its API is called in, and its sub-processors, in section 3. Doc 05 section 10.4 sends the sub-processor disclosure to counsel and says it has to be settled before the first municipal or EU sale; it is not settled here. Also in section 3: confirmation that the vendor's terms in force still say what that section says they say, and whether a zero data retention agreement has been signed since this draft was written.
- A decision on self hosting the typefaces, which would remove the only third party request these public pages make, and on self hosting the mapping library, which is the other one the tool itself makes.