Draft, not in force

This is a draft prepared for review by a lawyer. It is not legal advice and it has not been reviewed by a qualified lawyer. The description of what the software does and where it sends data is accurate and was written from the source code; the legal framing around it is what needs review.

Everything marked like [THIS] is a deliberate blank, for the entity, the jurisdiction, the retention periods and the contact address.

Privacy

Draft 2 · prepared 2026-09-08, revised 2026-09-12 for the optional assistant and 2026-09-13 for the limits of the redaction and the mapping library · not reviewed by counsel · not in force

The short version, because it is the question a cautious firm actually asks: to derive anything at all, this software sends your site boundary to public data services run by the United States government, and it sends an address you type into the search box to the United States Census Bureau. Section 3 says exactly which, and exactly what goes to each one.

One recipient in section 3 is not a government service. If the optional assistant is switched on for the deployment you are using, your questions and your site's record go to a commercial language model vendor. It is switched off by default, the tool tells you which state it is in, and section 3, the assistant says exactly what is sent and what is not.

1 Who is responsible for your data

[LEGAL ENTITY NAME] of [REGISTERED ADDRESS] is responsible for the personal data described here. If you have a question about it, write to [PRIVACY CONTACT EMAIL].

[CONFIRM WHICH PRIVACY LAWS APPLY, FOR EXAMPLE A STATE LAW SUCH AS THE CALIFORNIA CONSUMER PRIVACY ACT, OR THE UK AND EU GDPR IF ANY USER IS THERE, AND ADD THE SPECIFIC DISCLOSURES EACH ONE REQUIRES.]

2 What we collect

Only what the service needs to work. There is no tracking, no advertising and no analytics on this website or in the tool.

Your email addressrequired
It identifies your account, it is what appears as the attribution on an override you make, and it is how we reach you about billing or about your account.
Your name and organisationoptional
Stored if you give them, and used the same way. Leave them blank if you prefer.
Site boundaries and addresseswhat you draw and type
The polygon you draw, the acreage computed from it, and the site address if you enter one. This is the material that has to leave our servers, and section 3 is about where it goes.
Project and site detailswhat you type
Project name, site name, client name and jurisdiction, if you enter them. A client name is somebody else's information, so enter one only if you are entitled to.
Design parametersyour engineering inputs
Segments, areas, curve numbers, impervious fractions, design storm depth and duration, time of concentration, practice dimensions and any infiltration test result you record.
Overrides and the reasons you writethe audit trail
When you change a value, we store the prior value, the new value, the reason you wrote, your email address and the time. This record is append-only and cannot be edited afterwards, because a report's value depends on it. Write reasons on the assumption that they will be read by a reviewer.
Results and reportscomputed
Each run and the report built from it, kept so a report can be reproduced rather than recomputed.
Assistant conversationsonly if the assistant is on
If the deployment you are using has the optional assistant switched on and you ask it something, we store the conversation against that site: your questions, the answers, what the assistant recorded as said earlier, anything you told it about the site, any document you attached to it, and a log of each turn including a response that was blocked before you saw it. Section 3 is about where a question goes while it is being answered. You can delete all of it for a site at any time, and section 6 says exactly what that removes.
Billing recordsa ledger, not a card
Free sites used, credit added, and each charge with its date and the site it was for. We do not take or store card details. Payment is by invoice, handled through [INVOICING OR PAYMENT PROVIDER], who will hold whatever they need for that.
An API keystored as a hash
The key itself is shown to you once and is stored by us only as a hash, so we cannot recover it. Your browser keeps it in local storage on your own device, along with your light or dark theme choice. Neither is a cookie and neither is sent anywhere except to our own API as your credential.
Server logsordinary web logs
Our web server records the requests it receives, including IP address, time, path and status. These are for keeping the service running and for investigating abuse.

3 What is sent to third parties

This is the part worth reading properly. CurveNumber derives its inputs from public datasets, and there is no way to do that without asking those services about your site. The first six services below are run by agencies of the United States government; the three after them are commercial and are labelled as what they are. We have no agreement with any of the public ones, we do not control them, and what they do with a request is governed by their own policies, not ours.

One further recipient is a commercial company rather than a public dataset, it receives much more than geometry, and it only exists when the optional assistant is switched on. It has its own part of this section, below the list.

USDA Soil Data Access sdmdataaccess.nrcs.usda.gov
Sent: your site boundary, as coordinates, in a spatial query. Returns the soil map units under it and their hydrologic groups. Sent from our server, not from your browser.
USGS and MRLC land cover dmsdata.cr.usgs.gov, www.mrlc.gov
Sent: the bounding box of your site. Returns the annual NLCD land cover raster and the fractional impervious raster over that box. From our server.
USGS 3DEP elevation elevation.nationalmap.gov, epqs.nationalmap.gov
Sent: the bounding box of your site. Returns slope computed over it. From our server.
NOAA Atlas 14 hdsc.nws.noaa.gov
Sent: a coordinate inside your site. Returns the design rainfall depths for that point. From our server.
US Census Geocoder geocoding.geo.census.gov
Sent: the address you type into the search box. Returns candidate coordinates. This happens only when you use the address search. From our server.
USGS basemap tiles basemap.nationalmap.gov
Sent from your own browser: the map tiles you look at, which means the area you are viewing and your IP address, directly to USGS. This one does not pass through us at all, because the map draws itself.
Cloudflare's public code CDN cdnjs.cloudflare.com
Sent from your own browser, on every visit to the tool: a request for the MapLibre GL mapping library, which is what draws the map you draw your boundary on. It discloses your IP address and the fact that you loaded the tool to Cloudflare. It is not sent when you are only reading these public pages, and no site data goes with it — it is a request for a fixed, versioned copy of somebody else's open source code. It is listed for the same reason the typefaces are: this page names every third party request, or it names none of them honestly. [CONSIDER SELF HOSTING THE MAPPING LIBRARY TO REMOVE THIS.]
Google Fonts fonts.googleapis.com, fonts.gstatic.com
Sent from your own browser: a request for the typefaces these pages are set in, which discloses your IP address and page request to Google. It is listed because it is a third party request, and a page that names every other one would be dishonest to leave it out. [CONSIDER SELF HOSTING THE FONTS TO REMOVE THIS.]
Hostingour infrastructure provider
The service runs on [HOSTING PROVIDER AND REGION], who hold the data in the ordinary course of hosting it.

Three things follow from this that are worth stating plainly:

The assistant, and the model vendor behind it

The tool has an optional assistant: you type a question about one of your sites and a language model answers it, using your site's record. It is switched off by default, and on a deployment where it is off there is no model, no vendor and no request: the assistant screen is not there, the routes answer "not enabled on this deployment", and the warnings the tool raises about your site are produced by the engine with no model involved at all. If it is on, you will see the assistant in the tool, and every question you ask it sends a request to a vendor.

Anthropic, the language model vendor api.anthropic.com
Sent, each time you ask the assistant a question: your question, the earlier turns of that conversation, our own instructions to the model, and whatever the model reads from your site's record while answering — the report document with its quantities, citations and assumptions, the segment table, every override with the reason you typed, every refusal and waiver with its reason, the change log, the site name, the project name and the jurisdiction, and the text of any document you attached to the site. From our server. The code calls Anthropic's Messages API at api.anthropic.com, which is the only vendor this software knows how to call; which model, and in which region the account calls it, are set by whoever runs the deployment. [NAME THE MODEL AND THE REGION IN FORCE ON THIS DEPLOYMENT.]
Not sentand this is enforced in the code
Your email address, and any other email address anywhere in the record: each one is replaced, before the request is built, with an opaque handle of the form person-abcdef, so the assistant can say that two changes were made by the same person without being told who that person is. That replacement runs over everything this software puts in a request on your behalf, on every route that sends anything — the record, the change log, an override or waiver reason you typed, and the text of a document you attached — and not only over the parts the assistant looks up while answering. The one thing it does not rewrite is the question itself, which is sent as you typed it; see the row below. Also not sent: the site address you entered in the address field, the client name you entered in the client field, your own name and organisation, your API key, your account id, and the drawn boundary itself — the polygon never goes to the vendor, only the acreages and the values computed from it. There is no user identifier attached to the request.
Where that stopsthe honest edge of it
Those two fields are held back because they are fields: the software knows which box you typed them into, and it replaces the contents of that box with a note saying it was withheld. A postal address written in ordinary prose is not reached by that. If an address appears inside the text of a document you attach, or in a site or project name, or in a reason you wrote against an override, it is part of that text and it goes to the vendor with it. We are not going to claim otherwise: recognising addresses inside a design manual would mean guessing, and a guess that missed one would be worse than no claim at all, because it would have been advertised as a protection. Email addresses are different and are genuinely handled everywhere the software builds a request from your record, prose included, because an email address can be matched exactly. The question you type is the exception and it is sent word for word, address and all: it is the one part of the request you wrote deliberately and addressed to the assistant, and rewriting it would mean answering a question you did not ask. So: give a confidential site a neutral name, and assume that anything you type or upload in words is sent as you wrote it.
Whenonly when you ask
Only on a question you type into the assistant, and on drafting actions you start yourself: asking it to draft an override reason, a waiver reason, a report section or a change log line, and asking it to read a manual you attached. Nothing is sent in the background, nothing is sent when you compute a site or generate a report, and the proactive warnings never involve a model. If you never open the assistant, nothing about your sites is ever sent to a vendor.
Under what commitmentread this one carefully
There is no per-request setting on that API that means "do not train on this", and we do not pretend otherwise: the code carries an empty set of such headers with a test that keeps it empty, so that nobody reads a plausible-looking flag as a protection. What the commitment rests on is the vendor's commercial terms for our account, under which API inputs and outputs are not used to train their general models. That is a contract, not a technical control, and it can change. We do not have a zero data retention agreement with the vendor, so content sent to them is retained under their own policy for their own period. [CONFIRM THE TERMS IN FORCE, THE VENDOR'S SUB-PROCESSORS AND THE REGION, WITH COUNSEL, BEFORE ANY MUNICIPAL OR EU SALE.]
What you can do about itfour things
Do not use the assistant: everything else in the product works without it, and the engine, the reports and the warnings are unchanged. Delete a site's conversation at any time, which section 6 describes. Ask whoever runs your deployment to switch it off, which is one setting and takes effect on restart. And if the name of a project or a site is itself confidential, give it a neutral one, because those two are sent and we would rather you knew that in advance.

Two honest notes about the assistant, in the same spirit as the rest of this page. The first is that an answer it gives is checked by the software before you see it — every figure has to be one the record holds, every citation has to be something retrieved in that turn — and that check is ours, it is not the vendor's, and it is not a guarantee that the answer is right. The second is that we cannot see what the vendor does with a request after it arrives, any more than we can see what the federal services do with a boundary. What we control is what leaves this server, which is what the two rows above describe.

4 What we do not do

5 Where it is stored, and for how long

Your data is stored on our own servers in [HOSTING REGION]. We keep it while your account is open, because the point of the audit trail is that it is still there when a reviewer asks about a report two years later.

When an account closes, we delete the account and its projects, sites, runs, reports and audit records from the live service after the export window in the terms, and they age out of backups within [BACKUP RETENTION PERIOD]. Server logs are kept for [LOG RETENTION PERIOD]. Billing records are kept for [PERIOD REQUIRED BY TAX AND ACCOUNTING RULES], because we are required to keep them.

Deleting a project or a site deletes what hangs off it, including its audit records. That is irreversible, and it is your decision to make.

An assistant conversation is stored against its site and goes when the site goes. You can also delete one on its own without deleting anything else, and section 6 says what that does and does not remove. A request already sent to the model vendor is out of our hands in the same way a report already sent to a reviewer is: deleting the conversation here does not reach their copy, and their retention is governed by their terms.

6 Your choices and your rights

You can see everything on your account from inside the tool, and you can export your reports and your audit trail at any time. You can ask us to correct something, to delete your account and its data, or to send you a copy of it, by writing to [PRIVACY CONTACT EMAIL]. We will respond within [RESPONSE PERIOD].

If you have used the assistant, there is a delete control on the assistant screen for each site. It removes that site's conversation and everything remembered from it: the messages, the statements the assistant kept from them, anything you told it about the site, the documents you attached, the dismissed warnings, and the log of each turn including any response that was blocked before you saw it. Three things survive it, and the tool says so rather than leaving you to assume: the operator's cost ledger, which holds a model name, a token count and a cost and no site data; the count of how much of your monthly allowance you have used, because an allowance you could reset by deleting a conversation would not be an allowance; and the site's own change log, which is the audit trail of the site rather than of the conversation, and which goes when the site goes.

Two honest limits. A report you have already sent to a client or a reviewing authority is out of our hands, and deleting your account here does not reach it. And an override record inside a report is part of the document's meaning, so we will not edit one in place; the remedy for a record you disagree with is to supersede it, which the software supports and which leaves both entries visible.

[ADD THE SPECIFIC RIGHTS AND THE COMPLAINT ROUTE REQUIRED BY WHICHEVER PRIVACY LAWS APPLY, INCLUDING THE SUPERVISORY AUTHORITY OR ATTORNEY GENERAL A USER MAY COMPLAIN TO.]

7 Security

Traffic to the service is encrypted in transit. Your API key is stored only as a hash, so a copy of our database does not yield working keys. Access to the server is limited to the people who operate it.

We will not claim more than that. This is a small pre-launch product and it has not been through an independent security audit. If you find a problem, write to [SECURITY CONTACT EMAIL] and we will take it seriously.

[ADD THE BREACH NOTIFICATION COMMITMENT REQUIRED BY THE APPLICABLE LAW.]

8 Children

This is professional engineering software. It is not for children and we do not knowingly collect data about anyone under [AGE, AS REQUIRED BY THE APPLICABLE LAW].

9 Changes, and how to reach us

If we change this notice in a way that materially affects you, we will email the address on your account before the change takes effect and keep the previous version available.

Write to [PRIVACY CONTACT EMAIL], or to [POSTAL NOTICE ADDRESS].

Blanks a lawyer or the owner has to fill in

  • Legal entity name and registered address, and the privacy and security contact addresses.
  • Which privacy laws apply, and the specific disclosures, rights and complaint routes each one requires, in sections 1, 6 and 7.
  • Hosting provider and region, in sections 3 and 5.
  • The invoicing or payment provider, in section 2.
  • Retention periods for backups, server logs and billing records, and the response period for a request, in sections 5 and 6.
  • The minimum age, in section 8.
  • The model vendor's name, the region its API is called in, and its sub-processors, in section 3. Doc 05 section 10.4 sends the sub-processor disclosure to counsel and says it has to be settled before the first municipal or EU sale; it is not settled here. Also in section 3: confirmation that the vendor's terms in force still say what that section says they say, and whether a zero data retention agreement has been signed since this draft was written.
  • A decision on self hosting the typefaces, which would remove the only third party request these public pages make, and on self hosting the mapping library, which is the other one the tool itself makes.