This Privacy Policy explains how Cividian ("Cividian," "we," "us," or "our") collects, uses, shares, and protects information when you visit our website, create an account, or use the Cividian platform (the "Service"). By using the Service, you agree to the practices described here.
Cividian operates a city intelligence platform that aggregates property, demographic, economic, and public-investment data to help real estate developers, businesses, and public officials evaluate American cities. Cividian is based in the State of Indiana, United States. The Service is intended for business and professional users located in the United States. It is not directed to, and we do not knowingly offer it to, individuals in the European Union or European Economic Area. For any privacy question, contact us at contact@cividian.com.
When you create an account, request full access, or contact us, we collect the information you submit, which may include your name, email address, phone number, company or organization, your stated role (for example developer, business, or public official), and the contents of messages you send us, including questions you ask the in-platform assistant.
If you publish a member concept, the concept text, its studio render, and the first name on your account are visible to other signed-in members, along with community activity on it (ratings, reviews, download and remix counts). That sharing happens only at your direction and is reversible at any time from where you published it. Reviews and ratings you leave on other members' concepts are shown with your first name.
Beta marketplace features collect what you enter to run them: listings you post (property address, terms, description, and an optional photo, which become visible to other users when you publish them; your email address is never shown on a listing, and buyer and seller contact is routed through the platform), saved search criteria and trade-area watches (used server-side to match new listings and send the notifications you chose, at the frequency you chose), and your onboarding answers (your selected role and tour progress, used to arrange your default view). If you create a listing API token, we store it to authenticate pushes from your systems; treat it like a password and rotate it in the app if it leaks.
If you use the in-app CRM board, we store what you enter there on your account record: the cities you are tracking and their pipeline stage, the contacts you record for each city (name, role, organization, and the contact details you choose to enter) with their outreach status and your notes on them, the parcels you flag with their acquisition status, and your ledger entries. This CRM store is your private workspace. It is not shared with other members, it is not published, and it is not used to score or enrich anything Cividian sells. Section 8 states its retention.
In cities that have enrolled to receive them, you can file a civic report: a problem you saw, such as a pothole, a dark streetlight, or a blocked storefront. A report holds the category you chose, your description, the location (coordinates and, if you add it, a street address or landmark), the time you saw the problem, and the web address of one photo if you attach one. Reports are public. Anyone can read a city's reports and their status history, and the enrolled city's staff can read and export them. What is never published is who filed a report: we collect no name, email address, or phone number with a report, and the link between a report and your account is stored only as a salted one-way hash. City staff exports carry that hash and nothing else about you. Reports are what a person said they saw; they are labelled as user content wherever they appear and they are never used to score a city. For native uploads, your device creates a resized JPEG and removes source metadata. The server strips JPEG metadata again and stores the photo in the operator-configured object store. The report holds an unguessable public photo address. Remove personal detail visible in the image before attaching it: metadata removal does not blur faces or text.
This table lists each category of personal information the Service holds today, why it is collected, where it lives, how long it is kept, and which providers receive it. It describes the features in this release; features requiring an operator-configured service share data only after that service is enabled. Where a provider is marked "if enabled", the sharing happens only when the operator has configured that provider.
| What | Why | Where it is stored | Retention | Who receives it |
|---|---|---|---|---|
| Name, email address, phone number, organization, stated role, city of interest, SMS consent and email preference | Create and operate your account; contact you as Section 4 describes | Your account record and the signup list in our data store | Until deleted on request (Section 8) | Resend (sign-in and transactional email); an operator notification webhook, if enabled, which receives a copy of the signup record |
| IP address and browser user agent at signup | Abuse prevention and attribution | The signup record | Until deleted on request | Cloudflare Turnstile, if enabled, which receives the IP address to verify the signup is not automated; the operator webhook, if enabled |
| Session token | Keep you signed in | An HttpOnly cookie on your device and a session registry in our data store | 30 days, or until you sign out or revoke it from account settings | Nobody |
| API keys you create | Let your own software or an AI agent call the Service as you | Only a one-way hash of the key, with its label, scopes and creation date | Until revoked; the raw key is shown once and never stored | Nobody |
| Saved projects, saved searches, trade-area watches, onboarding answers, view preferences, last city viewed | Run the features you use | Your account record | Until deleted on request | Nobody, except that saved project notes are sent to the assistant provider with your questions when you use the assistant |
| CRM board: the cities, contacts, parcels, contact log and ledger you enter, including other people's names and contact details | Your private pipeline workspace | Your account record | Until deleted on request | Nobody |
| Concepts, listings and reviews you choose to publish | Sharing at your direction | Community and marketplace records | Until you remove them | Other signed-in members, as Section 2 describes |
| Questions you ask the assistant, and saved notes sent with them | Answer your question | Not stored by Cividian | Not retained by Cividian; the provider's retention applies | The model provider that answers: Anthropic today, with OpenAI, Google, or xAI possible as Section 6 describes |
| Civic reports: category, description, coordinates, optional address, time observed, optional photo address, and a salted hash of your account | Route a problem to the enrolled city and show its status publicly | Report records in our data store | Until removed on request or at the end of the city's pilot; no automatic deletion schedule is implemented | The public, as the report; enrolled city staff, as the report plus the hash |
| Usage events (page and city viewed, feature used, no IP address, no user agent) | Understand which cities and features are valued | An anonymized event list and aggregate counters | Bounded list; counters kept 90 days by day | The operator webhook, if enabled |
| Page views | Visitor and device counts | Vercel Web Analytics, cookieless | Vercel's retention | Vercel |
| Unique username and salted password hash | Sign in and prevent duplicate username claims | Credential and username records in the account data store | Until account deletion; single-use verification records expire after 15 minutes | No raw password is stored or sent to analytics. Resend delivers the verification link. |
| Saved preferences and up to 40 city research selections from the last 30 days | Explain and tailor city suggestions | Private account personalization record | Selections are excluded after 30 days; turning personalization off clears recorded selections | Cividian account storage only; no advertising profile |
| Device registration token and opaque account hash | Optional civic status notifications | Account store | 90 days without renewal; removed by account erasure | Apple APNs or Google FCM when enabled; report ID and status only |
| Business name, address, verification method and public responses | Verify a business's relationship to nearby reports | Business and civic records | Claims removed and responses anonymized on account erasure | Operator for verification; public after verification or response publication |
| Erasure confirmation and encrypted work record | Confirm identity and finish deletion reliably | Account store | Section 8 describes code, receipt, failure and deletion-block retention | Resend delivers the code; Apple receives a revocation request for Apple-linked accounts |
| Operator actions: actor email, action, time, organization ID and action details such as organization name changes | Review administrative access and changes | Shared operator audit in the account store | Latest 200 events; events authored by an account are removed on account erasure | Verified configured owner through the private operator console |
These internal namespace labels make collection changes reviewable. The data collection map above explains their user-facing purposes.
| Record family | Collection and retention |
|---|---|
civic | Civic records, media references, device registrations, delivery and daily KPI records. Public report retention and account erasure are described in Section 8. |
pago:acct | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:allen | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:apikey | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:apikeys | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:authlimit | Security, confirmation, deletion workflow or operator configuration. Section 8 distinguishes short-lived codes from the opaque deletion block. |
pago:beta | Security, confirmation, deletion workflow or operator configuration. Section 8 distinguishes short-lived codes from the opaque deletion block. |
pago:city | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:citypage | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:community | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:concept | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:concepts | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:credential | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:criteria | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:dec | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:delete-code | Security, confirmation, deletion workflow or operator configuration. Section 8 distinguishes short-lived codes from the opaque deletion block. |
pago:delete-job | Security, confirmation, deletion workflow or operator configuration. Section 8 distinguishes short-lived codes from the opaque deletion block. |
pago:delete-pending | Security, confirmation, deletion workflow or operator configuration. Section 8 distinguishes short-lived codes from the opaque deletion block. |
pago:digest | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:erasure-block | Security, confirmation, deletion workflow or operator configuration. Section 8 distinguishes short-lived codes from the opaque deletion block. |
pago:events | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:gallery | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:geo | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:geocode | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:inbox | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:intelbrief | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:layer | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:listing | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:listings | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:oauth | Opaque OAuth handshake state, nonce and PKCE verifier; no account identity. Expires after ten minutes and is consumed once. |
pago:magic | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:metrics | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:news | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:obs | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:operator | Shared administrative audit, bounded to the latest 200 events. Account erasure removes that actor's events and their details, preserving other actors' events as Section 8 describes. |
pago:org | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:orginvite | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:parcels | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:personalization | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:phoneidx | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:pulse | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:reports | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:rl | Security, confirmation, deletion workflow or operator configuration. Section 8 distinguishes short-lived codes from the opaque deletion block. |
pago:sessreg | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:signups | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:st | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:suggest | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:uk | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
pago:username | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:webhook | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
pago:wizard | Public source caches, generated geographic readings, aggregate usage or scheduled job counters. Their expiry varies by cache; no password or private account workspace belongs in this family. |
user | Private account, credential or shared workspace records; retained and erased as Section 8 describes. |
When you use the Service, we and our providers automatically collect certain technical and usage data, which may include your IP address, device and browser type, pages and cities viewed, search queries entered, referring pages, and the dates and times of your visits. We use this to operate, secure, and improve the Service.
The property, parcel, demographic, and economic information displayed in the Service is sourced from third parties and public records (described in Section 7). This is information about places and properties, not personal information you provide to us.
By providing your email address and phone number and creating an account, you consent to receive communications from Cividian related to the Service, including updates, new features, relevant opportunities, and outreach.
You may opt out of marketing emails at any time by using the unsubscribe link in any such email or by emailing us. We may still send you non-marketing messages necessary to operate your account.
If you provide a mobile number, you consent to receive text messages from Cividian at that number, which may be sent using automated technology. Consent to receive marketing texts is not a condition of using the Service. Message and data rates may apply, and message frequency varies. You can opt out of texts at any time by replying STOP, and you can get help by replying HELP. We will honor opt-out requests as required by law.
Attorney review needed. If you run SMS marketing, you must follow the federal Telephone Consumer Protection Act (TCPA) and current carrier and CTIA rules, including clear consent capture at signup and honoring opt-outs. Have counsel confirm your consent language and your texting provider's compliance before sending.
We use cookies, local storage, and similar technologies to keep you signed in, remember your preferences, understand how the Service is used, and improve performance. Some are necessary for the Service to function; others support analytics. You can control cookies through your browser settings, though disabling some may affect functionality. Where required, we honor recognized opt-out signals such as the Global Privacy Control (GPC).
We do not sell your personal information for money. We share information only as described below:
Property, parcel, demographic, and economic data shown in the Service is compiled from public records and licensed third-party providers, and is subject to their terms. Sources include:
| Provider | Data |
|---|---|
| U.S. Census Bureau (American Community Survey, County Business Patterns, Building Permits Survey) | Population, income, housing, demographic, business establishment, and construction permit estimates (public domain) |
| ReportAll USA | Parcel boundaries, ownership, land use, and assessment data (licensed). Queried first for parcel records. |
| Regrid | Parcel boundaries, ownership, land use, and assessment data (licensed). Queried when ReportAll returns no coverage. |
| State of Indiana (IndianaMap) | Statewide parcel boundaries and parcel identifiers (public record). Publishes no owner or assessed value. |
| Mapbox | Maps and geocoding |
| OpenStreetMap | Geocoding fallback, and infrastructure features behind the access layer (open data) |
| Federal Communications Commission (Area API) | Resolving a coordinate to its county (public domain) |
| GDELT | Public news signals behind the city pulse read |
| Anthropic | The in-platform assistant |
| Vercel Web Analytics | Cookieless page-view and visitor counts (a hashed, daily-rotating visitor identifier; no cross-site tracking). Used only to understand how the Service is used. |
| Ordnance Survey (OS Open UPRN, OS Open USRN, OS Open Linked Identifiers) | Property and street reference numbers and their coordinates, England, Scotland and Wales (Open Government Licence). Contains OS data, Crown copyright and database right 2026. |
| Office for National Statistics (via postcodes.io) | UK postcode centroids and the census and administrative geographies a postcode falls in (Open Government Licence) |
| MHCLG Planning Data Platform (planning.data.gov.uk) | Planning designations published by English local planning authorities: conservation areas, listed building outlines, Article 4 directions, tree preservation zones, brownfield land, flood risk zones, and HM Land Registry title boundaries (Open Government Licence) |
| Historic England | The National Heritage List for England, the Heritage at Risk register, and heritage funding areas (Open Government Licence) |
| HM Land Registry | Price Paid Data and INSPIRE Index Polygons, England and Wales (Open Government Licence). Contains HM Land Registry data, Crown copyright and database right 2026, and Ordnance Survey data under licence number AC0000851063. An INSPIRE polygon carries the fixed caveat the Service renders wherever the geometry appears: Indicative extent only. Legal boundaries can only be established from the title plan. |
| MHCLG, Get energy performance of buildings data | Energy Performance Certificates for England and Wales. This dataset contains personal data. See the UK note below. |
| Food Standards Agency | Food hygiene ratings, used as a signal of active trading at an address (Open Government Licence) |
| Companies House | The public register of UK companies, used to resolve a corporate property owner to its registered office, incorporation date and filing history |
This data is provided for informational purposes and may be inaccurate, incomplete, or out of date. See our Terms of Use for the full data disclaimer and use restrictions.
Parcel records may include the name associated with a property owner of record, drawn from public records. If you are an individual and wish to request suppression or removal of owner information associated with you from the Service, contact us at contact@cividian.com and we will review the request and act as required by applicable law and our data providers' terms.
This reviewable inventory includes optional adapters and source links. Operator-configured webhooks, Redis, PostgreSQL, error monitoring and S3-compatible photo storage use deployment-specific hosts. The operator must name and review any enabled destination before activation; static checks cannot determine these hostnames.
| Service | Endpoints | Use |
|---|---|---|
| Accounts and security | accounts.google.com, oauth2.googleapis.com, www.googleapis.com, appleid.apple.com, challenges.cloudflare.com | OAuth identity, token revocation and optional signup verification. |
| Email and notifications | api.resend.com, api.push.apple.com, api.sandbox.push.apple.com, fcm.googleapis.com | Transactional email or optional notification delivery. |
| Assistant and generated media | api.anthropic.com, api.openai.com, generativelanguage.googleapis.com, api.x.ai, integrate.api.nvidia.com, api.higgsfield.ai, docs.higgsfield.ai | Only the provider selected for a request receives its prompt and supplied context. Generated images and videos remain labeled as concepts. |
| Mapping and geocoding | api.mapbox.com, nominatim.openstreetmap.org, overpass-api.de, overpass.private.coffee, www.openstreetmap.org, maps.mail.ru, services-eu1.arcgis.com, gisdata.in.gov, gis.acimap.us, app.regrid.com, reportallusa.com, geo.fcc.gov | Location queries, map features and licensed parcel records; Esri basemap images use server.arcgisonline.com in the staff portal. |
| US public signals | api.census.gov, data.census.gov, www.census.gov, www2.census.gov, api.gdeltproject.org, aca-prod.accela.com, bsd.sos.in.gov | Geographic queries and public records, without account credentials. |
| UK public sources | api.company-information.service.gov.uk, api.get-energy-performance-data.communities.gov.uk, get-energy-performance-data.communities.gov.uk, api.postcodes.io, api.ratings.food.gov.uk, historicengland.org.uk, landregistry.data.gov.uk, use-land-property-data.service.gov.uk, www.planning.data.gov.uk | Geographic and property queries described above. |
| Source references and first-party links | api.github.com, github.com, schema.org, cividian.com | Source metadata, documentation or first-party URLs. A literal reference is not evidence that personal information is sent there. |
Cividian's United Kingdom coverage is England only. Scotland, Wales and Northern Ireland use separate land registers, energy certificate registers and planning systems that the Service does not read, and it says so rather than returning an empty English result for an address in those countries.
Energy Performance Certificate records obtained from the MHCLG Get energy performance of buildings data service contain personal data relating to identifiable properties and, through them, to identifiable people. In processing that data Cividian acts as a data controller under the UK General Data Protection Regulation and the Data Protection Act 2018. Our lawful basis is legitimate interests under Article 6(1)(f): providing property and regeneration professionals with accurate building information that is already published on a public register, which we consider proportionate because the data is public, is used only to describe buildings rather than to profile individuals, and is not used for marketing. Address-level certificate data is available only to signed-in accounts and is withheld from anonymous visitors by the server, not hidden in the browser.
We do not display the home address of any company officer or person with significant control. The Service does not read the Companies House officer or persons-with-significant-control endpoints at all, and the registered office records it does read are reduced to a locality, region, postcode and country before they are stored.
Cividian derives an "absentee owner" signal only for corporate owners, from a registered office on a public register, and never for a named individual. It never states that a person is an absentee landlord, that a property is vacant, or that a VAT relief applies. Those outputs are presented as signals, confidence bands and evidence requirements, with the basis shown.
If you are in the United Kingdom you have rights of access, rectification, erasure, restriction, objection and portability in respect of personal data we hold about you, and a right to object to processing carried out on the basis of legitimate interests. Contact us at contact@cividian.com. You also have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk.
Deletion is on request. Open Account security, sign in again if requested, and request an email confirmation code. Confirming the code disables account access immediately and queues erasure after a two-minute grace period for active requests. Keep the receipt until the page confirms completion. If an external service or a concurrent write prevents completion, the receipt reports that erasure needs a retry; it does not claim success. You may also contact contact@cividian.com in Section 14.
No inactivity-based account deletion schedule is implemented. Account details, the private CRM store (including contacts, parcels you flag and ledger entries), preferences, saved workspace data and credentials remain until deletion is requested. Erasure scans account-linked records in both account stores, removes credentials and uploaded report photos, and removes the account's relational records. Shared organization records retain other members' work; an owner must transfer ownership before deletion if other members remain. Apple-linked accounts must have a revocable Apple token, which may require signing in with Apple again.
The shared operator audit keeps at most 200 recent administrative events. Account erasure removes events authored by the deleted account, including their action details, and redacts known account identifiers from remaining events. Other actors' events remain. Concurrent audit writes cause erasure to retry instead of overwriting those events.
Civic reports remain public with a deletion tombstone. The reporter link and attached photo link are removed. Known account identifiers in that account's report text are redacted. Account deletion cannot identify every piece of personal information typed into free text. To request removal of a report or additional text, contact us with its report ID. Public source records, aggregate counters, previously downloaded copies, provider logs and records retained under a legal obligation are outside automated account erasure.
Sign-in links and enrollment records expire after 15 minutes; deletion codes after 10 minutes. Completed erasure receipts expire after one day. An opaque, one-way hash remains to prevent deleted credentials from regaining access. Failed erasure jobs retain an encrypted identity anchor until erasure is completed by retry or support. Personalization uses at most 40 city selections from the last 30 days; older selections are excluded, and switching it off clears them. Device registrations become ineligible for delivery after 90 days without renewal and are pruned when used or updated. Your device keeps its offline report queue until you remove the app; account erasure does not reach device files. Hosting and third-party providers apply their own retention settings.
We use reasonable administrative, technical, and physical safeguards designed to protect your information. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to opt out of certain processing. To exercise any right, email us at contact@cividian.com. We will verify your request and respond as required by applicable law. We will not discriminate against you for exercising these rights.
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you the right to know what personal information we collect and how we use and share it, to request deletion or correction, and to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. We do not sell personal information for money. We have collected the categories of information described in Section 2 (identifiers, commercial information, and internet activity) for the purposes described in Section 3. To exercise your rights, contact us using the details in Section 14. You may use an authorized agent to submit a request on your behalf.
The Service is intended for business and professional use by adults and is not directed to children. We do not knowingly collect personal information from anyone under 18, and you must be at least 18 to use the Service. If you believe a minor has provided us information, contact us and we will delete it.
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above, and material changes may be communicated through the Service. Your continued use after an update means you accept the revised policy.
The native app lets you research city and housing fundamentals without creating an account. City searches, city-centre coordinates and basic request information reach Cividian and our hosting provider to retrieve readings and protect the service. Rate-limit records include the requesting IP address and expire with their short rate-limit window; hosting and operational logs are subject to the provider retention settings. City observations are stored as public geographic readings, without an app account.
Apple Maps supplies maps and place search. If you choose “Find my city,” the app requests location only while in use and asks Apple to resolve the city. Cividian receives the resolved city and its centre, not a background location trail. You may deny location and search by name instead. When filing a civic report, the exact pin or searched street address you select is sent to Cividian and published with the report; that report location is distinct from a city-centre research request. Apple processes its services under its own privacy policy.
Up to 12 recent places are stored on your device. Clear them in Settings → Clear recent places. City readings are fetched on demand and are not saved for offline use. Reports awaiting submission and their prepared photos are saved in a protected file on your device and retried when connected. An API credential you add is held in Keychain. Notification permission is requested after a report is confirmed; if you consent, Cividian stores your APNs token against an opaque account hash and sends only a report ID and status through Apple. This app version includes no purchases, advertising SDK, cross-app tracking or generative AI requests. The optional connected-parcel client is disabled in the App Store configuration; if enabled in a future version, its data use and permissions will be disclosed before distribution.
For native-app support or privacy requests, email contact@cividian.com. Include the app version and a description of the problem, and do not send passwords or API keys.
For privacy questions, requests, or notices, contact Cividian at contact@cividian.com.
Back to top