Privacy

Privacy notice.

Civic Data is built to need as little personal data as possible. This notice explains what is processed when you use the website, REST API, CLI or MCP server.

What we process

  • Request logs. The gateway records a request identifier, the route or tool name, the postcode or parameters requested, response status, duration, cache state and, for paid calls, a payment reference. Logs exist to operate, secure and debug the service and are retained for a limited period by the hosting provider before expiry.
  • Rate limiting. The anonymous free tier counts requests per client network address in a fixed window. The counter holds only the window start and count and expires with the window.
  • Edge caching. Deterministic responses are cached by canonical postcode and parameters so repeated lookups are fast. Cache keys do not contain client identifiers.
  • Payments. Paid calls use the x402 protocol with USDC on Base. Civic Data receives the signed payment authorisation needed to settle that single call and records the settlement reference. Blockchain transactions are public by design; Civic Data does not link wallet addresses to any other data.
  • Email. If you contact us, we keep the correspondence for as long as needed to resolve it.
  • Developer accounts. If you create an account, we retain your email address, workspace membership, API-key prefixes and composed-call usage. API-key secrets are shown once and are not retained in readable form.
  • Subscriptions. Stripe hosts checkout and billing management. Civic Data retains Stripe customer, subscription and price identifiers plus subscription status; Stripe processes payment details under its own privacy terms.

What we do not do

  • No Civic Data passwords; developer sign-in uses secure email links.
  • No advertising, tracking cookies or third-party analytics scripts on the website.
  • No sale or sharing of request data with third parties other than the infrastructure providers that run the service.

Hosting and processors

The website, API and MCP server run on Cloudflare; product data is stored in Supabase PostgreSQL in the London (eu-west-2) region; raw source archives are stored in Cloudflare R2 in Western Europe. These providers process infrastructure logs under their own terms. Stripe processes Developer subscription payments.

Public data

The civic data Civic Data republishes is published by UK public bodies under open licences (see sources). It is aggregated to postcode radius or statistical-area level and does not identify individuals.

Your rights and contact

You can ask what we hold about a request by quoting its request identifier, and ask for correspondence to be deleted. Contact [email protected] or see the contact page. This notice may change when the service changes; the canonical version is always at this address.