Skip to content

Privacy

Your privacy on Georgia Civic Data

Georgia Civic Data is a free, bilingual platform for Georgia's public data. We built it to work with as little of your information as possible: no accounts, no logins, and no advertising. This policy explains what we collect, how we use it, and the choices you have.

Effective date: July 22, 2026. Last updated: July 22, 2026.

Who we are

Georgia Civic Data is an independent, nonpartisan, public-interest organization. This policy covers our website at georgiacivicdata.org (including the Spanish pages under /es), the Data Explorer and Data Talk tools on that site, our public REST API, and the MCP connector at mcp.georgiacivicdata.org/mcp.

We are not affiliated with, endorsed by, or operated by the State of Georgia, the Georgia Department of Education, or any government agency or school district. We gather and organize public data; we are not a government service.

If you have any questions about this policy, you can reach us at shane@georgiacivicdata.org.

The short version

Here is the plain-language summary. The rest of this policy fills in the details.

  • No accounts, no logins. You never create an account or tell us who you are to use the site, the API, or the connector.
  • We do not sell your data. We do not sell or rent your information, we do not show ads, and we do not use your information to build a profile of you.
  • Chats are temporary. A Data Talk conversation is held in memory to answer your questions during your visit, then automatically discarded. We do not keep a permanent record of your chats.
  • Please leave out personal details. Our data is about places and groups of people, not individuals. Please do not type anyone's name or other identifying information into Data Talk.
  • A few trusted providers help run the service. We use Anthropic to generate Data Talk's answers, and Vercel, Railway, and Cloudflare to host the site and its data. They are listed below.

Information we collect

Because there are no accounts, the only information tied to you is whatever you choose to send, plus the standard technical information every website receives. Here is the full picture.

  • Data Talk chatbot. When you use Data Talk, we process the questions you type and the answers we generate during your conversation, along with the simple context that focuses an answer, such as the dataset, place, or breakdown involved. We do not ask for your name, email address, phone number, mailing address, or any payment information, and there is no account to create. The only personal information we receive is whatever you choose to type, so you stay in control of what you share.
  • Data Explorer, the API, and the MCP connector. These serve published data and do not ask you to identify yourself. When your browser or an AI assistant requests data, our servers receive the request itself, for example a dataset name, a place, a year, or a demographic filter, plus standard technical information such as your IP address.
  • Analytics and performance. We use privacy-friendly, cookieless analytics to count visits and measure how quickly pages load, as described in the next section.

Analytics and performance data

We use Vercel Web Analytics and Vercel Speed Insights to understand which pages people visit and how quickly the site loads, so we can keep it working well. These tools are privacy-friendly by design: they do not use cookies, they do not identify you personally, and they do not track you across other websites.

The analytics record aggregate information such as page views, referring links, the general type of device and browser, and an approximate, country-level location derived from your network connection. This data is used only for overall statistics. You can read how these tools work in Vercel's analytics privacy overview.

Server logs

Like most online services, our servers and our hosting providers keep short-term operational logs so we can run, secure, and debug the service. Our application records one log line per request or Data Talk turn with technical metadata: the endpoint or tool involved, query parameters such as a dataset or place, response timings, and, for Data Talk, token counts. It does not record a transcript of your conversation. Our hosting providers separately keep standard infrastructure logs that include an IP address and basic connection information, which are used to route, secure, and rate-limit traffic.

We use these logs only to operate and improve the service. We do not use them to build advertising profiles, and we do not sell them. They are kept for a limited time and then rotated out (see How long we keep information below).

The API and the MCP connector

The public REST API and the MCP connector at mcp.georgiacivicdata.org/mcp are open to everyone and need no sign-in or account. They are read-only: they answer requests for Georgia's published public data and do not write, change, or store anything about you. They do not collect names, emails, or accounts.

The MCP connector lets you connect an AI assistant you already use, such as Claude, ChatGPT, or Gemini, to Georgia data. When your assistant asks the connector for data, it sends a structured request, for example a dataset, a place, or a filter, and the connector answers from the public data.

One important point about your assistant. The AI assistant you choose is operated by its own provider under that provider's terms, not by us. Whatever you type into your assistant, and the data it retrieves through the connector, is handled by that provider, for example Anthropic, OpenAI, or Google. We do not control or receive your assistant's conversation.

For reliability and debugging, the API and connector record operational logs of the requests they receive, which can include the parameters sent, such as a dataset name or a place. As with our other logs, these are used only to operate the service and are kept for a limited time.

Cookies and local storage

We do not use advertising cookies or cross-site tracking cookies, and our analytics are cookieless (see above).

To make the chat work smoothly, your current Data Talk conversation is saved in your browser's session storage, a temporary storage area on your own device. This copy stays on your device so your conversation survives a page reload, and your browser clears it when you close the tab. Separately, the questions you send are transmitted to our service to generate answers, as described above.

How we use information

We use the information described above to:

  • Answer your questions. In Data Talk, your message, your recent conversation, and the relevant Georgia data are sent to our AI provider (Anthropic) to generate a response.
  • Serve the data you request. The API, the MCP connector, and Data Explorer return the published Georgia data your request asks for.
  • Keep your conversation coherent. We remember the recent turns of your Data Talk session so follow-up questions make sense during your visit.
  • Operate, secure, and debug the service. We use logs, IP-based rate limits, and error information to keep the service running and to fix problems.
  • Understand overall usage. We use aggregate analytics to see what is helpful and improve the site.

We do not sell or rent your information, we do not use it for advertising, we do not use it to build a profile of you, and we do not use your questions to train any AI models of our own.

Service providers we share data with

We do not sell your data. To run the service, we rely on a small number of trusted providers that process data on our behalf:

  • Anthropic (Claude). Generates Data Talk's answers. When you send a Data Talk message, its text, your recent conversation, and the relevant Georgia data are sent to Anthropic's API to produce a reply. Anthropic processes this as a service provider under its own privacy policy. Under Anthropic's commercial terms for its API, Anthropic does not use data sent through the API to train its AI models. The REST API, the MCP connector, and Data Explorer do not use Anthropic.
  • Vercel. Hosts our website and provides the cookieless analytics described above. See Vercel's privacy notice.
  • Railway. Hosts our backend services (the REST API, the MCP connector, and Data Talk), including their operational logs. See Railway's privacy policy.
  • Cloudflare. Stores the public datasets we serve (Cloudflare R2). Our backend reads from this storage to answer queries; your browser does not connect to it directly. See Cloudflare's privacy policy.

We may also disclose information if we are required to by law, or where we believe in good faith it is necessary to protect the safety, rights, or security of our users, the public, or the service.

Our datasets come from Georgia's public sources, such as the Governor's Office of Student Achievement and the Georgia Department of Education. We read that public data to build our datasets; we do not send your personal information to those sources.

Storage and security

Data Talk conversations are held in the server's memory only. They are not written to a database or long-term storage, and each conversation is identified by a random session code that is not linked to your identity.

We host the service with established providers (Vercel, Railway, and Cloudflare) that encrypt data in transit over HTTPS and maintain standard infrastructure security.

No method of transmitting or storing data is completely secure. We work to protect your information, but we cannot guarantee absolute security. Because this is a free service that does not require personal information, please avoid sending sensitive personal details through it (see Children's privacy below).

How long we keep information

  • Data Talk conversations. Temporary. A conversation lives in the server's memory only while it is active and is automatically discarded after a period of inactivity (about two hours after your last message) or whenever the server restarts. We do not keep a permanent record of your chats.
  • Session storage in your browser. Cleared by your browser when you close the tab.
  • Server and connector logs. Kept only for a limited time for debugging and security, then rotated out.
  • Analytics. Vercel's Web Analytics keeps only aggregate statistics and does not retain a reconstructable record of your visit.

Your choices and rights

You can use the entire platform without giving any identifying information, and you control what you send, so please share only what you are comfortable having processed.

  • Clear your local chat. Close the browser tab, or clear your browser's session storage, to remove the copy of a Data Talk conversation stored on your device.
  • Limit analytics. The site works fully without analytics. You can use your browser's privacy settings or a content blocker to opt out of non-essential analytics.
  • Ask us. Depending on where you live, you may have rights to access, correct, or delete personal information, or to object to how it is processed. Because we do not maintain accounts and chats are temporary, we usually hold little or no personal information tied to you. If you have a request or a question, email shane@georgiacivicdata.org and we will do our best to help.

We do not sell personal information, and we do not use it for targeted advertising.

Children's privacy

Georgia Civic Data is a general-audience resource for public data. It is not directed to children, and it is not intended for use by children under 13.

We do not knowingly collect personal information from children. No personal information is required to use the platform, and there are no accounts.

Our data describes places and groups of people, not individuals, so the tools never need a child's personal information. Please do not enter anyone's full name, contact information, photo, school or student ID, or other identifying or sensitive personal information into Data Talk.

If you believe a child has provided us with personal information, please contact us at shane@georgiacivicdata.org. Because chats are held only briefly and then discarded, such information is typically removed automatically, and we will promptly delete anything brought to our attention.

Changes to this policy

We may update this policy from time to time, for example if we add a feature or change a service provider. When we do, we will update the "Effective date" and "Last updated" shown near the top of this page and post the new version here, at georgiacivicdata.org/privacy (and /es/privacy in Spanish). If a change is significant, we will make it clear on the site.

Contact us

If you have questions about this policy or how your information is handled, please email us at shane@georgiacivicdata.org. Georgia Civic Data is a public-interest project.