CivicRecap

Privacy policy

Last updated August 25, 2026

CivicRecap publishes a searchable record of public meetings held by councils, boards and commissions. Almost everything on the site is that public record and has nothing to do with you. This page covers the small amount that does: what we keep about an account, who else handles it, and how to see, correct or delete it.

Who we are

This service is operated by Grizzly Studios LLC. For anything on this page — a question, a request, a complaint — write to support [at] civicrecap.com.

CivicRecap covers councils, boards and commissions in California. We are not set up to serve, and do not knowingly collect information from, people outside the United States.

You can read the record without an account

Searching, browsing, agency and place pages and every meeting briefing are open. You need an account only to watch a recording, read a transcript, follow a council or board, or receive email. If you never sign in, we hold no account for you at all: the follow list your own browser keeps in local storage never reaches us, and the only things that do are the usage counting described below and — if you open a link somebody shared with you — one record of that open, which includes your IP address for up to 90 days. That record is described in full below.

What we store when you do have an account

  • Your email address, as your sign-in provider reported it, plus an optional display name you choose.
  • Which councils, boards and places you follow, and the order you put them in.
  • Your email preferences — whether each followed scope sends you the daily recap, a reminder before a meeting, or neither.
  • A record of the emails we sent you: which kind, on which day. This is what stops you being sent the same recap twice; it does not record whether you opened anything.
  • Your sign-in sessions, stored as a hash of the session token rather than the token itself, with the time each was last used and when it expires.
  • Which meetings you have shared, and how many times a link you shared was opened — a count per meeting, with the first and last time somebody opened one, plus a record of each individual open, described in the next section. We do not record where you sent it. Your own visits to your own link are not counted.
  • Ordinary server logs, which include IP addresses and are kept briefly for security and debugging.

We do not store a password. Sign-in is handled entirely by our provider (below), and we never see your credentials. We set no cookies beyond the ones that keep you signed in and let a shared link open. A link you share carries a short-lived token that includes that same internal account number, which is how we can tell a link somebody opened was one you sent; it means nothing outside our own database.

When a shared link is opened

A link somebody shares carries a token that stops working after 14 days. Each time one is opened we write a single row recording that open — whether or not the person opening it has an account, and whether or not they ever come back. It holds the time, which shared link it was, whether the visitor was signed in, the browser and device their browser reported, and the approximate city our network provider derives from the connection.

It also records who the visitor was, one of two ways and never both. If they were signed in, we keep the internal account number of that account — so the row says that account opened a link to that meeting, at that time. If they were not signed in, there is no account number to keep, so we keep the IP address the request came from instead. This is a change from what this page said before August 25, 2026, when we recorded only that somebody had opened the link.

These rows exist so we can tell whether sharing works at all, and so the operator of this service can see whether a link went anywhere. Nobody else sees them: they are not shown to other readers, not shown to the person who shared the link, and not sent to any of the processors below. We delete them after 90 days, and any one link keeps only its 500 most recent opens — that limit is the whole of how long this record lives, so nothing here becomes a standing log of who read what. If you had an account and delete it, your account number is removed from these rows and the open stays counted without it.

Product analytics

We use Mixpanel to see which pages are read and which features are used — a page was opened, a recording was played, a transcript was read, a briefing was shared, a shared link was opened, a council or board was followed. It tells us what to build next and what is not working; it is not advertising, and we run no ad network, no conversion pixel and no cross-site tracking of any kind.

These events are tied to a random identifier stored in your browser's local storage rather than in a cookie. If you are signed in, that identifier is the internal account number we use in our own database — never your name, your email address, or anything you typed. We do not send what you searched for, and we do not send the query part of a web address, because that is where shared-link tokens live. Signing out — or deleting your account — starts a fresh random identifier.

The operator console at /admin is excluded entirely, and blocking Mixpanel — with an extension, a privacy-focused browser, or your own DNS — breaks nothing on this site.

Who else handles it

Three processors, each doing one job and holding only what that job needs:

  • Clerk runs sign-in. Your email address, any phone number you add, and your password if you set one live there, not here. Clerk tells us a stable identifier and the address attached to it.
  • Resend delivers our email. It receives your address and the message we send you.
  • Mixpanel counts product usage. It receives the events above, the random identifier they are tied to, your IP address at the time of the request — which it uses to derive an approximate city — and ordinary browser details such as the device type and screen size. It is a service provider acting on our instructions, and none of it is used for advertising.

Beyond those, we disclose personal information only when the law requires it. Meeting recordings and documents are processed by automated systems; they are published by the councils and boards themselves and contain nothing about you.

We do not sell or share your personal information

We have never sold personal information, and we do not share it for cross-context behavioral advertising, as the CCPA uses those terms. We have no advertising business, and nothing here is passed to a data broker.

Your rights under California law

If you are a California resident, the CCPA as amended by the CPRA gives you the rights below. Three of them are buttons rather than requests — you do not have to ask us, and we cannot be slow about it:

  • Know and access. Download everything we hold about your account as a JSON file, from your account page.
  • Correct. Change your display name, email address and phone number on the same page.
  • Delete. Delete your account there too. This removes your account, identities, sessions, follows, email preferences, send history and the record of what you shared, and asks Clerk to delete its copy. Where you opened a link somebody else shared, their count of that open stays and your account number is removed from it. It does not touch the public meeting record, which is not about you. Usage events are keyed to the random identifier described above and are not connected to your name or address; if you want those removed too, write to us and we will ask Mixpanel to delete them.
  • Opt out of sale or sharing. There is nothing to opt out of — see above.
  • Limit use of sensitive personal information. We do not collect any.
  • Non-discrimination. Exercising any of these changes nothing about what the service does for you.

You may also make any of these requests by writing to support [at] civicrecap.com, and you may authorize someone else to make one for you. We will verify that the request really comes from you — usually by asking you to confirm from the address on the account — before acting on it.

How long we keep it

Your account data stays until you delete it. Sessions expire on their own and are swept. The record of a shared link being opened is deleted after 90 days, and sooner for a link opened more than 500 times. Server logs are kept briefly. Deleting your account removes the account data immediately; backups age out on their own schedule.

Children

This service is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has created an account, write to us and we will delete it.

Changes

If this policy changes in a way that affects what we do with your information, we will update the date at the top of this page and, for anything material, say so by email to accounts it affects.

See also our terms of service.