Privacy Policy

An organization that opposes mass data collection should be able to explain its own in plain language, on one page. Here it is.

The short version. This site sets no cookies, runs no trackers, and makes no third-party requests of any kind. It does run a small amount of our own JavaScript — for the map, search, and the action templates — and none of it sends anything back to us. We collect nothing about you unless you choose to send us a message. If you do, it goes to our email inbox, it is never sold or shared, and we delete it if you ask. See exactly what the JavaScript does.

Who this policy covers

This policy applies to unsurveilled.org. Unsurveilled is an independent, nonpartisan civil-liberties project based in Arizona, United States. It is not yet a registered legal entity; when a formal organization is established, this policy will be updated with the entity name and a postal address.

For any privacy question, or to exercise any right described below, write to hello@unsurveilled.org.

Why there is no cookie banner on this site

You have probably noticed that this site never asked for your consent to anything. That is not an oversight.

Consent requirements — including the EU ePrivacy rules that produced the banners you see everywhere — are triggered when a site stores information on, or reads information from, your device for non-essential purposes. This site does none of that:

  • No cookies of any kind, first- or third-party.
  • No local storage, session storage, or fingerprinting.
  • No analytics. No Google Analytics, no privacy-branded analytics, no pixels, no beacons.
  • No third-party requests at all. Fonts, images, scripts, styles, and map data are served from this domain. Nothing on this page contacts another company as you read it.
  • First-party JavaScript only, and it sends nothing back. See the section below.

Because there is nothing stored and nothing tracked, there is nothing to consent to — so we do not interrupt you to ask. You can verify all of this yourself: open your browser’s developer tools, load any page on this site, and look at the network and storage tabs. We would rather be checked than believed.

The JavaScript on this site, and what it does

Until August 2026 this site ran no JavaScript at all. It now runs a small amount, all written by us and served from this domain, because some of the things we owe you — a searchable map of known cameras, a site-wide search, a records-request generator — genuinely need it.

Our objection has always been to tracking, not to interactivity. So the rule we hold ourselves to is narrower and more checkable than “no JavaScript”:

Nothing you do on this site is transmitted to us or to anyone else.

Concretely, here is every script this site ships and what it does:

  • The Atlas map. Draws camera and jurisdiction records on a canvas. It fetches two static files from this domain — the map records and the US state outlines — and contacts no mapping service. There are no tiles, no Google Maps, no Mapbox, no Leaflet. It never asks for your location, and the server sends a Permissions-Policy header that forbids this site from asking even if a future bug tried to.
  • Search. Downloads one index file from this domain and matches your query inside your own browser. What you type is never sent anywhere — not to us, and not to a search company.
  • Filters on Signal, the Atlas, and the decision record. These hide and show content already on the page.
  • The action template generator. Substitutes your city, state, and agency into records-request and public-comment templates. The substitution happens in your browser. We never receive the place you typed.
  • Copy buttons. Put text on your clipboard.

The browser enforces this rather than merely trusting us. The site sends a Content-Security-Policy that forbids loading a script from any other origin, forbids inline scripts, and restricts network requests to unsurveilled.org only. If we ever added a tracker, your browser would block it before it ran.

Local storage: this site currently writes nothing to your device — no cookies, no local storage, no session storage. If we later add an opt-in convenience such as a saved jurisdiction, it will be stored only on your device, it will be listed here before it ships, and there will be a visible way to clear it.

What we cannot honestly claim: our web host keeps ordinary server access logs, as described below. We do not control them and we will not pretend they do not exist.

What we actually collect

1. Messages you send us

If you use the contact form or email us directly, we receive what you chose to send: your name, your email address, optionally your city and state, which topic you selected, and your message.

  • Why: to read and reply to you, and to coordinate volunteer, chapter, or press inquiries you asked us about.
  • Legal basis (where the GDPR applies): your consent, given by choosing to contact us, and our legitimate interest in responding to correspondence.
  • Where it goes: our email mailbox at this domain. The form submission is processed by a script on our own server and is not stored in any database or file — it is emailed and discarded.
  • How long: we keep correspondence only as long as it is useful for the work, and we delete it on request. There is no mailing list you are added to automatically, and no email-capture pop-up anywhere on this site.
Please read this before sending anything sensitive

Ordinary email is not end-to-end encrypted. It passes through mail servers we do not control and can be retained by them, and it can be compelled by legal process. Do not send us anything through this form that would put you at risk if a third party read it. If you have sensitive information — records, documents, or firsthand knowledge that could expose you — write us a short message with no details and ask for a more secure channel first.

2. Server access logs

Our web host records standard server logs when any page is served. These typically include the requesting IP address, the time of the request, the page requested, and the browser’s user-agent string. This is automatic behavior of the web server, not a tracking system we added, and these logs are not connected to any analytics, profile, or advertising identifier.

We do not mine, analyze, or build profiles from these logs, and we work to keep their retention as short as our hosting allows. We disclose this because a site that claims to collect “nothing at all” while its server quietly logs visitor IPs would be doing exactly what we criticize.

What we never do

  • We do not sell, rent, or trade your information. Ever.
  • We do not share it with advertisers, data brokers, analytics firms, or social platforms.
  • We do not use it to build a profile of you or track you across sites.
  • We do not add you to any list you did not explicitly ask to join.

When we could be compelled to disclose

We will not hand over information voluntarily. If we ever receive a valid, legally binding demand — a subpoena, warrant, or court order — we would be obligated to respond to the extent the law requires. Our practical protection against that is not having the data in the first place, which is why this site stores so little. Where we are legally permitted to notify the person affected, we intend to.

Your rights

Regardless of where you live, you may ask us to:

  • Tell you what correspondence of yours we still hold;
  • Correct it if it is wrong;
  • Delete it;
  • Stop contacting you.

If you are in the European Economic Area or the United Kingdom, the GDPR also gives you rights of access, rectification, erasure, restriction, objection, and data portability, and the right to complain to your national data protection authority. If you are a California resident, you may ask what personal information we have collected and request its deletion. We do not sell or share personal information as those terms are defined under California law, and we will not discriminate against you for exercising any right.

To exercise any of these, email hello@unsurveilled.org. We aim to respond within 30 days. Because we deliberately hold so little, the usual honest answer is that we have nothing of yours beyond an email thread.

Do Not Track

Some browsers send a “Do Not Track” signal or a Global Privacy Control signal. This site does not track you in the first place, so there is no tracking for such a signal to switch off. We honor them by default and by design, not by exception.

Children

This site is intended for a general audience and is not directed to children under 13. We do not knowingly collect information from children. If you believe a child has sent us personal information, write to us and we will delete it.

Links to other sites

Our sources library and research posts link to outside material — court decisions, public records, and other organizations’ work. Those sites have their own privacy practices, and many of them do track visitors. We have no control over that. This site is configured not to disclose to those sites which page you came from.

Changes to this policy

If we change this policy, we will update the effective date below and describe what changed. If a change ever materially reduces your privacy, we will say so plainly rather than quietly revising the text.

Effective date

Effective . This is the first version of this policy.

Note: this policy describes our actual practices in plain language. It is not legal advice, and it will be reviewed by counsel when Unsurveilled establishes a formal legal structure.