Skip to content

Privacy policy

This Privacy Policy describes how SAUERAPPLE LLC collects, uses, and shares personal information in connection with CivicCatch.

Effective date: August 24, 2026

1. Who we are

CivicCatch is a product of SAUERAPPLE LLC, a California limited liability company ("SAUERAPPLE," "we," "us," or "our"). CivicCatch is independent software — it is not a newsroom product and is not an official government service. This Privacy Policy applies to personal information we collect through the CivicCatch marketing site, buyer application, place subdomains, public API, and related email communications.

Privacy questions and requests: hello@civcatch.com.

2. Personal information we collect

Depending on how you use CivicCatch, we may collect the following categories:

  • Identifiers and account data. Email address; authentication session data (including one-time sign-in codes); tenant configuration you provide — place name, bodies, sources, delivery preferences, and billing entitlement metadata; and API keys you create (we store only a hash of the secret, never the plaintext after you copy it).
  • Resident subscriber data. When a place site offers email, the address you submit, confirmation tokens, and unsubscribe tokens. We send a confirmation link before adding an address to digests.
  • Commercial / payment data. Card processing is performed by Stripe. We store Stripe customer and subscription identifiers on your tenant record. We do not store full payment card numbers on our servers.
  • Internet / electronic activity. Anonymous usage analytics only if you opt in via the consent banner (for example page views and product events such as tenant slug or plan id). We do not place email addresses in analytics events or build advertising profiles. If you decline or never choose, analytics are not recorded.
  • Diagnostics. Technical error reports (browser and runtime context) used to find and fix bugs — not for marketing.
  • Technical logs. Standard request data processed by our hosting and infrastructure providers (such as IP address, user agent, and timestamps) to deliver pages, maintain security, and diagnose issues. Sign-in requests may also be evaluated by a bot-protection challenge.

We do not knowingly collect sensitive personal information beyond what is needed to operate accounts, billing, and email delivery. Agenda capsules summarize public meeting materials and link to official agency packets; they are not government records.

3. How we use personal information

We use personal information to:

  • Create and secure buyer accounts and operate tenants.
  • Send confirmation messages and digests that you or residents requested.
  • Process subscriptions and maintain accurate billing entitlements.
  • Authenticate public API requests with keys you create.
  • If you opt in, understand product usage in aggregate so we can improve CivicCatch.
  • Operate, secure, and troubleshoot the Service — including bot protection on sign-in.
  • Respond to support and privacy requests and comply with law.

We do not use personal information for targeted advertising. We do not sell or rent personal information.

4. How we share personal information

We share personal information with service providers that process it on our behalf to operate CivicCatch, under contractual obligations appropriate to their role. We do not sell personal information or share it with third parties for their own marketing.

We may also disclose information if required by law, legal process, or to protect rights, safety, or security, or in connection with a merger, acquisition, or sale of assets, subject to appropriate confidentiality protections.

5. Service providers

  • Vercel — website hosting and delivery, including request logs.
  • Supabase — authentication, database, and related backend services for accounts, tenants, and subscribers.
  • Stripe — payment processing and subscription billing.
  • Resend — transactional and digest email delivery.
  • Trigger.dev — background jobs for meeting ingestion and digest delivery.
  • Cloudflare — Turnstile bot protection on buyer sign-in.
  • PostHog — anonymous usage analytics, loaded only after you opt in.
  • Sentry — error monitoring.

6. Global Privacy Control and Do Not Track

We honor Global Privacy Control (GPC). If your browser or an extension sends a GPC signal, we treat it as an automatic decline of analytics: the consent banner does not appear, analytics scripts do not load, and usage events are not recorded. Because we do not engage in targeted advertising or sell personal information, you receive equivalent protection with respect to older "Do Not Track" signals.

7. Cookies and similar technologies

We do not use advertising or cross-site tracking cookies. We use local storage to remember your analytics consent choice for CivicCatch. Only if you accept analytics do our tools set a first-party identifier used to count returning visits anonymously. Auth sessions may use cookies or similar storage required to keep you signed in. Cloudflare Turnstile may set a first-party challenge token when you request a sign-in code. You may clear or block these technologies in your browser; doing so may sign you out, reset your consent choice, or require you to complete the challenge again.

8. Retention

We retain buyer account and tenant configuration data for as long as the account or tenant remains active, and thereafter for a period reasonably necessary for billing records, security, dispute resolution, and legal compliance. Resident digest addresses remain on the active list only while subscribed; after unsubscribe, we stop sending and remove the address from the active list. Hashed API keys remain until you revoke them or the tenant is closed. Anonymous analytics and technical logs are retained for a limited period, then deleted or aggregated. Stripe retains payment records according to its policies and legal obligations.

9. Your choices

  • Unsubscribe. Every digest email includes an unsubscribe link.
  • Analytics consent. Analytics run only if you accept them in the consent banner. Enabling Global Privacy Control turns them off automatically.

    Your current choice: not set. .

  • API keys. Buyers may create and revoke keys from the signed-in account. Revoking a key stops it from authenticating.
  • Access, correction, and deletion. Email hello@civcatch.com to request access to, correction of, or deletion of personal information we hold about you, subject to legal exceptions. Buyers may also manage certain tenant settings in the signed-in application.

10. California privacy rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), provides rights to know what personal information a business collects about you, to request deletion or correction, and to opt out of the sale or sharing of personal information.

We do not sell or share personal information as those terms are defined under the CCPA, and we do not use personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA. To exercise your right to know, delete, or correct, email hello@civcatch.com. We will verify your request and respond as required by law. We will not discriminate against you for exercising CCPA rights.

Categories of personal information we collect are described in Section 2. We collect them for the business purposes described in Section 3. We have collected those categories from consumers, from you directly, and from our service providers in the preceding twelve (12) months as applicable to your use of the Service.

11. Children's privacy

CivicCatch is directed to adults — including city staff, publishers, and residents following local government — and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact hello@civcatch.com and we will delete it.

12. Security

We implement reasonable administrative and technical safeguards designed to protect personal information, including HTTPS encryption in transit, hashed API secrets, and access controls on production systems. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

13. Location of processing

SAUERAPPLE is based in California, United States. Personal information may be processed in the United States and in other locations where our service providers operate. By using the Service, you understand that your information may be transferred to and processed in the United States.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the effective date above and post the updated policy on this page. Material changes will be noted here or communicated by other appropriate means. Continued use of CivicCatch after an update becomes effective constitutes acceptance of the revised policy.

15. Contact

SAUERAPPLE LLC
Email: hello@civcatch.com

Related: Terms of Use.