Privacy Policy
Last updated: August 31, 2026
This policy explains what WardAtlas, a product of Andy.Build (“we,” “us”), collects when
you use wardatlas.com and the WardAtlas API, and what we do with it. The
short version: we collect what it takes to run an API service — contact-form messages,
key records, usage counts, and short-lived rate-limit counters — and nothing more. We do
not sell personal information, run ads, or use third-party tracking.
1. What we collect and why
| Data | Purpose | Where it lives & how long |
|---|---|---|
| Contact-form submissions (name, email, organization, message) | Answering your inquiry; issuing API keys | Delivered as email to the operator's inbox and retained there as ordinary business correspondence; not stored in a marketing database |
| API key records (key-holder name/organization, plan, SHA-256 hash of the key) | Authentication and plan enforcement | Our database, for the life of the key; we store only a hash — we cannot recover your key |
| Usage metering (key id, endpoint path, response status) | Rate-limit and quota accounting, billing, capacity planning | Cloudflare Analytics Engine, retained approximately 90 days; query parameters are not recorded |
| Rate-limit counters keyed by IP address (demo and contact form) | Abuse prevention on keyless endpoints | Cloudflare KV counters that expire automatically — about 65 minutes for per-IP counters (the demo's global counter, which contains no IP, lasts about a day) |
| Standard edge logs (IP, user agent, URL) | Serving requests, security | Cloudflare's infrastructure, per Cloudflare's short operational retention |
2. Addresses you look up
A lookup sends the queried address to a geocoding service — the U.S. Census Bureau geocoder, falling back to Geocodio — to convert it to coordinates. We cache the result (normalized address → coordinates), keyed by a hash of the address text, for up to 30 days so repeat lookups are fast; autocomplete suggestions are cached similarly for up to 7 days. These caches are keyed by the address alone — they are not linked to your API key, your IP, or any person — and our usage metering records which endpoint you called, never the address you queried. We do not build profiles from looked-up addresses.
3. Cookies
The public website and API set no cookies and load no third-party trackers or analytics scripts. A single session cookie exists only on the operator's own administration pages.
4. Data about elected officials
The product itself is a database about people — elected and appointed public officials, acting in their public capacity. That data (office, district, official contact channels, committee roles, term dates, official portraits) is compiled from official government sources and other public records, and every field carries its source URL and verification date. We collect officials' professional, public-role information — not private home details of officials as private individuals. If you are or represent an official and believe a record is inaccurate, or includes personal rather than official information, tell us via the contact form and we will review and correct it promptly.
5. Service providers
We run on a small set of infrastructure providers that process data on our behalf:
- Cloudflare — hosting, CDN, storage, usage analytics, and outbound email (contact-form delivery);
- Neon — the database (hosted in the United States);
- U.S. Census Bureau and Geocodio — geocoding of queried addresses, as described above;
- Anthropic — AI-assisted extraction from public government webpages during data collection; your personal data and your queries are never sent to it.
Beyond these providers, we disclose personal information only if required by law or necessary to protect the Service or others' safety, and — if the business is ever transferred — to a successor bound by this policy. We never sell it.
6. Your rights
You can ask us to access, correct, or delete personal information we hold about you via the contact form; we answer within 30 days. For visitors from the EEA/UK: we process the data above on the basis of performing our contract with you and our legitimate interest in operating and protecting the Service; you also have the rights to object, to restrict processing, and to lodge a complaint with your supervisory authority. For California residents: we do not sell or share personal information as the CCPA defines those terms.
7. Security and children
All traffic is encrypted in transit; API keys are stored only as SHA-256 hashes; access to production systems is limited to the operator. The Service is not directed at children and we do not knowingly collect personal information from anyone under 16.
8. Changes and contact
We will post changes to this policy here and update the date above; material changes will be emailed to active key holders. Questions or requests: wardatlas.com/contact.
Terms of Service · Acceptable Use · Privacy Policy · Data Sources & Attributions