Open Policing Data Hub

Scope and operator

This policy describes how Pop Datasets and the Open Policing Data Hub (collectively, the “Service”) handle information when you use the website, public API, MCP server, or ChatGPT app. The Service is independently provided by Michael Zidar. It is not operated on behalf of an employer, government agency, law-enforcement agency, or data publisher.

Information processed

  • Website, API, and MCP requests: requested URLs, research queries, document identifiers, public agency filters, FBI agency ORIs, API-key identifiers, timestamps, IP addresses, and ordinary device, browser, network, diagnostic, and security-log information.
  • Information you submit: an email address, name or project label, intended-use description, data-correction report, source URL, and other details you choose to provide when requesting an API key or reporting an issue. Do not submit confidential, restricted, or unnecessary personal information.
  • ChatGPT app inputs: the Service receives only the specific tool arguments ChatGPT sends to fulfill a request. It does not ask for account credentials, payment data, health information, government identifiers, criminal histories, or information about an individual person.
  • Public source content returned: indexed research and records may incidentally include public professional information such as author names, titles, institutional affiliations, citations, agency contact details, or names already present in source documents. The tools are not designed to retrieve private records or build profiles about individuals.
  • Preferences: a functional sidebar cookie that expires after seven days and local browser storage for the selected color theme. The Service does not use advertising or cross-site tracking cookies.

How information is used

Information is used to deliver requested pages and tool results, retrieve public research and aggregate agency data, operate and secure the Service, enforce rate limits, measure aggregate API usage, diagnose failures, issue and administer optional API keys, respond to questions, and investigate data-quality reports. The Service does not sell personal information, serve advertising, or use submitted information for targeted advertising.

Recipients and service providers

Information may be processed by vendors that provide infrastructure to the Service, currently including Vercel for hosting and network delivery, Turso for application data, and Upstash for API rate limiting. If you use Pop Datasets through ChatGPT, OpenAI also processes your conversation and decides which tool arguments to send under its own terms and privacy practices. If you voluntarily open a GitHub issue, the content is processed by GitHub and is normally public.

Information may also be disclosed when reasonably necessary to comply with law, protect the Service or others, investigate abuse, or complete a transfer of the Service. Pop Datasets does not control the independent practices of third-party sites and services.

Retention

  • ChatGPT tool inputs and ordinary search queries are processed to answer the request and are not intentionally saved in a Pop Datasets prompt database. Infrastructure providers may retain request and security logs under their own retention schedules.
  • IP-based rate-limit records are short-lived and are used for the applicable rate-limit window. Daily API usage counts retain a date, route pattern, count, and anonymous or API key identifier, not the request body or IP address.
  • API-key contact and account records are retained while the key is active and for up to 12 months after revocation. Data reports, source suggestions, and related contact details are retained for up to 24 months after resolution, unless a longer period is reasonably required for security, legal compliance, or an ongoing dispute.
  • Browser preferences remain on your device until their stated expiration or until you clear them.

Your choices and requests

You may use the public site and API without creating an account, omit the optional email field on data reports, avoid posting a public GitHub issue, clear browser cookies and local storage, or stop using the Service. Subject to applicable law, you may request access, correction, or deletion of information you submitted. Use the private profile contact options linked from the support page; do not put personal or confidential information in a public issue.

Security, children, and transfers

Reasonable administrative and technical safeguards are used, but no internet service can guarantee absolute security. The Service is not directed to children under 13 and does not knowingly collect their personal information. The Service and its providers may process information in the United States and other countries where they operate.

Changes and contact

This policy may change as the Service or its providers change. Material updates will be posted here with a revised date. For questions or privacy requests, visit the support page. Also review the Terms of Use and Data Disclaimer.