SidewalkSnitch

SidewalkSnitch · Privacy Policy

What we collect, what we don't, and how to make us delete it.

Last updated: 2026-07-27 · Disclaimer: outside legal counsel review pending; the content here reflects current code behavior.

The short version

  • We collect what you give us (photos, address, phone, optional email) and what we need to run a complaint flow (your GPS at the moment of submission, your photo's EXIF GPS). We also record and retain your IP address for security, abuse prevention, and traffic analytics.
  • We do not sell your information. We do not run ads.
  • Photos run through an explicit EXIF stripper on your device before upload, so no GPS or camera metadata is embedded in the stored file.
  • We read your photo's GPS to place your report and keep those coordinates with it — including to improve our AI. Deleting your account removes them.
  • If you choose to send a report to a business, that business sees your screenname and nothing else that identifies you — not your name, phone, email, or address.
  • You can delete your account and your data at any time via the More tab. We honor deletion requests within 30 days.
  • SidewalkSnitch is intended for adults. We do not knowingly collect information from anyone under 13.

What we collect

From you, directly: photos you upload, the text you write, the mobile phone number you verify, your real name and email and mailing address (collected once when you first verify a phone), a screenname you pick.

If you join our launch waitlist: the mobile number you enter, an optional first name, an optional 5-digit ZIP code, and an optional neighborhood — used to text you when we launch, tell you whether your neighborhood is covered, and order the waitlist. Reply STOP to any text to opt out. If your waitlist entry never becomes an active account, we delete it within 180 days.

From your device: your photo's EXIF GPS and timestamp (read to pre-fill where the issue is; we keep these coordinates with your report and remove them from the stored image file itself), your current GPS at the moment of submission (used only to check you are near the issue), your browser's IP address. We record and retain your IP address — not only for abuse rate-limiting, but also in our own visit log, which we use for security investigations, abuse prevention, and understanding how people find and use the site. It is stored in full, not hashed or truncated, and is readable only by SidewalkSnitch operators. It is never sold, and never shared with a business you report.

About your submissions: the AI's analysis of your photo (which rule was violated, confidence score, drafted complaint text), the rule it cited, the agency it routed to, and the city's acknowledgment if the complaint was filed.

How you move through the app (product analytics). We log step-level events as you use the app — opening the report screen, capturing a photo, each stage of the AI analysis, starting or abandoning a draft, signing in, and similar. Each event carries the event name, a session ID that lasts until you close the tab, your Firebase user ID (you have one even before you verify a phone number, so this includes anonymous visitors), how long the step took, and, where you arrived from a link or campaign, the referring URL and its tracking parameters. This log does not contain your phone number, your name, your email, your address, your GPS coordinates, or your photos. Our separate site visit log, described above, is what records your IP address. We use this to see where people get stuck, to fix the flow, and to decide which neighborhoods and categories to work on next. It is readable only by SidewalkSnitch operators and is never sold or shared.

What we do with your information

Photos and complaint text are stored to your account so you can view them in My Reports, and are sent to the city agency you select (DOT, DSNY, NYPD, or 311) as part of filing the complaint. The agency receives your real name, mobile number, email, and address — they require a contactable submitter for follow-up.

Other users never see your name, phone, email, or address. Your My Reports view is private to your own account. Anywhere else a submission of yours is shown to other people, the most that is ever attached to it is your screenname.

The public activity feed. Once you submit a report, it appears in a public activity feed — on the app's home screen and on the community map — that anyone can read without signing in or having an account. A feed entry carries only: the location, coarsened before it leaves our servers (the street address is reduced to its hundred block, so “312 E 9th St” becomes “300 block of E 9th St”, and the map coordinates are rounded to roughly 110 metres); a category label such as “Parking” or “Trash / Sanitation”; the status of the report; roughly when it was filed (the date is coarsened, and every report is withheld from the feed for at least 24 hours after you submit it); and aggregate like and comment counts. It does not carry your name, your screenname or any other identifier of you, the name of any business or person the report is about, the AI's written description of what it saw, or any license plate.

Photos on that feed. When you submit, you choose where the report goes. If you choose the public route (311), your photo may appear on that feed; if you send the report privately to a business instead, it never does. A photo only reaches the feed after an automated service blurs faces and license plates in it (see “Third parties we share data with”), and only the blurred copy is published — never your original upload. Be aware that once a blurred photo has been served publicly, we cannot guarantee that copies already downloaded, cached, or screenshotted by others stop being reachable, even after you delete the report.

Comments and votes. If you comment on a post, your screenname — never your name, phone, email, or address — appears next to your comment, publicly, to anyone who opens that post. Your comment text is screened by automated tools (see “Third parties we share data with”) before it's published; comments that fail screening or are flagged by other users are held for review and are not shown publicly until reviewed. Votes on posts and comments are recorded against your account but are never displayed publicly or attributed to you. If you flag someone else's comment, that action is recorded against your account for abuse-prevention purposes; it is not shown publicly.

License plates. For parking complaints, our AI may extract a plate visible in your photo. We then check that plate against NYC's public Open Parking and Camera Violations dataset and show you the vehicle's prior-violation summary ephemerally on the result screen. We do not store the prior-violation history on your complaint record. The plate itself is stored as a structured field on your complaint because the eventual 311 filing requires it.

Crime reports may be shown on a public city map. Faces and license plates in those photos are blurred server-side before publication. Your name and contact information are never displayed alongside crime reports.

AI processing. Photos and the text you write are sent to xAI's Grok vision model for analysis. We do not send your name, phone, email, or address to the AI — it doesn't need them.

Sending a report to a business. For some kinds of reports — not parking, and not lost & found — if you picked a specific business from the address search, you can choose to send the report to that business instead of, or as well as, filing it with the city. This is your choice; nothing is sent to a business unless you tap that button.

If the business has already claimed its listing with us, sending the report opens a private two-way message thread between you and that business. In that thread the business sees: your screenname only — never your real name, phone number, email address, mailing address, or account ID — plus the category of the report, the address you gave for the issue, the AI's written description of the photo, and anything you write in the thread. We also email the business to tell them a message is waiting; that email contains only the category of the report and the business's own publicly listed address, and describes the report as unverified and submitted by a resident. It contains no information about you and none of your text. Your photo of the issue is never sent to the business. If you attach a photo to a message inside the thread, a human reviewer at SidewalkSnitch checks it before the business can see it. The business can reply, and we email you to say they replied — that email names the business but does not quote what they wrote. The business can close a thread, after which neither side can add to it and it becomes read-only. No one other than you, that business, its invited managers, and SidewalkSnitch operators can read the thread.

If the business has not claimed its listing, no message thread is created and we do not email that business. We record internally that a report of that category was made about that address, together with your account ID, so the business can see it if it later claims the listing.

How we decide which businesses to approach. Every time a report is sent to a business we email ourselves a note containing the business's name, address, category of report, and its Google listing ID — and nothing about you. We also keep an internal list of businesses that reports have been filed about, ranked by how many reports there are, how recent they are, and how many different categories they span, so we can decide which business owners to contact and invite to claim their listing. That list is built from the reports themselves. It is never sold, shared, or licensed, and no business is ever told who reported it.

Business manager invites. A verified business owner can invite managers to help answer messages by entering their mobile number. We don't store that number in the clear — only a one-way keyed hash we use to match and confirm the invite, plus the last two digits so the owner can recognize who they invited. A manager record is created only after the invited person accepts.

Suggest a Rule. If you use Suggest a Rule, the text you write (and any photo you attach, with location and other identifying metadata removed the same way it is for other uploads) is sent to xAI's Grok model to check whether a similar rule already exists and, if not, to draft proposed language — see “Third parties we share data with” below. We also use your address (already collected for filing) to determine your City Council district using a public district-boundary dataset, entirely on our own servers; we do not send your address to any third party for this purpose. If your suggestion passes review, your screenname — never your name, phone, email, or address — appears publicly next to it, and other users can upvote or downvote it, the same as comments. We do not send your suggestion to any government official ourselves — we show you a pre-filled draft and public contact information for your Council member, and you decide whether and how to send it.

Photo metadata, in detail

Every photo path runs through a fail-closed strip-and-transcode step before upload (see src/lib/image/ensure-jpeg.ts). A JPEG is parsed byte-by-byte and its APP1 (EXIF/XMP), APP2 (ICC profile, camera maker notes), APP13 (Photoshop/IPTC), APP14 (Adobe), and APP11 (JPEG-XR/EXIF extension) segments are removed. A non-JPEG (PNG or HEIC, which can also carry GPS) is re-encoded to a fresh JPEG via the browser canvas, which drops all embedded metadata; if it cannot be processed, the upload is refused rather than stored. Either way, the stored JPEG has no camera model, no camera serial, and no embedded GPS.

We read your photo's EXIF GPS coordinates before stripping them from the file, and use them to pre-fill the location of your report. We keep these coordinates (latitude/longitude plus a reverse-geocoded address) on the complaint record, and — because location is a strong learning signal — we retain a copy in our AI training set so the model can learn where different kinds of issues occur. The stored image file itself still contains no embedded GPS. If you delete your account, we remove these coordinates from both your reports and the training set.

Retention and deletion

Photos and complaint records: retained as long as your account is active. When you delete your account, the records are soft-deleted and purged within 30 days.

Business message threads: when you delete your account, every thread you started is deleted outright — the messages on both sides, and any photos in them. We keep only a record that a thread with that ID existed and was purged, containing nothing about you or its contents. The internal note recording that a report of a given category was made about an unclaimed business is retained.

Abandoned analyses (you uploaded a photo but didn't submit): purged within 30 days.

Plate-lookup records: we keep an audit log of every plate lookup (which user, what plate, when, did they file a complaint) for 7 years, to support our own use justification under federal law. The audit log entries do not include the violation history itself — only the plate string.

Suggestions: if you delete your account, your published rule suggestions remain visible to preserve the public civic discussion, but your screenname is replaced with “[deleted]” and no longer linked to your account. Suggestions that were held for review, blocked, or removed at the time of your deletion request are permanently deleted, not retained.

To delete your account: open the app → More → Delete account. Or email hello@sidewalksnitch.com from the email address on file.

Your rights

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) give you the right to know what we collect, request deletion, and not be discriminated against for exercising those rights. We honor these requests for all users, not just California ones.

If you are a New York resident, the New York SHIELD Act applies; we maintain reasonable administrative, technical, and physical safeguards for the information we collect. Any breach affecting NY residents will be reported to the NY Attorney General within the statutory window.

We do not sell your information. We do not have any business arrangement under which any personal information is exchanged for money or anything of value.

Third parties we share data with (subprocessors)

  • Google / Firebase — authentication, Firestore database, and Storage hosting (us-central region).
  • xAI — AI photo analysis via the Grok API; automated screening of the text of comments and rule suggestions you post before they're published (checking for PII about other people, harassment, and unsupported accusations); and, for Suggest a Rule, checking whether a proposed rule already exists and drafting proposed rule language. We do not send your name, phone, email, or address to xAI for any of these purposes.
  • Vercel — application hosting and serverless functions.
  • Google Places / Maps Platform — resolves an address you type (for filing a complaint, or for Suggest a Rule) to geographic coordinates and a formatted address, including to determine your City Council district for Suggest a Rule. Part of the Google/Firebase relationship above.
  • Vercel Web Analytics — measures site traffic and how people find us using cookieless, aggregate analytics. It sets no cookies, does not build advertising profiles, and does not track you across other sites. Visitors are counted using a temporary hash derived from the incoming request that is discarded within 24 hours; we get only aggregate counts (pageviews, referrers, approximate location, browser/device type), never data tied to you as an individual. There are no third-party ad trackers on this site.
  • Twilio — When a business owner asks us to verify their ownership of a business listing by phone, we use Twilio to place an automated verification call to the phone number that Google publicly lists for that business, and to speak a one-time code. Twilio processes that business phone number and call metadata (such as call time and status) to place the call on our behalf. This is separate from the SMS sign-in codes we also send through Twilio via Firebase. We do not send your name, email, or address to Twilio for this purpose.
  • Resend — transactional email: the phone-auth email magic-link sign-in, and the notification emails described under “Sending a report to a business” (sent from the verified contact.sidewalksnitch.com domain).
  • SendGrid — email delivery of filed complaints to city agencies (e.g. DOT, DSNY) when configured; otherwise sent via direct SMTP.
  • Sightengine — server-side face and license-plate blurring. It receives the photo of any report you chose to make public, before that blurred copy is shown on the public feed, and would do the same for crime reports (that feature is currently switched off).
  • Upstash — rate-limit counters (keyed by phone number or IP).
  • Sentry — error monitoring: crash reports and error diagnostics (stack trace, browser/OS, route). Configured to send no default personal identifiers; photo data and request bodies are scrubbed before sending, and session replay is off.
  • Twilio (via Firebase Phone Auth) — SMS one-time verification codes.
  • Socrata / Tyler Technologies — host for NYC Open Data, the source of posted-sign and plate-violation lookups.
  • NYC 311 / city agencies — recipients of filed complaints (DOT, DSNY, NYPD).

Children

SidewalkSnitch is intended for adults. We do not knowingly collect personal information from anyone under 13. When you verify your phone number, you confirm you are at least 13 years old. If you believe a child has provided information to us, email hello@sidewalksnitch.com and we will delete it.

SMS verification

We use SMS one-time-passcodes (via Firebase Phone Auth, sent through Twilio) to verify your phone number before you can file a complaint. By tapping “Send code” you consent to receive that SMS. Standard message and data rates may apply. Reply STOP to any verification message at any time to opt out. We don't send marketing SMS. We may also send a single transactional text when you are admitted from the invite waitlist (a login link so you can sign in with that same number). Reply STOP to opt out of those messages.

AI-generated content

The complaint text you see on the result screen is drafted by an AI model from your photo. Before you submit, you must read the text, edit anything inaccurate, and explicitly attest that what it describes is what you personally observed. The submitted text is your statement on the record, not the AI's.

Contact us

Questions, complaints, or deletion requests: hello@sidewalksnitch.com.

← Back to SidewalkSnitch

Privacy Policy — SidewalkSnitch NYC Complaint App