Privacy
The short version, because it is the question a cautious firm actually asks: to derive anything at all, this software sends your site boundary to public data services run by the United States government, and it sends an address you type into the search box to the United States Census Bureau. Section 3 says exactly which, and exactly what goes to each one.
One recipient in section 3 is not a government service. If the optional assistant is switched on for the deployment you are using, your questions and your site's record go to a commercial language model vendor. It is off by default in the software and switched on for this service, the tool tells you which state it is in, and section 3, the assistant says exactly what is sent and what is not.
1 Who is responsible for your data
CZDTS LLC, whose mailing address is 4539 N 22nd St #5089, Phoenix, AZ 85016, USA, is responsible for the personal data described here. If you have a question about it, write to support@curvenumber.com. That is the one address this product publishes and it is the one that is read; it is used here for a privacy question, for a security report and for a formal notice alike, because no separate privacy or security mailbox exists and an address printed in a notice that receives no mail is worse than a general one that does.
Until 22 September 2026 this section named a different company. The product is now operated by CZDTS LLC and no part of it is operated by the previous entity.
[To be completed after legal review: the state CZDTS LLC is organized in, the law that governs, and the courts that hear a dispute.]
[To be completed after legal review: which privacy laws apply, and the disclosures they require in this notice.]
2 What we collect
Only what the service needs to work. There is no tracking, no advertising and no analytics on this website or in the tool.
3 What is sent to third parties
This is the part worth reading properly. CurveNumber derives its inputs from public datasets, and there is no way to do that without asking those services about your site. The first six services below are run by agencies of the United States government; the rows after them say what is commercial and what is not a request at all. We have no agreement with any of the public ones, we do not control them, and what they do with a request is governed by their own policies, not ours.
One further recipient is a commercial company rather than a public dataset, it receives much more than geometry, and it only exists when the optional assistant is switched on. It has its own part of this section, below the list.
The companies that handle your data for us (hosting, backups, email, the AI assistant and card payment) are listed on one page: companies that handle your data.
Three things follow from this that are worth stating plainly:
- A site boundary sent to those services is a statement that somebody is interested in that piece of ground. If the existence of your interest in a parcel is itself confidential, that is a reason to think before deriving it here, and we would rather you knew that before you started than afterwards.
- We cache the responses those services return, keyed on the request. That is partly speed and partly manners, since several of them are unfunded public endpoints. A cached response is data about your site sitting on our server, and it is deleted with the rest of your data.
- We do not send your name, your email address, your client's name or your project name to any of those services. They receive geometry, or an address, and nothing that identifies you. The assistant, below, is the one recipient that receives your project name, and it is the reason that sentence now says "those services" rather than "anyone".
The assistant, and the model vendor behind it
The tool has an optional assistant: you type a question about one of your sites and a language model answers it, using your site's record. It is off by default in the software and switched on for this service. On a deployment where it is off there is no model, no vendor and no request: the assistant screen is not there, the routes answer "not enabled on this deployment", and the warnings the tool raises about your site are produced by the engine with no model involved at all. If it is on, you will see the assistant in the tool, and every question you ask it sends a request to a vendor.
person-abcdef, so the assistant can say that two changes were made by the
same person without being told who that person is. That replacement runs over
everything this software puts in a request on your behalf, on every route that sends
anything, which is to say the record, the change log, an override or waiver reason you
typed, and the text of a document you attached, and not only over the parts it looks up
while answering. The one thing it does not rewrite is the question itself, which is
sent as you typed it; see the row below. Also not sent: the site
address you entered in the address field, the client name you entered
in the client field, your own name and organization, your API key, your
account id, and the drawn boundary itself: the polygon never goes to the vendor, only
the acreages and the values computed from it. There is no user identifier attached to
the request.Two honest notes about the assistant, in the same spirit as the rest of this page. The first is that an answer it gives is checked by the software before you see it: every figure has to be one the record holds, and every citation has to be something retrieved in that turn. That check is ours, it is not the vendor's, and it is not a guarantee that the answer is right. The second is that we cannot see what the vendor does with a request after it arrives, any more than we can see what the federal services do with a boundary. What we control is what leaves this server, which is what the two rows above describe.
4 What we do not do
- We do not sell your data, and we do not share it for anyone else's marketing.
- We do not run analytics, advertising or third party tracking on this website or in the
tool, and there are no tracking cookies. The tool sets two cookies, both needed for it to
work:
cn_sessionkeeps you signed in, for up to 14 days, or until 24 hours pass without use, or until you sign out, andcn_publicationremembers for up to one hour that you unlocked a password-protected published report. The website sets none. - We do not take card details.
- We do not use your site data to train anything, and we never will. Nothing you put in this product is used to train or tune a model by us.
- No number in this product is produced by a model. Every figure comes out of the engine: published tables, published methods, and arithmetic. That is true whether or not the assistant is switched on, and it is enforced rather than intended: the assistant can read every value and explain it, and a response containing a figure the record does not hold is blocked before it reaches you. What the assistant is, and what it sends where, is in section 3.
5 Where it is stored, and for how long
Your data is stored on our own server in the us-east-1 region, which is Northern Virginia in the United States, and the backups of it are stored in the same region. We keep it while your account is open, because the point of the audit trail is that it is still there when a reviewer asks about a report two years later.
Closing an account does not delete anything: its projects, sites, runs, reports and audit records are kept, and the account can be reopened, as the terms say. We never delete an account because it has not been used.
Deleting. [To be completed after legal review: draft wording, pending counsel approval.] You can download everything on your account as one ZIP file at any time, and the tool offers it before anything is deleted. A project or site you delete goes to the trash for 30 days, where you can restore it; after that it is deleted for good. Its published links stop at once and say the analysis was withdrawn by the author, with the date. You can also ask the tool to delete your whole account: after 30 days, in which you can change your mind, all of its content is deleted and we email you to confirm. Two things are kept after that: billing and payment records, with the record of money moved on the account, for 7 years, and a one-way fingerprint of your email address, so that free site codes cannot be claimed again. Deleted data then ages out of the backups, which takes about 120 days, as described below. What follows is what the infrastructure enforces rather than a period we would like to be true.
Backups. The server keeps the eight most recent database snapshots on its own disk and deletes the rest as each new one is taken, which at one snapshot an hour is roughly the last eight hours. That is a count and not a period, and it is written here as a count for that reason. The copies held in object storage expire on a rule: fourteen days for the hourly ones and ninety days for the one taken each day. A continuous copy, a few seconds behind the live service, is kept in the same storage for three days, and a file it retires stays recoverable for seven more. A copy that is replaced can be recovered for a further fourteen days (hourly) or thirty days (daily). So about 120 days is the outside figure for a backup of your data.
Logs. The web server's logs are rotated daily and fourteen are kept, so fourteen days is the most, and it can be less: the same rule rotates a log early if it passes 100 MB. The application's own log is not kept by age at all. It rotates when it reaches 5 MB and three rotations are kept, so what exists is the last 20 MB of request records rather than the last any number of days, and on a busy week that is a shorter period than on a quiet one. We would rather say that than quote a retention period the software does not enforce. The system journal is capped at 300 MB and at one month, whichever is reached first.
Those are the copies on the server itself. A second copy of the web server's logs and the application's log is sent, as each line is written, to Amazon CloudWatch Logs in the same region, so that a fault can still be investigated if the server is lost. That copy is deleted after thirty days, so thirty days is the outside figure for a log line.
Billing records are kept for 7 years, because we are required to keep them. [To be completed after legal review: the period, drafted as 7 years, pending counsel approval.]
Deleting a project or a site for good deletes what hangs off it, including its audit records, and cannot be undone. Keep your own copy of anything you may need to show a reviewer later.
An assistant conversation is stored against its site. You can delete one on its own without deleting anything else, and section 6 says what that does and does not remove. A request already sent to the model vendor is out of our hands in the same way a report already sent to a reviewer is: deleting the conversation here does not reach their copy, and their retention is governed by their terms.
6 Your choices and your rights
You can see everything on your account from inside the tool, and you can download all of it (every project, site, run, report and published copy) as one ZIP file at any time. You can ask us to correct something, to delete your account and its data, or to send you a copy of it, by writing to support@curvenumber.com. We will respond within [To be completed after legal review: the response time].
If you have used the assistant, there is a delete control on the assistant screen for each site. It removes that site's conversation and everything remembered from it: the messages, the statements the assistant kept from them, anything you told it about the site, the documents you attached, the dismissed warnings, and the log of each turn including any response that was blocked before you saw it. Three things survive it, and the tool says so rather than leaving you to assume: the operator's cost ledger, which holds a model name, a token count and a cost and no site data; the record of how much of the site's AI allowance has been used, because an allowance you could reset by deleting a conversation would not be an allowance; and the site's own change log, which is the audit trail of the site rather than of the conversation, and which goes when the site goes.
Two honest limits. A report you have already sent to a client or a reviewing authority is out of our hands, and deleting your account here does not reach it. And an override record inside a report is part of the document's meaning, so we will not edit one in place; the remedy for a record you disagree with is to supersede it, which the software supports and which leaves both entries visible.
[To be completed after legal review: your specific rights, and where you can complain.]
7 Security
Traffic to the service is encrypted in transit. Your API key is stored only as a hash, so a copy of our database does not yield working keys. Access to the server is limited to the people who operate it.
We will not claim more than that. This is a small pre-launch product and it has not been through an independent security audit. If you find a problem, write to support@curvenumber.com and we will take it seriously. There is no separate security address, and we would rather send you to the one that is read than print one that is not.
[To be completed after legal review: whom we notify of a breach, how quickly, and how.]
8 Children
This is professional engineering software. It is not for children and we do not knowingly collect data about anyone under [To be completed after legal review: the minimum age].
9 Changes, and how to reach us
If we change this notice in a way that materially affects you, we will email the address on your account before the change takes effect and keep the previous version available.
Write to support@curvenumber.com, or by post to CZDTS LLC, 4539 N 22nd St #5089, Phoenix, AZ 85016, USA.
Still to be completed after legal review
- Where CZDTS LLC is organized, the law that governs, and the courts that hear a dispute (section 1).
- Which privacy laws apply (section 1), and from that: your specific rights and where to complain (section 6), breach notification (section 7) and the minimum age (section 8).
- How long billing records are kept (section 5; drafted as 7 years, pending counsel approval).
- The deletion, trash and export wording in section 5 (drafted, pending counsel approval).
- How long we take to answer a request to correct, delete or export (section 6).
- The terms in force with the model vendor and its sub-processors (section 3).