Resident information
Privacy notice
What Spruce collects, why it is needed, what may become public, and the choices residents keep.
Last updated: 2026-08-29
The boundary in one minute
Anyone can browse public Spruce information without an account. Trust-bearing actions require Sign in with Apple. Public identity is pseudonymous by default.
Private drafts, original evidence, precise issue details, account identifiers, and safety or support records stay outside the public case unless you deliberately approve specific public material.
Information Spruce handles
Depending on what you choose to do, Spruce may handle an Apple account identifier, session and device-notification tokens, a pseudonym, private report text, issue location, evidence, approvals, community actions, points records, moderation or support records, and security logs.
- Location is used in the foreground to route an issue and find nearby cases. You can provide a location manually. Spruce does not use background location.
- A photograph is optional. Private originals are separated from any approved public derivative.
- Issue location is separate from a contributor's temporary location and is published only at the approved precision.
Public cases and X outreach
Before publication, the resident reviews the material public facts and any exact initial X copy. Spruce—not the resident—may later publish approved outreach from a Spruce-owned account after moderation and operator review.
An X post is public outreach, not an official government filing. Public copies and third-party caches may remain outside Spruce's control even after a correction or takedown request.
Scout and model data
Scout uses report material and versioned civic sources to offer editable, sourced guidance. Operational use is separate from model-training consent. Spruce does not place a report in a training dataset unless the resident separately opts in and the material passes provenance, redaction, licensing, adjudication, retention, and deletion checks.
Sharing and service providers
Spruce may use reviewed infrastructure, security, notification, mapping, support, and model-service providers only for documented product purposes. Providers must be contractually reviewed for access, protection, retention, deletion, incident duties, and exit.
The beta does not send an official filing to a municipality. A future official integration would require a separate exact authorization and disclosure before data leaves Spruce's boundary. Spruce may preserve or disclose information when legally required under a reviewed legal-process policy.
Retention, deletion, and consent
An unpublished private draft expires after 30 inactive days unless a valid safety or legal hold applies. Account deletion can be started in the iPhone app and is not blocked by an active case. Primary deletion is designed to complete within 30 days, with deletion tombstones reapplied before restored backups serve traffic.
Erased account identity, private payloads, and user-generated material are separated from mature non-personal civic facts and audit records that may remain under published retention rules or a lawful hold. You can withdraw optional training consent without losing core product access.
No behavioral advertising or sale of personal data
The first release has no ads, ad SDK, cross-app tracking, fingerprinting, data-broker enrichment, background location, or sale of individual data. Private evidence, identity, precise contributor location, civic viewpoint, and verification activity are not monetization inputs.
Age and contact
Accounts are for people age 13 or older. Spruce is not directed to children under 13 and does not knowingly permit them to create an account.
Use the privacy contact below to ask about access, correction, deletion, consent, or this notice. Legal rights can vary by location; counsel review remains a launch gate.