Privacy policy

Last updated 27 Jul 2026

VillageWatch exists to move safety information around a village without moving people's personal details with it. This page explains exactly what we hold, why, who else sees it, and how to get it back or get rid of it.

Before this village goes live

The contact details and data controller named below are placeholders. Your parish council must complete them, register with the ICO if it has not already, and have this notice reviewed alongside its own data protection policy before any resident signs up.

1. Who is responsible for your data

This notice covers VillageWatch, the community safety reporting service at villagewatch.app.

Your parish council is the data controller for everything described here. They decide what VillageWatch is used for and they answer for it. VillageWatch provides the software and processes data on their instructions.

[Parish Council name]

[Parish Council address line 1]

[Town]

[Postcode]

Email: [clerk@parish-council.example.uk]

Telephone: [01234 567890]

ICO registration: [ICO registration number]

2. What we collect

When you create an account

  • Your name and email address.
  • Your village, and a join code if your coordinator gave you one.
  • Optionally, your telephone number and street or address. The address is used by your coordinator to confirm you actually live in the village. It is never shown to other residents.
  • Optionally, an approximate home location that you pin on a map. We shift the point you drop by up to 100 metres before saving it, and we never ask for your exact address on the map. It is used for one thing only: deciding whether an incident is close enough to be worth alerting you about.

When you file a report

  • What you wrote, in your own words. This is kept separately from the version other residents see, and it is restricted to you, your village coordinators and moderators. Every single time one of them opens it, that is recorded with their name and the time.
  • The anonymised version. A rewrite with names, registration plates, addresses and other identifying details removed. This is what appears on the map, in the incident list and in alerts.
  • An approximate location. Every pin is moved by a random offset of up to 100 metres before it is saved. The exact point you tapped is never written to our database, so it cannot leak later.
  • Photos and video, after redaction. See the next section — the originals stay on your device.
  • The category, how serious you judged it, when it happened, any landmark you typed, and whether you have reported it to the police.

While you use the service

  • Your notification preferences: whether you want push alerts, the minimum severity worth disturbing you for, and how close an incident has to be.
  • A record of privileged actions — publishing, rejecting, editing, exporting, and every read of an original report — including who did it, when, and from what IP address and browser. This is the accountability trail. It cannot be edited or deleted, by anyone, including us.
  • If you turn on push notifications, an anonymous device identifier held by our notification provider so that a message can reach your phone.

3. What we do not collect

Photos with faces in them never leave your device

Face detection runs in your browser, on your phone or computer, before anything is sent. Every face found is covered there and then. Your village coordinator chooses how — a solid black box, or a mosaic that reduces the face to a handful of blocks and then blurs it — and you can always choose the black box for your own photo whatever your village is set to. Every one of those options destroys the face before the file is made: the original pixels are gone, not hidden. What gets uploaded is a re-encoded copy of the covered image, which also strips the EXIF block, including the GPS tag that would otherwise say exactly where the photo was taken. There is no server-side fallback that accepts the original. If the faces cannot be covered, the upload does not happen.

We also do not collect any of the following:

  • Your exact location, at any point. Not when you file, not in the background, not ever.
  • Your precise home address on a map.
  • Analytics, advertising identifiers, or any behavioural tracking. We run no third-party analytics and no advertising.
  • Payment details. VillageWatch is free for residents and takes no payments.
  • Special category data, deliberately. Reports sometimes touch on things like someone's health or ethnicity because a resident described what they saw — the anonymisation pass exists to take that out, and coordinators are asked to reject anything that survives it.

4. Why we use it, and our lawful basis

Running your account — contract, Article 6(1)(b)
We need your name, email and village to give you an account, put your reports in the right place and let you sign in.
Community safety reporting — public task, Article 6(1)(e)
A parish council keeping its residents informed about local safety is exercising a function in the public interest. This covers publishing anonymised reports, showing them on the map and alerting nearby residents.
Push notifications — consent, Article 6(1)(a)
Alerts only go to residents who have switched them on and granted their browser permission. You can withdraw that at any time in Settings, or in your browser, without affecting anything else.
Moderation and the audit trail — legal obligation and legitimate interests, Article 6(1)(c) and (f)
Reviewing reports before publication is what stops personal details reaching a few hundred neighbours. Logging who read an original report is what makes that promise checkable.

Reports frequently describe suspected criminal offences. Personal data about criminal offences has extra protection under Article 10 of the UK GDPR and Schedule 1 of the Data Protection Act 2018. This is precisely why the original wording of a report is restricted to coordinators, audited on every read, and never published — what residents see is the version with the identifying details taken out.

5. Automated processing with AI

When you file a report, the text you wrote — and a still frame from a photo, if you attached one and its faces have already been covered — is sent to Anthropic, the company behind the Claude AI models, and processed on their servers. Claude rewrites the report with identifying details removed, suggests a category and a severity, and pulls out a few keywords.

  • You see the result before anyone else does. The rewrite comes back to your screen for you to read, edit or reject. Nothing is saved until you press publish.
  • It is not a decision about you.There is no automated decision-making with legal or similarly significant effects, in the sense of Article 22. The rewrite is shown to you before anything is saved, and nothing is published unless you accept it — the AI's judgement is advice, never the last word.
  • Whether a coordinator reads it first is your village's choice.By default every report waits in a moderation queue until a coordinator approves it, and that is what the screens tell you as you file. A village's coordinators can switch that off, in which case reports are published the moment you press publish and you are told so on the screen before you do. Either way the anonymised text is what other residents see, and your original wording stays restricted to you, your coordinators and moderators.
  • If it is unavailable, nothing breaks. Reports filed when the AI cannot be reached use your own wording, and the screen says so — including a warning that they will be published as written if your village has turned review off.
  • Anthropic processes this data as a processor on our behalf, under their commercial terms, and does not use it to train their models.

The AI is a filter, not a guarantee. Assume a coordinator will read your original words, and write your report as though the person you are describing might one day read the published version.

6. Who else sees it

We do not sell your data and we do not share it for marketing. It is shared only with the following:

Other residents of your village
The anonymised report, its category, severity, approximate location and any redacted photos. Your name, unless you filed anonymously. Never your original wording, your address, your email or your home location.
Your village coordinators and moderators
Everything above, plus your original wording — recorded each time — and your name against the report even when you filed anonymously to other residents.
Anyone, if your village runs a WhatsApp Channel
A WhatsApp Channel is public: anyone holding the invite link can read it, in or out of the village. Your village coordinator decides whether to run one, and it is switched off unless they turn it on. Nothing is posted automatically — WhatsApp gives an app no way to write to a channel, so a coordinator copies the alert and posts it themselves, which means a person makes the decision each time. An alert carries a headline, an approximate area, how long ago it happened, a short extract of the same report your neighbours see, and a link back to this app. Never your name, never the coordinates, and never a photograph.
Your local police officer and parish council, in a summary from a coordinator
Your village coordinator can produce a written summary — of one report, or of everything published over a period — and send it to your PCSO or to the parish council. This is what a neighbourhood watch scheme is for, and it is the same information your neighbours already see: the anonymised description, the category, how serious it was, when it happened and the landmark the reporter named. Never your original wording, never your name or contact details, never the map coordinates, and never a photograph. A summary covering a period is recorded in your village’s audit trail. A single report’s summary is the same text already on the village map, so it is not recorded separately.
The police, on request
Separately from the above: where there is a lawful basis to disclose, such as a formal request in the investigation of a crime. That can include your original wording. Your parish council decides this, not VillageWatch, and the disclosure is logged.
The people who run this service
We keep an internal staff channel on Slack that is told when somebody registers, when a report is published, and when somebody applies to become a coordinator. It carries your name, and on registration your email address, so that the people running VillageWatch can see the service is working and spot abuse. For a published report it carries the same headline, severity and approximate area your neighbours see — never your original wording, never your address, never coordinates, and never a photograph.
Our processors
Supabase (database, authentication and file storage, in the UK or EU), Vercel (hosting), Anthropic (the AI pass described above), OneSignal (push notification delivery), and Slack (the staff channel above). Each acts only on our instructions, under a written data processing agreement in every case but Slack — see below.
Slack (Salesforce), and why it is listed separately
Administrative notifications only, to a private channel that only the people who run VillageWatchcan read. It is never used to deliver anything to a resident and no part of this service depends on it. What a message carries is an anonymised incident summary — the same headline, severity and approximate area published to your village — or the fact that somebody has registered, applied to coordinate, or been given coordinator access. Never your original wording, never your address, never coordinates, and never a photograph. It does carry your name, and on registration your email address, so that abuse can be spotted; nothing else about you is sent. We have no separate data processing agreement with Salesforce beyond Slack’s standard terms, which is why this is set out here rather than left inside the list above. If you would rather this disclosure did not happen at all, tell us using the contact details in section 13 and we will act on it.

Map tiles come from OpenStreetMap and are fetched by your browser directly, so their servers see your IP address as they would for any website you visit. No report data is sent with those requests.

Some of our processors operate outside the UK. Where data is transferred, it is protected by the UK International Data Transfer Addendum or an adequacy decision.

7. How long we keep it

Photos and video — 6 months
Deleted from storage entirely, redacted copies included. A photo is the most identifying thing in a report and the least useful once the incident is old.
Reports — archived at 12 months
Archived reports leave the map and the incident list. The anonymised text is retained beyond that only in aggregate, for the pattern history a village needs to see year-on-year trends.
Original report wording — 12 months
Deleted when the report is archived. After that, only the anonymised version remains.
Audit records — 24 months
Kept longer than the reports they describe, because their whole purpose is to show, afterwards, who looked at what.
Inactive accounts — 24 months
An account with no sign-in for two years is closed and its personal details removed. Reports already published stay up, detached from the account.
Accounts you close yourself — immediately
Closing your own account from Settings does not wait for any of the periods above. Every report you filed is deleted there and then, the photos are removed from storage, and your name, address, phone number and approximate home location are erased from your profile. Your email address is kept, because it is what stops the closed account being signed into again.

8. Your rights

Under the UK GDPR you have the following rights. Contact your parish council using the details in section 13 to use any of them. They must respond within one month, and it is free.

Access
Ask for a copy of the personal data we hold about you, including your reports in their original wording and the record of who has read them.
Rectification
Have inaccurate details corrected. You can edit your own report yourself, in the app, at any point before a coordinator has reviewed it.
Erasure
Ask for your data to be deleted — and you do not have to ask us. Any report you have filed has a Delete button on its own page, whatever stage it has reached, published included; and Settings has a Delete my account option that does the same to every report you have ever filed and closes the account. Both act immediately. Deleting a report removes its wording, its location and any photos or video, and takes it off the map; the photos are deleted from our storage, not merely hidden. What is left is the reference, the category, how serious it was and the date — a report the village can still count without a word of what you wrote. Audit records cannot be deleted: they are the accountability trail, and a trail that can be erased on request is not one. They record what a coordinator decided about a report, not what the report said.
Portability
Receive the data you gave us in a structured, machine-readable format, or have it sent to another controller.
Objection
Object to processing carried out under our public task or legitimate interests. Tell us why it affects you, and we will stop unless we can show compelling grounds that override your interests.
Restriction
Ask us to hold your data but stop using it, for example while a complaint about its accuracy is being resolved.
Withdraw consent
Turn push notifications off in Settings at any time. Withdrawing does not affect anything done before you withdrew.

9. Children and young people

You must be at least 16 to hold a VillageWatchaccount. We do not knowingly create accounts for anyone younger, and we do not ask for anyone's date of birth beyond that confirmation.

Reports frequently mention young people — a group causing a nuisance, a missing teenager, someone seen near a shed. That is legitimate and the service is built for it, with three safeguards:

  • The anonymisation pass removes names, schools, and descriptions distinctive enough to identify one particular child.
  • Faces are covered before any photo is uploaded, at every setting a village can choose, so a photograph of a child cannot be published even by mistake.
  • Coordinators are asked to reject any report that names or clearly identifies a child, and to route safeguarding concerns to the police or to children's services rather than onto a village map.

If you believe a published report identifies a child, contact your coordinator or the council and it will be removed while it is reviewed. If a parent or guardian asks us to remove data about their child, we will do so.

10. How we protect it

  • Everything is served over HTTPS, and the browser is instructed never to use anything else.
  • Your village is a hard boundary. Every query for reports, residents and alerts is scoped to it, and that scope comes from your session on our servers — never from anything a browser sends.
  • Original report wording sits behind a deliberate action that records who read it, rather than being loaded onto a page where a glance leaves no trace.
  • Passwords are handled by Supabase Auth and are never stored by us in any form we can read.
  • The database enforces access rules of its own, underneath the application, so a bug in one screen cannot expose another village's reports.

If a breach occurs that is likely to risk your rights and freedoms, we will report it to the ICO within 72 hours and tell you directly where the risk is high.

11. Cookies

VillageWatch sets only strictly necessary cookies: the ones that keep you signed in and protect the sign-in form. There are no analytics cookies, no advertising cookies, and nothing that follows you to other sites — which is why you have not been asked to accept anything.

12. Changes to this policy

We will update this page when what we do changes, and the date at the top will change with it. Where a change materially affects you — a new processor, a new purpose, a shorter or longer retention period — we will tell you in the app before it takes effect.

13. Contact and complaints

For anything in this policy, including a request to exercise your rights, contact your parish council at [clerk@parish-council.example.uk] or write to them at the address in section 1.

If you are not satisfied with the response, you can complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113. We would rather you came to us first, but you do not have to.

See also our terms of use, which cover what may and may not be posted.