San Francisco only during the initial launch. More cities soon.

Privacy

Privacy

What this service collects, which is very little, and what it does with it, which is less.

Last updated 20 August 2026

The short version

We hold your email address so you can sign in, and a list of the reports you have run so you can open them again. There is no analytics, no advertising and no tracking of any kind. Nothing is sold, and the only companies that touch any of it are the two needed to run the service at all — named below.

What we collect

Your account

That is the whole record. We do not ask for your name, your employer, your address or a password, because none of them are needed to run a report.

Your reports

Each time you run a report we keep a receipt: the address searched, its parcel number, the radius and period you chose, the time it ran, the version of the terms you accepted and when, and the size of the PDF produced. The PDF itself is stored so you can download it again.

We keep these for two reasons. You asked for the report and should be able to return to it, and the record of what was accepted and when is the only proof either of us has about the basis on which it was run.

Your security log

Every sign-in, report and download is written to a log, with the time, the IP address the request came from, and a coarse description of the browser — “Chrome on Mac”, not a full user-agent string, which would be a fingerprint.

The reason is your protection rather than our analytics. It is the only way you or we can tell whether somebody else has been in your account, and it is the first thing anyone asks for when something looks wrong. You can read it yourself under Your history, and export the whole of it as CSV or JSON at any time.

Kept for twelve months, then deleted automatically. A security log retained forever stops being a security measure and becomes a liability — for you, since it is your address in it.

It is scoped to you. Colleagues on the same plan share an allowance, not each other's searches.

What an administrator on your plan can see

A plan belongs to a company, and one person on it is the administrator — usually whoever the account was opened for. Because the reports are run against an allowance they are accountable for, an administrator can see more than a colleague can.

Nobody else on the plan can see any of that. A colleague sees only their own reports and their own log, and there is no setting that widens it for them.

If you are on a shared plan, treat the addresses you look up as visible to your administrator. Sole accounts have no second person on them, so nothing here applies to a plan of one.

Who else touches it

Four companies, each because a part of the service cannot work without them, and none for anything beyond the job named here. None of them is told who you are.

Neither is permitted to use any of it for their own purposes, and neither is sent anything for advertising, analytics or profiling, because we do none of those things.

What the city sees

Running a report queries San Francisco's own servers — data.sfgov.org, and the Planning department's map service — live, at the moment you ask. The address you searched goes to them as part of that query. Your identity does not: the request carries no email address, no account number and no cookie of ours, so the city can see that somebody asked about an address, not that you did.

This is also why the report is current rather than a copy of a copy. We hold no duplicate of the city's data, and every figure is read fresh.

What the report will not tell you about people

One section describes the housing around an address — how many homes there are, how many are lived in, and how many are owned rather than rented. Those are facts about buildings.

The same census survey publishes race and ethnicity, sex, marital status, household composition and the presence of children. This service does not request those figures and does not show them. Characterising who lives on a block is how a Fair Housing steering claim begins, and it would land on whoever forwarded the report as much as on us — which is the same reason the report gives distances to schools and refuses to rate them.

What we do not collect

Cookies

One cookie, named stb. It holds a signed token proving you signed in, it is HttpOnly so scripts cannot read it, and it is SameSite=Lax. It exists solely to keep you signed in and it expires.

There are no other cookies. No analytics, no tag manager, no advertising pixel, no session recorder. Your browser makes no third-party requests at all when it loads this site — the typefaces are served from this origin rather than a font CDN specifically so that stays true, and the one outside source the report uses is queried by our server rather than by you — which is why you are not being asked to make a choice about tracking. There is none to choose about.

Because the only cookie is strictly necessary to a service you asked for, no consent banner is required under the ePrivacy Directive or the CCPA. We would rather earn that by not tracking you than by asking you to click a box.

Where the data goes

Report content is fetched live from the City and County of San Francisco's open data portal and the Planning Department's public map services at the moment you run it. Those requests come from our server, not your browser, so those systems never see your address, your identity or your IP.

We do not sell personal information and we do not share it for cross-context behavioural advertising. We disclose it to no one except the service providers needed to operate the service — our email provider, to deliver your sign-in link, our host, which stores it, and two data services — a property listing service and an address and census lookup — which receive only the address you searched — and where the law requires it. Those are service providers in the meaning of the CPRA: they are contractually barred from retaining, using or disclosing the information for any purpose other than performing that service.

How long we keep it

Account records last as long as the account. Report receipts last until you ask us to remove them or the account is closed. Write to us and we will delete either.

Your rights

Wherever you live, you may ask what we hold, ask for a copy, ask us to correct it, or ask us to delete it. Write to hello@scantheblock.com from the address on the account and we will do it. California residents have specific statutory rights, set out on the California Privacy page.

Security

Sign-in links are single-use and expire. Session cookies are signed, HttpOnly and time-limited. That said, no service can promise perfect security, and we will not pretend otherwise.

If something goes wrong

If personal information we hold is exposed by a breach of our security, we will tell affected account holders by email without unreasonable delay, and in any case as California law requires. We will say what happened, what was affected and what we are doing about it, rather than issuing a notice that says nothing.

The best protection here is how little there is to lose. We hold an email address and a list of addresses you searched. There is no password to steal, and no payment details.

Changes

If this changes we will change the date at the top. Material changes to how we handle personal information will be told to account holders by email.

Questions about this page: hello@scantheblock.com