TownDesk ("TownDesk," "we," "us") provides civic software to municipalities ("towns") for citizen requests, records, meetings, and related services. This Privacy Policy explains what information we handle and how. It applies to the TownDesk platform, town-facing consoles, resident-facing embeds, and the towndesk.us website.
Who controls the data
For information about a town's residents and operations, the town is the data controller and TownDesk is its service provider (processor), handling that data on the town's behalf and under its direction. We do not sell data, we do not show ads, and we do not use residents' personal information to build advertising profiles.
What we collect
- Resident submissions — the content residents provide (a concern, question, records request, permit application), which may include a name, contact details, address or location, and photos. Reporter identity is never shown publicly.
- Staff accounts — name, work email, and role for town staff who sign in (authenticated with multi-factor sign-in).
- Operational records — meetings, agendas, documents, notes, and an audit trail of staff actions.
- Technical data — basic logs needed to operate and secure the service (e.g. request metadata, error logs). The website uses only essential cookies.
How we use it
To provide and operate the service the town has chosen — routing and tracking requests, notifying residents of updates, producing meeting materials, maintaining records for open-records (e.g. Kansas KORA) compliance, securing the platform, and supporting the town. We use it for these purposes only.
YouTube API Services
TownDesk offers an optional feature that pulls the transcript (captions) of a town's own council-meeting videos so staff can turn them into minutes. This feature uses YouTube API Services.
- By using this feature, you also agree to the YouTube Terms of Service.
- Google's handling of data is governed by the Google Privacy Policy.
- What we access: only when a town staff member connects the town's own Google/ YouTube account and clicks to pull a transcript, TownDesk uses the YouTube Data API to read the caption track of the specified video and store that transcript with the meeting record. We request read access limited to the connected account's own content.
- What we don't do: we do not access, store, or share any other YouTube data, we do not use it for advertising, and we do not share it with third parties.
- Revoking access: a town can disconnect its YouTube account from within TownDesk's settings at any time, and can also revoke TownDesk's access directly via the Google security settings page (https://myaccount.google.com/permissions). Revoking access stops any further transcript pulls; transcripts already saved to a meeting remain part of the town's records unless the town deletes them.
How we share it
We share information only as needed to run the service: with infrastructure providers that host and secure the platform (Amazon Web Services, U.S. regions), and where a town directs or the law requires. Resident submissions may be disclosable by the town under applicable open-records law; TownDesk protects reporter identity in public views.
Security
Data is encrypted in transit and at rest, staff sign in with multi-factor authentication, and staff actions are written to an audit trail. See our Security & Trust page for details.
Retention & your data
A town's records are the town's own. Towns can export their data at any time in a standard format, and can request deletion of data we hold on their behalf. We retain data for as long as the town uses the service or as required by law, and delete or return it on request when the relationship ends.
Children
TownDesk is intended for town staff and adult residents; it is not directed to children.
Changes
We may update this policy; we'll revise the effective date above and, for material changes, notify the towns we serve.
Contact
Questions about this policy or your data: privacy@towndesk.us.