How exposure data is de-identified
DRAFT placeholder. The public catalog publishes only de-identified, aggregate exposure data derived from human-subjects wearable runs. It is protected by a k-anonymity disclosure floor computed over distinct Subjects (not over records): an aggregate is shown only when it covers enough distinct Subjects to meet the floor, so no cell can be traced to one person.
Geography is published only down to a public county floor; finer location is never released publicly. Raw coordinates are never stored — the GPS polyline is dropped at ingestion (ETL) and only coarsened geography survives. Subjects are referenced by a pseudonym, never by name.
What visitor data we collect
We do not track visitors. Browsing the public catalog sets
no analytics, no advertising cookies, and no visitor identifier. The
site serves its own scripts only (Content-Security-Policy connect-src 'self');
there are no third-party trackers.
Your acceptance of these notices is remembered only in your own browser
(a terms_ack value in localStorage). It is
never sent to or recorded by the server — there is no per-visitor consent
record and no audit row for visitors. Standard transport/operational logs may record a
request's IP and timestamp for security, but these are not used to profile visitors.
Staff & researcher access
Access to the individual-record Limited Data Set (city-tier geography + dates + Subject pseudonyms) is restricted to vetted staff/researchers and gated behind a recorded, audit-logged Data Use Agreement. That is a separate, stronger control than this visitor notice — see the Terms.
Questions about this notice: contact the study team. (DRAFT — contact details pending.)