Privacy Policy

Last updated: 27 February 2026

1. Who we are

CitySieve is a free neighbourhood-matching tool operated by an individual developer based in the United Kingdom. You can reach us via our Contact page.

2. What data we collect and why

Account data (optional)

If you choose to sign in with Google, we receive and store your email address, display name, and profile image URL from your Google account. This is used solely to identify your account and link your saved surveys to it. You are never required to sign in — the tool works fully without an account.

Survey responses (optional)

When you explicitly save a survey using the “Save survey” button, your survey preferences (commute location, lifestyle ratings, budget range, and similar) are stored in our database linked to your account. Surveys you do not save are held only in your browser's local storage and never sent to our servers.

Session data

When signed in, NextAuth sets a session cookie in your browser (HttpOnly, Secure) to keep you logged in. This cookie contains a session token, not your personal data directly. Session records are stored in our database and expire automatically.

Location searches

When you type a location into CitySieve, the search query is sent to the Nominatim geocoding service (operated by OpenStreetMap) to retrieve coordinates. We do not log or store these queries on our servers.

3. Legal basis for processing

Under UK GDPR, we process your personal data on the following bases:

  • Contractual necessity — to provide the account and survey-saving features you have requested.
  • Legitimate interests — to operate, maintain, and improve the service.
  • Consent — for advertising cookies set by Google AdSense (see Section 5 below).

4. Third-party processors

Google

We use Google OAuth 2.0 for sign-in. Google may process your data in accordance with Google's Privacy Policy. We also display Google AdSense advertisements; AdSense may set advertising cookies on your device (see Section 5).

OpenStreetMap / Overpass API

Amenity data is fetched from the Overpass API (OpenStreetMap infrastructure). Candidate coordinates are sent as part of bounding-box queries; no personal data is included. Map tiles are served by CartoDB.

Postcodes.io

UK postcode lookups are used to label result areas. No personal data is transmitted.

5. Cookies

Necessary cookies

A session cookie is set when you sign in. This is strictly necessary for the sign-in feature and does not require consent.

Advertising cookies (Google AdSense)

CitySieve displays advertisements served by Google AdSense. Google may use cookies to show you personalised ads based on your browsing history. You can opt out of personalised advertising via Google's Ad Settings or by visiting aboutads.info.

Local storage

Your survey responses are saved in your browser's local storage so you can pick up where you left off. This data never leaves your device unless you explicitly choose to save a survey to your account.

6. Data retention

  • Account data and saved surveys — retained until you delete your account via Account Settings.
  • Session records — expire automatically (typically 30 days of inactivity).
  • Browser local storage — held in your browser indefinitely unless you clear it or delete your account.

7. Your rights (UK GDPR)

As a UK resident you have the right to access, correct, export, or delete your personal data. You can delete all stored data by deleting your account in Account Settings. For any other requests or questions, please use our Contact page. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

8. Changes to this policy

We may update this policy from time to time. Material changes will be noted at the top of this page with a revised “last updated” date.

9. Contact

For privacy-related queries, please use our Contact page.