What flock-watch knows about you
Last updated 12 August 2026
This is a tool for people who would rather not be tracked. Collecting more than the job needs would be an odd way to run it, so this page is short and it is the whole of it.
What the service does
flock-watch watches United States for automated license plate readers recorded in OpenStreetMap. When one appears inside a circle you picked, it sends you one message saying how far away it is, the road it sits on, and a link that opens the spot in your map app.
Message frequency varies: it depends entirely on how often somebody maps a camera near you, which is usually never in a given week. There is no newsletter, no marketing, and no other reason we will contact you.
What is stored
| Item | Why | How |
|---|---|---|
| Your contact | Somewhere to send the alert | Encrypted |
| The address you typed | Shown back to you on the manage page | Encrypted |
| Coordinates and radius | Matching is geometric; nothing else works | Plain, rounded to about 110 m |
| Notification, digest, and time-zone settings | Which changes to send, when to group them, and when not to wake you | Plain |
| A waiting-list entry, if you asked about an area we do not cover | Where to expand next, and one message if coverage reaches you | Point rounded to about 1 km, contact encrypted |
| Alerts already sent | Not telling you the same thing twice | Encrypted |
| Your manage link | Letting you change or stop alerts | Hash only, the link itself is not stored |
| A requested manage link and its destination | Sending the link outside the web request, with retries during an outage | Encrypted |
| An unconfirmed signup or contact change | Holding the code destination and requested settings until confirmation | Contact and request encrypted; code hash only. A contact change does not store a manage link; confirmation issues a fresh one. |
Coordinates are rounded on purpose. The smallest radius on offer is a quarter mile, so 110 m of precision changes no alert you would ever receive, and it keeps a precise home location out of the database.
What is not stored
No account, no password, no IP logs, no analytics, no advertising identifiers, no tracking pixels, and no cookies except the one that stops other sites submitting the form on your behalf. Query strings are stripped from server logs, and the address box sends what you type as a form post rather than putting it in a URL, so it does not turn up in browser history or in a log along the way. "First seen here" means when this service first stored the current camera record, not necessarily when the camera was installed. The 30-day counts on signup and manage pages are calculated live from those rows; searches and views do not create a history or counter.
Who else sees anything
Your contact and alerts are never sold, rented, traded, or shared for anyone else's marketing. Nobody buys anything here. Three kinds of service are involved in making it work, and that is the complete list:
- Address lookup. What you type in the address box is sent to a geocoder to turn into a point, the US Census Bureau geocoder first, then Photon or Nominatim if it cannot parse it. They receive the address, not your contact.
- Map tiles. The map on the front page loads the service's own copy of own copy of OpenStreetMap-derived vector tiles from this server. The attribution link does not receive anything unless you choose to follow it. No third-party script or resource loads on this site.
- Delivering the message. Whoever carries your chosen channel, your push service, your mail server, your phone carrier, necessarily handles the message and the address it goes to. Picking browser push keeps it between your browser vendor and you; there is no middleman to sign up with.
Camera locations themselves are public OpenStreetMap data, contributed by volunteers through projects like DeFlock. Nothing about you goes back to them.
How long it is kept
- Active watch areas and your contact: until you remove them or delete everything.
- Sent and failed alert history: 90 days, then deleted automatically. A pending alert is held until it can be sent or its watch area is deleted, including while that area is paused.
- Unconfirmed signups and contact changes: deleted as soon as the code is used. An unused request is deleted after its code expires on the next successful poll.
- Requested manage links: deleted as soon as delivery succeeds, and within a day regardless.
- Cancelled watch areas: 365 days, then deleted automatically with their remaining alerts. After a full unsubscribe ages out, the now-unused subscriber contact and manage hashes are deleted too.
- Waiting-list contacts: dropped the moment the one coverage message is sent, and after 365 days regardless. The rounded point stays, so we know where to expand; it is not attached to a contact after that.
This runs on every successful poll cycle. The manage page also has a separate, irreversible action that deletes the contact, watch areas, alerts, pending work, and any linked waiting-list row immediately in one transaction. Unlike ordinary waiting-list retention, that action removes the rounded point as well.
Stopping
Use the manage page to see what is being watched, download the live records held about you, change the radius, digest schedule, contact method, or what counts as news. Removing one watch area deactivates it for the retention period above; "delete everything now" erases all of it immediately. Every alert email carries a one-click unsubscribe your mail client can act on directly. Contact changes send a code to the new destination and leave the old one working until confirmation. Queued work follows the newly verified destination; a message already handed to a provider cannot be recalled. Switching to browser push is not offered there because it requires a browser permission gesture.
Each destination is a separate service record. Signing up by email and by text creates two manage links, histories, and watch-area limits, even if the contacts belong to the same person. Deleting one record does not guess at that relationship or erase the other.
A delayed digest is checked against the current camera table before it leaves. A camera removed before a digest leaves is omitted, and a one-camera digest uses the current road and operator details instead of week-old wording. Removal alerts are retained because the disappearance itself is the news.
Accuracy, and what this is not
Coverage is incomplete and always will be: a camera appears here when a volunteer maps it, which may be long after it was installed, and plenty are never mapped at all. A quiet alert history is not evidence that nothing was installed near you. This is an awareness tool, not a security system, and it comes with no warranty.
Scope
United States addresses only. It is not offered to children, and there is nothing here to sell to anybody.
Asking
Questions about any of this go to help@flock-watch.us. If this page ever changes in a way that matters, the date at the top changes with it.