Draft, not in force

This privacy notice is a draft and is not final. It has not been reviewed by a qualified lawyer, and it is not legal advice. What it says about what the software does and where it sends data is accurate. The legal wording around it is what still needs review.

Parts marked [To be completed after legal review] are still open. They are listed at the end of this page.

Privacy

Draft 3 · last revised September 22, 2026 · not reviewed by counsel · not in force

The short version, because it is the question a cautious firm actually asks: to derive anything at all, this software sends your site boundary to public data services run by the United States government, and it sends an address you type into the search box to the United States Census Bureau. Section 3 says exactly which, and exactly what goes to each one.

One recipient in section 3 is not a government service. If the optional assistant is switched on for the deployment you are using, your questions and your site's record go to a commercial language model vendor. It is off by default in the software and switched on for this service, the tool tells you which state it is in, and section 3, the assistant says exactly what is sent and what is not.

1 Who is responsible for your data

CZDTS LLC, whose mailing address is 4539 N 22nd St #5089, Phoenix, AZ 85016, USA, is responsible for the personal data described here. If you have a question about it, write to support@curvenumber.com. That is the one address this product publishes and it is the one that is read; it is used here for a privacy question, for a security report and for a formal notice alike, because no separate privacy or security mailbox exists and an address printed in a notice that receives no mail is worse than a general one that does.

Until 22 September 2026 this section named a different company. The product is now operated by CZDTS LLC and no part of it is operated by the previous entity.

[To be completed after legal review: the state CZDTS LLC is organized in, the law that governs, and the courts that hear a dispute.]

[To be completed after legal review: which privacy laws apply, and the disclosures they require in this notice.]

2 What we collect

Only what the service needs to work. There is no tracking, no advertising and no analytics on this website or in the tool.

Your email addressrequired
It identifies your account, it is what appears as the attribution on an override you make, and it is how we reach you about billing or about your account.
Your name and organizationoptional
Stored if you give them, and used the same way. Leave them blank if you prefer.
Site boundaries and addresseswhat you draw and type
The polygon you draw, the acreage computed from it, and the site address if you enter one. This is the material that has to leave our servers, and section 3 is about where it goes.
Project and site detailswhat you type
Project name, site name, client name and jurisdiction, if you enter them. A client name is somebody else's information, so enter one only if you are entitled to.
Design parametersyour engineering inputs
Segments, areas, curve numbers, impervious fractions, design storm depth and duration, time of concentration, practice dimensions and any infiltration test result you record.
Overrides and the reasons you writethe audit trail
When you change a value, we store the prior value, the new value, the reason you wrote, your email address and the time. This record is append-only and cannot be edited afterwards, because a report's value depends on it. Write reasons on the assumption that they will be read by a reviewer.
Results and reportscomputed
Each run and the report built from it, kept so a report can be reproduced rather than recomputed.
Assistant conversationsonly if the assistant is on
If the deployment you are using has the optional assistant switched on and you ask it something, we store the conversation against that site: your questions, the answers, what the assistant recorded as said earlier, anything you told it about the site, any document you attached to it, and a log of each turn including a response that was blocked before you saw it. Section 3 is about where a question goes while it is being answered. You can delete all of it for a site at any time, and section 6 says exactly what that removes.
Billing recordsa ledger, not a card
Free sites used, credit added, and each charge with its date and the site it was for. We do not take or store card details. Payment is by invoice, raised and settled outside this software, and what this product holds is the ledger and nothing else. A card path built on Stripe's hosted checkout exists in the software and card payment is built and switched off on this deployment, so nothing about you has ever been sent to Stripe. If it is switched on, what goes to Stripe is your email address, the identifier of the purchase request and your account identifier, and the card itself is entered on Stripe's own page and never reaches us. No site data, no boundary and no report goes to them at any point.
An API keystored as a hash
The key itself is shown to you once and is stored by us only as a hash, so we cannot recover it. Your browser keeps it in local storage on your own device, along with your light or dark theme choice. The theme choice never leaves your device, and the key is sent only to our own API, as your credential.
Server logsordinary web logs
Our web server records the requests it receives, including IP address, time, path and status. These are for keeping the service running and for investigating abuse.

3 What is sent to third parties

This is the part worth reading properly. CurveNumber derives its inputs from public datasets, and there is no way to do that without asking those services about your site. The first six services below are run by agencies of the United States government; the rows after them say what is commercial and what is not a request at all. We have no agreement with any of the public ones, we do not control them, and what they do with a request is governed by their own policies, not ours.

One further recipient is a commercial company rather than a public dataset, it receives much more than geometry, and it only exists when the optional assistant is switched on. It has its own part of this section, below the list.

USDA Soil Data Access sdmdataaccess.nrcs.usda.gov
Sent: your site boundary, as coordinates, in a spatial query. Returns the soil map units under it and their hydrologic groups. Sent from our server, not from your browser.
USGS and MRLC land cover dmsdata.cr.usgs.gov, www.mrlc.gov
Sent: the bounding box of your site. Returns the annual NLCD land cover raster and the fractional impervious raster over that box. From our server.
USGS 3DEP elevation elevation.nationalmap.gov, epqs.nationalmap.gov
Sent: the bounding box of your site. Returns slope computed over it. From our server.
NOAA Atlas 14 hdsc.nws.noaa.gov
Sent: a coordinate inside your site. Returns the design rainfall depths for that point. From our server.
US Census Geocoder geocoding.geo.census.gov
Sent: the address you type into the search box. Returns candidate coordinates. This happens only when you use the address search. From our server.
USGS basemap tiles basemap.nationalmap.gov
Sent from your own browser: the map tiles you look at, which means the area you are viewing and your IP address, directly to USGS. This one does not pass through us at all, because the map draws itself.
Typefaces and the map library served by us, not a third party
Sent: nothing to anyone else. The three typefaces these pages are set in (IBM Plex Sans, IBM Plex Mono and Source Serif 4) and the MapLibre GL mapping library that draws the map in the tool are copies kept on our own server and sent to your browser from it, on the public site and in the tool alike. No font service or code service learns that you loaded a page. The library carries a fingerprint check, so your browser refuses it if the copy on our server were ever changed.
waterdmd.info a link on the About page, not a load
Sent: nothing, unless you click it. The About page on this website links to the research site behind this product. No part of these pages fetches anything from it, so a reader who does not follow the link never contacts that host. It is listed because the rule this section follows is that every external host named in the markup appears here, and an exception made quietly is how the next one gets missed. The copy of this notice the tool serves does not carry this row, because no page in the tool names that host.
Hostingour infrastructure provider
The service runs on Amazon Web Services, on a single virtual machine in the us-east-1 region, which is Northern Virginia in the United States, with the database backed up to object storage in the same region. AWS hold the data in the ordinary course of hosting it.

The companies that handle your data for us (hosting, backups, email, the AI assistant and card payment) are listed on one page: companies that handle your data.

Three things follow from this that are worth stating plainly:

The assistant, and the model vendor behind it

The tool has an optional assistant: you type a question about one of your sites and a language model answers it, using your site's record. It is off by default in the software and switched on for this service. On a deployment where it is off there is no model, no vendor and no request: the assistant screen is not there, the routes answer "not enabled on this deployment", and the warnings the tool raises about your site are produced by the engine with no model involved at all. If it is on, you will see the assistant in the tool, and every question you ask it sends a request to a vendor.

Amazon Bedrock, and the Anthropic models behind it bedrock-runtime, us-east-1
Sent, each time you ask the assistant a question: your question, the earlier turns of that conversation, our own instructions to the model, and whatever the model reads from your site's record while answering: the report document with its quantities, citations and assumptions, the segment table, every override with the reason you typed, every refusal and waiver with its reason, the change log, the site name, the project name and the jurisdiction, and the text of any document you attached to the site. From our server, and never from your browser.
Which vendor, which model, which region on this deployment, not in general
The request goes to Amazon Web Services, through the Bedrock runtime in the us-east-1 region, and the model answering it is one of Anthropic's Claude models served there. Two are provisioned and nothing else can be called, because the deployment's cloud role grants those two and no others: Claude Sonnet 4.6 for an ordinary question, and the smaller Claude Haiku 4.5 once a day's allowance is reached. Both are called through a US-only cross-region inference profile, which means AWS may route an individual request to a region other than us-east-1, always one in the United States: your question is processed in the United States. We do not claim that it stays in Northern Virginia, because it may not. The service refuses to start if it is set up with a profile that could send a question outside the United States. The software can also call Anthropic's own API directly; this deployment is not configured that way, holds no key for it, and authenticates to Bedrock by the machine's own role instead.
Not sentand this is enforced in the code
Your email address, and any other email address anywhere in the record: each one is replaced, before the request is built, with an opaque handle of the form person-abcdef, so the assistant can say that two changes were made by the same person without being told who that person is. That replacement runs over everything this software puts in a request on your behalf, on every route that sends anything, which is to say the record, the change log, an override or waiver reason you typed, and the text of a document you attached, and not only over the parts it looks up while answering. The one thing it does not rewrite is the question itself, which is sent as you typed it; see the row below. Also not sent: the site address you entered in the address field, the client name you entered in the client field, your own name and organization, your API key, your account id, and the drawn boundary itself: the polygon never goes to the vendor, only the acreages and the values computed from it. There is no user identifier attached to the request.
Where that stopsthe honest edge of it
Those two fields are held back because they are fields: the software knows which box you typed them into, and it replaces the contents of that box with a note saying it was withheld. A postal address written in ordinary prose is not reached by that. If an address appears inside the text of a document you attach, or in a site or project name, or in a reason you wrote against an override, it is part of that text and it goes to the vendor with it. We are not going to claim otherwise: recognizing addresses inside a design manual would mean guessing, and a guess that missed one would be worse than no claim at all, because it would have been advertised as a protection. Email addresses are different and are genuinely handled everywhere the software builds a request from your record, prose included, because an email address can be matched exactly. The question you type is the exception and it is sent word for word, address and all: it is the one part of the request you wrote deliberately and addressed to the assistant, and rewriting it would mean answering a question you did not ask. So: give a confidential site a neutral name, and assume that anything you type or upload in words is sent as you wrote it.
Whenonly when you ask
Only on a question you type into the assistant, and on drafting actions you start yourself: asking it to draft an override reason, a waiver reason, a report section or a change log line, and asking it to read a manual you attached. Nothing is sent in the background, nothing is sent when you compute a site or generate a report, and the proactive warnings never involve a model. If you never open the assistant, nothing about your sites is ever sent to a vendor.
Under what commitmentread this one carefully
There is no per-request setting on that API that means "do not train on this", and we do not pretend otherwise: the code carries an empty set of such headers with a test that keeps it empty, so that nobody reads a plausible-looking flag as a protection. What the commitment rests on is the vendor's commercial terms for our account, under which API inputs and outputs are not used to train their general models. That is a contract, not a technical control, and it can change. We do not have a zero data retention agreement with the vendor, so content sent to them is retained under their own policy for their own period. Going through Bedrock puts a second company in that chain rather than one: AWS carry the request and the model runs in their infrastructure. [To be completed after legal review: the terms in force with both companies for this service, their sub-processors, and where a request may be processed.]
What you can do about itfour things
Do not use the assistant: everything else in the product works without it, and the engine, the reports and the warnings are unchanged. Delete a site's conversation at any time, which section 6 describes. Ask whoever runs your deployment to switch it off, which is one setting and takes effect on restart. And if the name of a project or a site is itself confidential, give it a neutral one, because those two are sent and we would rather you knew that in advance.

Two honest notes about the assistant, in the same spirit as the rest of this page. The first is that an answer it gives is checked by the software before you see it: every figure has to be one the record holds, and every citation has to be something retrieved in that turn. That check is ours, it is not the vendor's, and it is not a guarantee that the answer is right. The second is that we cannot see what the vendor does with a request after it arrives, any more than we can see what the federal services do with a boundary. What we control is what leaves this server, which is what the two rows above describe.

4 What we do not do

5 Where it is stored, and for how long

Your data is stored on our own server in the us-east-1 region, which is Northern Virginia in the United States, and the backups of it are stored in the same region. We keep it while your account is open, because the point of the audit trail is that it is still there when a reviewer asks about a report two years later.

Closing an account does not delete anything: its projects, sites, runs, reports and audit records are kept, and the account can be reopened, as the terms say. We never delete an account because it has not been used.

Deleting. [To be completed after legal review: draft wording, pending counsel approval.] You can download everything on your account as one ZIP file at any time, and the tool offers it before anything is deleted. A project or site you delete goes to the trash for 30 days, where you can restore it; after that it is deleted for good. Its published links stop at once and say the analysis was withdrawn by the author, with the date. You can also ask the tool to delete your whole account: after 30 days, in which you can change your mind, all of its content is deleted and we email you to confirm. Two things are kept after that: billing and payment records, with the record of money moved on the account, for 7 years, and a one-way fingerprint of your email address, so that free site codes cannot be claimed again. Deleted data then ages out of the backups, which takes about 120 days, as described below. What follows is what the infrastructure enforces rather than a period we would like to be true.

Backups. The server keeps the eight most recent database snapshots on its own disk and deletes the rest as each new one is taken, which at one snapshot an hour is roughly the last eight hours. That is a count and not a period, and it is written here as a count for that reason. The copies held in object storage expire on a rule: fourteen days for the hourly ones and ninety days for the one taken each day. A continuous copy, a few seconds behind the live service, is kept in the same storage for three days, and a file it retires stays recoverable for seven more. A copy that is replaced can be recovered for a further fourteen days (hourly) or thirty days (daily). So about 120 days is the outside figure for a backup of your data.

Logs. The web server's logs are rotated daily and fourteen are kept, so fourteen days is the most, and it can be less: the same rule rotates a log early if it passes 100 MB. The application's own log is not kept by age at all. It rotates when it reaches 5 MB and three rotations are kept, so what exists is the last 20 MB of request records rather than the last any number of days, and on a busy week that is a shorter period than on a quiet one. We would rather say that than quote a retention period the software does not enforce. The system journal is capped at 300 MB and at one month, whichever is reached first.

Those are the copies on the server itself. A second copy of the web server's logs and the application's log is sent, as each line is written, to Amazon CloudWatch Logs in the same region, so that a fault can still be investigated if the server is lost. That copy is deleted after thirty days, so thirty days is the outside figure for a log line.

Billing records are kept for 7 years, because we are required to keep them. [To be completed after legal review: the period, drafted as 7 years, pending counsel approval.]

Deleting a project or a site for good deletes what hangs off it, including its audit records, and cannot be undone. Keep your own copy of anything you may need to show a reviewer later.

An assistant conversation is stored against its site. You can delete one on its own without deleting anything else, and section 6 says what that does and does not remove. A request already sent to the model vendor is out of our hands in the same way a report already sent to a reviewer is: deleting the conversation here does not reach their copy, and their retention is governed by their terms.

6 Your choices and your rights

You can see everything on your account from inside the tool, and you can download all of it (every project, site, run, report and published copy) as one ZIP file at any time. You can ask us to correct something, to delete your account and its data, or to send you a copy of it, by writing to support@curvenumber.com. We will respond within [To be completed after legal review: the response time].

If you have used the assistant, there is a delete control on the assistant screen for each site. It removes that site's conversation and everything remembered from it: the messages, the statements the assistant kept from them, anything you told it about the site, the documents you attached, the dismissed warnings, and the log of each turn including any response that was blocked before you saw it. Three things survive it, and the tool says so rather than leaving you to assume: the operator's cost ledger, which holds a model name, a token count and a cost and no site data; the record of how much of the site's AI allowance has been used, because an allowance you could reset by deleting a conversation would not be an allowance; and the site's own change log, which is the audit trail of the site rather than of the conversation, and which goes when the site goes.

Two honest limits. A report you have already sent to a client or a reviewing authority is out of our hands, and deleting your account here does not reach it. And an override record inside a report is part of the document's meaning, so we will not edit one in place; the remedy for a record you disagree with is to supersede it, which the software supports and which leaves both entries visible.

[To be completed after legal review: your specific rights, and where you can complain.]

7 Security

Traffic to the service is encrypted in transit. Your API key is stored only as a hash, so a copy of our database does not yield working keys. Access to the server is limited to the people who operate it.

We will not claim more than that. This is a small pre-launch product and it has not been through an independent security audit. If you find a problem, write to support@curvenumber.com and we will take it seriously. There is no separate security address, and we would rather send you to the one that is read than print one that is not.

[To be completed after legal review: whom we notify of a breach, how quickly, and how.]

8 Children

This is professional engineering software. It is not for children and we do not knowingly collect data about anyone under [To be completed after legal review: the minimum age].

9 Changes, and how to reach us

If we change this notice in a way that materially affects you, we will email the address on your account before the change takes effect and keep the previous version available.

Write to support@curvenumber.com, or by post to CZDTS LLC, 4539 N 22nd St #5089, Phoenix, AZ 85016, USA.

Still to be completed after legal review

  • Where CZDTS LLC is organized, the law that governs, and the courts that hear a dispute (section 1).
  • Which privacy laws apply (section 1), and from that: your specific rights and where to complain (section 6), breach notification (section 7) and the minimum age (section 8).
  • How long billing records are kept (section 5; drafted as 7 years, pending counsel approval).
  • The deletion, trash and export wording in section 5 (drafted, pending counsel approval).
  • How long we take to answer a request to correct, delete or export (section 6).
  • The terms in force with the model vendor and its sub-processors (section 3).