An independent project
Privacy at My Panama City
My Panama City is an independently operated project. It is not an official City of Panama City service.
Updated October 4, 2026
You can browse public records and ask questions without an account. Optional Google sign-in is available. Facebook sign-in is not open to the public. The concern and email-update controls show whether intake is open. Email updates require a separate topic selection and confirmation of the receiving address.
Questions and AI answers
When semantic search is available, Cloudflare AI converts the beginning of your current question into a search vector to find related public passages in Neo4j. When AI explanations are available, we send your current question, selected public source excerpts, and their source details to OpenAI. Please leave personal or sensitive information out of questions. Your sign-in identity, email address, sign-in cookies, previous questions, and private application records are not automatically included in that AI request. Information you type into a question is part of the question sent.
The application does not save chat questions or answers in its database. The conversation is held in the current page’s memory and is cleared when that page is reloaded or closed. We keep daily request counts and reserved cost totals, without question text or account identifiers.
If you explicitly send a discovery topic request, we save only the selected topic, request type, daily count, and latest request time. These anonymous aggregates help prioritize checks of existing public city sources. Buckets older than 30 days are removed on the next successful scheduled check or topic submission. We do not attach your question, email, account, or IP address to them, and a request never becomes evidence for a city fact. Browsing discovery cards or using their filters does not send a topic request.
OpenAI requests use store:false. This setting does not guarantee zero provider retention; OpenAI’s own data controls and policies apply. See OpenAI’s API data controls.
Optional Google sign-in
If you choose Google sign-in, Google confirms your identity to this project. We request only the openid, email, and profile sign-in scopes. We save your Google account identifier, display name when provided, verified email address when provided, email-verification status, and account creation and last-login times in authentication tables hosted by Cloudflare D1. We also record the sign-in provider, issuer, and application client identifier so the account is associated with the correct sign-in service.
We use this information to recognize your local account, display its details, and handle account controls and deletion. An email address is saved only when Google reports it as verified. It is not used to combine accounts from different providers. We do not retain a profile picture, Google access token, ID token, or refresh token. Sign-in does not give this project access to Gmail, Google Drive files, or Google Calendar.
Google handles its sign-in interaction under Google’s privacy policy. Temporary sign-in verification data is used only to complete and protect this site’s sign-in process.
Existing Facebook test sign-in
Facebook was used for a limited account test. Its retained local record contains an app-scoped Facebook identifier, display name, app identifier, and account creation and last-login times. The Facebook access token was used during sign-in and was not saved. No email address, friends, posts, or profile picture was retained. This record remains separate from Google sign-in accounts.
Signing in does not submit a concern, create a subscription, or grant staff access. Every newsletter subscription requires a separate, explicit choice of topics and delivery preferences; signing in or sharing an email address is not newsletter consent. Staff access requires a separate administrator allowlist. Sign-in records are excluded from public search, the public knowledge graph, the document-embedding process, and AI answer context.
Cookies and browser storage
Each sign-in provider uses its own first-party verification and session cookies. These are Secure, HttpOnly, and SameSite=Lax; the application stores hashes of their random tokens on the server.
If this browser previously used prototype subscriptions, local storage may contain subscription IDs, private management keys, topic choices, frequency, status, and creation times under panama-city-commons-subscriptions-v1. Email addresses are not included in that browser record. It remains until removed through unsubscribe controls or cleared in your browser. Clearing it alone does not cancel a server-side subscription.
Concerns and optional topic emails
When intake is open, a submitted concern is saved in private application tables for the independent project operator to review. It is not automatically sent to City staff or placed on an official agenda. The text, optional location, selected and suggested topics, review status, and creation time are retained. Saving an optional contact email requires its own consent.
Choosing email updates is a separate opt-in. We save the email address, selected topics, frequency, consent version and time, confirmation status, and delivery records in Cloudflare D1. Cloudflare Email Service receives the recipient address and message to deliver confirmation and agenda-update emails. Messages use reviewed public agenda information and do not include the private wording of your concern. SMS is not enabled.
Email confirmation and management links act as private keys. Keep them private. Confirmation expires after 24 hours; management access lasts until revoked. Unsubscribing removes the saved recipient address and invalidates the keys, while retaining a one-way address hash to prevent further sends. Consent, suppression, and delivery audit records have no automatic deletion period in this version. Provider acceptance does not confirm inbox delivery, and a message already submitted cannot be recalled.
Email preferences are independent of Google or Facebook sign-in. Deleting a sign-in account does not unsubscribe a separately confirmed email address. Use the manage or unsubscribe link in an email, or contact the operator for help. Concern text, contact details, authentication records, and subscription records are excluded from public graph and AI answer context.
Public source records
We copy selected official public pages and documents into Cloudflare storage and a Neo4j knowledge graph to support search and citations. This includes original files, extracted text, source addresses, dates, hashes, and version history. Cloudflare AI may process public documents for text extraction and search embeddings. Public records may contain information already published by the city.
These public-source copies are separate from sign-in records. Deleting a sign-in account does not remove government documents or their archived versions.
Hosting, security, and retention
Cloudflare hosts the site and processes requests to serve and protect it. The application uses IP-derived keys for rate limits. It does not intentionally log chat text or provider responses, and application observability is disabled. Cloudflare may still process technical request data for hosting and security. We do not include advertising trackers or third-party analytics scripts in these pages.
A saved sign-in profile has no automatic deletion deadline; it remains until deleted. Session access expires after one hour, but expired server records are cleaned up on a later successful sign-in. Expired sign-in verification records are cleaned up when another sign-in begins. Expiration prevents use even if a record has not yet been physically removed.
Public source copies, version history, and non-content operational counters have no automatic deletion schedule in this version. Provider-managed retention and backups are not controlled by clearing this site’s cookies.
Deleting your sign-in data
You can delete a saved sign-in account from the account controls when you have a valid session. This removes that provider’s saved local identity and all its associated sessions. It does not remove a separate account used with another provider. Signing out alone does not delete a profile. See the deletion instructions and scope.
For privacy questions or deletion help, contact contact@mypanama.city. We may need to verify that a request concerns your own account. Do not send passwords, access tokens, or private management keys.
Email sent to this contact address is forwarded through Cloudflare to the project operator’s mailbox. We use your sender address, message, and any attachments to respond and process your request. No automatic deletion period is specified for this correspondence.