Privacy Policy
Version 1.7.0 · Last updated: August 9, 2026 · Applicable to Quebec residents (Law 25)
In short: iCivic collects only what is necessary to provide the service. Your reports are anonymous, your GPS location never leaves your device, and we sell no personal information. You can request deletion of your account and your data at any time.
1. Who we are
iCivic is a service of Solutions iCivic inc. ("iCivic", "we"), a company based in Gatineau, Quebec, Canada. Our mobile app and website let you check published wait times for certain Quebec public services, where such data exists.
Privacy Officer (Law 25): reachable at legal@icivic.app. We acknowledge receipt of any request within 30 days.
2. Data we collect
2.1 Data you provide to us
- Email address and display name — when you create an account or join the waitlist.
- Wait-time reports — submitted voluntarily from the app. Reports are anonymous from the moment of submission: no account identifier is attached to them. Each report is then published publicly, one by one: it is visible to anyone using iCivic, with no information that could identify you. That is what lets the next person see the current wait.
- Contact forms and B2G requests — name, organization, message.
- Proof of your acceptance — when you accept these terms or this policy, we record which version you accepted, on what date, in which language, and from which platform, together with a hashed IP address (never in clear text). We are required to: the burden of demonstrating your consent is ours, not yours to disprove. This register is immutable — we can neither alter it nor delete a line from it.
2.2 Geolocation — never stored
If you consent (explicit system permission), your location is read only once at the moment of a report, solely to verify that you are near the location (500 m radius). This verification is performed directly on your device: your GPS coordinates are never transmitted to our servers. Only a yes/no presence flag accompanies the report. No continuous tracking, no movement history.
2.3 Data collected automatically
- Pseudonymized usage data — screens viewed, actions in the app (via PostHog, hosted in the United States, in cookieless mode; pseudonymous identifier with no email or name).
- Technical logs — hashed IP address (never in clear text), timestamp, device type — for security and fraud detection. Retained for 90 days.
- Push notification token — if you enable alerts, a device identifier is shared with Apple (APNs) or Google (FCM) to deliver notifications.
- Crash reports — in the event of a crash, a technical report is sent to Sentry, with no personal information (email and identifiers removed before sending).
3. How we use data
We use your data to:
- Provide and improve the iCivic service
- Send you the wait alerts and notifications you have set up
- Send you launch notifications in your region (with your consent)
- Detect and prevent abuse and false data
- Publicly display reports, with no information that could identify you, so that anyone can see the current wait
- Generate aggregated, anonymized statistics on wait times
- Provide client public-sector organizations, for a fee, with anonymous wait-time data covering their own service locations
- Show you, if you have an account, your personal contribution statistics (number of reports and hours of wait avoided, accumulated for life)
- Comply with our legal obligations
We sell no personal information. The wait-time data we provide to client organizations is anonymous: a published report carries no account identifier, and no key in our database links it to yours.
One clarification, because the previous version of this text claimed "not even in our own database" without qualification. A separate technical table, kept to fight abuse, records that you submitted a report at a given location — with no reference to the report produced. For 48 hours, its precise timestamp makes it theoretically possible to match it against a report published at the same place at the same moment. After that, the timestamp is automatically coarsened to the hour, which removes that possibility; the row is deleted after 90 days. We perform no such matching, and this table is never shared with a client organization.
We never use your data for advertising profiling. No decision producing legal effects concerning you is made solely on the basis of automated processing.
4. Legal basis for processing
- Consent — for marketing communications (waitlist, newsletter), one-time geolocation and push notifications. Revocable at any time.
- Consent at the moment of reporting — before you send it, and without your having to expand anything, the app tells you that your report will be published without your identity.
- Performance of a contract — for providing the service to registered users.
- Exceptions provided by Law 25 — the Act allows us to use information without your consent in specific cases, notably where it is necessary to prevent and detect fraud or to improve our security measures, and to produce de-identified information for statistical purposes.
Use of the service is reserved for people 14 years and older. In accordance with Law 25, consent for a minor under 14 must be given by the holder of parental authority; we do not knowingly collect information from children under 14.
5. Artificial intelligence services
Some iCivic features (assistant, summaries, contextual search) rely on third-party AI services:
- Anthropic (Claude API) — generating responses and summaries. Processing in the United States. Your messages are not used to train models, and Anthropic deletes them within 30 days at most. One exception remains — if Anthropic flags an exchange through its automated safety systems, that exchange may be retained for up to 2 years.
- Cohere — text vectorization for contextual search. Processing in the United States. Your text is deleted within 30 days at most.
- On-device speech recognition — if you choose to dictate your question, transcription runs entirely on your phone, using Apple's (iOS) or Google's (Android) built-in recognition engine. No audio recording is sent to our servers. Only the transcribed text is then forwarded to Anthropic to generate the response, under the same conditions as a typed message. iCivic records only the length of the dictated text for telemetry, never its content or the audio.
These features have no access to your account data. Recommendation: do not share personal information (name, address, health status) in conversation areas with the assistant.
6. Data sharing and subprocessors
We share your data only with the providers necessary to operate the service:
| Provider | Role | Processing location |
|---|---|---|
| Supabase | Database, authentication | Canada (ca-central-1) |
| Vercel | Web and API hosting | Canada (Montreal) |
| Upstash | Rate limiting (no PII) | Canada (ca-central-1) |
| Brevo | Transactional emails | European Union (France) |
| PostHog | Pseudonymized analytics, cookieless | United States |
| Sentry | Crash reports (PII removed) | United States |
| Anthropic | AI assistant (deleted within 30 days, up to 2 years if flagged, no training) | United States |
| Cohere | Contextual search (deleted within 30 days) | United States |
| Apple / Google | Push notifications (device token) | International |
| Chatwoot (self-hosted) | Customer support (messages, user identifier) | Canada (OVH, Beauharnois) |
| OVHcloud | Encrypted backups (recovery copy, see §7.1) | Canada (Beauharnois, Quebec) |
| Inngest | Asynchronous tasks (processing payloads) | United States |
Your primary personal information (account, sessions, reports) is hosted in Canada. When information is disclosed outside Quebec, we ensure it benefits from adequate protection, in accordance with Law 25. All our subprocessors are contractually required to protect your data and to use it only for the agreed purposes.
7. Data retention
- Waitlist — kept until launch in your region, then deleted within 30 days of your unsubscription.
- Active user account — kept as long as the account is active; deleted within 30 days of a deletion request.
- Inactive account — an account with no sign-in for 12 consecutive months is automatically anonymized: email and display name are removed from our systems on the 1st of the month following the deadline.
- Wait-time reports (anonymous) — each report is anonymous from the moment it is created (no account identifier is ever attached to it) and kept indefinitely in this anonymous form, to power the public display of reports and aggregated wait-time statistics. The technical anti-abuse data that accompanies it (hashed IP address, hashed device fingerprint) is stored separately for 90 days then permanently deleted; after that window, no re-linkage to a device or a person is possible.
- Personal contribution statistics — for account holders, an aggregate counter (cumulative number of reports and wait minutes) powers your impact display. Kept for as long as your account exists and erased when the account is deleted; derived from your reports without re-exposing their detail.
- Proof of acceptance — the link to your account is severed as soon as it is deleted, and the hashed IP address is erased after 90 days, as with other technical data. What remains — "an acceptance of version X happened on that date" — no longer identifies you and is kept in that anonymous form, like the reports.
- Technical logs — 90 days, automatic purge.
- Pseudonymous analytics profile (PostHog) — 12 months, then deletion of the profile.
7.1 A backup copy survives for up to 90 days
The periods above describe our live systems: when data is deleted there, it is deleted right away and for good. An encrypted backup copy may nonetheless still contain it, for up to 90 days, until that copy expires in turn and disappears automatically. We say so because it is true, and because "deleted within 30 days" would otherwise read as instantaneous disappearance from everywhere.
These backups exist for one reason: to be able to restore the service if our systems are lost or compromised. They are never consulted, queried, or used for any other purpose, and no decision concerning you follows from them. They are encrypted before leaving our systems — the decryption key is not held by the hosting provider — and kept in Québec, in Beauharnois.
8. Your rights (Law 25)
You have the right to:
- Access your personal information — directly from the app: Profile → Download my data
- Rectify inaccurate information
- Erase your data ("right to be forgotten") — directly from the app: Profile → Delete my account
- Portability — receive your data in a structured, commonly used format, directly from the app: Profile → Download my data
- Cessation of dissemination / de-indexing — in the cases provided for by Law 25
- Withdraw your consent at any time (notifications, geolocation, marketing)
- File a complaint with the Commission d'accès à l'information du Québec (CAI)
Download my data, in your profile, exercises access and portability in one step: we prepare the information attached to your account and email it to you as an attachment, in JSON — a structured, commonly used format readable by you and by another service alike. It is always sent to your account's email address, never to an address supplied with the request.
Two limits, stated plainly. Your wait-time reports are not in this export: they are anonymous from the moment they are submitted and are attached to no account, including yours — which is also why we cannot produce a list of them for you. And information held by our processors (PostHog, Sentry, Brevo) is not included automatically; ask us and we will obtain it for you.
To exercise these rights another way, for any other request, or if the feature is temporarily unavailable: legal@icivic.app. Response within 30 days. That route stays open at all times and answers the same rights as the button.
9. Privacy incident
In the event of a privacy incident presenting a risk of serious harm, we will promptly notify the Commission d'accès à l'information du Québec as well as the individuals concerned, in accordance with Law 25, and we will keep an incident register.
10. Security
We apply the following security measures:
- TLS encryption for all communications
- Row Level Security (RLS) on all database tables
- Hashing of IP addresses before storage
- Encrypted local queue (AES-256-GCM) for offline reports
- Centralized secrets management (zero secrets in clear text in the code)
- Regular security audits and an audit log of administrative access
11. Cookies
Our website uses no advertising cookies or third-party tracking. The only cookies used are functional (language preference, sign-in session). Analytics is performed in cookieless mode via PostHog.
12. Changes
Any significant change will be communicated by email to registered users at least 30 days before it takes effect. The last-updated date appears at the top of this page.
13. French version and language primacy
This policy is drawn up in French. An English version is made available to you for convenience. In the event of any discrepancy between the French version and the English version, the French version is authoritative.
This policy is an information notice: it describes our practices, it is not accepted as a contract. The French version is therefore the one that states our commitments authentically — and it is the version number and fingerprint recorded when you consulted it that identify the text then in force.
14. Contact
For any question about this policy or your personal information:
iCivic — Privacy Officer
Gatineau, Quebec, Canada
legal@icivic.app