Privacy & Safety
What we collect and how we treat it.
The Restoration Project exists to restore power to people, not to collect unnecessary information about them. We design our systems to minimize the amount of personal information we hold and restrict access to it. No online system can guarantee absolute security, so we also limit what we collect, how long we keep it, and who can see it.
What we collect
Depending on how you participate, we may collect your name, email, city or metro area, ways you can help, organizing interest, information you voluntarily provide in an application or suggestion, and accessibility or participation support you request. We try to ask only for information we currently need.
Volunteer intake. Name, email, selected roles, hub preference, optional city and state/region, optional preferred contact method, and optional message. Stored in a private database for authorized reviewers only — not published on public hub pages.
City and general suggestions. Location or category feedback, capacity signals, and optional email if you want follow-up. Suggestion content may be retained as product feedback; contact information is removed when no longer needed.
What we do not want you to send
Please do not send sensitive information we have not requested. We do not intentionally ask through general intake for Social Security numbers, government ID numbers, immigration status, political-party affiliation, medical diagnoses, unnecessary employment information, or precise home addresses.
Who can see your information
Participation information is not a public directory. We do not publish volunteer applications, hosting offers, support requests, personal contact information, or private reviewer notes. Access is limited to authorized people who need the information to operate the relevant workflow.
What may be public
Some network information is public by design: hub names, cities, status, public needs, and contact information intentionally designated for public use by active hubs.
We do not sell your information
We do not sell participant information or use it for advertising or ad retargeting. We do not use Meta Pixel, TikTok Pixel, or similar retargeting tools on this site.
Hosting and transportation
Offering to host or transport someone does not mean your home address or personal details will be published. We will not launch person-to-person housing or transportation matching without additional safety, verification, consent, and privacy procedures.
Retention and deletion
We do not want permanent records of everyone who has ever raised their hand. Retention depends on why information was collected and whether you are actively participating. Some deleted information may remain temporarily in encrypted backup rotation until those backups expire.
You may request correction, withdrawal, or deletion of information we no longer need. Contact security@restoration-project.org. We may need to verify the request comes from you.
Third-party services
We use service providers for hosting (Netlify), database and authentication (Supabase), and bot protection (Cloudflare Turnstile). We may also publish public updates through external platforms when needed. Turnstile may process technical signals according to Cloudflare's privacy policy. We store hashed rate-limit identifiers locally — not raw IP addresses or email addresses — to reduce spam. Volunteer contact consent is separate from public update channels.
Report a concern
If you believe private information has been exposed, an account has been compromised, someone is impersonating The Restoration Project, or you found a security problem, contact security@restoration-project.org. Please do not post active vulnerability details publicly.
This is a living statement, not legal advice or a formal privacy policy. Expect it to evolve as the project does.