Privacy, in plain language

What we collect: your email, the address you give us (stored as coordinates to centre the streets we watch for you), your chosen radius and topics, and delivery records for the emails we send you.

If you asked us to cover a town we do not cover: we hold your email, the place you named, the day you asked, and whether you confirmed it. Nothing else — no street address, no radius, no topics — and you are not subscribed to anything. One message goes to that address, the one asking whether you meant it; that is the only mail this list sends. If Lamppost ever reaches the place you named, we would write once to say so. Nothing else is attached to it.

What we do with it: send you the digest you signed up for. That is the entire business model — Lamppost is a paid product, not an ad product.

What we never do: sell your data, share your address, show your location to any other user, or put your information in an advertising system. No ads, ever.

Deletion: the unsubscribe button hard-deletes your account — your email, your location, your subscription, and your notification history. It also deletes the archived copies of the emails we already sent you, your entry on our do-not-send list, and any dispute or correction you filed. Derived caches clear within 30 days.

Deleting a city request: deleting your account takes any city request with it, matched on your email address. But if a city request is the only thing we hold about you, there is no account to delete — an address with no subscription gets no sign-in link, so the delete button in your dashboard is not reachable. That is why the message asking whether you meant it carries a second link that deletes the row outright: no sign-in, no form, nobody to ask. The page you land on after confirming carries the same link.

If you never confirm: the link in that message stops working after a week, and we delete the request itself two weeks after you asked. We do not send a reminder, and we do not keep the address on the chance that you change your mind — once the link is dead the row cannot become anything, so we stop holding it. Asking again starts over, and nothing remembers that you asked before.

How long we keep things if you stay: every digest is archived with the address it went to, so we can answer “did that alert actually go out?” We delete that archive 90 days after the email was sent, whether or not you ever unsubscribe. The manage link in a digest footer is a credential rather than a bookmark, so it runs on the same 90-day clock and then stops working. Manage links from digests we sent before we added that expiry stop working on 31 October 2026.

What outlives deletion, and why: one thing does, and we would rather name it than round it down to nothing.

The administrative audit trail — the deliberate exception. Every administrative action on this system is written to a log that nothing in our own code can edit or delete, including this. An audit trail with a delete button is not an audit trail. If your email appears in it because of an action an operator took on your account, that is a record of what the operator did, and it stays there.

Write to hello@lamppost.fyi and we will tell you exactly what is held against your address.

The records in your digest are public records published by your local government; every entry links to its official source. If a record about your property or business is wrong, use the source link to reach the issuing agency, or write us and we'll flag it in our system: hello@lamppost.fyi.

lamppost.fyi · Louisville, KY · last updated July 2026