Privacy Notice
City Tracker · Last updated 27 July 2026
This notice explains what City Tracker collects about you, why, and how you get rid of it. It is written to be read, not to be survived.
Who is responsible for your data
City Tracker is run by David FitzGerald as an individual and is registered with the Information Commissioner's Office under registration number CSN3051856. For anything in this notice, including any request about your data, contact contact@citytracker.city.
City Tracker is an independent personal project. It is not operated by, affiliated with, or endorsed by any law firm or employer, and no employer has access to your data.
What we collect
| What | When | Why |
|---|---|---|
| An anonymous session identifier, stored in one cookie | As soon as you open the site | So your planner is still there when you come back. This is the only cookie we set. |
| A daily total of how often each City Tracker page or product area is opened, a daily total of moves from one named area to another, and a daily total of each research tool being opened | When you move around City Tracker | To understand which parts are useful and where the experience needs work. The total is not stored against your session, account or identity. |
| Your name, email address, profile picture and Google account identifier | Only if you choose to sign in with Google | To link your planner to an account so it survives across devices and browsers, and to enforce approved private-beta access. |
| A one-way hash and final four characters of a City Tracker access code, a non-identifying purpose label, its status and activation timestamps | When the owner creates a private-beta code, and when a new user activates one | To approve one Google account, administer access and prevent a used code being used again. City Tracker does not store the full code. |
| Your membership application: the name and email address on your Google account, your written answer, and a LinkedIn profile address only if you choose to add one | Only if you apply to become a member | Read by the site owner alone to review your application. Re-applying replaces your earlier application, and it is deleted with your account. |
| The applications you record (firm, route, deadline and milestone dates) and the engagement-event IDs you choose to save | When you use the planner | This is the product. It is stored so you can come back to it. |
| Your active firm and scheme, comparison choices, and private notes retained from earlier research interfaces | When you choose application context or used one of the earlier private research interfaces | So your current selections resume on another signed-in device and earlier private data is not silently destroyed. This data is part of your private planner and is never used as a Live Data contribution. |
| Your private Draft Answers and Application Question Bank text, their question and application identifiers, word counts, numbered version history, restore links and saved times | Only when an authorised member chooses Save Draft | So the draft can be reopened on another visit or device, restored and compared with earlier versions. Each question allows drafting up to twice its stated word limit; that writing cap is enforced before storage. |
| Your private work experiences: employer, role title, start and end month, days worked each week, draft text, selected word count and numbered version history | When an authorised member adds or saves a work experience | So up to 20 entries can be ordered, drafted, reopened on another device, versioned and compared. Entries allow drafting up to twice the selected 150, 250 or 300 word limit. |
| An optional Video Interview practice recording: your image and voice, the question identifier, file type, file size, answer length and saved times | Only when a user with access to the Video Interview prototype chooses Save to account or confirms Replace saved video | So that user can privately replay or download one saved answer per question. A new recording remains only in the current browser tab unless the user expressly saves or replaces the account copy. |
| A short-lived Google Drive access token and the selected draft content | Only when an authorised member chooses Create a Google Doc and grants Google Drive permission | To create the requested formatted document in that Google account. City Tracker requests only drive.file, uses the token for that request and does not store it. |
| Your opted-in application status check-ins: firm, scheme, status, status date and the time you checked in | Only if you turn on Live Data and make a check-in | To build current anonymous movement, rejection and still-waiting signals, and aggregate waiting-time statistics. |
| Records from the retired discussion, profile, reaction, vault and messaging features | Only if you used one of those features before it was retired | These records are no longer displayed or operational. They remain secured during the rollback window so we can preserve your export and deletion rights. |
| The firms and milestones you want alerts about | Only if you set up firm alerts | To show matching later reports from other opted-in applicants in your Alerts page and to know what to email you about when email delivery is available. |
| An issue report, the page it concerns and an optional reply email | Only if you choose Report Bug and send it | To investigate problems, correct recruitment data and consider improvements you suggest. |
| A firm, scheme, milestone, report time, public forum source and one-way deduplication hash | When a public forum post explicitly reports an application outcome with high confidence | To add a clearly labelled external signal to Live Recruitment without storing or republishing the forum username or message text. |
We do not use third-party analytics, advertising trackers or cross-site tracking. The owner dashboard shows aggregate totals only. It cannot display a person's name, email, firms, timeline or individual browsing history. We do not profile you, and we do not sell or share your data with anyone for their own purposes.
Our lawful basis
We rely on your consent (UK GDPR Article 6(1)(a)) for your account and Live Data contributions. The planner works without Live Data, and historical evidence remains open. You can withdraw Live Data consent without losing your private planner.
We also rely on your request and consent when you save your active firm and scheme, private application or work experience draft text and versions, an optional Video Interview practice recording, or ask City Tracker to create a Google Doc. Saving a recording is optional and happens only after you choose Save to account or confirm that you want to replace an existing saved answer. Creating a document is optional and Google Drive permission is requested only at that moment.
We rely on our legitimate interests when retaining and administering historic access grants, single-use access codes and code-reuse prevention records. The public site no longer requires an access code. Codes are not used for advertising or profiling.
We rely on our legitimate interests in operating and improving City Tracker when we handle an issue report you choose to send. Providing a reply email is optional.
We rely on our legitimate interests in improving City Tracker when we count page and product-area use, area-to-area movement and Research or Write tool opens in aggregate. These counters contain no user, account, session or device identifier and cannot be used to reconstruct an individual's activity or path.
We rely on our legitimate interests in providing timely recruitment-market information when we derive a minimal signal from a public forum report. City Tracker stores no forum username or post text, does not treat the signal as a City Tracker applicant, and does not include it in applicant counts or progression percentages.
We rely on our legitimate interests in keeping retired feature records secure and inaccessible during a limited rollback transition, while preserving account export and deletion. They are not used to operate a discussion service, build profiles or send messages.
The anonymous session cookie is strictly necessary to make the site work at all, so it does not require consent.
What other people can see
This matters more than the rest of this notice, so it is worth being precise.
If you turn on Live Data and keep your status current, other eligible users can see anonymous counts of applicants tracking, submitting, progressing, being rejected and confirming that they are still waiting at a firm and scheme. A current signal can start at one report.
They never see your name, email, account, exact submitted date, exact status date or full timeline. Live Recruitment returns only the firm, scheme, status, aggregate count and a rounded report time. Firm Profiles returns aggregate firm and scheme totals.
Live Recruitment can also show a separately labelled Public forum report. This means the signal came from an explicit public forum report rather than a City Tracker user. The public display contains the firm, scheme, milestone and rounded time only. It never republishes the forum username or message text, and it never increases City Tracker applicant counts.
Comparative statistics are withheld entirely until enough people have contributed, so that no figure can be traced back to any one person.
Retired social features are not public. Discussion posts, member profiles, reactions, saved items and messages from the retired features are no longer returned by the service. They remain available only through your own data export or deletion during the transition.
Your active firm and scheme, comparison choices, retained notes from earlier private research interfaces, draft text and version history are private. They are returned only to the signed-in account that saved them. They do not enter Live Data. Each written question has its own history. Restoring a version creates a new version rather than deleting later history. Creating a Google Doc sends the selected questions, answers, account name and document title to Google so Google can place the document in the Drive account chosen in its permission window.
Your SJT Practice choices and scores are not sent to City Tracker. They remain only in memory in the current page while you complete or review a practice group. They clear when you end or restart the attempt, reload or close the page, or sign out. They are not saved to your account and do not enter Live Data.
Your Video Interview recordings are private. An unsaved take remains in memory in the current browser tab and is cleared when the page closes, reloads or you sign out. A take is uploaded only when you choose to save it. A saved recording is returned only to the signed-in account that saved it, never enters Live Data and is not made available to law firms or other members.
Be aware: while City Tracker is small, a firm and scheme can show one applicant. Someone who already knows where you applied may be able to guess that a report is yours. If that matters to you, do not turn on Live Data. The planner and historical evidence work without it.
Who else processes your data
- Google verifies your identity when you choose to sign in. If a signed-in user chooses to create a Google Doc, Google also receives the selected draft content and creates the file in the Drive account chosen by that user. City Tracker requests only permission to create and manage files it creates, not access to the rest of Drive. Google's code is loaded from Google and Google may set its own cookies, governed by Google's privacy policy.
- Resend delivers alert emails and issue-report emails. For alerts, they receive your email address and the alert text. For issue reports, they receive the content needed to send it privately to City Tracker.
- Our hosting provider runs the server and stores the database and private saved Video Interview files on an encrypted volume in London.
Some of these providers operate outside the UK, including in the United States. Where data is transferred outside the UK, it is protected by the safeguards those providers have in place, such as the UK Addendum to the EU Standard Contractual Clauses.
How long we keep it
- Your session cookie expires after 30 days without use. After that the session is revoked and you sign in again.
- Your account, planner, active firm and scheme, comparison choices and retained notes from earlier private research interfaces are kept until you delete them. There is a button; see below.
- Your Draft Answers, Application Question Bank text and saved versions are kept with the account that saved them until the account is deleted, unless you permanently delete an individual saved version using the version tool. Saving edits updates the current question version; Version Up and restore create additional numbered versions for that question. Deleted versions cannot be recovered. A Google Drive access token is never retained. A Google Doc already created in your Drive remains there until you delete it through Google.
- An unsaved Video Interview take is kept only in memory in the current browser tab. A saved Video Interview answer is kept with the account until you explicitly replace it or delete the account. Only one answer can be saved for each question.
- Your historic access grant, if one exists, is kept with your account until you delete it. A consumed access code remains marked as consumed so it cannot be reused, but deleting the account removes its purpose label and link to the account.
- Your Live Data contributions and status check-ins are removed as soon as you leave Live Data, and when you delete your account.
- Records from retired social features are inaccessible to other users and kept only during the rollback transition. They are included in your export and erased if you delete your account.
- Queued alert emails are removed when you turn alerts off or delete your account.
- Issue reports are kept while needed to investigate the problem, correct repeat failures and understand whether the fix worked. If you include a reply email, you can ask us to remove the report.
- Aggregate usage totals are kept for no more than 400 days. They contain only a day, fixed product-area or tool labels and a total count.
- Public forum signals are kept for the relevant recruitment cycle and may be removed sooner if their accuracy is disputed. The one-way source hash exists only to prevent the same report being counted twice.
Your rights
Under UK GDPR you have the right to get a copy of your data, to correct it, to have it erased, to restrict or object to how it is used, to take it elsewhere, and to withdraw consent. Three of these are buttons rather than requests:
- Get a copy: sign in, open the account menu, and choose Download my data. It downloads your account data and saved-recording metadata immediately as a JSON file. A saved Video Interview file can also be downloaded from its expanded question.
- Stop Live Data sharing: open the account menu and choose Stop Sharing Live Data. Your contributions and alerts are removed immediately. Your private planner and account are not affected.
- Erase everything: sign in, open the account menu, and choose Delete my account. This erases your account, planner, Draft Answers, Application Question Bank text, saved Video Interview files, Live Data contributions, alerts and any records from retired features straight away and permanently. A Google Doc already created in your own Drive is controlled by you and is not deleted by City Tracker.
For anything else, email contact@citytracker.city. We will respond within one month.
Complaints
If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
Changes
If this notice changes in a way that affects you, we will say so on the site rather than quietly updating this page.