ColumbiaWalks

Privacy Policy

Effective September 28, 2026

Overview

ColumbiaWalks is an independent community pedestrian-safety application for Columbia, Pennsylvania. This policy explains what information the ColumbiaWalks mobile application and related website submission pages handle and why.

Information you choose to provide

The app does not require an account. Optional contact fields may be left blank.

The website’s anonymous police-tip page offers optional, device-only [TEST] text preparation and links to CBPD’s official CRIMEWATCH form. This helper does not upload or store the tip draft. You manually copy and paste the text, choose Anonymous and Other, and submit on CRIMEWATCH. A normal website tab cannot fill or dismiss prompts inside a separate CRIMEWATCH tab. ColumbiaWalks does not collect tip text or attachments on this page or forward them when you open the link. Information you enter on CRIMEWATCH is handled by that service and the Police Department under their own privacy practices.

In version 3.17.1 and the earlier police-assisted 3.17.10 build, you can prepare an anonymous tip from a new or previously saved ColumbiaWalks report, or start a standalone draft. The app inserts [TEST] between every word in the subject and message. When you choose Fill CRIMEWATCH Form, it opens CBPD’s official page inside the app, fills those two fields, selects “I wish to remain anonymous” and “Other,” and clears contact fields. The optional subscription notice is dismissed automatically; agreement, verification, and response dialogs are left alone. This makes the draft available to CRIMEWATCH under its own privacy practices; ColumbiaWalks does not collect this separate tip or route it through its private test intake. Existing CW reports remain saved separately. The app does not attach files automatically, accept the official agreement, complete CAPTCHA, or press Submit. You personally review and submit on the official page and read its response for receipt. Test markings are reapplied to edited subject/message text before submission inside the app. The external-browser fallback requires manual copying and review. Selecting anonymous does not conceal network information or identifying details you include in text or attachments.

In internal test build 3.17.0, the Community anonymous-tip form sends text only to private ColumbiaWalks test intake after you review the marked preview and confirm the test acknowledgements. Every submitted human-readable field contains [TEST] between every word, including optional placeholders. The private record contains the marked subject, observation time, location, direction, plate/state and vehicle details if supplied, observation, evidence notes, app version, receipt time, test flags, and a random request ID/content hash used to prevent duplicate retries. It includes no name/contact fields, account or device identifier, or media. Police are not contacted, and these tips are not published on public maps, feeds, or the Page of Shame. Do not identify yourself in the free text; hosting infrastructure can still process network information. A marked pending copy is saved privately on your device until a receipt is confirmed or you remove that local copy. Removing the local copy does not delete a test already stored by ColumbiaWalks.

In earlier 3.16.x builds, the Community police-tip assistant is different from a ColumbiaWalks submission. When opened by itself, its draft stays on your device until you copy it, and ColumbiaWalks does not receive or store that text or your police-tip evidence. When you choose Submit to CW & Notify CBPD, the CW report is saved first and the app prepares a separate tip draft from those report fields. In either path, ColumbiaWalks does not send the draft or media to CBPD. If you continue, the app opens the Columbia Borough Police Department's external website, where you must choose anonymity, paste and review the text, attach any evidence, personally make the site's attestation, complete reCAPTCHA, and press its Submit button. Opening the site is not delivery, and ColumbiaWalks cannot confirm receipt. The Police Department website controls its own collection, receipt, retention, and privacy practices.

Photos, location, and device permissions

ColumbiaWalks removes embedded metadata from report and trash-can photos before saving or uploading the processed copy. You can decline camera, photo-library, or report-location access and use the available manual options instead.

Estimated weather context

After ColumbiaWalks receives a report with an incident location and time, the server may request model-derived estimated conditions for that place and hour from Open-Meteo. Before making that request, the server rounds the incident coordinates to two decimal places. It sends Open-Meteo only those rounded incident coordinates and the incident calendar date and hour. It does not send the phone's live location, report narrative, photo, contact information, or ColumbiaWalks report or submission ID. The request comes from the ColumbiaWalks server rather than the phone, so it does not expose the reporter's device IP address to Open-Meteo; Open-Meteo may process the server request under its own terms and privacy information.

ColumbiaWalks may store the returned estimated conditions with the report together with provenance identifying the provider and the rounded query location and incident time. These values are model-derived estimates, not measurements taken by the phone or proof of the conditions a person experienced. Open-Meteo data is attributed to Open-Meteo under the Creative Commons Attribution 4.0 International license (CC BY 4.0).

Weather enrichment is best-effort and server-side. An Open-Meteo timeout, outage, or missing result never blocks acceptance or storage of the report; the report continues without estimated weather. This processing adds no phone permission, does not start background location access, and does not cause the mobile app to contact Open-Meteo directly.

Optional walking activity

If you explicitly start walk tracking, ColumbiaWalks uses location while an Android foreground service and persistent notification are active to calculate distance on your device. Tracking stops when you end it.

If you explicitly choose Health Connect import on Android 14 or later, ColumbiaWalks requests read access only to walking exercise sessions and distance. After you review and agree to submit, ColumbiaWalks uploads only aggregate distance, duration, time range, activity count, source, and app version. Raw routes, unrelated health records, and device identifiers are not uploaded. You can use the reporting features without starting walk tracking or connecting Health Connect.

How information is used

We use submitted information to receive, review, and follow up on pedestrian-safety reports and app feedback; calculate aggregate walking statistics when users opt in; manage requested iOS TestFlight and Android Google Play testing access; operate and improve the service; prevent misuse; and support community safety analysis and advocacy.

Ordinary safety reports, police-interaction reports, feedback, and contact information remain private by default. A report submitted through the Page of Shame path is reviewed by an administrator before its metadata-stripped photo and optional description can appear publicly. The full license plate is not published automatically.

Trash-can public comments begin in a private moderation queue. Only administrator-approved or redacted public text and its fixed categories may appear in the public trash-can feed, and only when the comment is linked to an active entry in the canonical public trash-can inventory. The raw comment, selected hauler, Residential/Commercial selection, photo, submitted address or coordinates, submission ID, app version, and submission source are not returned in that feed.

Trash-can complaints remain in a separate private collection with a new-review status. They and their photos are never included in the public trash-can feed. Submitting a trash-can complaint does not automatically send it to Columbia Borough or another government recipient.

Reports go first to ColumbiaWalks. Versions 3.16.1, 3.17.1, and 3.17.10 default to field-test destination mode. The eligible-report control is collapsed, off by default, and enabled only when its separate photo and in-area location safeguards are met. Those safeguards do not block submission of the underlying standard CW report. If you affirmatively opt in specifically for the test destination, ColumbiaWalks may generate an email marked [TEST] and send it only to a ColumbiaWalks-controlled test mailbox. The Police Chief, Mayor, and Codes Department do not receive a field-test message.

A separate official destination mode may later be enabled. It still requires your destination-specific authorization and is limited to these routes: a crosswalk-encroachment or Repeat Reporting vehicle crosswalk-incursion report to the Police Chief and Mayor, or a missing-sidewalk report to the Codes Department. Authorization for the test mailbox cannot be reused for official routing, and authorization for official routing cannot be reused for testing. No other report category activates automatic official email.

An eligible official email includes the reported issue, observation time, location and coordinates, reporter comments, a ColumbiaWalks report reference, and the saved metadata-stripped photo. A police-route email also prominently displays a license plate and state when the reporter supplied them; the attached photo remains the underlying evidence.

Beta tester requests and trash-can complaints remain private and are not included in public maps, public insights, the public trash-can feed, or the Page of Shame.

Storage and transmission

Pending reports, feedback, trash-can submissions, and walking summaries may be stored on your device until submission succeeds. Submitted information is sent over HTTPS to ColumbiaWalks services. ColumbiaWalks disables Android backup for its private local app data. We retain submitted information for as long as reasonably necessary for the purposes described above, to protect the service, and to meet legal obligations.

To deliver and protect the service, ColumbiaWalks and its reverse-proxy or hosting providers necessarily process connection metadata, including an IP address, while a request is in transit. That metadata is not written into a trash-can submission record or returned in the public trash-can feed. Infrastructure access or security logs are separate from submission records, access-restricted, and retained under the documented operational retention period.

The website-distributed Android app may send anonymous self-update lifecycle events containing a random event identifier, event type, current and target app versions, time, platform, and an allowlisted failure reason. These events do not contain a persistent device identifier, contact information, or location. The Google Play build disables this self-update workflow.

Sharing and tracking

We do not sell personal information and do not use it for third-party advertising or cross-app tracking. A field-test email remains within the configured ColumbiaWalks test mailbox and is not sent to a government recipient. Except for an eligible official-destination email that you specifically authorize as described above, ColumbiaWalks does not routinely send private submissions, contact information, walking summaries, or other user information to a government agency. Information may also be handled by service providers that operate ColumbiaWalks infrastructure, disclosed when required by law or to protect rights and safety, or published as described above after review.

When you deliberately open the official Police Department form inside the app or in an external browser, information filled, entered, or attached there is handled by that external service rather than through ColumbiaWalks intake. Opening the external page does not itself submit a tip, and ColumbiaWalks cannot confirm anonymity, receipt, investigation, or delivery.

If official destination mode is enabled and an authorized email reaches a government recipient, that email and its attachment may be retained and may become subject to Pennsylvania public-records, litigation, retention, or disclosure requirements. ColumbiaWalks cannot control, retrieve, or delete a copy after it reaches a recipient.

ColumbiaWalks is independent and is not a government agency. Sending or authorizing an official email does not guarantee acknowledgment, investigation, correction, enforcement, or any other response. ColumbiaWalks is not an emergency service; contact 911 for an emergency.

Your choices

You may delete locally saved reports from the app. To ask about access, correction, or deletion of submitted information, use Contact Us and include enough detail to identify the submission. You can also reach the ColumbiaWalks team at (717) 992-3102. Some information may be retained where legally required or reasonably necessary to protect the service.

Children

ColumbiaWalks is a general-audience community-safety service and is not directed to children under 13. Do not submit a child's personal contact information.

Changes

We may update this policy as the app or our practices change. The effective date above identifies the current version.