STRATAHELM · COMMUNITY AI EXPOSURE & RESILIENCE INDEX

Privacy Policy

CAERI National › Privacy

What we collect, why, how long we keep it, and what we will never do with it.

Version 1.0 · Effective September 1, 2026 · Applies to: stratahelm.com, the CAERI public county layer, and StrataHelm subscription services

1. Who we are and what this covers

StrataHelm LLC publishes the Community AI Exposure & Resilience Index (CAERI), a free county-level measure built from published federal statistics, and sells subscription analysis to local government.

This policy covers three different relationships, and they are genuinely different in what we hold:

For anything in this policy — a question, a request, or a complaint — use our contact page.

2. Reading the free public site

The county pages, state hubs, national index, methodology, articles, downloads and this policy are static files. When you read them:

One page is different, and section 3 is about that page.

Our hosting providers keep ordinary server logs — the requesting IP address, timestamp, page requested and user agent — as every web server does. We use them for security and troubleshooting, and they are held under those providers' own retention schedules rather than ours.

3. The contact page loads MailerLite

Our contact page is the one page on this site that loads third-party code. It runs MailerLite, which powers the contact and mailing-list form. MailerLite sets its own cookies and performs its own tracking on that page, under its own privacy policy and not ours.

We are stating this plainly rather than burying it, because the rest of the site genuinely does make the stronger promise in section 2, and we would rather name the exception than weaken the whole claim.

You can reach us without submitting anything to the form — that page also carries a direct email link. Opening the page still loads MailerLite's code, which is exactly why this section is here.

If you do give the form your address, MailerLite holds that address and the fact that you subscribed, and every message we send carries an unsubscribe link.

4. The index itself contains no personal data

CAERI is computed entirely from published aggregate statistics from federal statistical agencies — principally the U.S. Census Bureau and the Bureau of Labor Statistics, together with related federal programs. These publish counts and averages for geographic areas, not records about people.

We do not buy, scrape or infer data about individuals. No score, percentile, rank or data file we publish describes an identifiable person. We also do not use the index to judge any individual, and our terms of service forbid our customers from doing so.

5. Subscription accounts: what we hold

If your organization subscribes, we hold the minimum needed to run the account.

What we holdWhyHow long
The name, work email address and role of each named seat To sign you in and to know what your account may see While the seat is active; removal is recorded rather than erased, so the account admin can see who had access and when
Which jurisdiction your account is entitled to It determines what the product shows you While the entitlement is live
Your contract record — what your organization agreed to pay and the period it covers To bill correctly and to honour the price you actually signed, which we never re-derive later For the life of the contract and as long as financial record-keeping requires
Sign-in links We email a single-use link instead of using passwords. Only a hash of the link is stored; the link in your mailbox is the only copy Short-lived. It expires quickly, and requesting a new one immediately retires the old one
Your signed-in session So you are not asked to sign in on every visit Until it expires or you sign out
Peer links, shared projects, and the invitations behind them To run mutual sharing between two subscribing jurisdictions While the link or project exists; membership dates are kept, which is what makes section 7's visibility rule work
An append-only audit trail of who granted, accepted or revoked access, and when So the question “who could see this, and when?” has a truthful answer For the life of the account

6. What we deliberately do not hold

Stated plainly for a security reviewer: if our customer database were fully exposed, it would reveal a list of government work email addresses, which county each is entitled to, contract and billing terms, which jurisdictions have linked with each other, and an audit trail of those decisions. That is the entire blast radius.

7. Sharing between jurisdictions

Two subscribing jurisdictions can agree to a peer link, which lets each see the other's fuller view for the county it holds, and can work together in a shared project space.

Two honest limits. Revoking stops future sharing; it cannot retrieve what the other jurisdiction has already seen or exported. And because both parties are government entities, content in a shared space may be subject to public-records law and reachable by a request served on either one.

8. People we contact about StrataHelm

We keep a private contact list for outreach to public-sector staff — typically a name, job title, organization, work contact details, and notes about our own correspondence. This is business contact information, drawn from public official sources, about people in their professional capacity.

It is held privately, is not published or exposed to the internet, and is backed up encrypted. We do not sell it, rent it, or share it with anyone. If you would rather we did not hold your details, tell us and we will delete them — use our contact page.

9. Who else processes data for us

We use a small number of service providers to run StrataHelm, each processing data only to provide its service to us:

All processing of subscription data takes place in the United States. We will name any of these providers on request, and this list may change as the service grows.

We will also disclose data where the law requires it. If we receive a subpoena, records request or court order covering a customer's data, we will tell that customer unless we are legally prohibited from doing so.

10. How we use what we hold

To sign you in, provide and support the service, invoice you, keep the service secure, and send you service messages about your account.

We do not sell personal data. We do not share it with advertisers. We do not profile members of the public, and we do not use one customer's content to market to another.

11. Security

No system is perfectly secure and we will not claim otherwise. If a breach affects your personal data we will tell you, and any regulator the law requires, without undue delay.

12. Your choices and rights

You may ask us to show you the personal data we hold about you, correct it, export it, or delete it. Ask through our contact page and we will respond promptly — normally within 30 days.

Your account administrator can add and remove seats at any time; removing a seat ends that person's access immediately.

Depending on where you live you may have additional statutory rights. We apply the rights above to everyone rather than sorting requests by jurisdiction.

One point specific to our customers: if you are a government employee, your correspondence with us may itself be a public record of your own agency, independent of anything in this policy.

13. Children

StrataHelm is sold to government organizations and is not directed to children. We do not knowingly collect personal data from anyone under 18.

14. Changes to this policy

The version and effective date at the top always identify the operative version. Material changes will be announced before they take effect — the same no-silent-changes principle our governance & recalibration policy applies to the index itself.

15. Contact

Privacy questions, requests and complaints go through our contact page.

StrataHelm LLC.