Privacy
Enclerk.com runs public records portals for California public agencies. This page says what the service keeps about you, why, who can see it, and for how long.
Whose records these are
Each agency decides what happens to the requests made to it. We hold them on the agency's behalf and use them for nothing else. The platform's administrator can open an agency's records to support it, and every action taken that way is recorded in that agency's audit trail as the platform administrator's.
What we keep
If you make a request:
- your email address, which is how you sign in;
- your name, and any organization, mailing address and telephone number you choose to give;
- the language you would rather be answered in, if you name one on a request;
- your requests, your messages to the agency and the files you attach;
- when you signed in and out;
- a record of what happened on each request: when it was received, searched, answered and closed.
If you work for an agency:
- your name, username and work email;
- your passcode, kept only in a scrambled form that cannot be turned back into it;
- when you signed in and out, and what you did on each request, which is part of the agency's audit trail.
Requests are public records too
A public records request, and the agency's response to it, are records of the agency themselves, and may be released to anyone who asks the agency for them. Leave out of a request anything you would not want released.
Cookies and your browser
When you sign in we set one cookie, which keeps you signed in. The site needs it to work. It ends when you sign out, after an hour without activity, or after 24 hours at most, and it is used for nothing else. There are no advertising or analytics cookies.
How we count visits
Once a page has loaded, your browser tells us it was viewed. We keep the page's address, the site you followed a link from, your browser's time zone and language, how wide its window is, your internet address, and, if you are signed in, your role. We do not keep your name with it. Beside the address is a code made from the day, your address and your browser, which cannot be turned back into them and which changes every day. We ask a location service, ipinfo.io, which town and region your address belongs to; it receives the address and nothing else. A browser that asks not to be tracked is counted, and neither its address nor anything else about it is kept. These records are kept for 400 days and seen only by the platform's administrator.
Your browser also keeps a few things on the device you are using, and not on our servers:
- whether you prefer dark mode;
- which product's articles you last chose to see in the Help Center;
- what you were typing when a session ended. Only what you typed yourself is kept, and not text the page had already filled in for you. It is kept on that device for twelve hours and offered back to the same person at the next sign-in. It is thrown away as soon as it has been offered back, whether you put it back or discard it, as soon as you sign out, and once it is twelve hours old, which happens the next time anyone opens the portal on that computer;
- the answers of a signup you have not finished, with the key that picks it up again. Passcodes are never kept there;
- for staff using the redaction tool, whether you asked it to always, or never, look for other occurrences of text you highlight, once you tick the box to remember that answer.
- for the platform's administrator, the names and addresses of the last six agencies opened in the platform console, so its Overview can offer them again;
- a few things that belong to one browser tab and go when that tab is closed: the email address or username that was signed in and the request that was open, so the page you land on when a session ends can offer you the way back; the address of the page you were on, so signing in again returns you to it; the email address and key of a signup you have started; and, just after an agency is created, the new administrator's name and the usernames made for that agency, so the welcome page can name them.
On a computer other people use, a public counter or a library machine, sign out when you have finished and close the browser. Signing out removes what was being typed from that device and ends the session.
The pages load their typeface, Source Serif 4, from Google Fonts. Your browser asks Google's servers for it, and Google sees your internet address, as it would for any website that uses it.
We send email for the service and nothing else: sign-in links, notices about requests to the staff working on them, and the agency's messages and letters to the person who asked. Email is sent through a mail delivery service.
If you ask an agency to send you the agendas of its meetings, that agency keeps your email address and which meeting groups you chose, and uses them only to send you agendas. Nothing is sent until you confirm the address from a link we mail you, and an address never confirmed is deleted after seven days. Every mail has a link that stops them, and stopping deletes your address. The law makes a request good for the calendar year it is made in, so each January you are asked whether to go on, and an address not renewed by the end of January is deleted. The agency's clerk can see the list of subscribers.
If you apply to serve on an agency's board, commission or committee, that agency's clerk receives what you typed: your name, your email address, a telephone number and where you live if you gave them, and what you wrote. It is the agency's record, and like other records of the agency it may be disclosed under the Public Records Act. The public meetings page never shows an application or an applicant. A member who is appointed is shown by name, title, seat and term, never by an email address.
If you present a claim to an agency under the Government Claims Act, the agency's clerk types what your claim says into the agency's site: your name, your addresses, a telephone number and an email address if you gave them, what happened, and the amount. It is the agency's record of your claim, kept as its law requires, and seen only by the agency's own staff. Nothing about a claim is shown to the public here, and the site sends you no email about it: the notices the agency owes you go out on paper, from the clerk.
Who else handles it
We use other companies to hold or carry this information for us. We use them to run the service and for nothing else.
- Our hosting provider, DigitalOcean, runs the server the site sits on, and holds the nightly backups and any snapshots of that server. Where a deployment stores files in a bucket rather than on the server's own disk, that bucket is DigitalOcean Spaces. The servers and the bucket are in the United States.
- Our mail provider, Brevo, a French company, sends the email the service sends and keeps its own log of what was delivered. A reply you send to one of our messages reaches us through it.
If we change provider, this list changes with it, and this page says so with a new date.
How long it is kept
Files attached to a request are kept while the request is open, and then for the number of months the agency's plan sets, counted from when the request was closed or withdrawn (or from a file's upload, if that came later), and then deleted. Files on a request the agency has placed a records hold on, or held by an agency that has placed a hold on all its records, are kept until the hold is released.
An agency's logo, and the letter it sends us to have its account verified, sit beside its site and are kept until the agency is removed from the service. The audit trail of what staff did on each request is kept indefinitely: it is the agency's own account of how the request was handled.
We keep a copy of every message we sent. The text of the message is removed from that copy once the message is more than 90 days old, unless the agency has placed a hold on its records. Who it went to, what it was about and when it was sent stay, so an agency can show that a letter went out. A requester's record of signing in and out is kept for 365 days and then removed; a staff member's stays in the agency's activity log, which is trimmed only once that log has grown very long.
Deleting something does not reach the copies we keep so that we can recover from a failure. The database and the files are backed up every night, and each night's backup is kept for 14 days, so a deleted record is out of every backup within roughly two weeks. Where the operator has also turned on snapshots of the server, a snapshot holds everything on the machine as it was, for as long as the operator keeps that snapshot.
Requests, messages and their history are the agency's records, and we keep them until the agency asks us to dispose of them. The portal has no action that disposes of them: destroying a public record is the agency's own decision, under its own retention schedule, so it is done by asking us.
What we do not do
We do not sell information, share it for advertising, or use requests or their files for anything but running the service for the agency.
Questions, and your own information
To see or correct what an agency holds about you, ask the agency: it decides what happens to its records. For questions about this site, write to us with the form under Request a quote on the front page; a person reads every message.
Last changed 19 September 2026. If this page changes, the new version replaces it here, with its date.