The Public GalleryToronto

Privacy

Effective August 7, 2026

Accounts

You can read the entire site without an account. Nothing is behind a sign-in.

If you create one, it holds your email address, which is how you sign in and where the weekly email goes. It also holds your ward if you pick one, which is a ward number and not an address, and which you can change or clear whenever you like. A password is optional: you can sign in with an emailed link instead. If you do set one we store a scrypt hash of it and never the password, so nobody here can read it and we will never ask you for it.

We don’t ask for your name, your phone number, or your street address, and there is nowhere on the site to give them to us.

Why

Your email address signs you in and carries one email a week when council is sitting. While the election runs it also carries your ward’s races. Your ward puts the decisions and races that affect your streets ahead of the ones that do not: it changes the order things appear in, never how anything is described.

We don’t sell data, we don’t run advertising, and we don’t use retargeting cookies.

How signing in works

Signing in sets one cookie. It holds a random session identifier and nothing else: no email address, no name, no reading history. It expires after 90 days, or the moment you sign out. Signing out also deletes the session from our records, so a copy of the cookie taken off a shared computer stops working.

A sign-in link is stored as a hash of its token rather than the token, and expires after 15 minutes. To stop someone flooding a mailbox with links or guessing a password, we count recent attempts using a one-way hash of the network address that made them, never the address itself, and those records are deleted within a day.

What we collect whether or not you have an account

Three services record technical information about your visit. Vercel Analytics counts page views and measures load speed, using no cookies and no cross-site tracking. Google Analytics records which pages were read and where the visit came from, with IP anonymization on, so your full address is never stored. Microsoft Clarity records scrolling and clicks to produce heatmaps, and masks anything you type.

None of it is connected to your account. We don’t join analytics data to a reader record, and we don’t build a profile of what any individual reader has read. The purpose is to find out whether the site works and whether anyone is reading it.

How to turn it off

Creating an account is express consent to the account collection above. For the analytics, continuing to use the site is implied consent under Canadian privacy law, disclosed here. You can withdraw it with the Google Analytics opt-out add-on, by blocking cookies for this site, or by using a content blocker. Nothing stops working if you do, and every story is still readable without an account.

People named in our coverage

This is separate from information about you as a reader, and it matters more. Elected officials, filed candidates, and city staff acting in their official roles are named, because their public conduct is the subject.

Members of the public who speak at a meeting are not. Their names are in the official record and the meeting video, but we don’t publish them, we don’t create pages about them, and we don’t make them searchable. They are described by the role they stated, and if they didn’t say, we say only that they spoke. More on how that works in how scores work.

Everything else

Account information sits with our host, Vercel, and our database provider, Neon. Sign-in and weekly emails are delivered by Resend, which receives your address in order to deliver them. Beyond those and the three analytics providers, we share nothing. We may disclose information if required by law.

Account information is kept until you ask us to delete it. Under PIPEDA you can ask what we hold about you, correct it, withdraw consent, or ask us to delete it.

To delete your account, use the delete button on your account page. You confirm by typing your email address, and it goes immediately, along with everything attached to it. If you cannot sign in, email hello@publicgallery.app instead and a person will do it, confirming when it is done. Questions go to the same address.