What is processed
The assistant processes the message you submit, a random session identifier, and the location, month, crime category and boundary choices needed to answer it. The assistant Worker does not set a cookie.
Service providers
Messages, a small amount of recent conversational context, and a one-way hash of the session identifier are sent to OpenAI to produce replies and support abuse detection. OpenAI Responses requests are made with application-state storage disabled and are not used to train OpenAI models.
Disabling application-state storage does not itself disable OpenAI abuse-monitoring logs, which can include prompts and responses for up to 30 days unless the service account has approved Zero Data Retention or Modified Abuse Monitoring. See OpenAI’s API data controls.
Place searches use an operator-configured dedicated geocoder when one is available; otherwise they are sent to Postcodes.io, which provides UK postcode and OS Open Names place lookup. Administrative-boundary lookups are sent to mySociety MapIt. Street-crime queries are sent to the Partner in Crime data Worker and its public-data providers; Scottish annual council statistics are read from the site’s static official dataset.
Optional site analytics
The explorer offers optional Google Analytics measurement (property G-TJPKVJ25SD) for visits and feature usage. This is separate from assistant processing: the Google tag is not downloaded and Google is not contacted unless you select Accept analytics, and the application does not intentionally send chat-message content to Google Analytics.
If accepted, Google Analytics may set first-party _ga cookies. Advertising storage, advertising user data and advertising personalisation remain denied, and Google Signals are disabled. Only the analytics consent choice is stored in local storage by this consent feature. You can change it later using Analytics settings in the explorer. See the crime-data and site analytics notice for more detail.
Retention
Small session context and usage counters expire after 24 hours. Cached geocoding results expire after seven days and use hashed cache keys. Short-lived, hashed-IP rate-limit counters normally expire within two minutes.
The application does not store OpenAI response IDs. Cloudflare may retain operational request metadata and error logs under the site’s platform settings; message bodies are not intentionally written to application logs.
Reset and deletion
The app can request a reset by sending resetThread: true with the session UUID. The service advances a reset epoch and requests deletion of that session’s stored context and usage counter.
Cloudflare KV propagation is not instantaneous, so reset is not a hard real-time deletion guarantee across every edge location. Stale-epoch records are ignored once the reset epoch is visible. Shared geocoding-cache and abuse-prevention entries are not session records and expire automatically. You can also clear the site’s local browser storage to remove the browser-held session identifier.
Contact
For privacy questions or a deletion request that cannot be completed through reset, email support@partnerincrime.io. Include the assistant session UUID if you want a specific active session investigated.