Privacy
What we do with your information
Plain version: we keep what you give us, we do not sell it, and a handful of companies help us run the site and see parts of it. The rest of this page is the specific version, written from the code rather than from a template — including the parts that are not flattering.
Last updated August 27, 2026. Companion pages: Terms and where our information comes from.
Who we are
Wellington Roundup is an independent local information service for Wellington, Florida and the Western Communities, built and run by Felican.AI. We are not the Village of Wellington and not affiliated with any government body or venue we report on. Our postal address, which is on every newsletter we send, is 500 S Australian Ave, West Palm Beach, FL 33401.
What we keep
Only what you hand over. There is no analytics service on this site — no Google Analytics, no Facebook pixel, no session recorder, no product-analytics SDK of any kind.
Your account
Your email address, and whatever you put on your profile: username, display name, avatar, bio and location. There is no password — we email you a six-digit code instead.
stored in
app_user, profileQuestions you ask Fiona
The question and the answer, kept in full. If you are signed in, your email address is stored on the row. Questions asked by phone are stored the same way. We do not store your IP address with them.
stored in
interaction, chat_messageMessages you send
The text of every direct and group message, exactly as typed, plus who read what and when.
stored in
message, conversation_memberComments you post
The text, what it was about, and a score from the automated moderation check.
stored in
commentNewsletter signup
Your email address and name, the wording you agreed to, the time you agreed, where you signed up from, and the IP address you signed up from.
stored in
subscriberPhotos you upload
The image, stored under a name containing your account id. Location and camera data are removed from photos before they are saved.
stored in
profile.avatar_url, channel_post.media_urlsThings Fiona did for you
If you asked for an email or a text, we keep the address or phone number it went to and the words you consented to, so there is a record that you asked.
stored in
action_log
Signing in, and cookies
There is no password. You give us an email address, we email you a six-digit code that expires in ten minutes, and you type it back.
We set two cookies, both for your language preference, and neither of them tracks you. If you switch the site to Spanish, we store wr_locale so the choice survives to your next visit; when the one-time banner offering Spanish is answered — in either direction — we store wr_locale_offered so it is never shown to you again. Both last a year, both are first-party, and neither contains an identifier, an account, or anything that links one visit to the next. Clearing them puts the site back to English and lets the banner reappear. We set no other cookie of any kind: there is no advertising cookie, no analytics cookie, and no session cookie.
Signing in does not use a cookie. When you sign in, your browser stores a token, your email address and your display name in its own local storage. The token is valid for thirty days and it contains your email address in a readable form — it is signed so it cannot be forged, but it is not encrypted, so anyone who gets hold of it can read your address and use it until it expires. Signing out removes it from your browser, but we have no way to revoke a token that has already been copied elsewhere. Use a device you trust.
When you ask Fiona something
Your question is sent to companies that run the AI models. This is the part most privacy policies leave out, so to be explicit: the words you type go to Azure OpenAI, along with up to twelve earlier turns of that conversation. If our own records do not cover your question, it may also go to Perplexity and then to Google for a live web search. If Azure is unavailable, it goes to Groq instead.
Your name and email are not put into those requests. But you are typing free text, and free text contains whatever you put in it — so please do not type anything into Fiona you would not want leaving our systems.
The question and the answer are also saved on our side, and if you are signed in your email address is saved with them.
The phone line
We do not record calls. Florida requires everyone on a call to consent to being recorded, and our greeting does not ask for that, so recording is switched off. It is switched off explicitly in the assistant's configuration and there is a test that fails if anyone turns it back on.
What does happen: your audio is transcribed by Deepgram and the conversation is handled by an OpenAI model, both running inside Vapi, the service that operates the line. Your phone number is visible to the assistant during the call. When you ask a question that needs looking up, that question is saved on our side the same way a typed one is.
One thing we cannot tell you: what Vapi and its providers keep on their own systems. We have turned recording off in our configuration; their internal retention is theirs, not ours, and we are not going to claim knowledge of it we do not have.
Who else sees your information
We do not sell your information and we do not share it for anyone else's marketing. These companies process it so the site can work:
Azure OpenAI
Writes the answers Fiona gives you, and screens posts and comments.
The question you type, word for word, plus up to twelve earlier turns of the same conversation and the local records we found for it. Also the full text of any comment or channel post, for moderation.
When: Every AI answer on the site, and every comment or post you submit.
Groq
Stand-in for Azure OpenAI when it fails or is switched over.
The same question, history and comment text as Azure OpenAI.
When: Only when Azure errors, or an administrator selects it.
Perplexity
Searches the live web when our own records come up short.
Your question, with a line added telling it to answer about Wellington. Nothing else — no history, no name, no email.
When: Only when local retrieval is thin or you ask about something current, and only while the daily cap and the admin kill switch allow it.
Google (Gemini)
Second web-search fallback, with Google Search grounding.
Your question, same as Perplexity. The question drives a live Google search.
When: Only if Perplexity returns nothing or fails, and the cap still allows it.
Vapi
Runs the phone line and the in-page voice button.
Your live audio while you are on the call, and the number you are calling from.
When: Every call to the voice line, and every use of the voice button.
Deepgram
Turns your speech into text for the phone line. Chosen by us inside Vapi.
Your call audio.
When: Every voice call.
OpenAI
The model that reasons during a phone call. Also chosen by us inside Vapi.
The transcribed conversation, which includes the number you called from.
When: Every voice call.
Resend
Sends our email — sign-in codes, confirmations and the newsletter.
Your email address and the full contents of the message, which for a digest includes your name.
When: Whenever we email you.
Backblaze B2
Stores the photos you upload.
The image itself, under a filename that contains your numeric account id. Not your name or email.
When: Only if you upload an avatar or post a picture in a channel.
Cloudflare
Sits in front of the site as DNS and proxy.
Every request to the site passes through them, so they see your IP address, your browser and which pages you load.
When: Every visit, signed in or not.
Felican iMessage relay
Sends a text message when you ask Fiona to text you something.
The phone number you gave and the message text.
When: Only when you ask for a text and consent is recorded.
Separately, some pages load things straight from another company into your browser. We are not sending them anything, but because your browser fetches from them, they see your IP address the way any site you visit does:
- Google Maps — Your IP address and browser, plus the place being shown. Only on a page that renders a map.
- OpenStreetMap — Your IP address and which part of the map you are looking at. Only on /live.
- Cesium ion — Your IP address and browser. Only when the 3D globe loads.
Who can see what you post
Your profile is public. Your username, display name, avatar, bio and location can be read by anyone, including people who are not signed in, and they appear in search engines. Your email address is not shown on your profile.
Comments are public. Anyone can read them, signed in or not. Your display name, avatar and the time you posted appear alongside. Comments can be posted about an article or directly on another person's profile.
Direct messages are private to the people in them. Only members of a conversation can read it; anyone else asking for it is told it does not exist. Two honest qualifications:
- Messages are not encrypted. They travel over a secure connection, but they are stored as ordinary readable text in our database. Anyone with database access could read them. Do not use this for anything sensitive.
- Staff can read a message in two situations only: if someone in the conversation reports it, or if the automated filter blocked or held it when it was sent. There is no screen anywhere that lets us open a conversation and browse it.
- Joining a group shows you everything said before you arrived. Group chats are invite-only and only an owner or admin can add people, but once you accept, the whole history is visible to you.
Comments and channel posts are also sent to Azure OpenAI (or Groq) to be checked automatically before they appear. Private messages are not — those are screened by a word list that runs on our own server, with no outside call, unless someone reports the message.
Photos you upload
Location and camera data are stripped from photos. When you upload a picture we decode it and save it again, which drops the EXIF metadata — including GPS coordinates — by construction. That matters on a local site: a photo taken at home can otherwise carry the coordinates of your house.
Two limits worth stating. This applies to photos — JPEG, PNG, GIF and WebP. Video is not re-encoded, so any metadata inside a video file survives; if you post video, assume its metadata travels with it. And the link to a stored image is a long unguessable address rather than something protected by a login, so anyone you give that link to can open the picture.
Deleting things — read this part
This is where we have to be blunt, because the comfortable version would be false.
Removing a comment or a message does not erase it. It is hidden from everyone and shown as removed, but the row stays in the database with its original text, and a second copy of the text is written to a moderation record at the moment of removal. This is deliberate: if somebody sends an abusive message and deletes it thirty seconds later, the recipient's complaint next month still has the text attached to it. That protection is the reason the data survives.
We cannot currently delete your account. There is no button and no route for it, and the database is built to refuse it — the links between an account and its messages are set to block deletion. The only route available to us is a manual operation whose normal outcome is to detach your name from your content rather than remove the content. Even then, the message and comment text remains.
Unsubscribing does not delete your record. It marks your address as unsubscribed and stops the email. Your address, the consent wording and the IP address you signed up from are kept as the record that you did consent.
If you want your information dealt with anyway, write to us at [email protected]. We will tell you honestly what we can and cannot do rather than quietly doing nothing.
How long we keep it
We have not set a retention period for personal data, and nothing automatically deletes it. Accounts, messages, comments, questions asked of Fiona and newsletter records are kept indefinitely at present.
We do run a deletion clock, but it is for something else: business listing data licensed from Google must be cleared on a 30-day cycle, and the first of those falls due on 23 September 2026. That is a licensing obligation about business records, not about you, and we mention it only so the existence of that job is not mistaken for a personal-data retention policy. Setting a real one is on the list.
What you can actually control
Stop the emails
Every issue has an unsubscribe link. One click stops every email we send to that address, not just the newsletter.
Choose who can message you
Set direct messages to anyone, contacts only, or nobody, from your inbox settings.
Block someone
Blocking works both ways and takes effect immediately. The person blocked is not told.
Remove your own posts
You can remove your comments, messages, channel posts and saved chats. Read the section below on what removal actually does.
Leave the giveaway
You can opt out of the giveaway and stay subscribed to the newsletter.
Sign out
Signing out clears the token stored in your browser.
Children
We do not ask anyone's age and we have no way to tell whether a visitor is a child. We are saying that plainly rather than printing a minimum age we do not check. We cover local schools, so young people may well read this site — but accounts here come with direct messaging and public comments, and a parent should know that before a child signs up. If you believe a child has given us information and you would like it removed, write to [email protected] and we will act on it.
Our crawler, if you run a website
We read public pages to build the site. Our crawler identifies itself as WellingtonRoundupBot/0.1 (+felican.ai), fetches no faster than one request a second per site, and reads and obeys robots.txt — if a page is disallowed it is not fetched, and if your robots.txt cannot be read at all we stop rather than guess.
Three exceptions are written down rather than hidden, and each logs a warning when used: the National Weather Service API, the OpenStreetMap Overpass API, and a text-extraction proxy. One crawler, for the National Polo Center, presents a normal browser user-agent because that site refuses non-browser ones — but the robots rules are still matched against our own bot name, so we never use that disguise to claim permissions a human reader would have.
To be exact about the limits: a fetch made through a proxy is checked against the proxy's robots.txt rather than the origin site's, and a few live features on the site — traffic cameras, live streams, weather — make their own requests outside the crawler and are not robots-gated. We would rather tell you that than claim a blanket rule we do not keep.
If you want a correction, a removal, or for us to stop reading your site entirely, write to [email protected] and we will do it. That is a person reading email, not an automated system. Adding a rule for our bot name to your robots.txt works too, and that one is enforced in code.
Changes to this page
If we change how any of this works, this page changes with it. It describes the site as it is on the date at the top, not as we would like it to be.
Questions
Write to [email protected]. For official Village of Wellington information, always go to wellingtonfl.gov.
Wellington Roundup · 500 S Australian Ave, West Palm Beach, FL 33401
