Privacy Policy

Last updated 14 August 2026

Who runs this site

Streamflows.org is operated by Nick Steele, an individual hydrologist, as a personal portfolio and toolkit. It is not a company and not affiliated with any employer or agency. Questions about this policy can be sent to the address in /.well-known/security.txt.

What is collected

This landing page uses no cookies, no analytics, and no third-party trackers. It loads no external fonts, scripts, or images.

The applications behind the sign-in gate collect only what they need to work:

The web server also writes standard access logs — IP address, timestamp, requested URL, and browser user-agent — for security and troubleshooting.

What is not collected

No advertising identifiers, no behavioural profiling, no cross-site tracking, and no sale or sharing of information with third parties. Accounts are issued directly by the operator; there is no public sign-up, no mailing list, and no marketing email.

Hydrologic data

The data these tools display — streamflow, snowpack, weather, and forecast records — comes from public agency sources including USGS NWIS, NOAA River Forecast Centers, NRCS SNOTEL, NOAA SNODAS, and the Water Survey of Canada. It describes rivers and watersheds, not people, and carries no personal information.

How long it is kept

Account records are kept while the account is active; ask and the account and its saved preferences will be deleted. Server access logs rotate on a short cycle and are not retained long-term or archived.

Where it is stored

On a private virtual server in the United States, administered solely by the operator. All access is over HTTPS with Let's Encrypt certificates. Databases listen only on the local loopback interface and are not reachable from the internet.

Your choices

You may request a copy of the information held about your account, ask for it to be corrected, or ask for the account to be deleted. Because this is a small personal system with a handful of accounts, such requests are handled directly and promptly.

Changes

Any change to this policy will be reflected in the date at the top of this page.

Reporting a security issue

Security contact details are published at /.well-known/security.txt in the format described by RFC 9116. Good-faith reports are welcome.