Privacy
This page describes the data behavior of the Hamburgerlandia public website, citizen portal, and installable web app.
Browser-local records
The simple citizenship form on the public citizenship page creates a browser-local record for convenience. That local record remains on the device and is separate from the central citizen portal registry.
Clearing browser storage may remove browser-local records. A browser-local record does not by itself create a central citizenship, title, parcel, payment, prize, or government record.
Tommy Account and central country records
The citizen portal uses the shared Tommy Account sign-in service. Hamburgerlandia receives the account information required to identify the signed-in account and determine authorized administrative access.
When durable country storage is configured, the citizen portal stores central Hamburgerlandia records such as citizenship, applications, title requests and issuances, parcel holdings and transfer requests, contribution records, Daily Draw records, government appointments, official acts, prize claims, and audit events. Account references used by the country record store are derived from the authenticated account identity.
Contribution intent records do not mean money was received. A separate authorized confirmation record is required before the platform marks a contribution as confirmed.
Public registry
Official government acts, active appointments, issued titles, and recorded Daily Draw results may be published through the Hamburgerlandia public registry. Private account credentials and authentication tokens are not published through that registry.
Network and hosting data
Web hosting and identity infrastructure may process technical request information needed to deliver and protect the site, including IP address, requested URL, browser information, timestamps, authentication session information, and security or diagnostic logs.
Offline support
The installable web app may cache public application-shell files on the device for faster loading and limited offline access. Authenticated platform API responses are excluded from the service-worker cache.