Two kinds of change, kept separate

Surveillance figures are revised as later reports arrive, and FluTrack’s numbers move with them automatically on the next weekly refresh. That is the data updating as designed and it is not logged here. This page records the other kind: a mistake in how we computed or described something, or a deliberate change to the method.

  1. Privacy

    Named the analytics provider and every processor by legal entity

    The Privacy Policy said “if we enable analytics” and described vendors by role while Cloudflare Web Analytics was already live on the site. The policy now names Cloudflare, Inc. and the analytics product explicitly, a published vendor register at /vendors/ names every processor by legal entity with its lawful basis, retention and deletion route, and [email protected] is published for access and deletion requests.

  2. Privacy

    Consent gate implemented rather than promised

    Advertising and analytics storage now start denied for every visitor, a recorded decision is required before any non-essential tag can load, Global Privacy Control is honored as an opt-out, and the choice is manageable at /consent/ with Reject all offered as prominently as Accept all. Previously this was policy language with no implementation behind it.

  3. Correction

    Stopped describing the bundled sample file as a downloadable dataset

    The home page’s Dataset structured data advertised /data/snapshot.json as a DataDownload while the page itself called it a sample fallback — which could make illustrative demonstration content look like a current public data product. The DataDownload is now emitted only for a verified published snapshot; while the artifact is illustrative it is labelled as an example in both the page and the structured data, which additionally carry the artifact’s version, generation date and the weeks it covers.

  4. Accountability

    Named the publisher and the responsible editor

    Pages attributed the methodology only to “FluTrack”. The site now names Oak & Main LLC as publisher, identifies the responsible editor role that maintains the index method, states plainly that nothing here is medically reviewed, and publishes a route for reporting data issues.

  5. Security

    Completed the security header baseline

    Added Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy, script-src-attr, manifest-src and worker-src directives, and first-party CSP violation reporting. The policy also now names the Cloudflare Web Analytics host it was previously blocking, so the beacon and the privacy policy describe the same reality.

  6. Interface

    Cached and offline pages now state their own freshness

    A page served from the offline cache could be mistaken for a current respiratory signal. Cached and offline views now carry an explicit notice naming the last verified snapshot and a visible retry control, and no new severity notification is raised while offline.

  7. Correction Affected published readings

    Sample data could be badged “Live CDC data”

    A live refresh that returned HTTP 200 but no usable rows could flip the provenance badge to “Live CDC data” while deterministic sample data was still on screen. The badge now requires at least 25 of 51 states to have actually been replaced and a valid week-ending date. Any reading seen with a “Live” badge before this fix may have been sample data.

  8. Methodology Affected published readings

    CDC “Extremely High” activity level no longer dropped

    A duplicate label-mapping helper did not recognise the CDC’s “Extremely High” ARI category, so that signal silently fell out of the composite and its 0.25 weight was renormalised across the others. The canonical mapping is now used everywhere. States reporting “Extremely High” before this fix were scored from three signals instead of four.

  9. Correction Affected published readings

    State pages no longer fell back to national data

    When a state had no rows for the current week, the page could render the national aggregate under that state’s name rather than saying so. Missing data is now shown as missing.

  10. Methodology

    Initial publication of the Respiratory Threat Level

    First public version of the composite index: a weighted average over wastewater viral activity (0.30), ARI activity level (0.25), emergency-department visits (0.25) and laboratory positivity (0.20), renormalised over whichever signals a state actually has, then bucketed into five levels. Full thresholds are published on the methodology page.

Last updated: August 2026

How to report something that looks wrong

If a figure here does not match the CDC source, or a page says something the data does not support, tell us: [email protected]. We compare the reading against the underlying surveillance source, confirm whether the discrepancy is real, and fix confirmed errors promptly — usually on the next weekly refresh, and sooner where a page is materially misleading.

Where a correction changed what a page said, it is recorded above rather than quietly edited away, and entries flagged “Affected published readings” are the ones where a number someone saw was wrong. Entries are append-only: a mistake in this log is fixed by adding a corrective entry, never by rewriting an old one.

Privacy access and deletion requests go to [email protected] instead. Who is accountable for this site is set out on our About page.

Not medical advice

The information on FluTrack is provided for general informational purposes only and is not a substitute for professional medical advice, diagnosis, or treatment. Always seek the advice of a qualified health provider with any questions you may have regarding a medical condition.