Accountability
Corrections & changelog
Every correction we make and every change to how the index is computed, recorded here in the open — including which ones altered a reading someone had already seen.
Two kinds of change, kept separate
Surveillance figures are revised as later reports arrive, and FluTrack’s numbers move with them automatically on the next weekly refresh. That is the data updating as designed and it is not logged here. This page records the other kind: a mistake in how we computed or described something, or a deliberate change to the method.
-
Named the analytics provider and every processor by legal entity
The Privacy Policy said “if we enable analytics” and described vendors by role while Cloudflare Web Analytics was already live on the site. The policy now names Cloudflare, Inc. and the analytics product explicitly, a published vendor register at /vendors/ names every processor by legal entity with its lawful basis, retention and deletion route, and [email protected] is published for access and deletion requests.
-
Consent gate implemented rather than promised
Advertising and analytics storage now start denied for every visitor, a recorded decision is required before any non-essential tag can load, Global Privacy Control is honored as an opt-out, and the choice is manageable at /consent/ with Reject all offered as prominently as Accept all. Previously this was policy language with no implementation behind it.
-
Stopped describing the bundled sample file as a downloadable dataset
The home page’s Dataset structured data advertised /data/snapshot.json as a DataDownload while the page itself called it a sample fallback — which could make illustrative demonstration content look like a current public data product. The DataDownload is now emitted only for a verified published snapshot; while the artifact is illustrative it is labelled as an example in both the page and the structured data, which additionally carry the artifact’s version, generation date and the weeks it covers.
-
Named the publisher and the responsible editor
Pages attributed the methodology only to “FluTrack”. The site now names Oak & Main LLC as publisher, identifies the responsible editor role that maintains the index method, states plainly that nothing here is medically reviewed, and publishes a route for reporting data issues.
-
Completed the security header baseline
Added Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy, script-src-attr, manifest-src and worker-src directives, and first-party CSP violation reporting. The policy also now names the Cloudflare Web Analytics host it was previously blocking, so the beacon and the privacy policy describe the same reality.
-
Cached and offline pages now state their own freshness
A page served from the offline cache could be mistaken for a current respiratory signal. Cached and offline views now carry an explicit notice naming the last verified snapshot and a visible retry control, and no new severity notification is raised while offline.
-
Sample data could be badged “Live CDC data”
A live refresh that returned HTTP 200 but no usable rows could flip the provenance badge to “Live CDC data” while deterministic sample data was still on screen. The badge now requires at least 25 of 51 states to have actually been replaced and a valid week-ending date. Any reading seen with a “Live” badge before this fix may have been sample data.
-
CDC “Extremely High” activity level no longer dropped
A duplicate label-mapping helper did not recognise the CDC’s “Extremely High” ARI category, so that signal silently fell out of the composite and its 0.25 weight was renormalised across the others. The canonical mapping is now used everywhere. States reporting “Extremely High” before this fix were scored from three signals instead of four.
-
State pages no longer fell back to national data
When a state had no rows for the current week, the page could render the national aggregate under that state’s name rather than saying so. Missing data is now shown as missing.
-
Initial publication of the Respiratory Threat Level
First public version of the composite index: a weighted average over wastewater viral activity (0.30), ARI activity level (0.25), emergency-department visits (0.25) and laboratory positivity (0.20), renormalised over whichever signals a state actually has, then bucketed into five levels. Full thresholds are published on the methodology page.
Last updated: August 2026
How to report something that looks wrong
If a figure here does not match the CDC source, or a page says something the data does not support, tell us: [email protected]. We compare the reading against the underlying surveillance source, confirm whether the discrepancy is real, and fix confirmed errors promptly — usually on the next weekly refresh, and sooner where a page is materially misleading.
Where a correction changed what a page said, it is recorded above rather than quietly edited away, and entries flagged “Affected published readings” are the ones where a number someone saw was wrong. Entries are append-only: a mistake in this log is fixed by adding a corrective entry, never by rewriting an old one.
Privacy access and deletion requests go to [email protected] instead. Who is accountable for this site is set out on our About page.
Not medical advice
The information on FluTrack is provided for general informational purposes only and is not a substitute for professional medical advice, diagnosis, or treatment. Always seek the advice of a qualified health provider with any questions you may have regarding a medical condition.