Two kinds of change, kept separate

Surveillance figures are revised as later reports arrive, and FluTrack’s numbers move with them automatically on the next weekly refresh. That is the data updating as designed and it is not logged here. This page records the other kind: a mistake in how we computed or described something, or a deliberate change to the method.

  1. Correction

    Corrected several claims the site made about itself

    A sweep for statements that no longer matched the code found a cluster of them, all now fixed. The surge-alert pages described a weekly email service in the present tense although no alert has ever been sent — those pages now say so plainly, and the sign-up form states that joining reserves a place rather than starting a subscription. Seven pages said the site is supported by advertising while two others correctly said it serves none; all now say the same thing, which is that no advertising runs today. The offline notice called the bundled sample file the “last verified snapshot”, the one place on the site that described that file as real surveillance. Laboratory test positivity was listed among the feeds without noting that it has no live adapter, so a reading can rest on three signals rather than four. The privacy policy said the site stores two entries in your browser and then listed three. Structured data on all 51 state pages reported a modification date eight days before the publication date, which is not a possible state, and the methodology page carried three inconsistent dates. Three legal pages still showed “Last updated: July 2026” after being edited in August. None of these changed a reading; each was a description that had drifted from what the site actually does.

  2. Accountability

    Corrected the publisher’s registered legal name, and published its address

    The publisher was recorded here as “Oak & Main LLC”. That is not the entity’s registered legal name: the publisher is Oak and Main Developers LLC, a California limited liability company. Every page that names the publisher now carries the correct name, and the registered mailing address is published on /about/, /contact/ and /privacy/ and in the site’s structured data. The 2026-08-18 entry below is left as written, because this record is append-only and that entry is an accurate account of what the site said at the time. Publishing a verifiable address also removes the obstacle to any commercial email: the law requires a valid physical postal address in one, and until now there was none to give.

  3. Privacy

    Set out the California privacy position explicitly

    The policy previously referred to the CCPA in passing, alongside the GDPR, without stating this site’s position under it. FluTrack is published from California, so the policy now names the single category of personal information collected (an email address and a chosen state, only if you submit the alert form), states plainly that it has never been sold or shared for cross-context behavioral advertising, describes how a request is verified and how long a response takes, and records that Global Privacy Control is honored automatically. The governing-law clause in the Terms of Use, previously left as “the state in which FluTrack is operated”, now names California.

  4. Correction

    Pages disagreed with the methodology about which signals are measured

    The state-page FAQ, /alerts/, /medical-disclaimer/, /affiliate-disclosure/ and the home page each named three CDC surveillance signals and omitted the Acute Respiratory Illness activity level, which carries a weight of 0.25 — while /methodology/ and /data-sources/ correctly documented four. Across the site 54 of 69 pages contradicted the published method about what the index actually measures. The wording now comes from one shared definition, and the build fails if any page enumerates the sources without the ARI level. No reading was computed incorrectly: the scoring model always used four signals. What was wrong was the description of it.

  5. Correction

    “Nearby states” named states that are not nearby

    Every state page offered a list headed “Nearby states”, built by grouping states that share an HHS administrative region. HHS regions are administrative, not geographic, so California was told it could compare with Hawaii, Alaska with Idaho, and genuine bordering states such as Oregon were left out. The heading and the sentence now say what the grouping actually is — the HHS surveillance region — which is true whichever members are shown.

  6. Correction

    The social share card showed invented per-state severity

    The image used for link previews coloured each state on its map by a hash of that state’s own abbreviation, beneath a “Minimal → Very High” legend and with no indication the colours were not data. Anyone who saw FluTrack shared on social media saw fabricated severity for their state, with the site’s disclaimers stripped away by the preview. The map on that card now carries a single brand colour and claims only which places FluTrack covers and what scale it reports. The build fails if any severity colour reappears in the map area.

  7. Interface

    Every icon was cropped, and the favicon was blank

    The tool that renders the site’s icons and share card asked the browser for a window of a given size, but the browser reserved part of that height for its own interface, so each image was captured taller than it was drawn and lost its bottom rows. The favicon was reduced to a single painted row — an empty browser tab — and the app icons, home-screen icon and share card were all cut off. The renderer now measures that reservation rather than assuming it, and the build fails on any icon whose artwork does not reach the edge of its canvas. The Android home-screen icon, which had been an exact copy of the standard icon and was cropped by the system, is now a proper full-bleed variant.

  8. Privacy

    Named the analytics provider and every processor by legal entity

    The Privacy Policy said “if we enable analytics” and described vendors by role while Cloudflare Web Analytics was already live on the site. The policy now names Cloudflare, Inc. and the analytics product explicitly, a published vendor register at /vendors/ names every processor by legal entity with its lawful basis, retention and deletion route, and [email protected] is published for access and deletion requests.

  9. Privacy

    Consent gate implemented rather than promised

    Advertising and analytics storage now start denied for every visitor, a recorded decision is required before any non-essential tag can load, Global Privacy Control is honored as an opt-out, and the choice is manageable at /consent/ with Reject all offered as prominently as Accept all. Previously this was policy language with no implementation behind it.

  10. Correction

    Stopped describing the bundled sample file as a downloadable dataset

    The home page’s Dataset structured data advertised /data/snapshot.json as a DataDownload while the page itself called it a sample fallback — which could make illustrative demonstration content look like a current public data product. The DataDownload is now emitted only for a verified published snapshot; while the artifact is illustrative it is labelled as an example in both the page and the structured data, which additionally carry the artifact’s version, generation date and the weeks it covers.

  11. Accountability

    Named the publisher and the responsible editor

    Pages attributed the methodology only to “FluTrack”. The site now names Oak & Main LLC as publisher, identifies the responsible editor role that maintains the index method, states plainly that nothing here is medically reviewed, and publishes a route for reporting data issues.

  12. Security

    Completed the security header baseline

    Added Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy, script-src-attr, manifest-src and worker-src directives, and first-party CSP violation reporting. The policy also now names the Cloudflare Web Analytics host it was previously blocking, so the beacon and the privacy policy describe the same reality.

  13. Interface

    Cached and offline pages now state their own freshness

    A page served from the offline cache could be mistaken for a current respiratory signal. Cached and offline views now carry an explicit notice naming the last verified snapshot and a visible retry control, and no new severity notification is raised while offline.

  14. Correction Affected published readings

    Sample data could be badged “Live CDC data”

    A live refresh that returned HTTP 200 but no usable rows could flip the provenance badge to “Live CDC data” while deterministic sample data was still on screen. The badge now requires at least 25 of 51 states to have actually been replaced and a valid week-ending date. Any reading seen with a “Live” badge before this fix may have been sample data.

  15. Methodology Affected published readings

    CDC “Extremely High” activity level no longer dropped

    A duplicate label-mapping helper did not recognise the CDC’s “Extremely High” ARI category, so that signal silently fell out of the composite and its 0.25 weight was renormalised across the others. The canonical mapping is now used everywhere. States reporting “Extremely High” before this fix were scored from three signals instead of four.

  16. Correction Affected published readings

    State pages no longer fell back to national data

    When a state had no rows for the current week, the page could render the national aggregate under that state’s name rather than saying so. Missing data is now shown as missing.

  17. Methodology

    Initial publication of the Respiratory Threat Level

    First public version of the composite index: a weighted average over wastewater viral activity (0.30), ARI activity level (0.25), emergency-department visits (0.25) and laboratory positivity (0.20), renormalised over whichever signals a state actually has, then bucketed into five levels. Full thresholds are published on the methodology page.

Last updated: August 2026

How to report something that looks wrong

If a figure here does not match the CDC source, or a page says something the data does not support, tell us: [email protected]. We compare the reading against the underlying surveillance source, confirm whether the discrepancy is real, and fix confirmed errors promptly — usually on the next weekly refresh, and sooner where a page is materially misleading.

Where a correction changed what a page said, it is recorded above rather than quietly edited away, and entries flagged “Affected published readings” are the ones where a number someone saw was wrong. Entries are append-only: a mistake in this log is fixed by adding a corrective entry, never by rewriting an old one.

Privacy access and deletion requests go to [email protected] instead. Who is accountable for this site is set out on our About page.

Not medical advice

The information on FluTrack is provided for general informational purposes only and is not a substitute for professional medical advice, diagnosis, or treatment. Always seek the advice of a qualified health provider with any questions you may have regarding a medical condition.