Skip to content
Dispatch Report

Legal

Privacy policy

Version 2026-09-20

For the site owner: the highlighted fields below come from LEGAL_ENTITY, LEGAL_ADDRESS, LEGAL_CONTACT_EMAIL and LEGAL_JURISDICTION in .env. This policy is not complete until they are set.

Who is responsible

Dispatch Report is published by [LEGAL_ENTITY not set], [LEGAL_ADDRESS not set]. We are the “controller” of the personal data described here. For anything about your data, write to [LEGAL_CONTACT_EMAIL not set].

What we collect, and why

DataWhenWhyLegal basis
Name, handle, email address, password (stored only as a one-way hash)You registerTo run your account, show your name on comments, and reach you about your accountPerformance of a contract (the terms of use)
Whether and when your email was verified; when you accepted the termsYou register or verifyTo know the address is yours; to record your consentLegal obligation (Art. 7 GDPR); legitimate interest
Comments, likes, saved articles, writers and sections you followYou use those featuresTo provide them — they are the featurePerformance of a contract
A phone number, if you add one. Stored encrypted, with a keyed hash beside it so the same number cannot be verified on two accounts. The verification code is stored only as a keyed hash and expires in ten minutes.You add a phone number on your account pageTo send you a verification code; a second way to prove it is youConsent — withdrawn by removing the number, which deletes it
Which of your comments were posted anonymously. Readers see “Anonymous”; the comment stays linked to your account so moderators can act on abuse, replies reach you, and deletion removes it.You tick “Post anonymously”To withhold your name from readers while keeping the site accountablePerformance of a contract
A push subscription: the address your browser's push service issued for this device, and two encryption keys. Linked to your account only if you were signed in when you turned alerts on.You turn on “breaking news alerts”To deliver those alertsConsent — withdrawn by turning them off, which deletes the record
Sign-in events: time, IP address, success or failure, and account changes (a security audit log)You sign in, or a staff member changes somethingDetecting break-in attempts and account abuse; investigating incidentsLegitimate interest in the security of the service
Two-factor authentication secret (encrypted) and recovery codes (stored only as keyed hashes)You enable two-factor authenticationTo verify your codes, and to let you back in if you lose your authenticatorConsent; security
IP address, brieflyEvery requestRate limiting, so one person cannot flood the site or guess passwordsLegitimate interest in the security of the service
Article readership statistics: a view count per article per day, split by country (a two-letter code your network provider or our CDN reports — the IP address itself is never stored), by how you arrived (search, social, direct, or the referring site's domain — never the page), and by device class (phone, tablet, desktop); and how long the article was on screen and how far it was scrolledYou read an articleEditorial analytics — which stories are read, where, and whether people finish themNot personal data: every figure is a total for the article and day, with no identifier, cookie or IP attached

We do not collect anything else. There is no advertising, no tracking pixel, no analytics service, and no profiling. We never sell personal data and never have.

Cookies

This site sets only cookies that are strictly necessary to make it work, which is why there is no cookie banner: they need no consent under the ePrivacy rules, and there is nothing to opt out of.

CookiePurposeLasts
authjs.session-tokenKeeps you signed inSession, up to 30 days
authjs.csrf-token, authjs.callback-urlProtects sign-in forms from forgerySession
localeOnly if you choose a language from the switcher: remembers it. Holds a two-letter code and nothing else.1 year
themeOnly if you choose light or dark rather than following your device: remembers it. Holds that one word.1 year
mfa_trustOnly if you tick “don't ask for a code on this device”: remembers that this browser passed two-factor authentication30 days

Your browser's own storage may remember a tab or a filter you chose; that never leaves your device.

Who else sees it

These services process data on our behalf, under contracts that bind them to this policy:

ServiceWhat forWhat they receiveWhere
Google (Sign in with Google)Letting you sign in with a Google account instead of a password, if you choose to. Nothing is sent to Google unless you press that button.Google tells us your name, email address, whether Google has verified that address, and your profile picture. We ask for nothing else. The picture is copied here once and then served from this site, so viewing a page never contacts Google.United States (Google acts as its own controller for what it does with your Google account)
Have I Been PwnedChecking a chosen password against known breachesThe first five characters of the password's SHA-1 hash — never the passwordGlobal

Beyond those: nobody, unless the law requires it (a court order, for instance), in which case we will tell you unless we are legally forbidden to.

How long we keep it

  • Your account and content: until you delete your account (see below).
  • Security audit log: 365 days, then deleted automatically.
  • Notifications: 180 days.
  • Push alert subscriptions: until you turn alerts off or delete your account; a device the push service keeps rejecting is dropped after 30 days.
  • Last sign-in IP address: cleared after 90 days without a sign-in.
  • Rate-limit counters: minutes.
  • Email verification and password-reset links: one hour, single use.

Your rights

Wherever you are, you can do all of the following yourself from your account settings, without asking us:

  • See and take your data (access and portability): download everything we hold about you as a JSON file.
  • Correct it (rectification): change your name; change your password.
  • Delete it (erasure, “right to be forgotten”): delete your account. Your name, email, password and settings are erased immediately. Your comments are removed from the site; where a reply from someone else hangs off one, an anonymous placeholder keeps their reply readable. The security audit log keeps its entries for the retention period above, without your name or email.

You also have the right to object to processing based on our legitimate interests, to restrict it, and to withdraw consent where consent is the basis (for example by turning off two-factor authentication). To exercise any of these, or if something on the account page does not work for you, email [LEGAL_CONTACT_EMAIL not set]. We answer within one month.

If you are in the EU or UK and believe we have handled your data unlawfully, you can complain to your national data protection authority.

California residents — your privacy choices

Under the CCPA/CPRA you have the right to know what we collect (the table above), to delete it (your account page), to correct it, and to opt out of the sale or sharing of your personal information. We do not sell or share personal information, as those terms are defined in the CCPA, and we do not use it for cross-context behavioural advertising, so there is nothing to opt out of. We honour Global Privacy Control signals as a matter of course. We will never treat you differently for exercising these rights.

Children

The site is not directed at children. Registration requires you to confirm you are 16 or older. If you believe a child has created an account, tell us and we will delete it.

Security

Passwords are hashed with Argon2id; two-factor secrets are encrypted at rest; every page is served over HTTPS with a strict content security policy; staff accounts with full access must use two-factor authentication. If a breach ever affects your data, we will tell you and the relevant authority within 72 hours of learning of it.

Changes

When this policy changes materially, the version at the top changes and registered users are told by email or a notice on the site before the change takes effect.