Legal
Privacy policy
Version 2026-09-20
For the site owner: the highlighted fields below come from LEGAL_ENTITY, LEGAL_ADDRESS, LEGAL_CONTACT_EMAIL and LEGAL_JURISDICTION in .env. This policy is not complete until they are set.
Who is responsible
Dispatch Report is published by [LEGAL_ENTITY not set], [LEGAL_ADDRESS not set]. We are the “controller” of the personal data described here. For anything about your data, write to [LEGAL_CONTACT_EMAIL not set].
What we collect, and why
| Data | When | Why | Legal basis |
|---|---|---|---|
| Name, handle, email address, password (stored only as a one-way hash) | You register | To run your account, show your name on comments, and reach you about your account | Performance of a contract (the terms of use) |
| Whether and when your email was verified; when you accepted the terms | You register or verify | To know the address is yours; to record your consent | Legal obligation (Art. 7 GDPR); legitimate interest |
| Comments, likes, saved articles, writers and sections you follow | You use those features | To provide them — they are the feature | Performance of a contract |
| A phone number, if you add one. Stored encrypted, with a keyed hash beside it so the same number cannot be verified on two accounts. The verification code is stored only as a keyed hash and expires in ten minutes. | You add a phone number on your account page | To send you a verification code; a second way to prove it is you | Consent — withdrawn by removing the number, which deletes it |
| Which of your comments were posted anonymously. Readers see “Anonymous”; the comment stays linked to your account so moderators can act on abuse, replies reach you, and deletion removes it. | You tick “Post anonymously” | To withhold your name from readers while keeping the site accountable | Performance of a contract |
| A push subscription: the address your browser's push service issued for this device, and two encryption keys. Linked to your account only if you were signed in when you turned alerts on. | You turn on “breaking news alerts” | To deliver those alerts | Consent — withdrawn by turning them off, which deletes the record |
| Sign-in events: time, IP address, success or failure, and account changes (a security audit log) | You sign in, or a staff member changes something | Detecting break-in attempts and account abuse; investigating incidents | Legitimate interest in the security of the service |
| Two-factor authentication secret (encrypted) and recovery codes (stored only as keyed hashes) | You enable two-factor authentication | To verify your codes, and to let you back in if you lose your authenticator | Consent; security |
| IP address, briefly | Every request | Rate limiting, so one person cannot flood the site or guess passwords | Legitimate interest in the security of the service |
| Article readership statistics: a view count per article per day, split by country (a two-letter code your network provider or our CDN reports — the IP address itself is never stored), by how you arrived (search, social, direct, or the referring site's domain — never the page), and by device class (phone, tablet, desktop); and how long the article was on screen and how far it was scrolled | You read an article | Editorial analytics — which stories are read, where, and whether people finish them | Not personal data: every figure is a total for the article and day, with no identifier, cookie or IP attached |
We do not collect anything else. There is no advertising, no tracking pixel, no analytics service, and no profiling. We never sell personal data and never have.
Cookies
This site sets only cookies that are strictly necessary to make it work, which is why there is no cookie banner: they need no consent under the ePrivacy rules, and there is nothing to opt out of.
| Cookie | Purpose | Lasts |
|---|---|---|
authjs.session-token | Keeps you signed in | Session, up to 30 days |
authjs.csrf-token, authjs.callback-url | Protects sign-in forms from forgery | Session |
locale | Only if you choose a language from the switcher: remembers it. Holds a two-letter code and nothing else. | 1 year |
theme | Only if you choose light or dark rather than following your device: remembers it. Holds that one word. | 1 year |
mfa_trust | Only if you tick “don't ask for a code on this device”: remembers that this browser passed two-factor authentication | 30 days |
Your browser's own storage may remember a tab or a filter you chose; that never leaves your device.
Who else sees it
These services process data on our behalf, under contracts that bind them to this policy:
| Service | What for | What they receive | Where |
|---|---|---|---|
| Google (Sign in with Google) | Letting you sign in with a Google account instead of a password, if you choose to. Nothing is sent to Google unless you press that button. | Google tells us your name, email address, whether Google has verified that address, and your profile picture. We ask for nothing else. The picture is copied here once and then served from this site, so viewing a page never contacts Google. | United States (Google acts as its own controller for what it does with your Google account) |
| Have I Been Pwned | Checking a chosen password against known breaches | The first five characters of the password's SHA-1 hash — never the password | Global |
Beyond those: nobody, unless the law requires it (a court order, for instance), in which case we will tell you unless we are legally forbidden to.
How long we keep it
- Your account and content: until you delete your account (see below).
- Security audit log: 365 days, then deleted automatically.
- Notifications: 180 days.
- Push alert subscriptions: until you turn alerts off or delete your account; a device the push service keeps rejecting is dropped after 30 days.
- Last sign-in IP address: cleared after 90 days without a sign-in.
- Rate-limit counters: minutes.
- Email verification and password-reset links: one hour, single use.
Your rights
Wherever you are, you can do all of the following yourself from your account settings, without asking us:
- See and take your data (access and portability): download everything we hold about you as a JSON file.
- Correct it (rectification): change your name; change your password.
- Delete it (erasure, “right to be forgotten”): delete your account. Your name, email, password and settings are erased immediately. Your comments are removed from the site; where a reply from someone else hangs off one, an anonymous placeholder keeps their reply readable. The security audit log keeps its entries for the retention period above, without your name or email.
You also have the right to object to processing based on our legitimate interests, to restrict it, and to withdraw consent where consent is the basis (for example by turning off two-factor authentication). To exercise any of these, or if something on the account page does not work for you, email [LEGAL_CONTACT_EMAIL not set]. We answer within one month.
If you are in the EU or UK and believe we have handled your data unlawfully, you can complain to your national data protection authority.
California residents — your privacy choices
Under the CCPA/CPRA you have the right to know what we collect (the table above), to delete it (your account page), to correct it, and to opt out of the sale or sharing of your personal information. We do not sell or share personal information, as those terms are defined in the CCPA, and we do not use it for cross-context behavioural advertising, so there is nothing to opt out of. We honour Global Privacy Control signals as a matter of course. We will never treat you differently for exercising these rights.
Children
The site is not directed at children. Registration requires you to confirm you are 16 or older. If you believe a child has created an account, tell us and we will delete it.
Security
Passwords are hashed with Argon2id; two-factor secrets are encrypted at rest; every page is served over HTTPS with a strict content security policy; staff accounts with full access must use two-factor authentication. If a breach ever affects your data, we will tell you and the relevant authority within 72 hours of learning of it.
Changes
When this policy changes materially, the version at the top changes and registered users are told by email or a notice on the site before the change takes effect.