Privacy

This page describes what this site records about the people who read it, what it deliberately does not record, and how to get your data back or removed.

Not yet reviewed by a lawyer. This page was written from what the software actually does, which is the part an engineer can vouch for. It has not been checked by a qualified adviser.

Legal · Last updated 15 September 2026 · applies to Emo News

This page describes what this site records about the people who read it, what it deliberately does not record, and how to get your data back or removed.

If you never sign in

Reading the site requires no account and sets no cookie. We count page views on our own server — one row per view, with the path, the story if the view was a story, and the country our hosting provider reports for the request. We also store a value we call a visitor hash: a salted fingerprint of your address and browser that is rotated every day. It distinguishes two readers on the same day without being able to identify either, and it cannot be joined across days to reconstruct a history. We do not keep a log of IP addresses.

If you do sign in

Signing in is how you comment, save a story or follow a topic. It stores:

  • Your email address, and the name you give us. You get an account by asking for a sign-in link; there is no password to store.
  • A session record — a hashed token and an expiry, kept for 60 days. We keep at most 20 live sessions per account and drop the oldest beyond that.
  • What you write and collect — comments, saved stories and follows, each tied to your account.
  • Nothing about newsletters. No newsletter sign-up is offered on this site, so no newsletter interests are recorded. If one is added, this list and the cookie list change with it.

What we do not do

  • Advertisements on the homepage and within articles are served by this site as first-party images and links. We do not use third-party ad networks or tracking pixels.
  • No social media embeds that phone home when a page loads.
  • No cross-site tracking, and no building profiles of readers.
  • We do not sell, rent or trade personal data. Full stop.

Cookies

One cookie, and only after you sign in. It is listed with its lifetime on the cookies page.

How long we keep things

  • Sign-in links expire after 15 minutes and work once.
  • Sessions last 60 days, and end immediately when you sign out or an administrator revokes access.
  • Stories moved to the bin are deleted 30 days later.
  • Backups are kept for at least 30 days so that a mistake can be undone.
  • Page-view rows have no retention limit set on them yet and are kept indefinitely. We are deciding the period and will state it here before the site opens to readers.

Your rights

You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Use the contact route at the foot of this page and we will answer within one month (30 days).

One limit, stated plainly because it is a deliberate decision rather than an oversight: deleting your account removes your account and personal data, but it does not reach into published journalism. The archive is the record. Where a published item names you, we can remove the link to your account; we will not silently rewrite a story that has already been published and receipted.

How your data is protected

  • No passwords exist to be stolen — sign-in is a single-use link.
  • Session tokens are stored hashed, so a copy of the database is not a set of keys.
  • Sign-in requests and other public actions are rate-limited.
  • The site is served over HTTPS, and admin access is separate from reader accounts.
  • Nothing is sold on this site, so no payment details are ever collected.

Children

This site is not directed at children, and we do not knowingly collect their data. There is no minimum age check on an account, because there is nothing on the site that an adult has to be to use. If you believe a child has given us personal data, use the contact route at the foot of this page and we will remove it.

Who is responsible

The company that runs this site has not published its legal name here yet, so this page cannot name the data controller.

No data protection officer has been appointed, so questions about personal data go to the contact route at the foot of this page.

Changes to this page

If this page changes in a way that matters, we will say so on the site rather than quietly editing the date at the top.

Contact

No public contact address has been published for this site yet, so this page cannot give one.