Privacy Policy
Quick summary
- Information you provide: contact details, messages, form submissions, relevant advocacy material and information used to administer a reader-support payment.
- Security information: request metadata, pseudonymous visitor/session identifiers, browser and device signals, network labels, navigation provenance and security events.
- Statistics: visitor and traffic statistics are produced from the site’s own edge data and viewed through a private dashboard. No third-party analytics service is used. You can opt out of being counted.
- Why it is used: to operate and secure the site, understand how it is used, reply to enquiries, carry out agreed work, administer reader support and meet legal or accounting obligations.
- Payments: Stripe hosts the checkout and processes monthly and one-off contributions. Full card details are entered into Stripe’s checkout rather than this website.
- Cookies and local storage: there are no advertising cookies. Security and session storage is used for site operation, and a seven-day local dismissal marker may be used for the reader-support prompt.
- Your rights: access, correction, erasure, restriction, portability, objection and withdrawal of consent where applicable.
Please send only what is relevant: The ordinary contact form and ordinary email are not intended for unsolicited highly sensitive material. Do not send complete medical records, identity documents, criminal records or similarly sensitive files unless they are relevant to assistance I have agreed to consider or I have asked for them. If you are unsure, email [email protected] before sending the information. Information that is not needed will be deleted.
Contents
- Controller and contact details
- What this policy covers
- Information collected
- Please provide only relevant information
- Security telemetry and fingerprinting
- Signed internal-link provenance
- Cookies and similar technologies
- Statistics and search reporting
- Reader support and Stripe payments
- Purposes and lawful bases
- Automated security rules
- AI-assisted work
- Special category and criminal offence data
- Recipients and service providers
- International transfers
- Retention
- Your rights
- Security measures and incidents
- Children
- Secure submissions, policy changes and changelog
1. Controller and contact details
I am Kieron JH, founder of The Reasonable Adjustment, and I am the data controller for the processing described in this policy.
Privacy contact: [email protected]
I am not required to appoint a Data Protection Officer. Privacy questions and rights requests should be sent to the address above.
2. What this policy covers
This policy covers personal data processed through:
- the public website and its Cloudflare edge Worker;
- contact forms, email and secure submission tools;
- security telemetry, alerts and operational statistics;
- the private statistics dashboard and search-performance services;
- reader-support prompts and payments made through Stripe; and
- advocacy or correspondence that I have agreed to handle.
It does not make third-party websites part of my service merely because I link to them. Their own privacy notices apply when you leave this site.
3. Information collected
Contact details and communications
- Email and direct contact: your name, email address, message content, attachments and any other information you choose to provide.
- Formspree contact forms: the form fields you submit and technical submission metadata made available by Formspree, such as IP address and user agent.
- Communications: correspondence between you and The Reasonable Adjustment, including enquiries, complaints and rights requests.
Your circumstances and agreed work
- Advocacy and support material: information contained in correspondence, documents or other material relevant to a matter I have agreed to consider.
- Health and disability information: special category data where it is relevant, necessary and lawful to use it for an agreed purpose.
- Disputes and proceedings: information about allegations, complaints, disputes, legal proceedings, criminal allegations, offences or convictions where relevant and lawful.
Reader-support payments
- Stripe checkout: Stripe may collect your name, email address, billing details, payment-method information and transaction information when you begin or complete a monthly or one-off contribution.
- Records available to me: payment amount and date, payment status, payer contact details, limited payment-method details, Stripe transaction or customer identifiers, subscription status, refunds, disputes and related correspondence.
Stripe collects full payment-card details through its hosted checkout. Full card numbers and card security codes are not entered into or stored by this website.
Information generated when the site is used
- Edge request data: IP address, ASN and network organisation, country or region, Cloudflare data-centre location, request time, requested path and query, referrer, request ID, HTTP/TLS details, user agent, client hints and fetch-navigation headers.
- Client telemetry: browser and operating-system information, screen and viewport size, language, timezone, navigation type, page-history count, visibility state, touch capability, logical processor count, approximate device memory where exposed, and GPU or browser-rendering information where the browser makes it available.
- Pseudonymous identifiers: visitor, session, page-view, fingerprint, browser-profile and hardware-profile keys used to recognise repeat activity and correlate security events. These are not intended to reveal a person’s name, but they can still be personal data because they may distinguish or reconnect visits.
- Network labels: the organisation an IP address or ASN is registered to, including labels for IP ranges publicly registered to UK police forces (see section 5).
- Navigation provenance: signed internal-link markers, their validation status, and whether navigation appears direct, external, search-originated, signed internal or unmarked internal.
- Security outcomes: risk signals, scores, interstitials, challenge outcomes, temporary blocks or delays, and links between events that meet configured correlation rules.
- Aggregate operational statistics: counts of requests, visitors and sessions; traffic sources; guard actions; high-score events; protected-page requests; 404s; and leading paths, networks and countries.
I do not use these signals to discover a visitor’s real-world identity. Network allocation labels, device similarities and behavioural correlations are indicators only. They can be wrong and are not treated as proof of a person’s employer, identity or intention.
4. Please provide only relevant information
Only provide personal information that is relevant to your enquiry or the service you are requesting. Sending an entire record is rarely necessary where a smaller extract or explanation will establish the relevant point.
Do not send complete medical records, identity documents, criminal records or other highly sensitive information unless it is relevant to agreed assistance or I have specifically requested it. Email [email protected] first if you are unsure.
5. Security telemetry and fingerprinting
Some security systems generate identifiers or signals relating to a device, browser, network or pattern of activity. These may include IP addresses, browser characteristics, device information and other technical signals. Where a signal can be linked, directly or indirectly, to an identifiable person, I treat it as personal data.
The site uses Cloudflare and a custom edge Worker to monitor abuse, automated enumeration, suspicious navigation sequences, repeated access to protected material and other activity that may threaten the site’s security or integrity.
The Worker can combine request metadata with browser-provided telemetry to create pseudonymous profile keys and compare activity across visits or networks. Comparing a device’s hardware and browser characteristics with the network it arrives from helps identify automated traffic, for example proxy services that route requests through residential internet connections from machines that are not home devices.
Network labels, including police networks
The Worker uses public network-allocation information to label an ASN or IP range, including ranges that appear associated with institutions. This includes a list of IP ranges that are publicly registered in the RIPE database to UK police forces.
Where a request comes from one of those ranges, the related security alert is labelled as a possible police network and names the force and range. The label appears alongside the other technical details recorded for that alert. It records a network allocation only. It does not confirm who the visitor is, their employer, their role or why they visited. The list is incomplete, and ranges can be reassigned.
Alerts and summaries
Selected events may be sent to private Discord channels as detailed technical alerts. Alerts can include the requested path, IP address, ASN or organisation, network label, country, user agent, request ID, pseudonymous identifiers, device/browser signals, scores, relevant historical observations and the action taken. These channels also act as a secondary record of security events.
Every three hours, and once daily at UK midnight, the Worker may also send an aggregate operational summary to Discord. These summaries are designed to report counts and leading categories rather than reproduce each individual request. The underlying statistics events are stored in Cloudflare KV for up to 16 days and in a Cloudflare D1 database, which the private dashboard reads from, for up to 90 days.
Private dashboard
I use a private administration dashboard to view the security events and statistics described in this policy in a readable form. Only I can access it. It is not shared with third parties and does not publish information about individual visitors.
Lawful basis: legitimate interests under Article 6(1)(f), namely operating, securing and defending the website; detecting abuse; maintaining reliable records; and understanding whether security rules are proportionate. A Legitimate Interests Assessment is available here: Legitimate Interests Assessment (PDF).
6. Signed internal-link provenance
Eligible links generated on this website may include a short signed src marker. The marker is used to verify that a navigation was generated by this site’s own HTML rather than copied, altered or manufactured elsewhere.
The compact marker contains:
- a format version;
- the WordPress object ID of the page containing the link;
- the eligible link’s position on that source page; and
- a shortened cryptographic signature tied to the destination path.
It does not contain your name, email address, IP address, visitor ID or device profile. The secret used to create the signature is not sent to the browser.
The edge Worker validates the marker before the request reaches WordPress. The marker may be removed from the origin request and from the visible browser URL after processing. The Worker can retain the validation result and decoded source/link position as part of security logging.
A missing or invalid marker is not automatically treated as hostile. Direct article visits can arise from bookmarks, search results, external links, copied URLs, old cached pages or privacy settings. Marker status becomes more significant only when combined with other indicators, such as a confirmed homepage-to-unmarked-page sequence, protected content, watched networks, abnormal navigation headers or linked probe-like activity.
7. Cookies and similar technologies
The site does not use advertising cookies or behavioural-advertising pixels. The security system does use cookies, device information read by the browser and similar storage. I treat these as strictly necessary to provide the site securely, including preventing or detecting fraud and technical faults in connection with the service you have requested, under the Privacy and Electronic Communications Regulations 2003 as amended by the Data (Use and Access) Act 2025.
The same pseudonymous identifiers are also used to produce the readership statistics described in section 8. That use is not strictly necessary for security. For it, I rely on the exemption in the same Regulations, as amended, for collecting information for statistical purposes to improve the site. The statistics are used only to understand and improve this website, are not used for advertising and are not shared with anyone for their own purposes. You can object at any time on the statistics opt-out page.
Security and service cookies
tra_vid and fp_statictra_sidtra_pvtra_home_srctax_*, challenge and guard-state cookiestra_stats_optoutWhere the visitor has consented to this use, the site may use the existing fp_static cookie and its stored view and session totals to decide whether to show a returning-reader support prompt. The browser receives only the view total, session total, returning status and reader band. The endpoint does not return the fingerprint identifier and requesting it does not add another page view.
If you dismiss the support prompt, the browser stores trsa_support_snooze_until in local storage for seven days. This prevents the prompt from reappearing during that period. It is stored on your device and is not used for advertising.
The precise cookie names and durations can change as the security implementation is adjusted, but they are not used for advertising or sale of data. Blocking essential security cookies may cause repeated challenges or prevent some protected pages from working normally.
8. Statistics and search reporting
- Private statistics dashboard: visitor, session, page and traffic-source statistics produced from the site’s own edge data and viewed only by me. Visitor and session counts are derived from the pseudonymous identifiers described in section 3. The dashboard is used to understand how the site is read and to improve it, not to identify or profile individual readers.
- Google Search Console and Search Console Insights: aggregate information about how pages appear and perform in Google Search, such as clicks, impressions and query trends.
- Bing Webmaster Tools: aggregate search-visibility and indexing information relating to Bing.
- Cloudflare: operational, performance and security information generated at the edge.
Plausible Analytics was used for cookieless aggregate audience measurement until September 2026. I keep an export of its aggregate statistics as a historical record. That export contains counts by date, page, source, device and location, not records of individual visits.
If you do not want your visits counted in the dashboard statistics, use the statistics opt-out page. It sets a cookie that stops your page views and reading time from being recorded for statistics in that browser. The choice applies to one browser at a time, so clearing cookies or using another device resets it. You can also email [email protected]. Opting out does not switch off security processing, which is needed to operate the site.
These services are used to understand site operation and discoverability, not to create advertising profiles of visitors on this website.
9. Reader support and Stripe payments
The site links to Stripe-hosted checkout pages for £5 monthly support and one-off contributions. When you open or use a Stripe checkout page, Stripe collects and uses transaction, device and fraud-prevention information under its own privacy arrangements. Stripe may collect information entered into a checkout form even if the transaction is not completed.
I use the transaction information made available through Stripe to process the contribution, administer a recurring subscription, issue receipts or refunds, respond to payment queries, handle disputes or chargebacks, prevent fraud and maintain financial records.
Lawful bases: steps taken at your request and performance of the payment arrangement under Article 6(1)(b); legitimate interests under Article 6(1)(f) in administering reader support, preventing fraud and resolving payment disputes; and legal obligation under Article 6(1)(c) where financial, tax or accounting records must be kept.
Returning-reader prompt: where the prompt uses stored or accessed device information and past browsing totals to decide what content to display, the basis is consent. A visitor who has not provided that consent should not receive the personalised prompt. Dismissing the prompt records the visitor’s preference for seven days.
You can read Stripe’s Privacy Policy for information about Stripe’s own processing, recipients, international transfers, retention and data-protection rights.
10. Purposes and lawful bases
I identify the lawful basis that corresponds to each purpose before processing begins. The basis used depends on what I am doing with the information:
- Contract or steps at your request: where information is needed to provide an agreed service, arrange that service or administer a payment you requested.
- Legitimate interests: where processing is necessary to operate and secure the site, respond to enquiries, maintain proportionate records, administer reader support or protect legal rights, after considering the effect on the person concerned.
- Legal obligation: where processing is necessary to comply with a duty imposed by law, including applicable financial and accounting duties.
- Consent: where I ask for agreement to a particular use. At present this applies to the personalised returning-reader prompt described in section 9. Consent can be withdrawn at any time without affecting processing that occurred before withdrawal.
Main purposes and lawful bases
11. Automated security rules and manual review
The Worker uses automated rules to score and classify requests. Depending on the combination of signals, it may:
- record a request or send an alert;
- show an interstitial or verification page;
- redirect a visitor through a short verification flow;
- temporarily slow a request; or
- temporarily block a high-confidence automated or abusive pattern.
These controls affect access to the website only. They are not used to make employment, credit, healthcare, legal or other decisions that produce legal or similarly significant effects.
Scores and profile matches are probabilistic. A VPN, shared device, privacy tool, cached link, network change or common hardware configuration can produce an innocent match. Where the evidence is weak, the system is intended to log or challenge rather than make a definitive attribution.
If you believe a security restriction was applied incorrectly, email [email protected] with the approximate date, time, page and any request ID shown. I will review the available records.
12. AI-assisted work
I may use third-party AI services, including OpenAI’s ChatGPT, for limited drafting, organisational or analytical tasks. This may include organising information, summarising documents, identifying themes, assisting with correspondence and improving the clarity or presentation of material.
- Necessity and minimisation: before personal information is considered for use with an AI service, I assess the purpose, necessity, proportionality and sensitivity of the information. I limit input to what is reasonably necessary and redact or pseudonymise identifiers where practical.
- Sensitive matters: special category and criminal offence data receive separate consideration under Articles 9 and 10 UK GDPR and the Data Protection Act 2018. If suitable safeguards and a valid legal basis are not available, identifiable sensitive content is not submitted.
- Training controls: I use available account controls to limit use of content for model improvement where appropriate.
- Human review: outputs are reviewed before being relied upon. AI does not make decisions about individuals on my behalf that produce legal or similarly significant effects.
- Retention: AI-assisted working chats are kept only while useful to an active matter and are normally deleted within 12 months. Provider-side deletion and safety-retention periods are governed by the provider’s current terms and privacy information.
OpenAI’s current privacy and data-control information is available through its privacy policy and Data Controls FAQ.
13. Special category and criminal offence data
Special category data
Health and disability information can be special category personal data. I process special category data only where it is necessary for a specific purpose, an Article 6 lawful basis applies and an Article 9 condition is satisfied. Depending on the circumstances, the Article 9 condition may be explicit consent or processing necessary for the establishment, exercise or defence of legal claims.
Where the relied-upon condition also requires a condition or policy document under Schedule 1 of the Data Protection Act 2018, that additional requirement must be met before the information is used for that purpose.
Criminal offence data
Information about criminal allegations, offences, convictions or related proceedings is processed only where relevant and necessary, an Article 6 lawful basis applies, and Article 10 UK GDPR and the Data Protection Act 2018 permit the processing. If no suitable condition applies, the information will not be retained for that purpose.
The fact that a matter involves a dispute or possible legal proceedings does not by itself mean that every item of information is being processed for the establishment, exercise or defence of legal claims.
14. Recipients and service providers
- Cloudflare: hosting-edge, security, performance, Workers, KV storage and D1 database storage.
- Formspree: contact-form transmission and, depending on account configuration, submission storage.
- Google: Search Console and Search Console Insights.
- Microsoft: Bing Webmaster Tools.
- Discord: private delivery and storage of security alerts and aggregate operational summaries, including a secondary record of security events.
- OpenAI: AI-assisted drafting where used.
- Stripe: hosted checkout, payment processing, recurring contribution administration, fraud prevention, refunds and disputes.
- Email and hosting providers: delivery, storage, backup and operation of communications and website content.
The contractual role of a provider can vary by service and context. Each provider’s own privacy information explains its independent processing. I do not sell or rent personal data.
15. International transfers
Some service providers operate globally and may process information outside the UK. Discord, for example, processes security alerts in the United States. Where UK personal data is transferred internationally, I rely on the provider’s applicable safeguards, which may include UK adequacy regulations or data bridges, the UK International Data Transfer Agreement, the UK Addendum to Standard Contractual Clauses, or another lawful transfer mechanism.
The exact location and safeguard depend on the provider, service and account configuration. Information about the applicable countries and transfer mechanism can be requested from [email protected]. Provider privacy notices and contractual terms should be read alongside this policy.
16. Retention
I keep information only for as long as reasonably necessary for the purpose for which it was collected. Current operational periods include:
Typical retention periods
Advocacy and support records: information relating to an agreed matter is retained for as long as reasonably necessary to provide the service, deal with follow-up issues and meet applicable legal or record-keeping requirements. Once the matter has concluded, the records are reviewed and retained only while a documented reason continues to apply.
Stripe and financial records: payment and subscription records are retained while a subscription remains active and afterwards for as long as required to deal with refunds, disputes, fraud prevention and applicable financial, tax or accounting requirements. Stripe applies its own retention periods to information it controls.
Retention may be extended where reasonably necessary to investigate repeated abuse, respond to a complaint, comply with law, or establish, exercise or defend legal claims. I review the continuing need and delete or minimise the information when that reason ends.
17. Your rights and complaints
Depending on the circumstances, you may have rights to:
- request access to your personal data;
- have inaccurate information corrected;
- request erasure;
- request restriction of processing;
- receive portable data where the right applies;
- object to processing based on legitimate interests;
- withdraw consent where consent is relied upon; and
- ask for human review of an automated security restriction.
These rights are subject to legal exceptions and are not available in every circumstance.
Right to object: Where processing is based on legitimate interests, you have the right to object. I may continue only where applicable law permits it, including where compelling legitimate grounds override your interests and rights or the processing is needed for the establishment, exercise or defence of legal claims.
I will respond to a valid data-protection request without undue delay and within the applicable statutory period. Where the law permits, the period may be paused or extended, including where clarification is reasonably required or a request is complex. I may ask for information reasonably necessary to verify your identity, particularly where a request concerns security logs or pseudonymous identifiers.
To exercise a right: email [email protected].
Privacy complaint: email [email protected] so I can investigate and respond.
ICO complaint: You also have the right to complain to the Information Commissioner’s Office, the UK’s independent data-protection supervisory authority, at ico.org.uk/make-a-complaint/. You do not have to contact me before approaching the ICO.
18. Security measures and incidents
I use appropriate technical and organisational measures designed to protect personal information against unauthorised access, accidental loss, destruction, alteration or disclosure. These include HTTPS, Cloudflare edge protection, restrictive security headers, access controls, account security, two-factor authentication on key services where available, encrypted or locked devices, data minimisation and separation of public content from private correspondence.
No method of transmission or storage can guarantee absolute security. I review security measures as the service and risks change. If a personal-data incident occurs, I will assess the risk, take reasonable containment steps and notify the ICO or affected people where the law requires it.
19. Children
The site is aimed at a general and adult audience and is not designed to collect information directly from children. If I learn that a child has submitted personal data without an appropriate reason or involvement of a responsible adult, I will assess and delete it where appropriate.
20. Secure submissions, policy changes and changelog
For highly sensitive material, use one of the following rather than the ordinary public contact form:
- Encrypted browser tool: TRSA Secure Whistleblower Tool. The tool lets you encrypt text before sending it through another channel.
- PGP email: encrypt your message to the public key below and email it to [email protected].
Show PGP public key
-----BEGIN PGP PUBLIC KEY BLOCK----- mQENBGjgzEoBCAC1f7v296odbZkd/1YcRWq5nF89vcbgssfwTUn/ljpmWA4fbTew gqVI1My8FQfaeAKNK6ItMDy6bX9H3Ks6cwYT/sMbI3qX9bl6TgpL3cSLsclLwhv+ ilhRTPkEt1d1VoiWpKFNdYme32D4mUQ7bkGSkLBLUvQuhhXlmVz6Oz/4W/0lSXYS mABUPPr/VVTYIOCPkUsxO35YmoOZFohZSBwjNo0qA4huMlle+mKYiYu/ApE1Yl+B BAFITuafDD8hJyXnQVsIY4M79kNP0mef9hxJLkV/RL0IN+D6pD8/0Gn9/FO755eg Com6UQUbmvJUy7c4h64p4uCcs51liUME2t2RABEBAAG0QlRoZSBSZWFzb25hYmxl IEFkanVzdG1lbnQgPGFkdm9jYWN5QHRoZXJlYXNvbmFibGVhZGp1c3RtZW50LmNv LnVrPokBTgQTAQgAOBYhBMwbkJWq1QzDjLZ8QrbuO4b5qZmJBQJo4MxKAhsDBQsJ CAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJELbuO4b5qZmJgQsIAKMqO7Lc4ytTC93r nnJyJR/vtk/+IRiOCMf5mdyqB3fcUzFbvsTN1t7Ybl8eUITOqKW67SpVUrN6LmqK bvKb4mcE6tNE9iWXm7dVNzmmKRm5dgWRYXrtcfLz5h2BpqyxQ08ZQTCyBvOmXDG7 JS7BSCo+GNMEjxf4zYg/dkdJI3IXWtRLW3Ul1kLo/pennKe99D6arYQJyMQp/pUF O6WfWCCUxuYnTbafJVhUpxxvgr5ss+dEfxKUTicHWN310h5QK3Si1R6fcvyawxh1 0Rtxz5Ng4I/pohlXtAUw7rB2NnPqlLADcsyPFrkMslhQ+FLyp1BvCXeRSXef8Mj3 eiu1joS5AQ0EaODMSgEIAMmGeDOV+psOf1XakNqDZackakFn9n3braG0GemtMsSK qBaN86wRVJ4Wm+OkxkDnX6WdH7FZvwAA0qDylRdgXwyLlaHTPtMkvSYDMBLd/Ejb 0kOAng3s0WXMgHmM2IPAg9WA6/jBANFAtJT5a5qxQnFtVPhh3yi/y6KSPdbW3PyY KpPA030kGFULX6N/4M+TZx09rONJsTtqGPOUl7kpYjLydy1yGT1PIvnDcvq8h3Gm ONlBp3X89g7MGefkozqNSc+hwKXLw3Chn2sOWi8KDf4E4+m0E2p9eF6tylew9tjV ZYM1rPb+QPgll3ifY2mhMMzeQP0AOcNN1y2vllzPz0cAEQEAAYkBNgQYAQgAIBYh BMwbkJWq1QzDjLZ8QrbuO4b5qZmJBQJo4MxKAhsMAAoJELbuO4b5qZmJRBcH/ji8 ynCJVBxFAzMUc96krzlfbLo8oJmImmy19oUWvqDHW626kgveZPfjvtQc+iGqhQd9 iJG2IB2yRic2jqvQvqiGccxaKHKND6oTlyW4q9dwZaaTUvtshulICBeIpknyeFB0 sXaUEwcm/XcjtnB+IH6+kZemAWPLrT9gofw/puUnLbmbPv57cu42ocEsw9tJl4gG Pg9BuLPTkDIjBKHD9UK+rCf8/CrP457cFH0XmojoepPNn/YA6V+cvqaz31IwK+bO qXw+ZNmwYqEHxo9jqzsA2HrkzBvPtlZdGzzUGzWyH75kQAPI9MNL89xqqb6XoqVu oDIDOw3/+G60wWUgwHE= =u8MU -----END PGP PUBLIC KEY BLOCK-----
Changes to this policy
I may update this policy when the service, security controls, providers or legal requirements change. Material changes will be recorded in the changelog below and the revised date will appear at the top of the page.
Changelog
- 25 September 2026: Added a self-service statistics opt-out page and its cookie. Stated the lawful basis under the Privacy and Electronic Communications Regulations for using pseudonymous identifiers in readership statistics. Added Cloudflare D1 as the store for statistics events, with a 90-day retention period.
- 24 September 2026: Replaced Plausible Analytics with a private statistics dashboard built from the site’s own edge data, and added a way to opt out of being counted. Explained how IP ranges registered to UK police forces are labelled in security alerts, the legal basis for security cookies and device information, and Discord’s role as a secondary record of security events.
- 18 August 2026: Clarified data categories, minimisation, purpose-specific lawful bases, special category and criminal offence data, AI use, international transfers, retention, rights and complaints. Added Stripe-hosted reader-support payments and returning-reader support prompts.
- 22 July 2026: Expanded the explanation of edge security telemetry, pseudonymous identifiers, essential security cookies, signed internal-link provenance, automated security rules, Discord alerts, and three-hour/daily aggregate reporting.
- 14 January 2026: Added Formspree, Google Search Console Insights and Bing Webmaster Tools.
- 6 October 2025: Added secure submission options and information about special category data.
If you have a privacy question, email [email protected].
Comments are closed.