Privacy by restraint
Privacy
What this site collects, what it deliberately does not collect, how local tools and newsletter processing work, and which assumptions change when services are configured.
Summary
The site is designed to publish civic-policy material without building political-interest profiles. It works without behavioral analytics, advertising pixels, cross-site tracking, fingerprinting, session replay, or nonessential cookies. A cookie banner is not shown because the default site sets no nonessential cookies.
Data collected by ordinary web delivery
The hosting provider may receive routine request information needed to deliver and protect the site, such as IP address, date and time, requested path, browser information, security signals, and response status. Exact log retention depends on the Cloudflare account configuration and has not been represented here as a formally approved retention policy.
Data not collected by this project
- No advertising identifiers, third-party advertising cookies, or political-profile enrichment.
- No fingerprinting, session replay, or recording of mouse movement.
- No database storage of Build Your Deal selections.
- No search-query analytics by default.
- No issue-interest fields attached to newsletter subscriber records.
- No hidden combination of email addresses with priority selections.
Build Your Deal
Selections and the optional title live in the page state and, after you generate or restore a share link, in the URL query string. The tool does not send them to a project database or store them in cookies. A shared URL necessarily reveals the selected guarantee IDs and title to the people and services through which you share it. Browsers, messaging services, recipients, and hosting logs may retain the URL under their own practices.
Search
The search index is generated at build time and the query runs in the browser. The tool does not call an external search provider. The query also appears in the page URL so it can survive navigation or be shared; as with any URL, it may appear in browser history or routine server logs if requested from the server.
Newsletter processing
The newsletter form collects an email address, optional first name, explicit consent, and a hidden honeypot used to reject automated abuse. It does not collect issue priorities. When a provider is configured, the server sends the minimum subscription data to that provider. When no provider is configured, the form reports that truthfully and does not return fake success.
The production provider is disabled by default. A retention schedule, processor agreement, deletion workflow, and confirmed provider-specific privacy terms should be approved before public activation. Subscriber email addresses are not intentionally written to application logs.
Local browser storage
The initial implementation does not use localStorage, IndexedDB, or cookies for priorities, search, or navigation. Shareable state is encoded only in the visible URL when intentionally generated.
Analytics
Analytics is disabled unless an operator explicitly configures Plausible or Umami. When disabled, no analytics script is rendered. If enabled later, the operator must update this notice with the selected service, hosting mode, event scope, IP handling, retention, and contractual terms. Build Your Deal priorities and search queries must not be sent as analytics events.
Third-party services and links
Cloudflare Workers is the documented hosting target. A newsletter provider is optional and currently unconfigured. Evidence cards link to outside institutions; following a link subjects the request to that site’s practices. No third-party media embeds or external font providers are used.
Retention assumptions
Editorial content and public source metadata remain in the repository and deployed build. Build Your Deal state has no project-side retention. Newsletter retention and infrastructure-log retention require deployment-specific configuration. The documentation data map lists every input and destination known to this build.
Contact
No public privacy contact address is configured. Set PUBLIC_CONTACT_EMAIL
before inviting privacy requests.
Working notice last reviewed August 12, 2026. It is not a substitute for deployment-specific legal review.