What the current application uses to operate public pages, accounts, and support.
Draft for review · Last reviewed: pending
Public browsing
Public research pages do not require a reader account. A web server may record basic request and error information, such as requested paths, timestamps, and network details, to operate and diagnose the service. Hosting configuration determines the exact logs and retention period.
Accounts
If you create an account, the application stores your name, email address, and a hashed password. Session cookies keep you signed in, and a security token protects form submissions. Password-reset emails are transactional and use a short-lived reset token.
Contact messages
If you use the contact form, we process the name, email, category, and message you submit so we can respond. Contact messages are delivered to a configured support mailbox and are not published on the site.
Owner desk
A separately provisioned owner account can access private research operations. Owner credentials are managed outside public registration.
Cookies and security
The application uses a session cookie and CSRF protection. Session cookies are HTTP-only; production configuration requires HTTPS and a Secure cookie.
Optional analytics
When explicitly enabled in production configuration, the site may load Google Analytics 4 with IP anonymization to understand aggregate traffic after launch. Analytics scripts are not loaded when measurement is disabled. Analytics cookies, if present, are governed by Google’s terms for that product. This draft does not claim advertising profiling or sale of personal data.
What we do not do in V1
This draft does not claim payment processing, advertising profiling, marketing email lists, or sale of personal data. Those features are not part of the current application.
Questions
Use the Contact page for privacy questions. Before commercial launch, add the appropriate operating entity and retention details after professional review.