Privacy
The default release is designed to collect as little information as practical.
Default collection
The site does not include advertising, analytics, tracking pixels, social embeds, remote fonts, or third-party JavaScript. Standard web-server logs may still record IP addresses, user agents, requested URLs, timestamps, and errors according to the host’s configuration.
Charter comments
The participation form stores the fields a visitor submits. Name, organization, and email are optional. A one-way hash derived from network and browser information is stored for abuse-rate limiting; the application does not store the raw IP address in the comment record.
Cookies
A first-party session cookie is used for CSRF protection and temporary success messages. It is marked HttpOnly and SameSite=Strict, and Secure when HTTPS is active.
Retention
Comment retention is controlled by the site operator. Before launch, the operator should establish a documented retention period, access policy, deletion process, backup policy, and lawful basis appropriate to the deployment jurisdiction.
Security limitation
No website can guarantee absolute confidentiality. Do not submit secrets, credentials, medical records, private allegations, or personal data about another person.
Contact
Privacy questions may be sent to editor@outrightattack.com.