Privacy by restraint
Privacy
What this site collects, what it deliberately does not collect, how local tools and newsletter processing work, and which assumptions change when services are configured.
Summary
The site is designed to publish civic-policy material without building political-interest profiles. It works without behavioral analytics, advertising pixels, cross-site tracking, fingerprinting, session replay, or nonessential cookies. A cookie banner is not shown because the default site sets no nonessential cookies.
Data collected by ordinary web delivery
The hosting provider may receive routine request information needed to deliver and protect the site, such as IP address, date and time, requested path, browser information, security signals, and response status. Exact log retention depends on the Cloudflare account configuration and has not been represented here as a formally approved retention policy.
Data not collected by this project
- No advertising identifiers, third-party advertising cookies, or political-profile enrichment.
- No fingerprinting, session replay, or recording of mouse movement.
- No database storage of Build Your Deal selections.
- No search-query analytics by default.
- No issue-interest fields attached to newsletter subscriber records.
- No hidden combination of email addresses with priority selections.
Build Your Deal
Selections and the optional title begin in page state. A generated link includes the selected guarantee IDs; the optional title is omitted unless you explicitly choose to include it. The tool does not send this state to a project database or store it in cookies. A shared URL reveals every value it contains to the people and services through which you share it. Browsers, messaging services, recipients, and hosting logs may retain the URL under their own practices.
Build Your Deal, search, and evidence pages set a document-level no-referrer policy to
keep their full query-bearing URLs out of normal link referrers. This reduces incidental disclosure
on the next navigation; it does not remove the URL from browser history, copied messages, direct requests,
or infrastructure logs.
Search
The search index is generated at build time and the query runs in the browser. The tool does not call an external search provider. The query also appears in the page URL so it can survive navigation or be shared; as with any URL, it may appear in browser history or routine server logs if requested from the server.
Newsletter processing
Newsletter signup is currently disabled, so the site does not render newsletter fields or accept newsletter submissions. If a provider is approved and enabled later, the form may collect an email address, optional first name, explicit consent, and a hidden honeypot used to reject automated abuse. It will not collect issue priorities, and the server will send only the minimum subscription data to the approved provider.
The production provider is disabled by default. A retention schedule, processor agreement, deletion workflow, and confirmed provider-specific privacy terms should be approved before public activation. Subscriber email addresses are not intentionally written to application logs.
Local browser storage
The initial implementation does not use localStorage, IndexedDB, or cookies for priorities, search, or navigation. Shareable state is encoded only in the visible URL when intentionally generated.
Analytics
The application does not configure Plausible, Umami, or another analytics provider. An August 24, 2026 deployment audit nevertheless found Cloudflare automatically injecting a Web Analytics beacon; the site's Content Security Policy blocked it. Cloudflare automatic injection must be disabled before production sign-off. If analytics is approved later, this notice must be updated with the selected service, hosting mode, event scope, IP handling, retention, and contractual terms. Build Your Deal priorities and search queries must not be sent as analytics events.
Third-party services and links
The public site is hosted on Cloudflare Workers. A newsletter provider is optional and currently disabled. Evidence cards link to outside institutions; following a link subjects the request to that site's practices. No third-party media embeds or external font providers are used.
Retention assumptions
Editorial content and public source metadata remain in the repository and deployed build. Build Your Deal state has no project-side retention. Newsletter retention and infrastructure-log retention require deployment-specific configuration. The documentation data map lists every input and destination known to this build.
Contact
Privacy questions may be sent to privacy@nextsquaredeal.org . This public role address forwards to an operator-managed mailbox; the sender's and project's mail providers process the message.
Working notice updated August 24, 2026. No independent legal review is claimed, and this is not a substitute for deployment-specific review.