What We Collect
We collect the information you choose to send through forms, email subscriptions, replies, contact requests, team requests, and case submissions. This may include your email address, name, role, message text, selected topics, submission metadata, and operational email events such as delivery, bounce, unsubscribe, complaint, open, or click events.
Why We Use It
We use personal data to send requested diagnostics, manage subscriptions and preferences, respond to messages, prevent unwanted email, review submitted cases, operate the campaign system, protect the site from abuse, and keep audit evidence for privacy and security actions.
What Not To Send
Do not submit passwords, secrets, financial account numbers, health data, minors' data, legal files, employment files, or unnecessary third-party identifiers. Do not submit a form if you are under 18. Public case submissions are for patterns, not private dossiers.
Consent, Analytics, And GPC
The site uses only essential storage by default. Google Analytics, first-party behavior measurement, and any future optional marketing measurement stay off unless you choose optional analytics or marketing in the privacy banner. If your browser sends Global Privacy Control, optional measurement is treated as opted out. Website measurement is configured for bounded site behavior only, with advertising personalization and Google signals disabled.
Email And Unsubscribe
Every marketing or diagnostic email should explain why it arrived and include an unsubscribe route. Global suppression is used to prevent future marketing email after unsubscribe, complaint, or manual suppression.
Case Submissions
Raw case submissions are not public teardowns. A submitted case must be reviewed and redacted before it is used publicly. We do not publish identifying details without a separate permission and review basis.
Vendors And Processing
The site uses Firebase and Google Cloud for hosting, functions, authentication, storage, tasks, records, first-party consented behavior-event records, and BigQuery campaign analytics. It uses Mailgun for email delivery, events, and inbound replies. Google Analytics may be used only for consented website measurement. Additional analytics, AI, or marketing processors must be approved in the vendor register before they process personal data.
AI Boundary
AI assistance may help classify replies or draft internal review material after minimization. AI must not decide privacy rights, publication permission, breach notification, legal outcomes, or whether a private case is safe to publish.
Retention
We keep records only while needed for the stated request, subscription, suppression, safety, operation, privacy action, or legal/accounting evidence. Raw payloads, replies, exports, and AI artifacts should expire or be anonymized according to their retention class.
Your Choices
You can request access, name correction, deletion, anonymization, unsubscribe support, consent withdrawal, restriction, objection, or publication withdrawal. Some minimal records may be retained when needed to prevent unwanted email, protect the service, or preserve required operational evidence.
Security And Incidents
Suspected data exposure, vendor problems, overcollection, unauthorized publication, or secret leakage should be recorded as an incident and reviewed. The privacy promise is to detect, contain, assess, repair, and communicate honestly when required.