Launch policy draft · 28 August 2026

Privacy.

This page is intentionally conservative while launch integrations are being verified. It will be re-audited against the live system before indexing.

Pre-launch status

The deployed system and operator facts must pass their final audit before this draft is indexed.

Information you provide

Event reports, contact messages, feature requests, and newsletter signups include the fields shown on their forms. Newsletter addresses remain pending until confirmed. We store limited security evidence needed to prevent abuse without deliberately logging form text or raw verification tokens.

Why it is used

Reports are reviewed for listing accuracy, messages are handled according to their selected type, and confirmed email addresses receive the weekly roundup. Security evidence protects the same forms and their underlying records.

Service providers

The launch architecture uses Payload with Supabase-hosted PostgreSQL, Vercel application hosting, Cloudflare DNS and bot verification, Resend email, and privacy-reviewed analytics. Production processing locations and contracts will be confirmed before this policy is finalized.

Retention

Contact and report records currently carry a one-year review date in the data model; operational deletion rules must be validated before launch. Newsletter consent, confirmation, suppression, and unsubscribe evidence is retained as needed to honor email choices.

Cookies and analytics

Payload Admin uses secure authentication cookies. Public analytics will not receive raw search terms, email addresses, messages, or report text. Nonessential analytics behavior remains subject to the final launch configuration.

Your choices

You can unsubscribe from email through the link in each issue. To ask about, correct, or remove information you submitted, use the contact route.