Privacy Policy
Last updated: 2026-09-16
The public site — the feed, framework pages, and deadlines — is usable with no account and no cookies. If you subscribe to Telegram alerts, we hold a small amount of personal data to deliver them. No analytics. No third-party scripts on any page.
Who is responsible
- Controller
- Oleksii
- Established in
- Ukraine
- Contact
- [email protected]
The controller is established outside the European Union, and this policy is written to meet the GDPR anyway: we make the service available to people in the EU, which brings us within Article 3(2). Where the law of Ukraine imposes its own data-protection duties, those apply in addition, not instead.
What we collect
Access logs. Every request to this site is logged by our hosting provider: your IP address, the time, the URL you asked for, the HTTP status we returned, your browser's user-agent string, and the referring page if your browser sent one. An IP address is personal data under the GDPR, so we treat the whole log as personal data.
Filters on the feed are submitted with GET, which means the choices
you make — framework, jurisdiction, severity, period — appear in the URL and
therefore in that log. Nothing else about your visit is recorded.
Email you send us. If you write to the address above, we keep the message and your address for as long as it takes to deal with it, and no longer.
Account data, if you subscribe to Telegram alerts. When you press Start in the Telegram bot, we receive your Telegram user ID and public username from Telegram and store them to identify your account. We also store the frameworks you select and your subscription state (free or Pro). We collect nothing beyond what you actively provide. You can delete your account at any time from the account page, which erases all of the above.
No fingerprinting, no A/B tests, no embeds. We do not fingerprint browsers and do not embed anything served by another company — no fonts from a CDN, no social buttons, no tag managers.
Cookies and other storage on your device
We set no cookies at all. One item is written to your browser's
sessionStorage so the Back button works, and it disappears when you
close the tab. The cookie page describes exactly
what it is and why it needs no consent banner.
Why we process it, and on what legal basis
Access logs are processed to keep the service running, to diagnose faults, and to detect abuse such as scraping that degrades the site for everyone else. The legal basis is our legitimate interest in operating and defending the service, GDPR Article 6(1)(f). We do not use the logs to build profiles, to measure audiences, or to make decisions about individual visitors.
Correspondence is processed on the same basis, or on Article 6(1)(b) where you are writing about a contract with us.
Account data is processed to deliver the alerts you signed up for. The legal basis is Article 6(1)(b): performance of the contract between us. Without a Telegram user ID we cannot deliver alerts to you; without your framework selections we do not know which alerts to send.
Personal data inside the changes we publish
This is worth stating plainly, because it is the one place where we process data about people who never visited the site. The documents we monitor are official publications — regulator decisions, enforcement notices, guidance — and some of them name individuals or organisations. We publish the title, a short summary, and a link back to the source. We do not enrich those records, cross-reference them against other datasets, or keep material a publisher has withdrawn. When we remove an entry, its old address answers "410 Gone" with the reason for the removal and none of the original text, and any Telegram message we sent about it is edited to say it was withdrawn.
The legal basis is our legitimate interest, and the public interest, in reporting accurately on regulatory developments that are already public. If you appear in such a record and object to our summary of it, write to us: we will look at it, and where the objection is well-founded we will remove or correct the entry. Note that we cannot change the underlying official publication — for that you have to go to the body that issued it.
Who else sees the data
Our hosting provider operates the servers and holds the access logs on our behalf, as a processor. Telegram is the delivery channel for alerts: your Telegram user ID originates with them, and alerts are sent through their platform. No other company sees your data. We do not sell data, do not share it with advertisers, and do not send anything about visitors to an analytics service, because we do not use one.
We use a language model to summarise the official documents we collect. It is given those public documents and nothing else — no visitor data of any kind ever reaches it.
Because our hosting provider runs infrastructure outside the European Economic Area, access logs and account data may be stored outside it. Those transfers rely on the standard contractual clauses in our agreement with the provider.
How long we keep it
We operate no log storage of our own: the application writes to standard output, and the hosting platform retains that stream under its own rolling retention policy before deleting it automatically. We do not export logs, copy them into a database, aggregate them, or archive them. In practice this means access logs survive days, not years, and nothing about a visit outlives that window.
Account data is kept for as long as you have an account. You can delete your account at any time from the account page. Deletion is immediate and complete: your Telegram user ID, username, framework selections, and subscription record are all erased. Nothing tied to you is retained afterwards.
Your rights
If the GDPR applies to you, you have the right to ask for access to your personal data, to have it corrected or erased, to have its processing restricted, to object to processing based on legitimate interest, and to receive it in a portable form. You also have the right to complain to your national supervisory authority.
Write to [email protected] and we will answer within one month. One honest caveat: a request about access logs is hard to satisfy usefully, because we hold no identifier that links a log line to you beyond the IP address you would have to tell us yourself, and we have no way to confirm it was yours.
Children
This service is aimed at security, legal, and compliance professionals. It is not directed at children, and we knowingly collect nothing from them.
Changes to this policy
If we change what we collect, we change this page first and update the date at the top. There is no mailing list to notify, by design.
This page describes our practices. It is not legal advice — see the Terms of Service.