allx.uk
← Back to writings

Privacy Policy

Last updated: August 30, 2026 • Effective for all visitors and contributors of

1. Overview & Philosophy

We believe in minimalist, distraction-free publishing and digital privacy. We collect only the minimum amount of data required to operate this service securely, facilitate constructive discourse, and deliver content to readers. We do not sell your personal data, run advertising networks, or deploy cross-site tracking trackers.

2. Information We Collect & Log

A. Server Access Logs

When you browse the platform, our web servers log standard technical connection information:

  • IP address and approximate geographic location (country/region level)
  • Date, time, and requested URL/resource
  • Browser User-Agent string and referring URL
  • HTTP response code and bytes transferred

These logs are maintained strictly for operational security, identifying abuse, DDoS mitigation, rate-limiting, and debugging server errors.

B. Writer & Contributor Accounts

For authenticated writers who register via invitation, we store:

  • Email address (for authentication and password recovery)
  • Display name and role (Writer or Administrator)
  • Cryptographically salted password hashes (bcrypt)
  • Two-factor authentication (TOTP) secret keys (if enabled)
  • Articles, drafts, uploaded media assets, and timestamps

C. Comments & Reader Responses

We allow both authenticated writers and anonymous readers to comment on published articles:

  • Authenticated Writers: Your comment text, timestamp, and account display name with a verified badge.
  • Anonymous Readers: Your comment text and an automatically generated pseudonym (e.g., Anonymous Mouse 838432). An anonymous ownership token is stored in your local session to allow you to edit or delete your response. No email or personal identity is linked to anonymous responses.

D. Media Proxying & External Links

When articles reference external third-party images or media, we route them through a local caching proxy when possible so third-party servers cannot log your IP address. When you choose to view or download original source files on third-party servers, a confirmation warning is displayed to notify you before exposing your IP address to that external host.

3. Cookies & Local Storage

We use only essential functional storage:

  • Session Cookie (PHPSESSID): An essential first-party cookie used solely to manage writer authentication sessions and verify CSRF protection tokens against malicious request forgery.
  • Local Storage: Used in your browser to store editor draft backups and your anonymous comment ownership tokens for managing your responses.

We do not use tracking cookies, analytics pixels, or third-party advertising cookies.

4. Third-Party Services & Security

  • Cloudflare Turnstile: Used to protect forms (such as logins and comments) from automated spam and bots. Turnstile runs non-intrusive security challenges without harvesting personal profiles.
  • Transactional Email (SMTP): If configured by the site administrator, your email address is used solely to deliver invite links and password reset notifications.

5. Data Retention & Your Rights

Under GDPR, UK GDPR, and applicable privacy regulations, you have the right to:

  • Request access to any personal data associated with your account or comments.
  • Request correction or complete deletion of your account, published articles, or comments.
  • Export your articles and data at any time.

6. Contact & Data Inquiries

For any privacy concerns, data access requests, or deletion requests, please contact our data controller directly at:

[email protected]