Privacy notice — editorial data practices
This site is editorial. The privacy notice explains what we collect — and what we don’t.
The desk runs an editorial website. We do not run contests, do not operate a user account on this site, and do not collect personal data beyond the basics of web analytics. We do not sell reader data. We do not profile readers for advertising. The data the desk holds about you is what a standard web analytics platform collects: a page view, a referrer, a country code.
This page explains the data the desk holds, the third-party services the desk uses (and what each one collects), and the rights of European and Indian readers. The notice is reviewed every quarter. The review is published as a dated editor’s note at the bottom of this page.
What we set, what we read.
The site sets a small number of functional cookies (session, theme) and a single analytics cookie (page-view count, country code, referrer). The site does not set advertising cookies on its own — the third-party advertising services on the news section may set their own cookies, and those services’ notices apply. The desk does not control those services’ cookies; their notices are linked in this page.
Reader rights
European readers have the right to access, rectify and erase the data the desk holds about them. Indian readers have the right to access and rectify under the Digital Personal Data Protection Act, 2023. The desk responds to data-rights requests within thirty days.
What we use, what they collect.
Web analytics
A privacy-respecting analytics service. Page views, referrer, country code. No personal identifier, no advertising profile.
CDN
A standard content-delivery network for the static site assets. The CDN logs IP address and request URL for performance monitoring.
Advertising
Selected advertising services on the news section. The advertising notices are linked in this page. The desk does not control advertising cookies.
Privacy questions, answered.
What data do you collect?
A standard analytics profile: page views, referrer, country code. No personal identifier, no advertising profile.
Where do you store the data?
On a privacy-respecting analytics service. The data is held in the EU, with a mirror in the US.
Do you sell reader data?
No — the desk does not sell reader data. We do not profile readers for advertising.
Where do I send a data-rights request?
[email protected]. The desk responds within thirty days.
What about the cookies set by third-party advertising?
The advertising notices are linked in this page. The desk does not control third-party cookies.
Can I opt out of analytics?
Yes — the analytics opt-out link is in the site footer. The opt-out is enforced for thirty days.
What about European rights?
European readers have the right to access, rectify and erase the data the desk holds. The request email is on this page.
What about Indian rights?
Indian readers have the right to access and rectify under the Digital Personal Data Protection Act, 2023. The request email is on this page.
How long the desk holds what it collects.
The desk holds the analytics data it collects for thirty days. After thirty days, the data is rolled up into an anonymised aggregate and the row-level data is deleted. The CDN logs (IP address, request URL) are held for thirty days for performance monitoring and then deleted.
The corrections inbox holds the correction request, the source reference, and the published correction for as long as the article is live. When an article is retired, the corrections record is moved to the desk’s editorial archive and held for seven years under editorial-record retention rules. The corrections are not published with the reader’s name unless the reader has explicitly opted in.
The tips inbox holds tips for as long as the desk needs to verify them. Verified tips are moved to the editorial archive with the corrections; unverified tips are deleted within thirty days of receipt.
The complaints inbox holds complaints for seven years under editorial-record retention rules. A complaint about editorial coverage is reviewed by the editor-in-chief; the editor’s reply is held with the original complaint; the record is published in anonymised form on the methodology page every year.
Why the desk doesn’t knowingly collect under-18 data.
The desk does not knowingly collect data from readers under the age of 18. Operators linked from the site carry 18+ age gates; the desk respects the gate and does not direct editorial coverage at under-18 audiences. Where the desk learns that data from an under-18 reader has been collected (through the analytics service or through the inboxes), the data is deleted within thirty days.
How the notice is reviewed.
This privacy notice is reviewed every quarter by the editor-in-chief. Where a term changes, the change is highlighted at the top of the notice with a dated editor’s note. The desk does not silently update the notice.
The quarterly review covers: the analytics service, the CDN logs, the corrections inbox retention, the tips inbox retention, the complaints inbox retention, the advertising services, and the regulator’s data-protection rules. Where a service changes (a new analytics provider, a new advertising network), the change is documented with the date and the reason.
The desk publishes the quarterly review as a dated editor’s note at the bottom of this page. The review is the audit trail for the notice — the user can see exactly what changed and when.
European and Indian readers, in plain language.
European readers have the right to access, rectify, and erase the data the desk holds about them. Indian readers have the right to access and rectify under the Digital Personal Data Protection Act, 2023. The desk responds to data-rights requests within thirty days, in line with both regulations.
To exercise either right, the reader sends a request to [email protected] with the email address on file (or the email address the reader wants the data sent to). The desk verifies the request, executes it, and sends the written confirmation within thirty days.
How to reach the desk for a privacy question.
Privacy enquiries go to [email protected]. The desk responds within thirty days. Where the enquiry is a data-rights request, the response is verified, executed and confirmed in writing. Where the enquiry is a question about the desk’s data practices, the response is a plain-language answer with the source of every claim.
Where the enquiry is about a third-party service (a CDN, an analytics provider, an advertising network), the desk redirects the user to the third party’s privacy notice — because the third party’s data practices are governed by the third party’s terms, not the desk’s.
What the editorial cookies do.
The desk sets a small number of functional cookies: a session cookie (so the user doesn’t have to sign in on every page within a session), a theme cookie (so dark-mode and light-mode preferences persist), and a single analytics cookie (so the analytics service can record page views and referrer). The session cookie expires at the end of the session; the theme cookie expires after thirty days; the analytics cookie expires after twenty-four hours.
The desk does not set advertising cookies on its own. The third-party advertising services on the news section may set their own cookies — those services’ notices apply, and the desk does not control those cookies. The user can opt out of the desk’s analytics cookie through the cookie banner.
What the cookie banner covers.
The cookie banner covers the analytics cookie, the functional cookies, and the third-party advertising cookies. The user can accept all cookies, accept only the necessary cookies, or customise the cookie categories. The choice is stored for thirty days; after that, the banner reappears.
The cookie categories are: necessary (session, theme), analytics (page view, referrer), and advertising (third-party services on the news section). The user can opt in or out of each category individually.