Legal
Privacy policy
Last updated 19 August 2026
Short version: this website runs no analytics, no advertising and no third-party tracking of any kind. We do not build a profile of you, and we have nothing about you to sell.
We checked this rather than assuming it. As of the date above, the only external addresses this site loads are a standard WordPress profile link and a link to the ethical manifesto on ethical.net. There is no Google Analytics, no tag manager, no advertising pixel and no session recording.
Who we are
We are Digital Partnership for Regeneration and Reconnection, a non-profit that develops mission-oriented digital projects and writes about the ethics of technology. This policy covers dprr.org only. The projects we build, such as Earth.fm and Smmry, are separate services with their own policies.
What we collect
Almost nothing. There is no account to create here, no newsletter sign-up and no shop. The only thing you can actively send us is a message.
- Server logs. Our host and our CDN keep standard access logs, which include IP addresses, for security and to keep the site online. We do not use them to identify or profile visitors.
- Comments. If you leave a comment we store what you type in the form, along with your IP address and browser user agent, which help catch spam.
- The contact form. If you use the form on our contact page, we receive your name, email address, subject and message. It arrives as an ordinary email in our inbox. The form is run by software on our own site, so your message is not passed through an external form service.
- Anything you email us. If you write to us we keep the message so we can reply.
Cookies
We set no tracking or advertising cookies. WordPress itself may set two kinds:
- If you leave a comment and tick the box to be remembered, cookies save your name, email and website so you do not retype them. They last about a year and you can decline them.
- If you log in as a member of our team, cookies keep that session going. These do not apply to ordinary visitors.
Media and embedded content
If you upload an image, be aware that images can carry embedded location data (EXIF GPS) which others could extract. Pages may embed content from other websites, such as video. Those embeds behave exactly as if you had visited the other site directly, and can collect data and set their own cookies under their own policies, not ours.
Gravatar
When you comment, an anonymised hash of your email address may be sent to the Gravatar service to check whether you have a profile picture. Their policy is at automattic.com/privacy. After your comment is approved, your profile picture is visible alongside it.
Who else sees your data
We do not sell, rent or trade anything about you, and we run no advertising. Two suppliers process data on our behalf purely to run the site: our hosting provider, Kinsta, and our content delivery and security provider, Cloudflare. Both act on our instructions.
How long we keep things
Comments and their metadata are kept indefinitely so that follow-up replies still make sense, unless you ask us to remove them. Server logs are kept for a short period on a rolling basis by our host and CDN. Messages sent through the contact form, and emails, are kept for as long as the conversation is useful, then deleted.
Your rights
You can ask us for a copy of any personal data we hold about you, ask us to correct it, or ask us to delete it. We will do so unless we are legally required to keep it. Because we collect so little, in most cases the answer will be that we hold nothing beyond a message you sent us or a comment you left. Write to us through the contact page.
Children
This site is not directed at children and we do not knowingly collect data from them.
Changes
If we change what we collect, we will update this page and change the date at the top. We are not in the habit of adding tracking, and if that ever changed we would say so here plainly.
Contact
Questions about this policy, or a request about your data, can go through our contact page.