Privacy notice

Last updated 14 September 2026

This site records who opens embargoed and controlled material, and counts visits to its public pages without identifying who made them. This notice sets out exactly what is recorded, why, how long it is kept, and how to contact us about it.

Why we say this plainly

The research published here is about the silent, unlogged modification of what people see. A site making that argument should not run silent instrumentation on the people reading it. Telling recipients that access is recorded costs nothing operationally, and it keeps our posture consistent with our own findings.

Who is responsible

nDiligence is the data controller for the processing described here. Write to with any question about it, including a request to exercise any of the rights set out below. We answer within one month.

Two regimes, and the difference between them

What is recorded changes on 14 September 2026, when the public release opens. Before that date, the whole site is embargoed and access is by code. After it, most of the site is open to anyone and only the controlled shelves under /intel/ still require a code. The two situations call for different records, so they get different ones.

Before 14 September 2026: embargo enforcement

While the embargo is in force, redeeming an access code and opening embargoed material produces a full record. That record may include:

  • the access code's identifier, such as EA-0042, and the grants it carries
  • the network address the request came from, and the length of any proxy chain
  • the country, region, city and network timezone that address resolves to
  • the autonomous system number of the network
  • the browser's user agent string and its reported platform, platform version, architecture and device model
  • the language preferences the browser sends
  • a TLS handshake fingerprint
  • a hash computed in the browser from characteristics of the device, including screen dimensions, timezone, processor count, available memory, graphics renderer, and the way the device renders a test image and a test tone
  • the path requested, the time of the request, and whether it was allowed

These records are deleted on 14 September 2026. Aggregate counts, which identify nobody, are kept.

We never record the access code itself, only its identifier. A record can therefore be shared with counsel or a coordination partner without a working credential going with it.

From 14 September 2026: controlled material

After the public release, opening controlled material under/intel/ produces a much smaller record: the code identifier, the grants it carries, the time, the country, and the path requested. No device characteristics, no fingerprint, no user agent.

These records are kept for twelve months on a rolling basis, then deleted.

The reason for keeping anything at all is narrow and worth stating. If a controlled resource surfaces somewhere it should not, the only useful question is which codes opened it and roughly from where. Answering that needs a code identifier, a timestamp and a country. It does not need a graphics renderer string, which is why that regime stops on 14 September 2026.

Page statistics on public pages

Public pages are not logged against you, but visits to them are counted. We use Vercel Web Analytics to see, in aggregate, which pages are read and where readers arrive from. It does not set a cookie to do this. Vercel recognises a visit by a hash derived from the request and discards that hash after 24 hours.

Each page view may carry:

  • the time of the view
  • the address of the page, and the address of the page that linked to it
  • query parameters in that address, after Vercel's filtering
  • the country, region and city the request resolves to
  • the operating system and browser, their versions, and whether the device is a desktop, tablet or phone

Vercel states that these data points are not tied to an individual or to a network address, and are used only for aggregate statistics. We see totals and breakdowns, not visitors.

Nothing under /intel/ is counted, and neither are the pages that ask for an access code. The address of a controlled product is itself restricted information, so it is filtered out in your browser before anything is sent.

Vercel keeps these statistics available to us for twenty-four months, and may hold them for longer.

Our lawful basis

We rely on legitimate interests under Article 6(1)(f) of the UK GDPR and the EU GDPR. The interest is enforcing a coordinated disclosure embargo on our own research, and controlling access to material that remains restricted after it.

We consider this proportionate for three reasons. Everyone holding a code received it directly from us, by name, as part of a coordinated disclosure. The records exist only to establish who opened material that was shared in confidence. And the more intrusive of the two regimes is time-limited by design and ends on a date fixed in advance.

You have the right to object to processing based on legitimate interests. Write to us and we will consider it. In practice, objecting is likely to mean we cannot give you embargoed access, because the record is the condition on which it is shared.

Page statistics rest on the same basis. The interest is understanding, in aggregate, how a public disclosure is read, so that we can tell whether it reaches the people it is written for. The data carries no identifier that outlasts a day. A browser setting or extension that blocks analytics scripts stops the collection, and nothing on the site depends on it.

Who else sees this

The site runs on Vercel, which processes requests, holds short-term platform logs, and collects the page statistics described above. Alert messages are delivered by Resend. Both act as processors under contract. No advertising network and no third-party tracking script runs on this site. This site loads no resource from any origin other than its own, including its typeface and the page statistics script.

We do not sell, rent or share these records for any commercial purpose. We would disclose them to a law enforcement authority or a court only where legally obliged, or where a leak of restricted material is being investigated with our involvement.

Cookies

Two, both strictly necessary, neither used for advertising or analytics.

  • atg_ea holds your access grant after you enter a valid code, signed so it cannot be altered. It is not readable by any script on the page. It expires with your code.
  • atg_did holds a random identifier so a returning browser is recognisable across visits. It lasts ninety days.

Page statistics do not use a cookie; see above. A preference for the light or dark theme is stored in your browser and never sent to us.

Your rights

Under the UK GDPR and the EU GDPR you may ask us for a copy of the records we hold about you, ask us to correct them, ask us to delete them, ask us to restrict what we do with them, and object to the processing. Write to .

You may also complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office. In the European Union it is the authority in your country of residence.

Changes

If this notice changes materially before 14 September 2026, we will tell every code holder by email rather than relying on you to re-read this page.