News A/B

Privacy and Submission Notice

Version: 2026-09-02 · Consent identifiers recorded with each form: suggestion-terms-2, suggestion-privacy-2, submission-terms-2

This notice explains what News A/B collects, why, where it is kept, for how long, who can see it, and what you can ask us to do. It covers reading the site, suggesting a topic, and submitting a report. The English text is the authoritative version; translations are provided for convenience and the English text prevails where they differ.

1. Who operates this site

News A/B is operated by an individual, not a company. Requests about your data go to the contact address shown in the "About this site" panel on every page. Where the phrase "we" appears below, it means that operator.

2. Reading the site

3. Suggesting a topic

3.1 What we collect

When you send a topic suggestion, we receive only the fields on the form: the topic in one sentence, the two media groups, an optional time and language range, up to five reference links, whether you want to be credited publicly, an optional name, and an optional email address. We also record the version identifiers of this notice you agreed to and a hash of the form used to detect duplicate sends.

We do not record your IP address, request headers, or the human-verification token. Reference links are stored as text only; we do not fetch them when you submit. Submitting a suggestion invokes no AI model.

3.2 Why we use it

3.3 Where it goes and who sees it

  1. Your suggestion is written once into a private Cloudflare D1 database. It is never edited in place; only status events are appended.
  2. We periodically pull unprocessed suggestions to a private working copy on our own machine. Names and email addresses are excluded from the review panel and from the default working context of any AI assistant we use; scripts show them only to a human who explicitly asks.
  3. Email addresses and names never enter Git or any public page unless you ticked "credit me publicly", in which case the name you entered appears in the contributor line of the page record for the resulting topic.

3.4 How long we keep it

3.5 What a suggestion is not

A suggestion is not a commission. We do not guarantee that a suggestion will be adopted, processed, or answered, and the receipt you see does not offer a status query.

4. Submitting a report

Report submission is by invitation. You produce a report with the open-source toolkit, pack it into a submission archive, and upload the archive through this site.

4.1 What we collect

We do not record your IP address, request headers, or the human-verification token.

4.2 Why we use it

4.3 Where it goes and who sees it

  1. The archive is uploaded directly from your browser to a private Cloudflare R2 bucket. The bucket is not publicly readable. The intake service never opens or executes the archive.
  2. We pull the archive to a private store on our own machine. Once the pull is verified, the cloud copy is deleted immediately. An archive that is never pulled is deleted from the cloud no later than 14 days after upload.
  3. On our machine the archive is treated as untrusted data: it is inspected without executing anything in it, and the report is rebuilt from the artifacts using our own copy of the toolkit. Contact addresses, credentials, and signed URLs are excluded from the review panel and from the default working context of any AI assistant we use.
  4. A published report shows its topic page, the sponsor credit you chose, and which AI models performed which pipeline stage. It never shows your email, the invitation code, the withdrawal key, or the private source snapshots.

4.4 How long we keep it

4.5 Licence to your contribution

By uploading an archive you confirm that you are entitled to submit it and you grant us a non-exclusive, worldwide, royalty-free licence to reproduce, verify, re-render, translate, publish, distribute, and archive your own contribution: the report, its structure, annotations, analysis, and any text you wrote. The licence to display the report publicly lasts until it is withdrawn under section 4.7 or removed under section 4.8; the licence to keep it in our private audit records is permanent.

You cannot grant us rights you do not hold, and we do not ask for them:

4.6 Acceptance is not publication

An upload does not guarantee review, acceptance, or publication. Every submission must pass deterministic checks, an independent audit, and a final human review before it is published, and we may decline it at any stage without giving reasons.

4.7 Withdrawal

The holder of the withdrawal key may withdraw a published report at any time by uploading a withdrawal archive produced by the toolkit together with the key. Withdrawal removes the report from the public site and records a withdrawal event; the private audit records are kept under section 4.4.

There is no revision procedure. To publish a corrected report, withdraw the existing one and submit a new archive under a new invitation.

An anonymous sponsor holds the same withdrawal right as a named one, but only through the key. If you lose the key and gave no email address, no one can prove the report is yours, and we cannot act on a withdrawal request.

4.8 Our right to remove

We may remove or temporarily withdraw a published report at any time, without waiting for the contributor, for safety, suspected infringement, misleading content, legal requests, or any other reason we consider sufficient. We will tell you if you gave an email address.

5. Human verification by Cloudflare Turnstile

Both forms use Cloudflare Turnstile to tell people from bots. Turnstile processes the technical data it needs for that check, such as your IP address and browser characteristics, under Cloudflare's privacy policy. The site keeps only the result of the check, never the token.

6. Your rights over personal data

What counts as personal data here is small: an email address, a name you entered for credit, and anything personal you chose to type into free-text fields. Reports, suggestions, audit records, third-party text, and status events are not your personal data and are not covered by this section.

You may ask us to:

How we verify it is you. Write to the contact address from the email address you gave on the form, or, for a submission, include the withdrawal key. If you gave neither, we have no way to confirm that a request comes from the person who submitted, and we will not act on it. This is a verification requirement, not a denial of the right.

What deletion does. We delete the personal fields from the cloud record and from our private working records, and re-publish any affected page without your credit line. We keep an event that records the deletion without your text. We do not delete the suggestion or report itself, published pages, or audit records, because those are not your personal data and are kept as this site's publishing record.

We act on a verified request within 30 days. We do not sell personal data, and we do not share it with anyone except the service providers named in this notice.

Do not put other people's personal data in the forms. Suggestion fields and archives should describe news coverage, not private individuals.

7. Service providers

ProviderRoleData involved
Cloudflare Pagesserves the public sitevisitor IP and request headers, as any host
Cloudflare Workers and D1receives forms and stores recordsform fields, submission records
Cloudflare R2temporary archive storageuploaded archives, until pulled or 14 days
Cloudflare Turnstilehuman verificationIP and browser characteristics for the check

All four are services of Cloudflare, Inc. We use no other third-party processor for form data.

8. Changes to this notice

The version at the top of this notice is recorded with every form you send, so we always know which text you agreed to. If we change what we collect or how we use it, the version changes and the forms ask for agreement to the new text.