Privacy Policy — Intelligence Chronicle
Last updated July 22, 2026.
Intelligence Chronicle is built to collect as little as possible. The public site sets no cookies for readers, runs no cross-site trackers, and keeps no per-visitor profiles. We never sell or share personal information, and we run no advertising. The only place we handle reader-supplied data is the Contact & Corrections form. This page explains, plainly, what we process and why — including how AI is used to write the publication, to screen the feedback we receive, and to help the operator triage hostile traffic.
The Feedback Form
When you use the Contact & Corrections form, we receive the message text you write and any name and email you choose to add — both are optional, and anonymous messages are welcome. If you leave them blank, we cannot reply to you directly.
To keep the form from being abused, our server also records a few technical details with each submission: your IP address, a coarse location derived from it (country, region, and city only), your browser user-agent, and the page you came from. These are used solely to prevent spam and abuse and, where you asked, to reply. They are visible only to the site’s operator and are never shown publicly.
How the Publication Is Made
Each edition is produced by an AI model — Anthropic’s Claude — that researches public reporting on the open web. No reader data of any kind is used to write the brief. The content is AI-generated from public sources and, like any automated process, may contain errors; material errors are corrected in the affected edition and can be reported through the Contact & Corrections form. For the fuller editorial explanation, see About & Methodology.
AI Screening of Feedback
To help triage the inbox, the message text only of a feedback submission is sent to Anthropic’s Claude to automatically flag likely spam. Your name, email, IP address, and location are never sent to the model. This is only an aid for the operator — it does not block your message, and it makes no legally significant or automated decision about you. A human operator reviews the inbox.
AI Providers & Training
Our primary AI provider is Anthropic, whose Claude models we use in three ways: to research and write each edition from public sources, to screen the message text of reader feedback for spam, and — for security only — to summarize the behavior of a hostile traffic source for the operator, as described under Security Monitoring. Data sent to Anthropic through its API is not used to train its models.
For the optional illustration on an Editorial Desk article, we use Google (the Gemini image model). The only thing sent to Google is the operator-written image prompt — text about the article itself — never reader data of any kind. Under the API terms that govern our access, that data is not used to train Google’s models. We use no other AI providers; if that changes, it will be disclosed here in the same way.
Replies
If you provide an email address and the operator replies, your email address is used to send that one reply through Resend, our email delivery provider. We do not add you to any mailing list or send unsolicited email.
Analytics
We keep aggregate, cookieless page-view counts only: the date, the path viewed, the referring host, and whether the visitor looked like a bot. To count unique visitors we compute a one-way, day-salted hash from the visit; the hash cannot be reversed to recover your IP or device and changes every day, so we do not use it to recognize or track visitors across days. We also keep daily aggregate counts of visitor country (country only, derived from the IP address, which itself is not stored in analytics) and device class (desktop, mobile, or tablet). We do no cross-site tracking and build no per-visitor profiles. Daily visitor hashes are deleted after about 60 days; aggregate counts are retained for about 365 days.
Security Monitoring
To protect the site against attacks, we monitor technical request metadata (IP address, request path, and similar details) on our own infrastructure. What we store is deliberately minimized: request bodies are never recorded, precise location details are dropped before storage (coordinates are rounded to roughly city scale, no street-level data), stored security request records are deleted after about 14 days, and per-IP security counters are kept for at most about 30 days. Ordinary reading is excluded by design: a normal page view is never forwarded to this monitor at all — from the public site, only requests matching known vulnerability-probe signatures, or a rapid series of repeated not-found requests from the same source, are recorded.
When a source shows signs of hostile behavior — automated scanning, probing for vulnerabilities, or repeated failed attempts to access the administration area — the operator may look up that IP address against threat-intelligence services. Only the IP address itself is ever sent — never a name, a message, or any browsing history. AbuseIPDB reports whether the address has been reported for attacks; GreyNoise reports whether it is a recognized internet-wide scanner; CrowdSec may likewise be consulted about an address already flagged as hostile. (We also periodically download CrowdSec’s public blocklist — a plain download that sends no visitor data at all.) Cached lookup results are deleted after about 14 days. Ordinary reading of this site never triggers such a lookup.
To help the operator triage hostile automation, an AI model — Anthropic’s Claude — may be shown an aggregated, anonymized behavioral summary of a suspicious source: counts and coarse categories only, never an IP address, never a raw browsing history, and never anything about ordinary readers. The server enforces this: a summary can only be produced for a source that has already shown corroborated hostile signals — failed administration logins, vulnerability-probe requests, sustained scanning for missing pages, or an external attack reputation. All of this is advisory security triage for a human operator — it never automatically blocks anyone and is never used to profile readers.
Cookies
The public site sets no cookies for readers. The only cookie-like technology you may encounter is Cloudflare Turnstile’s own technical cookies on the feedback page, which exist to distinguish humans from bots when you submit the form.
Third Parties
- Anthropic — writes each edition from public sources, screens feedback message text for spam, and summarizes the behavior of hostile traffic sources for security triage (counts and coarse categories only — never an IP address, never reader data).
- Google (Gemini) — generates the optional illustration on an Editorial Desk article from an operator-written prompt; no reader data is ever sent.
- Cloudflare Turnstile — bot protection on the feedback form.
- Resend — delivers the operator’s reply email to a reader who provided an address.
- IP-geolocation lookup — turns an IP address into a coarse location: country/region/city for feedback abuse triage, and country only for aggregate analytics.
- AbuseIPDB — attack-report reputation: the IP address of a source already showing hostile behavior (and only the IP address) may be checked against its database of reported attackers.
- GreyNoise — internet-scanner recognition: the IP address of a hostile source (and only the IP address) may be checked to see whether it is a known internet-wide scanner.
- CrowdSec — threat intelligence: the IP address of a hostile source (and only the IP address) may be checked against its attack database; separately, we download its public blocklist, which involves no visitor data.
Purpose & Legal Basis
Under the GDPR, we rely on legitimate interest for abuse prevention and security (the technical details recorded with a submission, the security monitoring above) and for aggregate, cookieless analytics. The optional name and email you type into the form are processed on the basis of your own choice (consent) — you decide whether to provide them.
Retention
Feedback submissions are kept until they have been triaged and are no longer needed, then removed. Daily visitor hashes used for unique-visitor counting are deleted after about 60 days. Aggregate analytics are retained for about 365 days. Security-monitoring request records are deleted after about 14 days, per-IP security counters are kept for at most about 30 days, and cached threat-intelligence lookup results are deleted after about 14 days.
Your Rights
Where the GDPR applies, you have the right to access, correct, and request deletion of your data. To exercise any of these, contact us through the Contact & Corrections form and we will handle your request.
This page is a plain-language disclosure drafted from how the site actually handles data. It is not certified legal advice.