Skip to content

Privacy

Last updated 19 September 2026

What we store

Browsing Matter of Record needs no account. If you sign up, we store your email address, the profile details you choose (username and display name), the cases you follow, the coverage you log, and any ratings, tags or reviews you write. Your email address is never shown publicly.

Your profile, follows, logs and ratings are private unless you opt in. A published review appears on the coverage item with your handle only if you make both the profile and reviews public.

Always private: your email address, password, notification delivery mode, and calendar feed token. Public only if you opt in, independently: the profile page itself, the cases you follow, the coverage you log (including ratings), and published reviews. A published review on a coverage item shows your handle only when both the profile and reviews are public; otherwise it is attributed to "A member" or is not shown.

Analytics and cookies

We use PostHog, an EU-hosted analytics provider, and nothing is sent until you accept. Declining changes nothing about how the site works. We never use advertising or cross-site tracking cookies, autocapture (which records every click and keystroke) and session recording are switched off entirely, and analytics never runs on admin pages.

What you search for is never sent. Free-text search terms are stripped from every page URL before it reaches PostHog, and none of the events below carry the words you typed — only whether a search returned results and which one you picked.

This is every category of event we send, and the properties attached to each:

CategoryWhat's attached
Page viewsThe page URL, with any q, query or search parameter removed before it is sent.
Following a caseWhich case (its internal id, not the case name), your notification delivery mode, and whether the action succeeded.
Logging and reviewing coverageWhich coverage item, the status or rating you set, which tag you applied, and the character length of a review — never the text of the review itself.
SearchHow many results a search returned and which result you picked, and — when a search found nothing — whether any filters were active, whether we could offer near matches, and whether you asked us to add the case. The words you typed are never sent as an event property, and are stripped from the page-view URL before it leaves your browser.
HomepageViewport and consent state, result-count and query-length buckets, and homepage control interactions. Raw search text is never sent.
Signing upThe sign-up method (email or Google) and which part of the site started the flow.
Reading a case pageWhich case, which timeline control you used, which control expanded a timeline entry (the title chevron or the Clipping scan affordance — BAS-1310), which element opened a source link (the row citation, the clip card's badge, the full-scan dialog, or the fallback caption — BAS-1311/BAS-1313), and — on a podcast excerpt card — the show name, episode title, excerpt start position and segment count (never the quote text). If you open or download that episode's full transcript, the show name, episode title and how many lines it has (never the transcript text). Adding a hearing to a calendar records which case and event, and which surface (the Next up card, the hearings list, or the timeline) — never the hearing title. Asking to be reminded about one hearing records which surface you used and the timing you chose (day before, morning of, both, or off) — not the case, event or hearing title.
Your dashboardHow many cases you follow, how many updates were listed, which update you opened, and which event's watch link you used.
ErrorsA stack trace, with no page content attached. This is the one category not blocked on admin-only pages, so a crash on a page only staff use is still visible to us.
Internal operationsOperational counts and flags only — outcome and action names, the retrieval-backend enum (particle, elevenlabs, or manual), the query algorithm version label, minutes-since-creation, high-risk and had-identifiers flags, the coverage item's internal id that links one episode's lookup → candidate → review events together, and a per-run correlation id that joins one retrieval attempt's events to its run-history row. Attached to the case's internal id or to the episode, excerpt, coverage item, or staff account the operation concerns. Provider identifiers (Particle episode ids, provider_response_id), URLs, headlines, quote text, transcript text, notes, and other member data are never sent.
Supporting the recordWhich payment link was opened (Stripe $5/$10/$25/custom, or Ko-fi). Server-side: the contribution's origin and currency, and the reason a payment needs manual review. A payment is never tied to an analytics identity — these events share the constant id support-anonymous.
MCP toolsThe tool name and that the call came from MCP, attached to the signed-in account id when available or an anonymous operational id otherwise.

Once you sign in, these events are tied to your account id so we can, for example, tell how many people who follow a case also log coverage of it. We keep raw event data in PostHog for up to 12 months, after which it is deleted automatically; aggregated statistics with no per-person identifier may be kept longer. Internal jobs (the search index, scheduled crawls) also send a small number of operational events that never carry member data.

Supporting the record

One-time contributions on the support page are processed by Stripe. The payment itself happens on the processor's pages; card and account details go to them, never to us.

We keep a contribution ledger of what the processors report: the amount, the currency, the payment date, and the billing email used for the payment, which we need for the accounting and record-keeping the law requires. Contributions are never published, and there is no public supporter list. Deleting your account does not remove this ledger — it keys to the billing email the processor reported, not to your account, and the rolling five-year tally is a legal record either way.

Email

We send account email only — sign-up confirmation, password resets and similar. There is no marketing email.

Your data

You can download a copy of your data from the settings page at any time — your profile, follows, logs, ratings, reviews and review tags as a JSON file.

You can change your profile at any time in settings. Deleting your account is immediate and cannot be undone: it removes your profile, follows, logs, ratings, reviews — including any hidden or awaiting review — and review tags. Some records outlive it: a report you filed on someone's review keeps an anonymous record id with no name attached; a correction or erasure request you sent keeps the name and email you gave for our reply; anything others have already seen, quoted or cached cannot be recalled; and copies inside provider backups, plus the analytics events described above, age out on their own retention schedules. For anything else, write to contact@matterofrecord.app.

Related policies