Legal
Privacy and cookies
What LevantLeaks collects, which cookies we set, and how we protect the people who send us tips. Plain language, no dark patterns.
01
What we collect
Only what is necessary to run the site. When you visit any page, our infrastructure provider (Vercel) records the IP address, request path, timestamp, referrer, and user agent to serve the page and detect abuse. These access logs are retained by Vercel for up to thirty days and then deleted. We do not run Google Analytics, Facebook Pixel, or any third-party advertising, tracking, or fingerprinting scripts. We do not build user profiles. We do not sell or share any data.
02
Cookies and browser storage
We set exactly one cookie, and only for editors when they log in to the admin panel: a session cookie named "ll_admin" that is HttpOnly, Secure, and expires after seven days. Public readers of the site receive no cookies from us. We also use browser sessionStorage (cleared when you close the tab) to remember whether you have already seen our intro animation on this visit. Both are classed as strictly necessary under GDPR and PECR, so no consent banner is required. If we ever add analytics or advertising, we will introduce a consent banner before enabling them.
03
Submissions and tip data
When you send us a tip via /submit, we store only the fields you provide (headline, summary, body, and optional name, location, and category). If you leave the name blank it is recorded as "Anonymous Contributor". Your IP address is kept in a separate rate-limit table for one hour to prevent spam and is then automatically discarded. Submissions are permanently immutable at the database level once received: nobody, including us, can silently edit the text of your tip after it lands. Once we review a tip we may promote it to a published article, or reject it; the original submission remains locked as an evidence-of-source record.
04
Third-party services we rely on
Vercel hosts the site and terminates HTTPS. Supabase hosts the database and file storage in a Frankfurt-region data centre, encrypted at rest with AES-256. OpenStreetMap and CARTO serve the map tiles on /map. When you load /map, your browser will fetch tile images directly from those providers and their servers will see your IP address in the process. We have no other embeds, no fonts loaded from third parties beyond Google Fonts (self-hosted via next/font, so Google does not see visitors), and no external scripts.
05
Your rights
Under GDPR, UK GDPR, and CCPA you can request access, correction, or deletion of any personal data we hold about you. Email privacy@levantleaks.com and we will respond within thirty days. Fully anonymous submissions cannot be retrieved or deleted on request because we hold no identifier linking them back to you, which is by design.
06
Updates
We will revise this policy as the platform evolves. Material changes will be flagged at the top of this page for at least thirty days. This version was last reviewed on 4 August 2026.
Questions
Email privacy@levantleaks.com for anything about this policy.