Privacy Policy
Last updated: August 7, 2026
Who we are
PolicyWatcher is an independent civic-tech platform created by Fabrizio Degni, based in the European Union. This platform monitors and analyzes publicly available privacy policies and terms of service of major technology and fintech companies.
For any privacy-related questions, you can contact us at: privacy@policywatcher.online
Protected dashboard measurement
The authenticated administrative dashboard can record four allowlisted operational events: time to the first tagged action, an Action Center destination attempt, confirmed arrival at its canonical protected route, and mobile distance to the first priority. The authenticated role is derived by the server and arbitrary destinations or metadata are rejected.
Each event retains a random per-visit identifier, event type and key, Admin or Auditor role, an allowlisted priority and destination when applicable, a bounded numeric value, viewport class and server timestamp. Records are retained for at most 90 days and per-visit event keys are deduplicated.
Dashboard measurement does not store an IP address, user agent, referrer, email, username, account identifier, query string, free text or arbitrary metadata. Event-derived values remain hidden until their stated minimum sample is available. Missing or unavailable measurements are not converted to zero and do not establish task completion, usability improvement, accessibility conformance, service levels or operational health.
What data we collect
PolicyWatcher is designed to collect as little personal data as possible.
Data you provide voluntarily
If you subscribe to email alerts, we collect:
- Email address (required): to send you policy change notifications.
- Name (optional): for personalization of communications.
- Region and industry preferences: to filter alerts relevant to you (e.g. "EU", "FinTech").
This data is stored in our database and used exclusively for sending the alerts you requested. We do not share, sell, or transfer your email address to any third party, for any reason.
Excluded data
- Public pages use no tracking or analytics cookies. A protected administrator or auditor login uses one essential HTTP-only signed session cookie with a 24-hour maximum age.
- We do not use Google Analytics, Meta Pixel, or any third-party tracking service.
- We do not collect IP addresses for profiling purposes.
- We do not fingerprint your browser or device.
- We do not serve advertising of any kind.
Cookie-free newsroom event counting
The Press Kit and Editorial Pulse use a first-party endpoint to count allowlisted aggregate newsroom events: press-package and Story Pack actions, Data Room and Pulse story views, social-card actions, citation and embed copies, press-contact intentions and launch-destination actions. A valid Pulse campaign link can also record its fixed, allowlisted campaign cohort. This counting uses no analytics cookie and no third-party analytics service.
Each accepted event record retains exactly:
- Event type: one of the documented newsroom or editorial-funnel actions.
- Allowlisted target: a published locale, story slug, card format, copy category, contact route or launch destination.
- Locale: English or Italian.
- Server timestamp: when the event request was accepted.
The event record does not retain an IP address, user agent, referrer, URL query, cookie or session identifier, fingerprint, email address, outlet name, free text or message recipient. An IP address can be used transiently in server memory for rate limiting, but is not written to the newsroom event record or its rate-limit log.
Download, copy, contact and launch events measure actions or click intentions only. They do not confirm a completed transfer, publication, delivered message, conversion or unique person. Data Room and Pulse story events are requested once per page-component load. Automated traffic can affect all counts. A failed event write does not prevent the requested public action.
Campaign URLs may contain one public parameter, campaign, whose value must match a published allowlisted campaign cohort identifier. Unknown, duplicate or additional values are ignored for campaign measurement. PolicyWatcher does not retain the raw query string.
Authenticated administrators may record aggregate outreach operations for an allowlisted cohort: pitch sent, reply received, interview requested, coverage confirmed or correction requested. These records use the same event type, allowlisted target, locale and server timestamp fields. The administrative endpoint rejects recipient, journalist, outlet, email, subject override, message body, notes and arbitrary target values. Auditors can inspect aggregate totals but cannot create them.
Enterprise agents and Word contract evidence review
The public Agent Evidence Gateway accepts only allowlisted topic, company, sector, region, language and result-limit fields. It does not accept prompt transcripts, document text, tenant identifiers, account identifiers, access tokens or arbitrary metadata. Requests are rate limited without writing a client IP address to an application event record.
In the Word task pane, the selected clause is read only after an explicit action and is classified locally against a fixed topic taxonomy. The selection, document name, document identifier, user identity and Office access token are not sent to PolicyWatcher. After a separate acknowledgement, the task pane sends only the displayed controlled topic labels, language and bounded result limit to retrieve related public evidence.
Customer-side Microsoft 365, Google Cloud and AWS agent configurations remain subject to the customer's own tenant, project or account controls. PolicyWatcher does not administer those environments through the supplied source packages.
Local storage
We use your browser's localStorageto remember the Terms of Use disclaimer, language and display preferences, the administrator's release-versioned outreach-readiness checklist, and your optional Adaptive Workspace configuration and onboarding completion. These settings contain no email address or account identifier, do not leave your browser, and can be cleared at any time through your browser settings.
The global context setting stores only a selected macro-region, country code and EN/IT language preference. It does not request, derive or store an IP-based location, GPS position, street address, citizenship or legal jurisdiction. PolicyWatcher Civico also stores bounded watchlist identifiers and review states locally. Organization suggestions are not submitted automatically: the form prepares a draft in your configured email client.
Policy-update inquiries
When you use the “What changed?” workflow, the notification you paste is treated as an unverified clue and is parsed locally in your browser. The original text, sender and recipient addresses, subject, message body and any content fingerprint are not included in the API request and are not stored by PolicyWatcher.
If you select a saved .eml file, the bounded MIME parser also runs locally in browser memory. PolicyWatcher does not connect to your mailbox or upload the file. Recipient headers and attachments are excluded before clue review; attachments are not opened. Unsupported, attachment-only and oversized messages are rejected locally.
Only operational, non-personal clues needed for human review are sent: an organization or registrable domain, a query-free official URL when supplied, policy categories and dates. These clues are not sent to Gemini, and submitted links are not fetched before an administrator approves the source. The random public inquiry reference contains no user identifier.
A reference is shown only after the inquiry has been saved in the protected administrator queue. When operational SMTP is configured, PolicyWatcher may notify the administrator using the same minimized clues and reference; the pasted notification, email addresses, subject and fingerprint are never included. If storage is unavailable, no queue item or administrator email is created and the interface says that the request was not registered.
PolicyWatcher browser extension
Browser extension 3.8.3 Beta 3: Chrome Web Store and Microsoft Edge Add-ons published · Safari not yet available. Beta status does not reduce the privacy, permission-minimization or data-handling controls described here.
The browser extension receives temporary access to the active tab only after you press its inspection button. It does not request persistent access to Gmail, Outlook, your mailbox, browsing history, cookies or the clipboard. The visible notice is processed inside that tab to identify minimal operational clues and is immediately discarded.
Before any request is sent, you can review and correct the organization, sender domain, query-free official URL, policy categories and relevant dates. Only those confirmed fields can be transmitted over HTTPS to PolicyWatcher. The extension does not transmit or store the email address, recipient, subject, message body, attachments or a content fingerprint, and it contains no analytics, advertising, telemetry or remotely hosted executable code.
The deployment infrastructure may process an IP address transiently for security logs and rate limiting. It is not used for profiling, advertising or extension analytics. The extension does not retain inquiry history, language or disclosure state after its popup closes.
PolicyWatcher's use of information accessed through the browser extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. The information is used only to provide the user-facing notice-to-evidence feature and is not used for advertising, profiling, credit decisions, resale or unrelated purposes.
AI assistant conversations
When you use the Policy Live Assistant (chat feature), your questions are sent to our server and processed using the Google Gemini API. We do not store your conversation history. Each session is ephemeral: when you close the assistant, the conversation is gone. Google's data handling for the Gemini API is subject to Google's API Terms of Service.
Legal basis for processing (GDPR Art. 6)
- Consent (Art. 6(1)(a)): When you subscribe to email alerts, you explicitly consent to the processing of your email address for that specific purpose.
- Legitimate interest (Art. 6(1)(f)): We process minimal technical data (server logs) for security and platform stability purposes.
Your rights under GDPR
As a user located in the European Economic Area, you have the right to:
- Access your personal data and request a copy.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"). We will delete your email and all associated data upon request.
- Withdraw consent at any time by unsubscribing from alerts or contacting us.
- Port your data in a structured, machine-readable format.
- Object to processing based on legitimate interest.
- Lodge a complaint with your national Data Protection Authority.
To exercise any of these rights, contact us at privacy@policywatcher.online. We will respond within 30 days.
Data storage and security
- Subscriber data is stored in the production SQLite database. PolicyWatcher does not claim application-level encryption of the live database file; filesystem, volume and backup protection depend on verified hosting controls.
- Production traffic is configured to use HTTPS/TLS; transport security depends on the active hosting and proxy configuration.
- Access to the database is restricted and protected by API authentication.
- Application logs use masked recipient references for email operations. Hosting-level request logs and their retention remain subject to the active provider configuration.
- The protected Admin dashboard can store allowlisted aggregate-use events with a random per-visit identifier, server-derived role, viewport class and bounded numeric values. It does not store an IP address, user agent, referrer, email, username, account identifier, query string, free text or arbitrary metadata in this telemetry table. Retention is 90 days.
- We do not store data longer than necessary. If you unsubscribe, your data is marked as inactive and can be permanently deleted upon request.
The dated Residency and Processor Evidence register separates reviewed public documents, operator declarations, deployment-dependent facts and evidence that remains open. It does not infer the active server or backup region from a provider contract.
Data transfers
When you use the AI assistant, your query text is sent to Google Gemini API servers. Google may process this data in the United States or other countries. This transfer is covered by Google's Standard Contractual Clauses and Data Processing Addendum. No other personal data is transferred outside the EEA.
Children
PolicyWatcher is not directed at individuals under the age of 16. We do not knowingly collect personal data from children.
Changes to this policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date. We will not reduce your rights under this policy without your explicit consent.