Privacy Policy
This policy was written without a lawyer's review. It describes what Officially actually stores and does, measured from the product on 4 October 2026, and it will be revised after legal review; any change will be dated here.
Last updated: 4 October 2026
1. Who is responsible
The controller of personal data processed on officially.news is Ștefănigă D. Cosmin-Lucian PFA (persoană fizică autorizată), CUI 34668358, trade register F11/350/2015, Str. Dacilor nr. 11, 325400 Caransebeș, Caraș-Severin, Romania, which runs Officially as a non-commercial project. Contact: [email protected].
The supervisory authority is Romania's ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), dataprotection.ro.
2. Reading without an account
Reading Officially never requires an account — the pages, the API and the feeds.
When you load a page, our servers receive your IP address and browser headers, as any website does. Officially sits behind Cloudflare, which passes your address to us so that:
- Rate limits can be applied per address. The counters live in the application's memory for a minute and are not stored.
- Request logs record each request's path, time and outcome, on our server. What you search for is filtered out of these logs. They are capped at 10 MB per server process and overwritten as they fill — about a day of traffic — and discarded entirely on every deploy.
Page counts. We count page views as one number per publication (or organization) per day. That table has no column for an address, a browser, a user or anything else about you: nobody, us included, can tell who read what.
Analytics. We run Plausible, self-hosted on our own server. It sets no cookie and stores no personal data. It is not loaded at all on operator pages, on the publishing pages, or when you are signed in. Plausible never stores your IP address: it counts visitors with a hash of the address and browser, salted afresh every day and then discarded, so a visit cannot be linked to the next day's. The counts it keeps — pages, referrers, countries — are aggregate and kept indefinitely.
Cookies. If you sign in: a signed, http-only session cookie, and the framework's session cookie that remembers where to send you after signing in and carries one-off messages. No advertising, tracking or third-party cookies.
3. If you create an account
We store:
- your email address, a hash of your password (never the password), and whether and when you confirmed the address;
- a record of each signed-in session: when it started, and the IP address and browser it started from. A session ends when you sign out or after 90 days without use, and its record is deleted;
- which organizations you follow, your alert settings, and your dashboards and columns, including any saved search text;
- for each email alert sent: which alert, which publication, when, whether it was delivered, and the email provider's message id and any error — not the email's content. Kept for 180 days.
Our email provider tells us if a message bounced or was marked as spam, and we stop sending to that address. Every alert has an unsubscribe link that works without signing in.
Following an organization is private. It is never shown to anyone, and there are no follower counts. It gives you no relationship with that organization.
Closing your account. Close it yourself from your account page (you will be asked for your password), or email [email protected] from the account's address. We delete your sessions, follows, alerts and dashboards, and replace your email address and password hash so the account can no longer be identified or used. If your account took part in an action recorded in the audit log (section 5), that entry stays, attached to the anonymised account. Your address is then free to register again.
4. If you claim an organization or publish
A claim stores the organization, your account, the domain, the DNS check and its result, the claim's status and dates, and the note left by whoever reviewed it.
An approved claim creates a membership (owner, admin or editor). An API key stores its name, a short visible prefix, a one-way hash of the secret, its permissions, and when it was created, last used, expires or was revoked, and by which account. The secret itself is never stored or logged — it is shown once, when it is made.
When an integration retries a write, we keep the first response for 24 hours so the retry gets the same answer instead of publishing twice.
5. The audit log
Actions that grant or use authority — claims and their review, verification, memberships, API keys, publishing, corrections, withdrawals and text removals — are written to a permanent log: what happened, when, which account or integration did it, and for which organization.
This log is kept indefinitely and cannot be edited, because it exists to answer who was allowed to do what. It never holds secrets, and it never holds the text of a publication — not its title, not a correction note, not a withdrawal note — so that a removal can always reach every copy of a text. An entry is kept after the account that made it is closed because it is the record of who was authorised to act for an organization, which may be needed to establish or defend a legal claim (Article 17(3)(e)), and which we have a legitimate interest in keeping accurate (Article 6(1)(f)).
6. People named in official publications
We import publications from organizations' own official sources: governments, regulators, agencies, central banks, international bodies and some companies. Those publications sometimes name people — in enforcement actions, sanctions designations, appointments, consultations, court and tribunal decisions.
For each one we store the publisher's text, show an extract, keep every version, and make the current version searchable. We do this on the basis of legitimate interests (Article 6(1)(f)): the public's interest in an accurate record of what official bodies published, and ours in keeping that record. Where it applies, we also rely on the protection of freedom of expression and information (Article 85 GDPR and Article 7 of Romanian Law 190/2018).
We weighed that interest against the interests of the people named, and limited what we do accordingly: we carry only what the official body itself chose to publish; for most publishers we show an extract rather than the whole text, and always send readers to the source; when a publisher removes a text from its own site, we can remove ours; and we do not carry the sources where the balance falls the other way.
We cannot contact everyone named in a publication, so this policy is the notice to them (Article 14(5)(b)).
Police forces that publish appeals naming private people — wanted or missing persons, arrests — are not carried.
To assign broad topics, we send the title and up to 600 characters of the summary of each imported publication to OpenAI (section 7). No data about readers is ever sent.
Removal. If a publication concerns you, you can ask us to remove its text: see section 9 of the Terms of Use. In short, we remove it where the publisher's own page no longer carries it, or on a legal order; the record that it existed stays, saying when and why the text was removed, never what it was. The removal is logged without your name, and we do not ask for identity documents.
7. Who else processes data
| Service | What for | What it receives | Where | Agreement and transfers |
|---|---|---|---|---|
| Hetzner | Hosting the application, databases, backups and Plausible | Everything we store | Helsinki, Finland (EU) | Data processing agreement under Art. 28 GDPR, being put in place; no transfer outside the EU |
| Cloudflare | Edge network, caching, TLS | Every request, including your IP address | Global; US company | Cloudflare's DPA, part of its self-serve terms, with the EU Standard Contractual Clauses |
| Resend | Sending email | Your email address and the message | US company | Resend's DPA, in force for every account; EU–US Data Privacy Framework and Standard Contractual Clauses |
| Sentry | Error reports | Error details and the address of the request that failed; configured not to send personal data, with credentials scrubbed | United States (Sentry's US region) | Sentry's DPA, on all plans; EU–US Data Privacy Framework |
| OpenAI | Topic classification | Titles and summaries of imported publications — never reader data | US company | OpenAI's API data processing addendum with the EU Standard Contractual Clauses, being put in place; API data is not used for training |
| Plausible | Analytics | Self-hosted on our own server; cookieless, no IP addresses stored | Helsinki, Finland (EU), with the application | Runs on our own server; not a separate processor |
Where data goes to the United States, it is protected by the EU–US Data Privacy Framework where the provider is certified under it, and otherwise by the European Commission's Standard Contractual Clauses in the provider's agreement.
8. How long we keep things
| Data | Kept |
|---|---|
| Imported publications, every version, and where we saw them | Indefinitely — this is the archive |
| Text we removed on request (section 6) | Gone from the live service immediately; from backups within 14 days |
| Database backups | 14 days |
| Accounts and what belongs to them | Until you close the account |
| Signed-in sessions | Until you sign out, or 90 days without use |
| Email alert records | 180 days |
| Audit log | Indefinitely, without publication text |
| Page counts | Indefinitely — they contain no personal data |
| Write-retry responses | 24 hours |
| Request logs | About a day (10 MB per process, and cleared on every deploy) |
| Error reports | Sentry's retention for our plan — at most 90 days |
9. Your rights
You can ask for access to your data, correction, erasure, restriction, a portable copy, and you can object to processing. Email [email protected] — from your account's address if it is about your account. For text in a publication that names you, see section 6.
We answer within one month (extendable by two months for complex requests, in which case we tell you why). You can also complain to ANSPDCP.
If you object to, or ask us to erase, your data in an official publication, we weigh your request against the public interest in an accurate record of what official bodies published (Articles 17(3)(a) and 21(1)). As a rule we follow the source: where the publisher no longer publishes the text, we remove ours. Where you tell us of exceptional circumstances — for example, that the publication puts you at risk — we consider them on their own facts.
10. Security
Passwords are hashed; API secrets are never stored; operator tools sit behind a separate credential and refuse access if it is not configured; everything fetched from other sites is treated as untrusted; every connection uses TLS. Development systems cannot connect to production data.
11. Changes
Changes to this policy are dated here, and material ones are announced on officially.news before they apply.