Privacy Policy
What the Compute Terms Observatory processes, and why.
Compute Terms Observatory (termsobservatory.org) Effective: 20 July 2026. Changes are listed at the bottom of this page with dates.
The short version
This site has no accounts, no cookies, no analytics, no advertising, no tracking pixels, and no third-party scripts. Every page is static and self-contained. We do not build profiles of visitors and we have no visitor database to breach, sell, or subpoena. The only personal data we process is what you send us yourself, plus the minimal technical data our hosting and email providers generate to deliver the service.
What we process, and why
1. Hosting logs. The site is hosted on GitHub Pages. Like any web host, GitHub processes technical data about requests to the site (such as IP address and user agent) to serve pages and maintain security. We do not receive, store, or analyze this data; GitHub's processing is described in the GitHub Privacy Statement. Legal basis where one is required: legitimate interest in operating a website.
2. Email you send us. If you write to contact@termsobservatory.org, we receive your address and whatever you include, and we use it to respond. Mail is hosted on Google Workspace under the Google Cloud Terms of Service and the Cloud Data Processing Addendum, which restrict Google's processing of correspondence to providing the service, and we have executed the EU Standard Contractual Clauses with Google. We keep correspondence as long as needed for the matter it concerns, and longer where it documents an error report, a provider communication, or a legal matter. Legal basis: legitimate interest in handling the correspondence you initiated.
3. Error reports on GitHub. If you file an error report as a GitHub issue, that report is public and is processed under GitHub's terms and privacy statement, not ours. Do not include personal information in a public issue; use email instead if your report is sensitive.
4. Email authentication reports. Mail providers automatically send us aggregate DMARC reports about messages claiming to come from our domain. These describe sending infrastructure, not readers of this site.
That is the complete list. If a future feature (such as an alert subscription) processes anything more, this policy will be updated before it launches, with the change dated below.
What we do not do
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act or any similar law. We do not use personal data for advertising, profiling, or training AI models. We do not set cookies. The only thing stored in your browser is per-tab display state (which sections of the matrix you have collapsed), kept in sessionStorage: it contains no personal data, is never transmitted anywhere, and is deleted automatically when you close the tab. The site makes no requests to any third-party domain.
Where we operate, and international transfers
The Observatory operates from the United States. The site is available worldwide, as any public website is, but it is not directed at any particular market. If you email us from outside the United States, your message arrives in a US-hosted inbox; that is the practical extent of any international transfer. Our email provider processes mail under the Standard Contractual Clauses we have executed with it.
Your rights
Depending on where you live, you may have rights to access, correct, or delete personal data we hold about you. Since the only such data is correspondence you sent us, the exercise of these rights is usually as simple as asking us to delete the thread. Write to contact@termsobservatory.org and we will handle it. If you are in the EU or UK, you may also complain to your supervisory authority; for matters arising under the Standard Contractual Clauses executed with our email provider, the designated authority is Ireland's Data Protection Commission.
Children
This site is a legal reference publication and is not directed to children.
Contact
Change history:
- 20 July 2026: First published.