Privacy
What is collected, what is published, what is never published, and what you can ask for.
Last updated
This platform holds material about online abuse. Some of that material concerns people who never chose to interact with it — reporters, the people they are reporting, and third parties who happen to appear in a screenshot. This notice describes how each is handled.
If you submit a report
ReportBase stores:
- Your email address, so a reviewer can ask you questions. It is never published and is never disclosed to the person you reported.
- An optional contact handle, if you provide one.
- What you wrote and what you attached.
- A one-way hash of your IP address and your browser’s user agent string, used to detect coordinated or automated abuse of the submission form. The address itself is not stored, and the hash is keyed so it cannot be reversed by testing candidate addresses.
- A police or crime reference, if you supply one. This is stored privately and is never published.
Reports that are rejected are retained with their decision so that the same material resubmitted repeatedly can be recognised. You can ask for a rejected submission to be deleted.
If you are named in a report
A published record contains the account’s username, display name, platform user ID, the aliases it has been observed using, the categories alleged, and the evidence cleared for publication.
ReportBase does not publish, under any circumstances:
- home or workplace addresses
- phone numbers or personal email addresses
- IP addresses
- passwords, authentication tokens or session data
- financial or payment information
- government-issued identifiers
- information about relatives or associates
- the identity of the person who submitted a report
Where a document is relevant but contains any of the above, a redacted display copy is prepared and published. The unredacted original is retained privately, is not addressable by any public URL, and is served only to signed-in staff through an authorising route that records the access.
Evidence handling
Uploaded images are re-encoded on receipt, which removes embedded metadata — including the GPS coordinates that cameras attach to photos. A cryptographic digest of each stored file is recorded so a copy can be checked against the record. Files are stored in private object storage and are never served directly from it.
Search engines
Record pages are indexable, but they are served with directives asking search engines not to generate text snippets or image previews. A record read out of context is exactly the failure this platform exists to avoid.
Retention
- Published records are retained while they remain accurate and relevant, and are reviewed when a correction request is received.
- Submissions are retained with their review decision.
- Evidence originals are retained for as long as the record they support.
- The moderator audit trail is append-only and is not deleted. It records which staff account took which action and when. It does not contain evidence contents or reporter contact details.
- Rate-limiting counters expire automatically.
What you can ask for
Anyone may request a correction, including the subject of a record. You can ask for a record to be corrected, for unsupported information to be removed, for a dispute to be recorded alongside it, or for a record to be removed entirely. Requests are reviewed by a person and you will receive a decision.
Where a record is removed or amended, the change and its reason are recorded in the audit trail. That trail is internal and is not published.
Security
Staff accounts use password hashing designed for the purpose, sessions are held server-side and can be revoked, and every administrative action is checked against the acting account’s role on the server. Access to restricted evidence is logged.