Privacy Notice
Effective from 1 August 2026. Version 1.0.
This notice explains what personal data The Harm Watch collects, why we collect it, how long we keep it and what rights you have. We have tried to write it in plain English rather than legal boilerplate, because a privacy notice nobody reads protects nobody.
Who we are
The Harm Watch is operated by volunteers and submissions are passed to governing bodies once verified. The creator, Pete Trainor, is the data controller for the personal data described here. Please note the service is not registered with the Information Commissioner's Office.
Data protection enquiries: privacy@harm.watch
The short version
If you report a website, you can do so anonymously. We do not ask for your name, and we do not need it. The only personal data we collect from an anonymous report is an irreversibly hashed version of your IP address, used to stop the form being flooded by bots, and a two letter country code.
If you choose to give us an email address so we can follow up, we use it for that and nothing else. It is never passed to the organisations who receive our data.
If you register an organisation for access, we collect ordinary business contact details in order to run the account.
We never publish reports, and we never sell data to anyone.
What we collect when you report a website
- The report itself. The web address you submit, the harm categories and descriptors you select, any tag you suggest, and any free text you add in the context field. This is the core of what we do and it is shared with approved organisations, so please do not put personal information about yourself or anyone else into the free text field. There is a warning on the form to that effect. If you do include personal details, we may remove them.
- Your email address, only if you provide it. This field is optional and clearly labelled. We use it solely to contact you about your report. It is never shared with the organisations who access our data, never used for marketing, and never appears in any export or API response.
- A hashed IP address. We take the IP address your report arrives from and run it through a one way keyed hash before storing it. We do not store the address itself and we cannot recover it from the hash. This is used only to enforce rate limits and detect abuse of the form.
- A two letter country code and a hashed browser signature. Used to spot coordinated abuse and to understand roughly where reports come from. Neither identifies you.
- Bot protection data. We use Cloudflare Turnstile to distinguish people from automated scripts. Cloudflare processes technical signals from your browser as part of that check. See the Cloudflare privacy policy for detail on their processing.
What we do not collect when you report
We do not use analytics or advertising cookies, we do not fingerprint your device beyond the bot check described above, we do not track you across other websites, and we do not require or offer an account for reporting.
Crucially, we do not visit, fetch, crawl, screenshot or archive the website you report. Your report tells us an address, and we store the address. Nothing goes out from us to the site in question.
Reports we deliberately refuse
If you select child sexual abuse material or terrorist content as a category, we stop the submission and direct you to the Internet Watch Foundation or the government's terrorism reporting route instead. In that situation we store nothing at all. No address, no hashed IP, no context, no record that you were the one who tried. We increment an anonymous counter recording that a routing event happened in that category, and that is the entirety of it.
What we collect when your organisation registers for access
Organisation name, website, charity or company registration number, the contact's full name, work email address and job title, and the written justification for access. Once approved we also hold account authentication data managed by our authentication provider, login timestamps, and a record of actions taken in the admin or organisation portal.
This is ordinary business contact data, processed to operate a service your organisation has asked to use.
Why we are allowed to process this, in legal terms
- Legitimate interests, for operating the reporting service, deduplicating and classifying reports, protecting the service from abuse, and sharing submission records with approved organisations. We have completed a Legitimate Interests Assessment and it is available on request.
- Consent, for the optional reporter email address. You give it freely, you do not have to, and you can withdraw it at any time.
- Contract, for administering organisation accounts and access.
- Legal obligation, where we are required to retain or disclose information by law.
Who we share it with
- Approved organisations. They receive the submission record: the web address, its domain, its status, its categories and descriptors, the number of times it has been reported, and the relevant dates. They do not receive reporter email addresses, hashed IP addresses, country codes, the free text context field, or our internal notes.
- Our service providers, who process data on our behalf under contract. These currently are Supabase (database and authentication, hosted in [REGION]), Vercel (application hosting), Cloudflare (bot protection), Resend (transactional email), and Sentry (error monitoring). Each is bound to process data only on our instructions.
- Law enforcement and regulators, where we are legally required to disclose, or where disclosure is necessary to prevent serious harm.
We do not sell data, we do not share it for advertising, and we do not pass it to anyone else.
International transfers
Some of our providers process data outside the UK. Where that happens we rely on UK adequacy regulations or the International Data Transfer Addendum to the European Commission's standard contractual clauses. Details available on request.
How long we keep things
- Submission records are kept indefinitely. The historical record of what was reported, when, and how often is the substance of the service.
- Report level metadata — hashed IP addresses, country codes, hashed browser signatures and the free text context field — is deleted 24 months after the report is made.
- Reporter email addresses are deleted 24 months after the report, or immediately on request.
- Organisation account data is kept for the life of the account and for 24 months after it closes.
- Audit logs of privileged actions are kept for six years.
Your rights
Under UK data protection law you have the right to ask for a copy of the personal data we hold about you, to have inaccurate data corrected, to have data erased in certain circumstances, to restrict or object to our processing, to receive your data in a portable format, and to withdraw consent where consent is the basis we rely on.
There is a practical limit worth being honest about. If you reported anonymously, we hold nothing that identifies you, and we cannot connect you to a report in order to action a request. The hashed IP is one way by design and we cannot reverse it. That is a deliberate privacy protection rather than an evasion, but it does mean anonymity and subject access pull in opposite directions.
If you gave us an email address, we can find your reports from that address and act on any of the rights above.
To exercise any right, write to privacy@harm.watch. We respond within one month.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, by phone on 0303 123 1113, or in writing at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
If your website appears in our data
The Harm Watch holds reports about websites. Where a website is operated by an individual rather than a company, information about that site may constitute personal data relating to that individual.
If you believe your site has been reported wrongly, write to listings@harm.watch with the address and your explanation. We will review it, and where a report is inaccurate, malicious or mistaken we will mark the record accordingly. We do not delete records outright, but a record marked as rejected is excluded from everything we share.
Cookies
We use a single essential cookie to maintain your session if you log in, and Cloudflare Turnstile may set a short lived cookie as part of the bot check. We use no analytics, advertising or tracking cookies, which is why you are not being asked to dismiss a banner.
Automated decision making
We do not make automated decisions with legal or similarly significant effects. Reports are classified by the person making them and reviewed by a human.
Changes to this notice
We will update this notice as the service develops. Material changes will be flagged on the site with the version number and effective date above.