Privacy

What the SANDL Project collects, why we collect it, who it goes to, and how to have it removed. Last updated August 1, 2026.

Scope

This statement covers sandlproject.org and the API at api.sandlproject.org. It applies to people who visit the site, create an account, or use an API key. The public index pages can be read without an account, and we do not require you to identify yourself to view them.

What we collect

Account. Your email address, the name and profile picture you sign up with, and which method you used to sign in. If you sign in with Google we receive only your email, basic profile, and a Google account identifier (the openid, email, and profile scopes). We never see your Google password. If you sign up with an email and password, we store only a one-way hash of the password.

API keys. The key name you choose, a short non-secret prefix, a one-way hash of the key, and the times it was created, last used, and revoked. The key itself is shown to you once and is not recoverable from our records.

Operational records. Server logs of requests (time, path, response status, request identifier, and IP address) for security, rate limiting, and debugging, plus error reports sent to Sentry with personal data collection turned off.

Why we collect it

To sign you in, to apply the access limits on your account, to send transactional email (address verification and password resets), and to keep the service available and resistant to abuse. That is the whole list. We do not sell personal data, we do not run advertising, and we do not build behavioral profiles.

Cookies and browser storage

We set one short-lived cookie during Google sign-in, which exists only to protect that request from cross-site forgery and is deleted as soon as the sign-in completes. Your session tokens are held in your browser's local storage, not in cookies, and are cleared when you log out. There are no analytics or advertising cookies on this site.

Who else sees it

Only the providers that make the service run, each seeing only what its job requires: Google for sign-in if you choose it, Amazon Web Services for hosting, the database, and transactional email, and Sentry for error reporting.

We disclose data beyond this only where the law requires it. We do not share your data with other customers or with data brokers.

How long we keep it

Account data is kept while your account exists. Revoked API keys keep their hash and usage timestamps as an audit record. Server logs are kept for a short operational period and then discarded.

The data behind the indexes

The indexes and the labeled feed are built from publicly published news metadata: headline, link, outlet, and publication time, sourced from GDELT and labeled by our own models. That pipeline is entirely separate from user accounts. It is not used to profile individuals, and nothing you do on the site feeds into it.

Your choices

You can view and change your account details, and create or revoke API keys, from your dashboard at any time. You can ask us for a copy of your data, ask us to correct it, or ask us to delete your account and the personal data attached to it. Write to us and we will action it.

If you signed in with Google, you can also disconnect this app at any time from your Google account permissions page. Doing that stops future sign-ins but does not by itself delete the account here, so send us a deletion request as well if that is what you want.

Changes

If this statement changes we will update the date at the top of this page. Material changes affecting how we use your data will also be sent to the email address on your account.