Privacy and Terms of Service

Privacy protection is not a legal constraint to manage: it is the very foundation of our work. The people we document trust us. This trust begins with our own infrastructure.

Our commitment

For public visitors of SAMT Archive:

  • zero cookies.
  • Zero trackers.
  • Zero analytics.
  • Zero local storage.

Your browsing is invisible — deliberately and structurally.

1. Zero surveillance by design

The SAMT Archive platform was built with an absolute requirement: public visitors must leave no measurable trace during their navigation.

This is not a policy promise — it is a verifiable architectural reality. Here is what we do not use:

  • Cookies: No cookie is deposited on your browser during a public visit.
  • Analytics: No audience measurement tool (Google Analytics, Matomo, Plausible, Fathom, etc.) is integrated.
  • localStorage / sessionStorage: No data is stored in the local memory of your browser.
  • Tracking pixels: No third-party pixel (Meta, X, LinkedIn, TikTok...) is present on the site.
  • Fingerprinting: No browser fingerprinting technique is employed.
  • Third-party scripts: No external script is loaded from third-party domains on public pages.

Self-hosted fonts

The fonts used on this site (Geist Sans & Geist Mono) are downloaded and integrated during the compilation of the site, and served from our own infrastructure. No request is sent to Google Fonts servers during your visit.

2. Exception: The secure editor space

The restricted administration space is strictly isolated from the public site and is exclusively intended for authenticated members of the SAMT editorial team.

This content management interface (Decap CMS) uses temporary session cookies exclusively to maintain the authentication of logged-in editors. These cookies:

  • are never deposited on a public visitor's browser;
  • expire when the editor's session is closed;
  • are not shared with third parties;
  • contain no data relative to public visitors.

If you are not a member of the editorial team, you will never have to access this route and none of these mechanisms will concern you.

3. Incident submission form

The form available on the Submit an incident page constitutes the only visitor-initiated data collection point.

Secure transmission pipeline

  1. Local input: Data is entered directly into your browser.
  2. Encrypted ephemeral proxy: The submission passes through an edge proxy (Cloudflare Worker) which instantly routes the data to our inbox.
  3. E2EE encrypted reception: The data arrives in a ProtonMail inbox, end-to-end encrypted.
  4. No database: The submitted information is never written to a central database.

4. Tracker-free anti-bot protection

Our forms are protected against automated submissions by passive and privacy-respecting methods, without using third-party CAPTCHA services.

  • Honeypot field: a form field invisible to human users.
  • Time analysis: a submission made in less than a few seconds is detected and rejected.

We do not use Google reCAPTCHA, nor hCaptcha, nor any third-party verification service.

5. Visibility model & source protection

Public publication

Incidents for which distribution has been explicitly authorized or whose public nature is established.

Restricted circulation

Incidents shared only with specific partners or organizations.

Retention without distribution

Testimonies and situations kept solely in internal archives, without any distribution.

6. GDPR compliance & individual rights

The processing of personal data carried out by SAMT is fully in compliance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679).

  • Right of access to their data;
  • Right to rectificationin case of inaccuracy;
  • Right to erasure("right to be forgotten");
  • Right to object to processing;
  • Right to data portability.