Privacy Policy
Last updated: July 28, 2026
Horn Reporter collects as little personal data as we can. You do not need an account to read the Site, we do not sell data, and we do not run advertising or third-party tracking. This policy explains what we do collect, why, and what you can ask us to do about it.
1. What we collect
If you only read the Site
We do not ask you for anything. Our servers automatically record:
- Technical request data — your IP address, browser type and version, operating system, the page requested, the referring page and the time of the request. This is standard web server logging, and we use it to keep the Site running and to detect abuse.
- Cookie choices — if you respond to our cookie banner, we store your choice together with your IP address, your browser’s user-agent string and the date, so that we can prove what you consented to and not ask you again. This is described in our Cookie Policy.
We do not build reader profiles, and we do not track you across other websites.
If you are staff or a contributor
- Your email address, which is how your access is granted and how you sign in.
- Your name and byline details, which are published alongside your articles.
- Sign-in records — one-time codes are stored only in hashed form, expire after ten minutes and are deleted after use or expiry. Your session token records the IP address it was issued to, as a protection against token theft.
- What you publish — your articles, the media you upload and the edit history associated with your account.
If you contact us
When you email us — a tip, a correction request, a complaint, a pitch — we keep your message and your address so that we can reply and, where relevant, act on it.
2. Why we use it, and on what basis
- To operate and secure the Site (legitimate interests): serving pages, preventing abuse, rate-limiting, diagnosing faults.
- To authenticate editorial staff (contract, legitimate interests): sending one-time sign-in codes and maintaining sessions.
- To publish journalism (legitimate interests, and the special regime that applies to processing for journalistic purposes): attributing articles to their authors, and reporting on matters of public interest.
- To respect your cookie choices (consent, and legal obligation): recording what you chose and applying it.
- To answer correspondence (legitimate interests): replying to what you send us.
We do not use your data for automated decision-making or profiling.
3. Journalism
Reporting the news necessarily involves processing personal data about the people we write about, and we rely on the exemptions that data protection law provides for journalism. We will not disclose a confidential source, or material that could identify one, in response to a subject access request or any other request. Our Editorial Policy sets out how we weigh privacy against public interest before publishing.
4. Who we share it with
We do not sell personal data and we do not share it for advertising. We use a small number of service providers, who process data only on our instructions:
- Cloud hosting and storage — Amazon Web Services hosts the Site and stores published images, video and audio.
- Email delivery — a transactional email provider delivers sign-in codes. Only the recipient address and the message itself are shared.
We will disclose personal data where we are legally required to do so by a valid court order or a binding legal process — and where we are permitted to tell you about it, we will.
5. Where your data is held
Our servers and storage are operated by Amazon Web Services and your data may be processed in a region outside your own country. Where personal data is transferred internationally, we rely on our providers’ contractual data protection commitments.
6. How long we keep it
- Server logs — retained for up to 90 days, then deleted.
- Cookie consent records — retained for one year from the date of consent, after which the record expires and you are asked again.
- One-time sign-in codes — deleted on use, on expiry, or by our nightly cleanup, whichever comes first.
- Staff and contributor accounts — retained while the account is active. When access ends, we delete the account. Published bylines remain on the articles they belong to, as part of the public record.
- Correspondence — retained for two years, or longer where a complaint or a legal claim is unresolved.
7. Security
The Site is served over HTTPS. There are no passwords to steal: sign-in is by one-time code, codes are stored hashed, they expire in ten minutes, they can be used once, and they are burned after five failed attempts. Session tokens are held in an HTTP-only cookie, which JavaScript cannot read. Sign-in requests are rate-limited. No system is perfectly secure, but we design to keep the amount of data at risk small.
8. Your rights
Subject to the journalism exemptions in section 3, you may ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything inaccurate;
- delete your data, where we have no continuing need or legal obligation to keep it;
- restrict or object to our use of it;
- withdraw consent where our use of your data rests on consent — you can change your cookie choices at any time on the Cookie Preferences page.
Email contact@hornreporter.com to make a request. We will respond within 30 days. A request to correct or remove something we have published is handled under our Editorial Policy, not as a data request, since it concerns the accuracy of our journalism.
9. Children
The Site is intended for a general adult audience. We do not knowingly collect personal data from children under 13. If you believe we have, contact us and we will delete it.
10. Changes
We may update this policy. The date at the top of the page reflects the current version, and where a change materially affects your rights we will place a notice on the Site.
11. Contact
For any privacy question or request, write to contact@hornreporter.com. If you are not satisfied with our response, you may complain to the data protection authority in your country.
