LEGAL

Privacy Policy

Last updated: 2026-08-31 — added the subscription and report-intake sections below.

Who we are

TASFGA (Transparency, Analysis & Stewardship Foundation for Governance Accountability — a public-interest project currently in formation; "TASFGA," "we," "our") operates tasfga.com.

What we collect

We collect only what is necessary to operate the site and respond to inquiries:

  • Server logs — IP address, user-agent, request path, timestamp. Retained for operational purposes only.
  • Anonymous analytics — page views and referrer data via Plausible Analytics, a privacy-respecting, cookieless service (no cookies, no cross-site tracking, no personal identifiers stored).
  • Email — when you email us at contact@tasfga.com, we retain the message and your address so we can reply.
  • Subscriptions — if you use a subscribe form, we store your email address, the page you subscribed from, the date, and anything you typed into the optional role field. Nothing else. Details below.

Subscribing

The subscribe forms post to tasfga.com/api/subscribe, which is proxied to our own automation server inside our own infrastructure. We use no third-party mailing vendor, so your address is not handed to Mailchimp, Substack, or anyone comparable, and there is no tracking pixel in anything we send.

  • What is stored: the address, the source page, the timestamp, and the two-letter country code our CDN reports. No name is asked for and none is required.
  • What it is used for: sending the Governance Brief. Nothing else. It is not used to profile you, and it is not combined with analytics data.
  • Unsubscribing: one click from any email, or reply and ask. On unsubscribe the address is deleted rather than flagged and retained.
  • Honesty about the transport: the form is submitted over HTTPS, but email itself is not a confidential medium. Do not use the subscribe form to tell us anything sensitive.

Sending us a report

Reports sent to tips@tasfga.com are treated as confidential by default: we do not publish the identity of a person who sends one, and we do not confirm to a body under review who reported it. The limits on that are stated in full, without euphemism, on the report page — in particular that ordinary email is not secure in transit, that TASFGA is pre-incorporation and holds no legal privilege of any kind, and that a court could compel production of what you send. Read those before sending anything that could put you at risk.

What we do not do

  • We do not sell personal information.
  • We do not share personal information with advertisers, brokers, or other third parties for marketing.
  • We do not use tracking pixels, social-media trackers, or ad networks.
  • We do not rent, trade, or otherwise pass on a subscriber list.
  • We do not add anyone to a mailing list because they emailed us, sent a report, or made a correction request. Subscription requires the form.

Your rights

You may request access to, correction of, or deletion of any personal information we hold about you by emailing contact@tasfga.com.

Security

To report a vulnerability, see security.txt.

Updates

We will revise this policy as needed. Material changes will be noted at the top of the page.