This policy replaces the SITREP Privacy Notice last updated 1 March 2025. That notice said SITREP collected no location data and did not let users post content. Both have changed: SITREP now has Community features and an optional Near me feature, and this policy explains the data they use.
01Who we are and what this policy covers
SITREP is provided by Artorias, Inc. ("Artorias", "we", "us", "our"), 169 Madison Ave, Suite 11590, New York, NY 10016, United States. We decide how your personal information is used for SITREP, and we are responsible for it (in EU and UK terms, we are the "controller").
This policy covers SITREP on the web, on iOS and on Android, SITREP Academy (when it is available), and related services (together, the "Service"). Words such as "SITREP Reporting", "Community features", "Community Content", "handle", "SCATTER", "Near me", "incident report", "geolocation", "verification mark" and "SITREP staff" have the meanings given in the SITREP Terms of Service (artorias.com/legal/sitrep/terms).
Questions, requests or complaints about privacy: hello@artorias.com (subject "Privacy request"), or write to us at the address above.
02Summary
- What we collect: your sign-in details, your plan and purchases, how you use SITREP, device and log data (including IP addresses), and, if you use them, what you create in the Community features, your Near me area, and your SITREP Academy progress.
- Location: Near me is off unless you turn it on. For Near me, SITREP's servers never receive your exact location: your device sends us only a rough area, about 5 km across, or about 20 by 40 km if you choose a wider area. If you allow location access, the map software from our map provider, Mapbox, may also receive location data from your device (section 3.8). The place you pin on an incident report is different: it is public, and you choose it.
- Messages are encrypted at rest but are not end-to-end encrypted. Staff see message content only in the safety and legal cases described in section 3.6.
- Images have all metadata (including GPS location) removed before anyone else sees them.
- Anonymity: handles and SCATTER hide your identity from other users, not from us.
- No sale, no ads: we do not sell your personal information or share it for targeted advertising.
- No AI reads your Community Content, messages, images or location.
- Your rights: you can see, correct, download and delete your data, as described in section 11.
- Age: SITREP is for people aged 18 and over.
03What we collect
3.1 Account and sign-in
When you create an account, our sign-in provider (Clerk) collects your name, email address and password, and gives your account a sign-in ID. We never see your password. Artorias uses the same sign-in for SITREP Academy and for some other Artorias services. It also tells us whether you have turned on two-step verification (we check this for verification marks, section 3.13). The SITREP database stores your sign-in ID, not your email address.
3.2 Plans and payments
- Web purchases are processed by Stripe. Stripe collects and stores your card details and billing address; we do not store your full card number. We receive records of your plan, payments and subscription status.
- App Store and Google Play purchases are processed by Apple or Google. We use RevenueCat to receive and manage your purchase and subscription records. We do not receive your card details.
- We keep records of your plan, entitlements, credits (if your plan has them) and purchase history.
3.3 How you use SITREP
- The SITREP alerts and reports you open, when you open them, and the IP address you used at the time.
- Your settings, the topics and areas you choose to watch, saved searches, bookmarks and favorites, and notification settings.
- The searches you run in SITREP, which we use to return your results.
- Product analytics events. When you use the app we record the kind of action (for example "opened a channel") and a result code, linked to your account. These events never contain your handle, what you wrote, post or message IDs, or your location.
- Artificial intelligence features. If you use AI features (for example Harmonia, where available on your plan), we keep the questions you ask, the answers, and any profile text you give the feature, until you delete them or your account. To produce answers, we send your question and the related SITREP Reporting to Google Cloud Vertex AI.
3.4 Device and log data
- Device and browser type, operating system, app version, language and time zone.
- IP addresses, with the time and the address of each request, in our server and load balancer logs.
- A push notification token, if you allow push notifications. We use OneSignal to send SITREP alert notifications. Community activity never sends a push notification.
- Error and crash reports, sent to our error-monitoring provider (Sentry) with your account ID. The contents of requests to Community and Near me features are left out of error reports.
- Deep link data: if you open SITREP from a link, our deep-link provider (Branch) tells the app which link you used. If you arrive through a partner or affiliate link, our affiliate provider (Insert Affiliate) records that link with any resulting purchase so that the partner can be credited.
3.5 Your profile, handles and SCATTER
- Your handle (a username you choose, or a random hash handle we generate, which is never derived from your name, email, device or sign-in ID), bio, up to two profile links, avatar choice and privacy settings (who can message or mention you, read receipts, and whether your badges and marks show), and your follows, blocks and mutes.
- Handle history. When you change your handle or SCATTER, other users see no link between your old and new handles. We keep the history of handles your account has held, linked to your account, so that restrictions follow the account. Only a small number of named SITREP staff can look up handle history. Each lookup needs a recorded reason and is logged. We disclose handle history outside SITREP only under our Law Enforcement Guidelines.
- Retired handles are never given to anyone else. To make sure of that, we keep a list of retired handle names with no link to any account and no date, even after you delete your account.
3.6 What you create in the Community features
- Posts, replies, edits (with their history), reactions, mentions, channel posts, context notes, geolocation proposals and votes (including the point, radius and reasoning), incident reports (section 3.9) and confirmations, reports you file, and appeals.
- Messages. Direct and group messages and conversation titles are encrypted at rest with keys that Artorias controls. They are not end-to-end encrypted. SITREP staff do not browse conversations. Staff see message content only:
- when a message is reported, in which case the report includes the reported message and up to 20 earlier messages in that conversation that the reporter could see, stored encrypted as evidence;
- when an automated rule holds a message (for example suspected child exploitation, or the same message sent to many conversations); or
- when we must preserve or disclose it for legal reasons.
Every staff access is logged. We run automated, rule-based checks (not artificial intelligence) on message text and links: blocked or shortened links, child-safety terms, contact details in message requests, possible live positions in group chats (you are asked to confirm before sending, and your confirmation is recorded), and repeated identical messages. We also keep conversation membership, message requests, read state (read receipts are off by default and show only when both people turn them on), and a one-way digest of message text used to detect the same message sent to many people. Community moderators never see messages.
- Your acceptance of the Terms and Community Guidelines: which version, and when.
3.7 Images
Images you upload are re-encoded on our servers, and all embedded metadata is removed (including EXIF data, GPS location, camera details, XMP, IPTC and color profiles) before anyone other than you can see them. We do not read, keep or show that metadata to anyone, including you. The original file is held only until processing finishes and is deleted automatically within 1 day at most. We keep a checksum (SHA-256) of the file uploaded to us, the processed versions (full size, thumbnail and a blurred preview), optional alt text, and a technical fingerprint of the image (a perceptual hash) used to detect duplicates and re-uploads of removed images. The picture itself can still reveal a place or a person, so please check before you post. If you attach an image, the app asks for access to your photos or camera; we receive only the images you choose to upload.
3.8 Near me (your approximate area)
Near me is off until you turn it on.
- SITREP's servers never receive your exact location for Near me. If you choose "current location", your device or browser takes one approximate reading while the app is open, turns it into a rough area (a grid square about 5 km across, or an area of about 20 by 40 km if you choose a wider area), and sends us only that area. You can instead choose a place on a map, and the device turns it into a rough area in the same way.
- Our map provider. If you allow SITREP to use your location, the map software from Mapbox that runs in the app may also receive location data from your device, as described in section 6. SITREP does not receive that data from Mapbox.
- We keep only your current area, not a history of areas. It is not shown to other users, not included in anything about you that other people see, not shown to SITREP staff, and our systems are designed to keep it out of our application logs and error reports.
- We use it only to find SITREP alerts and community incident reports near you.
- No background location. The app reads your location only while it is open, and no more often than every 10 minutes.
- Turning Near me off deletes your area at once. If you use current location and your area has not been updated from your device for 30 days, Near me pauses. No later than 120 days after your area was last updated, we clear it and turn Near me off. A place you chose on the map stays until you change it, turn Near me off or delete your account.
- The in-app records of SITREP alerts near you (kept 30 days) and of community reports near you (kept 90 days) can show roughly where your area was.
- When you use current location, your device's operating system or your browser provides the reading under its own terms (for example Apple's or Google's).
3.9 Incident reports: the pin is public
The place you pin on an incident report is public Community Content, and it is different from your Near me area.
- By default your device moves the pin by a random 150 to 400 meters before sending ("Approximate my pin"), and we never receive the original point.
- If you tap "Use my location" and turn off "Approximate my pin", the pin you send can be exactly where you are.
- We store the pin as we receive it (to 6 decimal places). Other users see it only on a coarse grid: at least 250 m, 500 m for approximate pins, and 5 km in conflict areas.
- 90 days after the event, we reduce the stored pin to a 5 km grid.
- If you delete your account, your pins are deleted.
Geolocation proposals are also stored to 6 decimal places and shown to other users on the map.
3.10 Trust and moderation data
- An internal trust level, calculated from your account age, reading activity (days you opened SITREP alerts), plan history, verification marks and past enforcement. It sets limits on what new accounts can do and is never shown to other users.
- Moderation records: rule matches, reports about your content, community and staff decisions, votes you cast as a community moderator (with their weight and any note), restrictions, appeals, and a permanent log of moderation events.
3.11 Ban evasion and fair voting
When an account is banned or suspended for 7 days or more, we store one-way digests of the identifiers of its App Store, Google Play and Stripe purchase records, so that a new account made with the same purchases inherits the restriction. We use similar digests to stop one payer's accounts from dominating community votes. We do not use your IP address, device identifiers or email address for these purposes.
3.12 SITREP Academy
SITREP Academy uses your SITREP sign-in. It stores your account ID with your course progress, quiz answers and scores, completions and certificate IDs. Your certificate shows a username, or a name you type, only if you choose. When you complete a course, the Academy tells SITREP so that your gray mark can appear.
3.13 Verification marks
For gold (government official) and blue (practitioner) marks, SITREP staff check identity outside the app, for example by reviewing official contact details or documents you choose to provide. SITREP's systems store only result codes (for example the kind of mark, a sanctions-screening result code, your visibility choice, and grant and expiry dates) and an internal reference to the check. We keep the evidence from the check only as long as needed to grant and re-confirm the mark, and we delete it when the mark ends or when you delete your account. We also read, from our sign-in provider, whether your account has two-step verification turned on, when a mark is granted and every 30 days while you hold it.
3.14 Support and correspondence
If you contact us, we keep your message, your contact details and our reply.
3.15 What we do not collect
- Your precise location for Near me: SITREP's servers receive only a rough area (section 3.8).
- The metadata of your images (section 3.7).
- Your contacts, microphone or background location.
- Information about you bought from data brokers or other third parties.
04How we use your information
We use your information to:
- create and run your account, and let you sign in;
- provide the Service, including SITREP Reporting, alerts you choose, the Community features, Near me, AI features and SITREP Academy;
- process payments and manage subscriptions and credits;
- keep users and the public safe: enforce the Terms and Community Guidelines, review reports, prevent spam, abuse and ban evasion, and keep community votes fair;
- protect the Service, find and fix errors, and prevent fraud;
- understand how SITREP is used so we can improve it;
- respond to your questions and requests, and send you service messages (for example about changes to our terms);
- meet legal obligations, including reporting child sexual exploitation and responding to valid legal process; and
- protect someone's life or safety in an emergency.
Automated decisions. Some restrictions are applied automatically by rules, without a person deciding first: for example a hold on a post, a trust limit on a new account, or a restriction carried over to a new account whose purchase records match a banned account (section 3.11). In outline, the rules compare content with fixed patterns and compare one-way digests of purchase records. You can ask for a person to review any of these decisions by appealing (see the Terms, section 8.4); SITREP staff decide appeals.
05Legal bases (users in the EU, UK and Switzerland)
| Purpose | Legal basis |
|---|---|
| Your account, SITREP Reporting, alerts, Community features, messages, channels, AI features, SITREP Academy, payments | Performance of our contract with you |
| Safety, enforcing the Terms and Community Guidelines, preventing abuse and ban evasion, fair community voting, security, fixing errors, understanding and improving the Service | Our legitimate interests in a safe, secure and working service for users and the public |
| Verification marks | Our legitimate interests in accurate marks; your choice to apply, and your choice whether a gold mark is shown |
| Near me | Your consent, given when you turn Near me on and allow location access. You can withdraw it at any time by turning Near me off |
| Child-safety reporting and preservation, responding to valid legal process, and other legal duties | Legal obligation (for duties outside the EU or UK, our legitimate interests in complying with them) |
| Protecting someone's life or safety in an emergency | Vital interests |
If you post something that reveals sensitive information about you (for example your political opinions), you have chosen to make it public in the Community features.
06Who can see your information, and who we share it with
- Other users see your public profile, posts, public channel posts, geolocations, incident reports (with the coarse pin), badges and visible marks. Members of a conversation or private channel see what is posted there. Nobody else sees your Near me area, trust level, handle history, the reports you filed, or who you blocked.
- Community moderators (eligible members on Plus or above) see reported public posts and the author's public handle only. They never see messages, private channels, who reported something, handle history, or content held for OPSEC, doxxing, child-safety, terrorism, violent-threat or graphic reasons.
- Channel moderators see reports on posts in their channel (the reason, never who reported).
- SITREP staff see what they need to review reports and enforce the rules, through tools that log their actions.
- Service providers that process data for us under contract, only to provide their service to us:
- Amazon Web Services (hosting and storage, United States);
- Clerk (sign-in; the same sign-in is used for SITREP Academy and some other Artorias services);
- Stripe (web payments); RevenueCat, Apple and Google (app store purchases);
- OneSignal (push notifications for SITREP alerts);
- Resend (email delivery, for emails you choose to receive and service emails);
- Sentry (error monitoring);
- Mapbox (maps; when a map loads, Mapbox's map software may receive technical and usage data from your device, such as your IP address and the map area on screen, and, if you allow SITREP to use your location, location data from your device);
- Google Cloud Vertex AI (answers for AI features you use);
- Vercel (SITREP Academy and some web pages, including the Academy's database);
- Branch (deep links) and Insert Affiliate (partner and affiliate links).
- The National Center for Missing & Exploited Children (NCMEC). US law requires us to report apparent child sexual exploitation to NCMEC's CyberTipline, including the content and information about the account involved. NCMEC may share reports with law enforcement in the US and other countries.
- Law enforcement and other authorities, only as set out in our Law Enforcement Guidelines (artorias.com/legal/sitrep/law-enforcement): in response to valid legal process, in an emergency involving a risk of death or serious injury, or to report information about a threat to life or safety where the law requires.
- In a business transfer (a merger, acquisition, financing, or sale of all or part of our business), subject to this policy.
We do not sell your personal information, and we do not share it for cross-context behavioral (targeted) advertising. Community Content, messages and location are never used for advertising.
07Artificial intelligence
- No artificial intelligence reads your posts, images, messages, incident reports or location. If we ever change this, we will update this policy first.
- Community Content never goes into SITREP Reporting, alerts, briefings, search of SITREP Reporting, AI features or exports.
- SITREP Reporting itself is produced with the help of automated systems, including artificial intelligence.
- AI features you choose to use work as described in section 3.3.
08How long we keep your information
We keep information for the periods below. When a period ends we delete the information, or remove anything that identifies you. "Legal hold" means we may keep specific information longer when we need to comply with the law, respond to legal process or a preservation request, or investigate serious harm.
| Information | How long we keep it | What happens then |
|---|---|---|
| Sign-in record (name, email address, password) | While your account exists | Deleted when you delete your account |
| Settings, watched topics and areas, saved searches, bookmarks, favorites | While your account exists | Deleted with your account |
| Records of the alerts you open, including the IP address at the time | While your account exists | Deleted with your account |
| Searches you run | As long as needed to return your results, and in server logs for the period below | Deleted |
| Plan, purchase and credit records | While your account exists, and afterwards as long as needed for tax, accounting and legal purposes | Identity removed where the law allows |
| AI feature questions, answers and profile text | Until you delete them or your account | Deleted |
| Product analytics events | As long as needed to understand and improve how SITREP is used | Deleted, or kept only as totals that do not identify you |
| Server and load balancer logs (including IP addresses) | As long as needed for security, troubleshooting and abuse prevention | Deleted |
| Error reports | As long as needed to fix the problem, within our error-monitoring provider's retention limits | Deleted |
| Push notification token | While notifications are allowed on your device | Stops being used when you turn notifications off or delete your account |
| Support correspondence | As long as needed to handle your request and keep a record of it | Deleted |
| Profile, current handle, privacy settings, follows, blocks, mutes | While your account exists | Deleted with your account |
| Handle history (linked to your account) | While your account exists | Deleted with your account |
| Retired handle names (no account link, no date) | Indefinitely | Never reassigned |
| Posts, replies, channel posts, context notes | Until you delete them or your account | Deleted by you: text removed within 30 days, except where we must keep it to enforce our Terms or comply with law: up to 180 days, or 1 year for safety cases. Removed by staff: kept 180 days for appeals and evidence, then text removed. Account deleted: text removed and a "Deleted account" stub kept so replies still make sense |
| Post edit history | With the post | Deleted with the post |
| Messages | 365 days from sending | Deleted with their images |
| Empty conversations | 30 days after the last member leaves | Deleted |
| Reported-message evidence | Until 90 days after the case closes | Deleted; child-safety cases: see below |
| Images | While attached to live content | Uploads never attached: 24 hours. Original file: within 1 day of upload. Images of deleted content: 30 days, except where we must keep them to enforce our Terms or comply with law: up to 180 days, or 1 year for safety cases. Images removed by staff: 180 days |
| Geolocation proposals and votes | With the content they relate to | Account deleted: your name and reasoning removed; confirmed points stay on the map without attribution; held proposals deleted |
| Incident reports | While live | Pin reduced to a 5 km grid 90 days after the event; deleted when you delete your account |
| Near me area | Your current area only, while Near me is on | Deleted when you turn Near me off or delete your account. Current-location areas: Near me pauses after 30 days without an update, and the area is cleared no later than 120 days after the last update |
| In-app records of SITREP alerts near you | 30 days | Deleted |
| In-app notifications (including community reports near you, replies, mentions and moderation outcomes) | 90 days | Deleted |
| Reactions, follows, mentions | While your account exists (mentions: with the post) | Deleted with your account or the post |
| Payment digests used to keep community votes fair | While your account exists | Deleted with your account |
| Reports you file, moderation votes and ratings | As a record of moderation decisions, while the related case record exists | Account deleted: your identity replaced with a code, free text removed, reason codes kept |
| Moderation cases and the moderation event log | Kept as a permanent record of moderation decisions | Account deleted: appeal statements you wrote removed; the event log uses a code that cannot be linked back to you |
| Restrictions and bans | While in force, and afterwards as a record | Account deleted: your identity replaced with a code |
| Ban-evasion digests (section 3.11) | While the restriction lasts, plus 12 months, even if the account is deleted | Deleted |
| Verification records | While the mark is active; expired marks are recorded as expired | Account deleted: your identity replaced with a code; check evidence deleted (section 3.13) |
| SITREP Academy progress and certificates | While your account exists | Deleted when you delete your account |
| Terms and Guidelines acceptance | As a record of acceptance | Account deleted: your identity replaced with a code |
| Staff action logs | As a security record | References to your account replaced with a code when you delete your account |
| Child-safety evidence and CyberTipline records | At least 1 year from the report, and longer if the law requires or law enforcement asks us to preserve it | Deleted when the hold ends |
Deleted data can remain in backups for a limited time until they are overwritten.
09Security
Data is encrypted in transit. Messages, conversation titles and report evidence are encrypted at rest in the application. Images are stored in a private storage bucket and served only through links that expire after 60 seconds, after an access check. The most sensitive staff tools (handle history, the list of government mark holders, and child-safety material) are limited to named staff, and staff moderation actions are logged. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10Children
SITREP is for people aged 18 and over. We do not knowingly collect personal information from anyone under 18. If we learn that a person under 18 has an account, we close it and delete its personal information, except what the law requires us to keep (for example child-safety evidence). If you believe a child is using SITREP, tell us at hello@artorias.com.
11Your choices and rights
11.1 Choices in the app
- Hide your badges and marks, stop being findable by username, limit who can mention or message you, turn read receipts on or off, and block and mute.
- SCATTER your hash handle (limits apply).
- Delete posts, and delete messages (for everyone within 60 minutes of sending; after that, only for you).
- Turn off Near me, which deletes your area at once. You can also withdraw location permission in your device settings.
- Turn off push notifications in your device settings.
11.2 Deleting your account
You can delete your account in the app's account settings ("Delete account"), or by emailing hello@artorias.com from the email address linked to your account. When you delete your account:
- your sign-in record, profile, handles and handle history, follows, blocks, mutes, badges, channel memberships, Near me area, settings, watched topics and areas, bookmarks, favorites, records of alerts you opened, AI feature history and SITREP Academy records are deleted;
- deleting your account deletes your sign-in, which also ends your access to SITREP Academy and to any other Artorias service that uses the same sign-in;
- your posts, messages and context notes become "Deleted account" stubs with their text removed, so replies still make sense; your incident pins are deleted; your images are deleted from storage;
- reports and votes you made keep only their reason codes; confirmed geolocations stay on the map without your name;
- channels you own pass to one of the channel's moderators or, if there is none, are archived;
- verification records are kept with your identity replaced by a code, and the evidence from the identity check is deleted; and
- some records are kept as described in section 8: content under legal hold (including child-safety evidence), evidence for open cases, ban-evasion digests, the unlinked list of retired handles, moderation logs that use a code not linked to you, and records we must keep for tax and accounting.
Subscriptions. Deleting your account does not cancel an App Store or Google Play subscription. Cancel it in your store account first. If you have a web subscription, cancel it first or ask us at hello@artorias.com and we will cancel it. We keep payment records in Stripe and RevenueCat as long as needed for tax and accounting (section 8). Apple and Google keep their own billing records under their own policies.
11.3 Access, correction, copies and other requests
Email hello@artorias.com with the subject "Privacy request". You can ask to know what we hold, get a copy (including your Community Content and messages), correct it, delete it, or object to or restrict how we use it. There is no self-service download yet: we will confirm the request with you from inside your signed-in SITREP account or from the email address linked to it, and staff will compile your data. We reply within 45 days (California and other US states, extendable where the law allows) or within one month (EU, UK and Switzerland, extendable by two months for complex requests).
You can use an authorized agent where the law allows. We will ask for proof that the agent is authorized and may need to confirm your identity directly.
We will not discriminate against you for exercising your rights.
11.4 If we say no
If we decline your request, we will tell you why. Where US state law gives you a right to appeal, reply to our decision with the subject "Privacy appeal", and we will answer in writing. If your appeal is denied, you may contact your state attorney general.
11.5 Complaints to a regulator
- EU, EEA and UK: you may complain to your data protection authority (in the UK, the Information Commissioner's Office).
- Switzerland: the Federal Data Protection and Information Commissioner.
- Canada: the Office of the Privacy Commissioner of Canada.
- Australia and New Zealand: the Office of the Australian Information Commissioner, or the Office of the Privacy Commissioner of New Zealand.
- South Africa: the Information Regulator (enquiries@inforegulator.org.za).
We would like the chance to help first, so please contact us at hello@artorias.com.
12Information for US residents
Depending on your state, you may have the right to know what personal information we hold and how we use it, to get a copy, to correct it, to delete it, and to opt out of its sale, of targeted advertising, and of profiling that has legal or similarly significant effects. We do not sell personal information, we do not use it for targeted advertising, and we do not carry out that kind of profiling. You can exercise your rights as described in section 11.
Categories of personal information we collect (with the sources and uses described in sections 3 and 4, and the periods in section 8):
| Category | Collected | Examples |
|---|---|---|
| Identifiers | Yes | Name, email address, sign-in ID, handles, IP address, push token |
| Customer records (California Civil Code 1798.80) | Yes | Name, email address; card details are held by Stripe |
| Protected classification characteristics | No | We ask only that you confirm you are 18 or older |
| Commercial information | Yes | Plans, purchases, subscriptions, credits |
| Biometric information | No | |
| Internet or other electronic network activity | Yes | Alerts opened, searches, product analytics events, logs, error reports |
| Geolocation data | Yes | Your Near me area (about 5 km across, or about 20 by 40 km); incident report pins and geolocation proposals you choose to post, which can be precise; areas you choose to watch; location data our map provider's software may receive from your device (section 3.8) |
| Audio, electronic or visual information | Yes | Images you upload |
| Professional or employment information | Yes, only for verification marks | Your official role or practitioner status |
| Education information | No | |
| Inferences | Yes | Your internal trust level |
| Sensitive personal information | Yes | The contents of your messages; incident pins placed with "Use my location" (approximate or not) or sent without "Approximate my pin", which can be your precise location; your account log-in (email address and password, held by our sign-in provider); documents you choose to provide for a verification mark |
We use sensitive personal information only to provide the Service you asked for, for safety, security and integrity, and to meet legal duties. We do not use it to infer characteristics about you.
Disclosures. We disclose each category above to service providers and, where section 6 applies, to NCMEC, authorities and other users, for the purposes in section 4. We have not sold personal information or shared it for targeted advertising in the last 12 months, and we do not do so.
Shine the Light. California residents may ask once a year, free of charge, for information about personal information we disclosed to third parties for their direct marketing in the previous year. We do not make such disclosures.
Do Not Track. There is no agreed standard for browser "Do Not Track" signals, so we do not respond to them. We do not track you across other companies' websites or apps for advertising.
13International users
SITREP is operated from the United States. We collect your information directly from you and store and process it in the United States (Amazon Web Services, US East region). Some of our service providers may process it in other countries, under contracts that require them to protect it. For personal information from the European Economic Area, the United Kingdom or Switzerland, those contracts include the European Commission's standard contractual clauses (with the UK and Swiss addenda), unless the provider is certified under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. You can ask us about these safeguards at hello@artorias.com. By using SITREP from outside the United States, you understand that your information will be processed in the United States, where data protection law may differ from the law where you live.
14Changes to this policy
We will tell you in the app before material changes to this policy take effect. The version and effective date are shown at the top.
Version history
- 2.1 (27 September 2026): section 8 now says that posts and images you delete are removed within 30 days, except where we must keep them to enforce our Terms or comply with law: up to 180 days, or 1 year for safety cases.
- 2.0 (1 October 2026): replaces the SITREP Privacy Notice last updated 1 March 2025.
15Contact
Artorias, Inc., 169 Madison Ave, Suite 11590, New York, NY 10016, United States. Email: hello@artorias.com (subject "Privacy request").