BONNER.AIRETURN HOME →

PLAIN-LANGUAGE DATA NOTE

PRIVACY

The audience signal should improve the work without turning people into an advertising profile.

WHAT THE SITE MEASURES

Bonner.AI uses first-party signals such as page route, useful link or button clicks, reading-depth milestones, article reactions, helpfulness, topic votes, and member download activity. Event labels are bounded; form values and arbitrary article text are not copied into analytics events.

WHAT THE SITE DOES NOT STORE AS ANALYTICS

Raw IP addresses are not written to the analytics tables. The server converts connection context into a one-way keyed fingerprint for deduplication and abuse prevention. The system is not designed for cross-site advertising or sale of audience profiles.

MAGIC-LINK ACCOUNTS AND SESSIONS

Requesting a secure member or admin magic link is an account action: the current sign-in request is allowed to create an account for that email if one does not already exist. Joining the Field Letter waitlist alone does not create member access. After a magic-link callback, access and refresh tokens are kept only in page memory, not local storage; the URL fragment is cleared, and a reload requires a new sign-in link. This is not an HttpOnly server-session architecture.

MEMBERS, COMMENTS, AND DOWNLOADS

Protected comments and downloads are checked by the server, not unlocked by a browser flag. Submitted comments start pending. If approved, the chosen display name, comment body, and date are publicly readable on the article; do not submit anything you want kept private. Download and access events are recorded so Bonner can understand which released field tools are useful. Member media is shown only when its published access record is available.

QUIZ AND AUDIENCE SIGNALS

The Open Knowledge quiz is scored in the browser. Individual answers are not submitted. Only the resulting lane is sent as a bounded event used for aggregate reporting, with the site session and one-way request fingerprint used for counting and abuse prevention. The quiz request sends no name, email, or member identifier, and the current implementation does not join the quiz lane to Field Letter or member identity.

WEEKLY FIELD LETTER AND CONSENT DATA

The Field Letter form is a waitlist and consent request, not member sign-in. It records name, email, optional phone, separate email and SMS choices, source page, timezone when available, consent-copy version, timestamps, and a one-way request fingerprint. Consent and preference changes may also be recorded as an event history. Site-generated email is designated to display bonner@bonner.ai as the sender. Text consent is separate and optional and remains held until a compliant programmable SMS rail, confirmation, and STOP controls are verified.

RETENTION AND REQUESTS

No fixed automated retention or deletion window is currently proven or enabled for all of this data. Records may remain until they are handled directly or a reviewed retention control is activated. For a privacy, access, correction, unsubscribe, or deletion request, contact bonner@bonner.ai. This local repository does not by itself prove the production backend state or completion of a request.