All theCapitals

Privacy

What All The Capitals holds about you, why, how long, and how to get it back or get rid of it.

Last updated

You can read every page on this site without an account, and reading a page does not create a record that identifies you. Most of what follows applies from the point you sign up, post something, or trip a rate limit. One section does not: "Counting visits without following anyone" describes what happens when anybody reads a page, signed in or not, and it is the part that applies to you right now.

This notice is written to the UK and EU General Data Protection Regulation and to Nigeria's Data Protection Act 2023. Where the two differ, the stricter rule is the one we follow.

Who is responsible

All The Capitals is run by one person, Joshua, who is the controller of the personal data described here. Requests about your data reach him through the contact page, and the account tools described under your rights do most of the same work without waiting for a reply.

What we hold, and why

Your email address

Held because it is how you sign in and how we tell you when something of yours has been hidden or removed. Signing in with a one-time code, a sign-in link, a password or a passkey all use it; signing in with Google gives us the address Google releases and a subject identifier that identifies your Google account to us. The legal basis is performance of the contract you enter by opening an account.

Your display name

It is public, by design. It is shown on everything you post, and it is required before your first contribution. Choosing a name that is not your own is allowed and is the sensible default.

What you write and upload

Entries, ratings, comments, reports, corrections, seat suggestions and photographs, with the time you submitted them and the account that did. Everything except a report and a correction is published; a report is visible to moderators only, so that reporting something is not a public act.

Credentials

A hashed password if you set one, and the public key of any passkey you register. We never hold a password in a form that can be read back, and a passkey's private key never leaves your device.

Sessions

A record of each active session so that signing out, or having an account suspended, ends access straight away rather than whenever a cookie expires.

A hash of your IP address, for rate limits

Sign-up, sign-in and posting are capped per address so that one person cannot open two hundred accounts in an afternoon. The cap is counted against a keyed hash of the address, held with an automatic expiry, and the address itself is not stored beside it. The legal basis is our legitimate interest in keeping the site usable.

Your country, for counting visits

Described in its own section below, because it is the part people most expect to be worse than it is.

A record that a suspended account existed

If an account is deleted while it is suspended, everything about it goes except a keyed hash of the normalised email address, a keyed hash of the Google subject identifier if one was linked, and the date the suspension ends. Those hashes cannot be turned back into an address; they can only be compared against a new sign-up. They exist so that deleting an account and immediately re-registering the same address does not wipe a suspension, which is otherwise the easiest way to defeat moderation. The legal basis is our legitimate interest in enforcing the rules, and the record is deleted when the suspension ends or after 24 months, whichever comes first.

Cookies and what your browser keeps

There is no third-party script on this site. No advertising network, no analytics vendor, no social widget, no font served from someone else's domain, no consent banner, because there is nothing to consent to.

Everything this site stores in your browser is set by this site, is listed here, and is shared with nobody. Nothing below is set for a signed-out reader except the two local storage entries, which are settings you chose.

NameHow long it lastsWhat it holds
__Secure-atc.session_token30 days, or until you sign outThe session cookie: a signed reference to a row in our sessions table. It is the credential itself, so it is strictly necessary; it carries nothing about you.
__Secure-atc.session_data5 minutesA signed copy of that session and of the account fields a page shows — your display name, your email address, whether it is verified — so an ordinary page view needs no database query. If the copy is long it is split over more than one cookie of the same name.
__Secure-atc.device180 daysA signed marker that this browser has signed in to this account before, so that someone flooding your address from elsewhere cannot lock you out of your own mailbox. It holds your account identifier and the dates it was issued and expires, keyed so it cannot be forged. No address, no device fingerprint.
atc.signed_in30 days, cleared when you sign outThe character 1, and nothing else. It is deliberately readable by the page, so the header can decide whether to ask the server who you are without every page being different for every reader.
atc.state5 minutes, and only while you are signing in with GoogleA random value that ties the trip out to Google and back to the request that started it. It is spent as soon as you return.
atc.dont_rememberThe browser session, and only if a sign-in asked not to be rememberedThe fact of that request, nothing more. No form on this site offers the option today, so you should not see this one at all.
atc-themeLocal storage, until you clear itlight or dark, so the page does not flash the wrong colours before it loads.
atc:place-media-faceLocal storage, until you clear itphoto or map, so the next place you open shows the one you last chose.

Over plain HTTP, which happens only when the site is run on a developer's own machine, the three names beginning __Secure- lose that prefix and are atc.session_token, atc.session_data and atc.device.

None of these is an advertising or analytics identifier, none is read by anyone else, and none of them follows you to another site.

Counting visits without following anyone

We do want to know which pages are read, because that decides which places get a photograph and a description next. We do not want to know who read them.

So the counting happens in the server logs of the content delivery network, not in your browser. There is no script on the page that reports anything. For each request the log records the path and the country the network derived from the IP address, and a daily job aggregates those into counts by page, by country and by day. The IP address is not copied into any table we keep, and no row in the analytics data is about a person.

That is the whole of it. There is no cross-site identifier, no fingerprint, no profile, and nothing sold or shared with anyone.

Where your data is, and who can reach it

The site and its database run on Amazon Web Services in the Asia Pacific (Singapore) region. If you are in the United Kingdom, the European Economic Area or Nigeria, your data is therefore transferred outside your country. The transfer relies on the standard contractual clauses in the AWS data processing addendum, which AWS applies to every customer by default.

Email is sent through Amazon Simple Email Service in the same region. AWS is the only processor with access to any of this. Nobody else has a copy, and there is no analytics or marketing tool in the chain.

Moderators and administrators can see reports, and can see the account behind a piece of content when they act on it. Every action they take is logged with who did it and why.

How long things are kept

Your account and what you have posted stay until you delete the account. Deleting it removes the profile, detaches your name from your entries, which remain as the work of a deleted user, and removes your ratings.

Rate-limit counters expire automatically, within hours.

Suspension records on deleted accounts go when the suspension ends, or after 24 months at the latest.

Moderation logs are kept, because a record of why something was removed is what makes moderation reviewable. They name the moderator and the content, not the reporter.

Aggregated visit counts are kept indefinitely. They hold no personal data.

Your rights

You can do three of these yourself, at once, without asking:

See what we hold, on your account page.

Download everything as a JSON file, from export.

Delete your account, from delete.

You also have the right to have inaccurate data corrected, to restrict or object to processing that rests on our legitimate interests, and to ask for a copy in a portable form, which is what the export gives you. Ask through the contact page and we will answer within one month, as the GDPR requires, and within the timescales the Nigeria Data Protection Act sets where it applies.

One right has a limit worth stating plainly. If your account is suspended, deletion removes everything except the suspension record described above. We will not delete that record before the suspension ends, because doing so would defeat the only mechanism the site has for making a suspension mean anything.

If you want to complain

Complain to us first, through the contact page, because most things are fixable that way.

If you are not satisfied, you can complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office. In the European Economic Area it is the authority in your own country. In Nigeria it is the Nigeria Data Protection Commission.

Changes

The date at the top of this page is the date it last changed. If a change affects what we hold or why, signed-in accounts are told by email before it takes effect.