PRIVACY IN THE LAB

Share less.
Stay in control.

Current implementation · 20 September 2026

This is a publicly accessible research preview. No sign-in is required to browse. Use fictional data in forms. A public operator, contact address and launch privacy policy have not yet been established.

What the form stores

Your contribution type, destination, optional passport category, purpose, optional year, selected experience events, contribution text, optional source link, optional display name, consent choices and optional email. No real name, passport number, exact travel date, medical document or file upload is required. Avoid including identifying details in free text.

How reports are handled

Private report details and email are encrypted in the application database. Authorised moderators can decrypt them for review. The hosting provider processes the site and may retain access logs and backups. No system can promise absolute anonymity or freedom from legally required disclosure.

Publication needs separate optional consent and moderator approval. An edited contribution, its type, destination, optional year, purpose, selected experience events, chosen display name (or Anonymous), and an optional moderator-reviewed source link may be published. A display name can identify you: leave it blank or use a pseudonym if you prefer. Email and the passport selection are excluded from the public API. Distinctive stories may still identify people; do not include details you would be uncomfortable making public.

Retention and removal

Private details and email expire after 90 days. Reports expire after one year. The application purges expired data when its report service is next accessed. Your withdrawal code removes the report and its published version from the active database immediately. Technical backups and copies others made may remain.

We store a hash of the withdrawal code and cannot recover the original. Keep it somewhere private. Remove a report.

Email and payments

Email is optional and only for clarifying your report, with consent. No newsletter or automated follow-up is currently sent. A future update subscription would need its own clear consent and unsubscribe flow.

Payments go through Stripe in test mode in this Lab. No card details are handled by the report database. We do not attach health information, report IDs, passport selections or stories to Stripe transactions.

Browser and external services

No advertising analytics have been added. Public pages do not require authentication. The contribution record does not store an account ID. The hosting provider may retain technical access logs; moderation uses a separate authenticated route. “Anonymous” describes the public author label, not guaranteed untraceability. The contribution form requires no account. The resources page loads an image from Unsplash, whose server receives a network request. External source links and Stripe have their own privacy practices. We set links to omit referral information.

Before accepting real contributions

Identify the operator and privacy contact; confirm the applicable legal basis and sensitive-data safeguards, hosting/backup retention and international transfers; assign moderators and test access; publish support/refund terms; and review this policy for the actual service. This preview is not presented as a finished clinical service.