Privacy Policy
This page describes what actually happens when you read Sawti: what is collected, what is not, and who else can see you. It is written to be read, not signed.
Last updated:
1Who we are, and what this covers
Sawti is an independent news platform. This policy covers the public site only — the pages where you read the news. It does not cover the newsroom's editing system, which is separate and reachable only by staff.
We are based in Brussels, Belgium, with a bureau in Baghdad. Because we operate in the European Union, our handling of data is governed by the GDPR.
Before publishing: add the registered legal entity, its registration number and its official address here.
2No account, and no cookies from us
Reading Sawti requires no account. We do not ask for a name or an email address in order to read.
The public site sets no cookies of its own. No tracking cookies, no advertising cookies, no reader session cookies.
3What is kept in your own browser
Instead of cookies, the site uses three keys in your browser's storage. They stay on your device, are never sent to a third party, and you can clear them at any time from your browser settings:
- sawti:anonymous-session — a random number your browser generates, used to tell one visit apart from another when counting article reads. It carries no name, no email and nothing that identifies you, and it is linked to no account.
- sawti:viewed:… — a marker that expires when you close the tab, so one article is not counted twice.
- sawti-theme — your choice between light and dark mode.
4Measuring article reads
When you open an article, your browser sends one signal to our server carrying: the random number above, the page language, and the page you arrived from (the referrer).
On the server we do not keep those values as they arrived. We keep instead:
- A fingerprint derived from the random number and your IP address, truncated and salted with a secret key — used to avoid double-counting, and not reversible back to your address.
- A fingerprint derived from the IP address alone, the same way. The raw IP address is never stored in the database.
- The device category only: phone, tablet or desktop. The user-agent string itself is not kept.
- The referring domain only — for example "google.com" — not the full link and not what you searched for.
The purpose is one thing: so the newsroom knows which coverage is read. We do not build a profile of you from it, do not use it to target you with anything, and do not sell it.
The lawful basis is legitimate interest (Article 6(1)(f)): aggregate measurement that does not identify you, which any newsroom needs in order to know what its work reaches.
5Server logs
Like any site on the internet, our server logs incoming requests. Those logs contain the full, unhashed IP address, the page requested, the referrer and the browser type. We need them to run the site, protect it from abuse and diagnose faults.
This is the one place your full address appears, and we say so plainly because many policies leave it out.
Before publishing: state the retention period for server logs and for read events. Neither is enforced in the system today, and a retention promise nothing implements is not a promise.
6What we do not do
Stated explicitly, because the absence is the point:
- No Google Analytics and no third-party analytics platform on the public site.
- No advertising, no ad networks, no tracking pixels.
- We do not log what you search for on the site.
- Fonts are served from our own server, so your browser makes no request to Google when a page loads.
- We do not sell your data or share it for marketing, and we do not use it in automated decisions that affect you legally.
7Content embedded from other platforms
Some articles include posts from social platforms. This is where it leaves our control, and we say so clearly: when you open an article containing an embedded post, your browser connects directly to that platform's servers, which therefore receive information about you — your IP address at minimum — and may set cookies of their own.
The platforms that may appear: X (Twitter), Instagram, Facebook, TikTok, YouTube, Vimeo.
We use the privacy modes available where they exist — YouTube through youtube-nocookie.com, and Vimeo with tracking disabled — but that does not remove the connection itself. That data is governed by those companies' policies, not ours.
Some default images may also be loaded from unsplash.com.
8Contact and newsletter forms
We spell this out because the technical reality differs from what you would reasonably expect: the contact form and the newsletter signup on this site send nothing to our servers as they currently stand. What you type into them is neither stored nor received by us.
To reach us for real, write to contact@sawti-eu.info. Your message is then ordinary email, kept for as long as answering you requires.
Before publishing: both forms appear to work, and the contact form says "we will get back to you shortly". Either wire them to the server or remove them. Leaving them as they are while this paragraph exists is a visible contradiction.
9Who can reach the data
Aggregate readership data is seen by editorial staff, for one purpose: knowing what is read.
The infrastructure providers we host on process data on our behalf and on our instructions alone.
Before publishing: name the hosting and infrastructure providers and the country of storage, and note any transfer outside the EU and its lawful basis.
10Your rights
Under the GDPR you have the right to access your data, correct it, erase it, restrict or object to its processing, and port it.
But we owe you honesty about what we can actually do: what we hold about article reads are salted fingerprints we cannot reverse to a person. Which means we cannot find "your data" in order to show it to you or delete it — because we hold nothing that ties it to you. That is a limit on our ability, not a way around your right.
What you can do yourself, immediately: clearing the three storage keys from your browser settings breaks any continuity in the counting.
For any request or question: contact@sawti-eu.info.
Before publishing: if a data protection officer is appointed, add their details. Add the right to lodge a complaint with the competent supervisory authority — in Belgium, the Data Protection Authority (Autorité de protection des données).
11Children
The site is aimed at readers generally rather than at children, and since we ask no identifying details of anyone, we knowingly collect nothing about any person whatever their age.
12Changes to this policy
If how we work changes — by enabling third-party analytics, say, or adding a real newsletter subscription — this page is updated before the change rather than after it, and the date above changes with it.
