Privacy

Privacy Policy

This page explains the basic privacy posture for Grok Archive Hub, including source tips, logs, third-party services, paid display, and cookies.

Plain-language note: do not send illegal material, private personal data, passwords, or anything requiring secure legal handling through ordinary email or web contact paths.

Information readers may provide

If you email a source tip, correction request, broken-link report, or archive question, the site may receive the information you choose to send, including your email address and message content. Grok Archive Hub does not intentionally sell user-submitted source tips.

Newsletter subscriptions

If you subscribe to the GAH newsletter, the site stores the email address you submit, whether the subscription is active or unsubscribed, the consent-version identifier, the page where you subscribed, and subscription timestamps. The subscriber record does not intentionally store your IP address. The list is used to deliver GAH newsroom updates and is not sold. Newsletter messages will provide an unsubscribe mechanism when delivery begins.

Logs and standard request data

Hosting, security, and infrastructure providers may process ordinary request data such as IP address, user agent, requested URL, timestamps, referrer, and security signals. These records may exist in server, Cloudflare, analytics, or operational logs.

Third-party services

The site may use third-party services for hosting, security, search, analytics, email, payments, and seller-file readiness. Those providers may process standard request, device, payment, or interaction data according to their own policies.

Consent choices

Essential site functions stay available without optional analytics or advertising storage. The privacy choices control lets readers accept all optional storage, reject nonessential storage, or choose analytics and advertising purposes separately. Choices are stored in first-party browser storage and can be changed from the persistent privacy choices control.

Analytics

Server-side analytics events, when configured, are limited to allowlisted operational events such as investigation views, evidence opens, PDF render status, source-link clicks, correction starts, and membership flow results. The site does not intentionally send document text, private source-tip text, full sensitive search terms, Patreon identity data, OAuth data, session tokens, passwords, or secret identifiers to analytics.

Advertising, Consent Mode, and regional requirements

Grok Archive Hub uses Google Consent Mode defaults that deny analytics storage, ad storage, ad user data, and ad personalization until a lawful choice is recorded. Ads data redaction remains enabled while ad storage is denied. Public proof pages and source-first content are not replaced by advertising.

European Economic Area (EEA), United Kingdom, and Switzerland: When personalized advertising is offered in these regions, Google requires a Google-certified consent management platform (CMP) that supports the IAB Europe Transparency and Consent Framework (TCF) v2.2 or later, including TCF v2.3. The publisher configures that certified CMP through Google AdSense Privacy & messaging. Until that publisher-side CMP is configured and live-verified, this site must not claim that a Google-certified CMP is active.

While a Google-certified CMP is not yet live, optional advertising and nonessential analytics storage remain denied by default. The first-party privacy choices control continues to manage optional storage outside competing-CMP scenarios. When Google Privacy & messaging / Funding Choices is active on a page, that certified CMP takes precedence for regulated European traffic and the first-party banner defers to it so users are not shown conflicting consent UIs.

What a certified CMP controls

When active, the certified CMP presents purposes and vendor disclosures required for TCF, records end-user choices, and signals those choices into Google Consent Mode so tags and ads respect analytics_storage, ad_storage, ad_user_data, and ad_personalization states. Users in the EEA, UK, and Switzerland can withdraw or change consent through the CMP interface and, where available, the persistent privacy controls on this site.

Legal bases and international processing (high level)

Essential security, hosting, and delivery of the public archive are processed as necessary to provide the service. Optional analytics and advertising storage, when enabled by choice, rely on consent in the EEA/UK/Switzerland. Infrastructure providers such as Cloudflare and Google may process request metadata and, where permitted, measurement or advertising signals according to their terms. Readers may contact grokcloudflare@gmail.com for privacy questions or to request correction of contact-related personal data that is not itself a public archival record.

Seller files and AdSense readiness posture

ads.txt and app-ads.txt identify the authorized Google publisher account. Display inventory, when enabled after AdSense approval, is limited by route policy: search tools, archive finding aids, raw document readers, Book of Black reader surfaces, and many sensitive source routes remain ad-free even if the page is publicly readable.

Seller files and cookies

Grok Archive Hub publishes seller-file entries such as ads.txt/app-ads.txt. If paid display services are enabled, those services may use cookies, device identifiers, or similar technologies to serve or measure ads, subject to their policies and user controls. Ads do not replace public proof or source-first content.

Source-tip limits

Contact

Questions, corrections, and privacy-related requests can be sent to grokcloudflare@gmail.com.