Privacy foundation
Contribution stays under your control.
This preview describes product commitments and the staged beta-signup collector. It is not a final production legal policy.
Beta signup
The staged collector accepts the email, region, platform and product interests, optional role, consent choice, privacy-notice version, submission time, and source campaign shown in the beta form. It uses MariaDB only for beta-signup contact preferences and consent evidence.
It does not collect incidents, Watch Zones, Radar data, Scanner or Sentinel telemetry, GNSS or location data, raw IP addresses, User-Agent strings, cookies, advertising IDs, or full request bodies. Failed submissions are not saved to browser local storage.
Website analytics
Analytics is disabled in local development, tests, and ordinary builds. A production build can load the exact owner-approved vironsignal.com Plausible snippet only when the production environment and analytics enable flag are both set. No Plausible site identifier or script URL is stored in this repository.
When enabled, the site records page views plus these named interactions: beta CTA click, first beta-form interaction, validated new signup, validated existing-signup update, coarse signup validation/network errors, privacy-notice view, and source-network/methodology view. It does not use automatic form-submit tracking as the signup conversion.
VIRON Signal sends no email, region, role, consent value, form value, request ID, database ID, precise location, IP-derived property, response body, or stack detail as an analytics event or property. Error events contain only one coarse category: validation, network, rate_limited, server_unavailable, or unexpected_response. The site does not persist analytics payloads or failed signup data.
The browser connection to the selected analytics service necessarily exposes ordinary network and browser request metadata to that service. The exact owner-supplied snippet, account settings, processing terms, retention, geographic processing, and jurisdiction-specific consent requirements must be reviewed before enablement. This preview does not claim that analytics is exempt from consent in every jurisdiction.
Owner decisions required before production collection
- OWNER_REVIEW_REQUIRED — Controller identity: exact legal identity has not been approved.
- OWNER_REVIEW_REQUIRED — Controller contact: exact privacy contact has not been approved.
- OWNER_REVIEW_REQUIRED — Retention duration: no final signup retention period has been approved.
- OWNER_REVIEW_REQUIRED — Processor wording: final hosting/processor and geographic-processing wording has not been approved.
- OWNER_REVIEW_REQUIRED — Deletion contact: the exact correction/deletion request channel has not been approved.
The beta-signup endpoint is not production-ready and must not collect public submissions until every OWNER_REVIEW_REQUIRED item is resolved and operational deletion, export, backup, restore, access-control, and breach-response procedures are approved.
Location
Features request only the location access they need. Watch Zones, Scanner telemetry, and account identity are separated. Public device positions are quantized or aggregated.
Scanner
Analysis defaults to local-only. Upload is opt-in and uses rotating pseudonymous identifiers, time windows, capability flags, aggregated metrics, and a coarse privacy cell—not advertising IDs, contacts, or unnecessary route history.
Community reports
Reports remain private and unverified until moderation or correlation thresholds are met. Approximate location is the default, and media metadata must be stripped before publication.
Your controls
Retention, consent revocation, export, and deletion controls remain requirements before production launch.
Preview version: 2026-07-29-analytics-preview. Updated 29 July 2026.