Privacy Policy

Last updated:

mutualaidspace.org is a public mutual aid discovery and amplification platform. This Privacy Policy describes what information may be collected or processed when you visit the website, leave comments, upload media, use an account, submit a community mutual aid request, or interact with services used to operate and protect the website.

The website address is https://mutualaidspace.org/. The Terms of Use are available at https://mutualaidspace.org/tou, and rules specifically governing community submissions are available at https://mutualaidspace.org/community-submission-policy/.

1. Community submissions and public information

When you submit a mutual aid request through https://mutualaidspace.org/submit-a-campaign/, you provide information for public amplification. Depending on what you choose to submit, this may include a chosen name or alias, the content of your request, crowdfunding links, payment handles, images, financial goals, deadlines, organising or recruitment information, original social-media links, and other information you include in the submission.

Community submissions are intended for public circulation. Information included in the published request may appear on mutualaidspace.org, federate through ActivityPub and the Fediverse, circulate through project or community accounts, appear under public hashtags, be indexed by search engines, be included in feeds, newsletters or roundups, and be copied or redistributed by other people and services. Only include information in the public portion of a submission that you are comfortable making public.

Community submissions remain published on mutualaidspace.org for seven days (one week) unless removed earlier by the administrator in accordance with the Community Submission Policy. Removal from mutualaidspace.org does not guarantee deletion of copies already received, cached, indexed, archived, screenshotted, downloaded, included in newsletters, or otherwise reproduced by independent third parties.

2. Administrative information submitted with a request

The community submission form may collect an email address for administrative purposes in addition to the information intended for public publication. An email address entered into an administrative field is not part of the public request unless you separately choose to include that address in the content intended for publication.

Administrative contact information may be used for communications directly related to the submission, including publication or removal notices and other necessary administrative messages. Providing an administrative email address does not subscribe you to a newsletter, create general promotional consent, or authorise mutualaidspace.org to publish that address, and it is not retained as a general contact record after it is no longer required for the submission and its administrative handling.

3. ActivityPub and federated distribution

mutualaidspace.org uses ActivityPub and the Fediverse as part of its publishing and amplification infrastructure. When public material is federated, the content and technical information necessary to transmit it may be sent to independently operated servers with their own administrators, software, moderation practices, retention systems, and privacy policies.

mutualaidspace.org does not control how an independent server stores, displays, copies, or processes information after receiving it through federation. Where the relevant software supports deletion activities, mutualaidspace.org may send a deletion request when material is removed from the originating site, but there is no guarantee that every receiving server will process that request or erase every copy it has previously received.

4. Comments, Gravatar, and spam detection

When visitors leave comments on mutualaidspace.org, the website collects the information shown in the comment form together with the visitor’s IP address and browser user-agent string to assist with spam detection. Visitor comments may also be checked through an automated spam-detection service, and comments together with their associated metadata may be retained indefinitely so that WordPress can recognise and automatically approve follow-up comments instead of placing every subsequent comment into a moderation queue.

An anonymised string created from the email address supplied with a comment, also called a hash, may be provided to the Gravatar service to determine whether you use it. After a comment is approved, a Gravatar profile image associated with that address may become publicly visible in the context of the comment. Gravatar is operated by Automattic, whose privacy policy is available at https://automattic.com/privacy/.

5. Uploaded media

If you upload images to mutualaidspace.org, you should avoid uploading files containing embedded location information such as EXIF GPS data unless you deliberately intend that information to remain attached to the file. Visitors may be able to download publicly available images and extract metadata contained within them, so removing visible location information from the image itself does not necessarily remove location information embedded in the underlying file.

The same principle applies to other metadata that may be stored inside an uploaded file. Before submitting media for public publication, check whether the file contains information that you do not want other people to access.

6. Cookies and WordPress accounts

If you leave a comment, you may choose to save your name, email address, and website in cookies for convenience so that you do not need to enter them again when leaving another comment. These cookies may remain for one year.

If you visit the WordPress login page, a temporary cookie may be set to determine whether your browser accepts cookies; it contains no personal data and is discarded when the browser is closed. When an authorised user logs in, WordPress also sets cookies to save login information and screen-display preferences. Login cookies normally last for two days, screen-options cookies may last for one year, selecting Remember Me may keep the login active for two weeks, and logging out removes the login cookies.

If an authorised user edits or publishes an article, WordPress may save an additional cookie indicating the post ID of the article that was edited. This cookie contains no personal data and expires after one day.

For registered users, if any, WordPress stores the personal information supplied in the user profile. Users can generally view, edit, or delete their profile information at any time except for the username, while website administrators can also view and edit that information where necessary for website administration. If a password reset is requested, the requesting IP address may be included in the password-reset email.

7. hCaptcha

mutualaidspace.org uses hCaptcha, a security service provided by Intuition Machines, Inc. (IMI), to help determine whether actions performed on the website, including form submissions or login attempts, are being performed by a human rather than by an automated system associated with spam, fraud, abusive crawling, or other misuse. Where hCaptcha is enabled, its analysis may begin automatically when you enter that part of the website and may occur in the background without displaying a visible challenge.

hCaptcha may evaluate information including your IP address, how long you remain on the website, mouse movements, and other behavioural or technical characteristics associated with the interaction. Information collected during this analysis is forwarded to IMI. IMI describes itself as a data processor acting on behalf of its customers for GDPR purposes and as a service provider for purposes of the California Consumer Privacy Act.

Where the GDPR applies, hCaptcha states that processing may be based on Article 6(1)(b), where processing is necessary for the performance of a contract or to take steps at a visitor’s request before entering into one, and Article 6(1)(f), based on a legitimate interest in protecting the service from spam, fraud, automated abuse, and harmful crawling. hCaptcha’s privacy policy is available at https://www.hcaptcha.com/privacy and its terms of use are available at https://www.hcaptcha.com/terms.

8. Caching and QUIC.cloud

mutualaidspace.org uses LiteSpeed Cache to improve website response times and performance. Caching may temporarily store duplicate copies of pages displayed on the website, and those cache files expire according to schedules configured by the site administrator or may be manually purged before their scheduled expiration.

Cache files are not ordinarily accessed by third parties except where access is necessary to obtain technical support from the cache plugin vendor. LiteSpeed Cache may also use QUIC.cloud services to process and cache data temporarily, and information about QUIC.cloud’s privacy practices is available at https://quic.cloud/privacy-policy/.

9. Embedded content and external services

Pages on mutualaidspace.org may contain embedded content from other websites, including videos, images, posts, articles, or other externally hosted material. Embedded content behaves substantially as though you visited the external website directly, which means that the external provider may collect information about you, use cookies, include additional third-party tracking, and monitor your interaction with its content, including where you have an account with that provider and are already logged in.

mutualaidspace.org also links to external crowdfunding services, payment platforms, social-media profiles, Fediverse servers, community organisations, and other websites. Those services may receive information directly from your browser when you visit them and process that information according to their own privacy policies. mutualaidspace.org does not ordinarily process payments associated with community submissions and does not hold the authoritative payment, transaction, supporter, or donor records maintained by those external services.

10. Technical information, security, and data retention

The WordPress installation, hosting infrastructure, federation software, caching systems, anti-spam tools, and security services used by mutualaidspace.org may automatically process technical information necessary to serve pages, transmit federated content, identify abusive activity, troubleshoot failures, and maintain the security and availability of the website. Depending on the system involved, this may include IP addresses, browser or user-agent information, requested URLs, timestamps, server responses, federation requests, and related technical or security logs.

Technical information may be retained for the period reasonably required by the relevant system for website operation, troubleshooting, security, abuse prevention, caching, federation, or technical support. Community submissions follow the seven-day publication lifecycle described in the Community Submission Policy, while comments and their metadata may be retained indefinitely and registered-user information may remain stored while the relevant account continues to exist or while retention is otherwise required for administration.

No website, hosting provider, plugin, server, or federated network can guarantee absolute security. Security incidents may include malicious attacks, denial-of-service attacks, unauthorised access, account compromise, compromised plugins or infrastructure, data breaches, or other events affecting the confidentiality, integrity, or availability of mutualaidspace.org, and affected parts of the website may be restricted or temporarily taken offline where necessary to investigate, mitigate, or contain such an incident.

11. Information not required for mutual aid amplification

mutualaidspace.org does not generally require people seeking amplification to submit legal identification, proof of poverty, medical records, bills, photographs of hardship, or similar evidence simply to qualify for publication. A requester may use a chosen name or alias and may decide what personal information is necessary for their own public appeal.

Information deliberately included in the public submission should nevertheless be treated as public information because the purpose of the submission system is circulation and amplification. Do not submit another person’s private or sensitive information unless you have their permission to make that information public.

12. Your rights over information held by mutualaidspace.org

If you have an account on mutualaidspace.org or have left comments, you may request an exported file containing personal information held about you, including information that you provided to the website. You may also request erasure of personal information held directly by mutualaidspace.org, although this does not include information that must be retained for administrative, legal, or security purposes.

Erasure from mutualaidspace.org cannot guarantee erasure of information that has already been made public and received, indexed, cached, archived, screenshotted, downloaded, federated, or otherwise copied by independent third parties. Requests concerning a community submission are also subject to the publication and removal rules in the Community Submission Policy.

13. Privacy questions

Rules governing community submissions are available at https://mutualaidspace.org/community-submission-policy/, the submission form is available at https://mutualaidspace.org/submit-a-campaign/, and general information about the project is available at https://mutualaidspace.org/about/. These pages should be reviewed first where the question concerns submission, publication, removal, or the operation of the amplification system.

If this Privacy Policy and the information above do not address your privacy query, the final contact option is to email admin@mutualaidspace.org about your query.

14. Changes to this Privacy Policy

mutualaidspace.org may update this Privacy Policy when the information processed by the website, the community submission system, federation infrastructure, WordPress configuration, security or caching systems, or third-party services materially change. The date at the top of this page identifies the current version.