What this site does with data — described precisely rather than reassuringly, including the one thing it does that is not nothing.
This page is published in English. The English text is the authoritative version.
This notice does not say "we collect no data whatsoever". That sentence would be false, and this archive does not write sentences like that. What follows is the precise version, written so that a technically minded reader can check each statement against what the site actually loads.
Like every web server, the hosting platform receives and logs the technical details of each request: IP address, time, page requested, response status and the user-agent string the browser sends. This is unavoidable in the operation of any website.
Those logs are the hosting provider's own. They are generated by its platform, for its purposes of delivering traffic and protecting its network against abuse, and are held under its own privacy policy and retention rules. The publisher of this archive does not receive them, access them, export them or analyse them. The hosting provider is Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, United States; its privacy terms are published on its own site.
This site runs Vercel Web Analytics. Precisely what that means here:
/_vercel/insights/script.js on stmichel.org, with no offsite redirect. No
third-party domain is contacted and no third-party request is made. The site's
Content-Security-Policy remains script-src 'self' and
connect-src 'self': the measurement beacon posts back to this origin and
nowhere else.Purpose and legal basis. The purpose is to know how much this archive is read and from which countries, so that translation and coverage decisions rest on evidence rather than guesswork. The basis is legitimate interests, Article 6(1)(f) GDPR: the processing is limited to what produces an aggregate count, no profile is built, no cross-site tracking occurs, nothing is shared with a third party, and no reader is identified to the publisher.
Why there is no consent banner for it. Article 5(3) of the ePrivacy Directive (2002/58/EC as amended by 2009/136/EC), and § 25 TDDDG in Germany (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, in force 14 May 2024, replacing the TTDSG), require consent for storing information on a user's device or gaining access to information stored there. This measurement stores nothing on your device, so the storage limb is not engaged. On the substance, the configuration matches the conditions the French supervisory authority sets out for consent-exempt audience measurement in délibération n° 2020-092 of 17 September 2020: a purpose strictly limited to measuring this site's own audience, for this publisher's exclusive account, producing aggregate statistics only, with no tracking of a person across other sites or applications, and with the practice disclosed here.
Consent-free operation of cookieless analytics is a reasoned judgement, not a settled certainty. The EDPB's Guidelines 2/2023 on the technical scope of Article 5(3) read the "gaining access to information stored in terminal equipment" limb broadly, and German authorities apply § 25 TDDDG strictly. A supervisory authority could take the view that consent is required. The position taken here rests on there being no storage on the device, no identifier, no cross-site tracking and an aggregate-only output — and it depends on the host's configuration continuing to behave as described, which the publisher verifies but does not itself control.
When you choose a language, the site writes a single entry to your browser's
localStorage: the key lang, with the value en,
fr, es or it. That is the entire contents. It stays
on your device, is never transmitted to any server, contains no identifier and is not used
to recognise you. It is the only thing this site writes to your device.
Storing a user-interface preference such as language choice is the standard example of the "strictly necessary" exemption to Article 5(3) — see Article 29 Working Party Opinion 04/2012 on the cookie consent exemption (WP 194), category "user-interface customisation". The EDPB's Guidelines 2/2023 confirm that Article 5(3) applies to local storage and not only to cookies. Delete the value at any time through your browser's site-data settings; the site falls back to English.
Two same-origin requests are made after the page loads:
/data/sources.json (the source register) and, if you have
selected a language other than English, /assets/i18n/{fr,es,it}.json (the
translation dictionary). Both are static files served from this domain, with no identifier
attached.
/api/hello is a health check. It returns
{ok, runtime, envSeen} — whether the function ran, which Node version ran it,
and whether a configuration variable was present, never its value. It reads no request
body, sets no cookie, writes no record and stores nothing about the caller.
The archive links out to governments, security services, courts and EU bodies. Once you
follow such a link you are on their site, under their rules, and this notice no longer
applies. This site sends a Referrer-Policy of
strict-origin-when-cross-origin, so those sites are told you came from
https://stmichel.org but not which page you were reading.
There is no contact form, no mailbox, no comment field and no submission route, so there is no correspondence to process and no message from you that this site could hold. Nothing sent to any address associated with this domain is received, read or monitored.
default-src 'self'; script-src 'self'; style-src 'self'; font-src 'self'; img-src
'self' data:; connect-src 'self'; frame-ancestors 'none'; object-src 'none'; base-uri
'self'; form-action 'self'; upgrade-insecure-requests.The hosting provider is established in the United States, so delivering these pages — and producing the aggregate counts described above — necessarily routes the technical request data through a platform outside the EEA and the UK. Vercel's published Data Processing Addendum incorporates the EU Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 and, for transfers from the United Kingdom, the UK International Data Transfer Addendum.
Stated honestly: the only way to eliminate this routing is to move the site to a host established in the EEA. That has not been done. What crosses is request metadata generated by the act of loading a page — there is no account, no profile, no history and no content about you, because none is created.
The archive quotes government reviews, security-service reports and court judgments. Those documents sometimes name people — the senior officials who wrote a review, the officer who signed a report, the parties to a judgment. Publishing those names is processing of personal data, and this notice does not pretend otherwise.
The archive publishes such material for journalistic and academic purposes, relying on Article 85(2) GDPR, which requires member states to provide exemptions reconciling data protection with freedom of expression and information, and — for the United Kingdom — on the special purposes exemption in Schedule 2, Part 5 of the Data Protection Act 2018. The standing editorial rule is narrower than the exemption allows: a person is named only where a qualifying primary source names them in a public or official capacity, and only for what that source says.
Where the GDPR or the UK GDPR applies you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and objection (Art. 21), and the right to lodge a complaint with a supervisory authority (Art. 77). Those rights exist whatever this page says.
Being precise rather than reassuring about what they can reach here:
Article 13(1)(a) and (b) GDPR expect a controller to give its identity and its contact details. This notice gives neither: the publisher is anonymous and operates no contact channel. Article 12 expects a controller to facilitate the exercise of data subject rights; with no channel, this site does not. Those are real gaps, accepted deliberately for the safety reason set out in the legal notice, and no wording here cures them. What limits their practical effect is that the site holds nothing about readers on which those rights could bite.
Article 27 GDPR requires a controller outside the Union that targets people in the Union to designate a representative there. Article 27(2)(a) exempts processing that is occasional, involves no large-scale special-category data and is unlikely to result in a risk to people's rights. The processing described here is judged to fall inside that exemption. That is a judgement, and the addition of audience measurement — even aggregate and cookieless — makes the "occasional" limb of it a closer question than it was.
This archive documents terrorism, extremism and political violence and is written for an adult readership. It is not directed at children, and it identifies no visitor of any age.
The site is served over HTTPS with HTTP Strict Transport Security, the
Content-Security-Policy quoted above, X-Content-Type-Options: nosniff,
X-Frame-Options: DENY and a Permissions-Policy disabling camera, microphone,
geolocation, payment and USB access. There is no database, no user store and no credential
to steal, because there are no users in the technical sense — only readers.
If this site's data behaviour changes again, this notice will say so. Substantive changes are dated in the record at accuracy and corrections.
Version 2.1 — published and last reviewed 14 August 2026. Version 2.1 records the addition of aggregate, cookieless audience measurement.