← RegSignal

Privacy Notice

Version 1.0 · Effective 5 October 2026

Operator details to confirm before publication: registered company name, company number, registered office address, and the privacy contact address are marked [LIKE THIS] below. See LEGAL-TODO.md in this repository.

This notice explains how RegSignal handles personal data. It is written to describe what the software actually does in its default configuration, which is deliberately minimal, and it now includes optional user accounts for alerts, watchlists and plan association — the dashboard itself is open and needs no account. RegSignal is a self-hosted dashboard for public regulatory information. It does not use analytics or advertising trackers, and it sets exactly one cookie — a strictly necessary session cookie described below. If you create an account, we hold the details set out here.

1. Who is responsible

The data controller is [COMPANY LEGAL NAME], company number [COMPANY NUMBER], registered office [REGISTERED OFFICE ADDRESS] (“we”, “us”). Privacy contact: [PRIVACY CONTACT EMAIL].

RegSignal is distributed as open-source software. If you run your own copy, you are the controller for that deployment and this notice serves as a template for the processing it performs.

2. What we process, and why

CategoryDetailLawful basis
Account and profile data Your name, email address and (optionally) your company, plus a hashed password. We never store your password itself — only a salted scrypt hash, which cannot be reversed. Performance of a contract (Art. 6(1)(b)) — providing the account you asked for
Session cookie A single first-party cookie, rs_session, is set when you sign in. It is HttpOnly, SameSite=Lax, and Secure over HTTPS. It holds an opaque random token; only its SHA-256 hash is stored server-side. It exists solely to keep you signed in. Because it is strictly necessary it is not consent-based, and there is therefore no cookie banner. Strictly necessary / performance of a contract
Transactional email We send address-verification and password-reset messages to the address on your account. Delivery is handled by the mail provider the operator has configured, which sees the recipient address and the message content. Performance of a contract; security of the account
Security and audit records Authentication events (sign-in, failed sign-in, password change, consent given) are recorded with a one-way hash of your IP address — never the raw address. These records exist to detect abuse and to evidence your consent. Legitimate interests (Art. 6(1)(f)) — account security; legal obligation for consent evidence
Consent record When you create an account we record which version of these documents you accepted, and when. Optional product emails are recorded separately and can be withdrawn at any time from your account page. Legal obligation (Art. 7(1)) — demonstrating consent; consent for marketing email
Subscription data (paid plans only) If you subscribe, payment is processed by Stripe. Card details are entered on Stripe's own hosted page and never reach our servers. We store only the resulting customer and subscription identifiers, and your plan name. Performance of a contract
No local storage, no trackers We write nothing to localStorage or sessionStorage, and load no analytics, advertising or tag-manager scripts. The cookie above is the only value we store in your browser. Not applicable
Server access logs When RegSignal is reachable on the internet, the web server in front of it (for example nginx) records each request: IP address, timestamp, requested path, user agent and response code. This is used only to operate, secure and troubleshoot the service. Legitimate interests (Art. 6(1)(f)) — service security and availability
Optional alert webhook If the operator configures WEBHOOK_URL, a summary of detected regulatory changes is POSTed to that URL. The payload contains regulatory publication data only; it contains no personal data about visitors or account holders. Legitimate interests / the operator's own configuration

2a. Sub-processors

Depending on how this deployment is configured, the following third parties may process data on our behalf. Each is bound by its own terms, and only the data described above is disclosed to it:

3. Outbound requests to public data sources

To build the dashboard, the RegSignal server requests publicly available information from third-party publishers — including the U.S. Federal Register API, the EU Publications Office (Official Journal via Cellar), the U.S. Securities and Exchange Commission, and national regulator websites. These are server-to-server requests for public data. No personal data about you is transmitted in them. Those operators will see the IP address of the server making the request, as with any HTTP request.

4. Optional AI (LLM) layer

RegSignal can optionally send a compact summary of the current sweep to a third-party large-language-model provider, in order to generate compliance action items. That summary consists solely of public regulatory publication data — rule titles, identifiers (such as CELEX or Federal Register document numbers), dates and regulator names. It contains no personal data and no data about visitors to the dashboard.

The AI layer is disabled unless the operator sets LLM_PROVIDER. If enabled, the chosen provider becomes a sub-processor, and its own terms and privacy policy apply to that transfer. Output produced by the AI layer is labelled as such in the interface.

5. What we do not do

6. Retention

Server access logs are retained for [LOG RETENTION PERIOD, e.g. 14 days] and then deleted or rotated. Sweep results are stored locally as JSON files and contain public regulatory data, not personal data.

Account data is retained for as long as the account exists. Verification and password-reset tokens are single-use and expire automatically (24 hours and 1 hour respectively), and expired sessions are purged. When you delete your account, your profile, password hash, active sessions, tokens and consent records are deleted, and free-text audit entries are detached from your identity. Records we are legally required to keep for tax or accounting purposes are retained for [FINANCIAL RECORD RETENTION PERIOD]; nothing else is kept.

7. Your rights

You have the right to: access the personal data we hold about you; have it rectified; have it erased; restrict or object to its processing; and receive it in a portable form. You can change your name, company and email preferences directly from your account page. To exercise any other right, or to ask us to delete your account, contact [PRIVACY CONTACT EMAIL].

You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your national authority.

8. Security

Passwords are stored only as salted scrypt hashes, and are never written to logs. Sessions use opaque random tokens of which only a SHA-256 hash is stored. Cookies are HttpOnly, SameSite=Lax and Secure over HTTPS. The application sets a strict Content-Security-Policy, transport security headers and cross-origin protections, verifies the origin of every state-changing request, and rate-limits authentication attempts. Access records are written with a one-way hash of the IP address rather than the address itself.

No system is perfectly secure. If you believe your account has been compromised, reset the password and contact [PRIVACY CONTACT EMAIL].

9. Changes

We will update this notice if the software's behaviour changes in a way that affects personal data, and will update the version and effective date above.