Privacy

State of Privacy is a public evidence project. You can browse the public report without creating an account.

What trackers we use

This website uses one tracker: PostHog (posthog.com). It counts which pages people visit so we can understand which parts of the report are being read. It does not know your name. No advertising trackers, screen-recording tools, or tools that figure out who you are run on this website. We name our tracker because we believe every website should.

What we collect when you request a report

When you fill out the report access form, we collect: your work email, name and job title (if you provide them), which report you asked for, your consent choices, and which page you were on. We store this in a secure database. We also send ourselves an email so we can review your request.

Report access is manually reviewed

A report request does not guarantee delivery of a company-specific report. We may share a public briefing, decline a request, ask for verification, or offer a review of your own company instead. We do not share company-specific reports with competitors or other third parties by default.

Unbundled consent

The report access form asks for two separate consents: one for receiving the evidence brief by email, and one for marketing consent to receive occasional updates from Meridian Bridge Strategy or State of Privacy. Each consent is independent. You can request the report without opting into marketing. You can change your mind at any time by contacting us. This is what unbundled consent looks like under DPDP.

Why we collect it

We use work email addresses to review access requests, send public brief or evidence brief responses where appropriate, handle business inquiries, prevent spam, and maintain a record of requests. Analytics help us understand which public pages are useful.

No sale of personal data

We do not sell personal data. We do not share your email with third parties for advertising. We do not ask you to submit secrets, credentials, customer lists, or private records through public site interactions.

Data storage and processing

Your report request data is stored on a server in Mumbai, India. Email notifications go through a US-based email service (Resend). PostHog analytics data is processed in the US. No other outside companies receive your data.

Opt out and contact

To opt out of marketing, request deletion of report request data, or ask a privacy question, contact dpo@meridianbridgestrategy.com. We will respond within 48 hours.

Back to State of Privacy