Privacy

Privacy-first by design.

Bank Harm Registry is designed to collect only what is needed for private intake, consent, routing, moderation and support matching. It does not automatically publish consumer stories.

What may be collected

Name or alias, contact email, institution, issue, state, timeline, evidence description, requested remedy, consent choices and submission metadata.

Where it may go

Depending on configuration, a private email inbox and/or confirmed private GitHub intake queue. A public GitHub repository must never be used for private intake.

What stays private

Names, emails, raw stories, documents and contact details are not automatically published. Public summaries require separate consent, redaction and review.

Do not submit

  • Social Security numbers
  • Full account or card numbers
  • Login credentials, PINs or security answers
  • Full dates of birth
  • Unredacted medical or identity documents

Retention and deletion

Before collecting sensitive real-world reports at scale, configure a privacy contact, written retention schedule, deletion process, authentication and secure storage controls. Browser receipt metadata can be cleared locally.

Launch requirement: Replace placeholder contact information and obtain qualified legal/privacy/security review before collecting sensitive reports at scale.