What may be collected
Name or alias, contact email, institution, issue, state, timeline, evidence description, requested remedy, consent choices and submission metadata.
Bank Harm Registry is designed to collect only what is needed for private intake, consent, routing, moderation and support matching. It does not automatically publish consumer stories.
Name or alias, contact email, institution, issue, state, timeline, evidence description, requested remedy, consent choices and submission metadata.
Depending on configuration, a private email inbox and/or confirmed private GitHub intake queue. A public GitHub repository must never be used for private intake.
Names, emails, raw stories, documents and contact details are not automatically published. Public summaries require separate consent, redaction and review.
Before collecting sensitive real-world reports at scale, configure a privacy contact, written retention schedule, deletion process, authentication and secure storage controls. Browser receipt metadata can be cleared locally.