Small footprint
The current public deployment does not load Plausible analytics. The optional build integration remains disabled, and the site does not use advertising trackers or ad-tech profiling.
The Echo Archives keeps the data footprint small. This page explains what information the current site uses for browsing, ratings, submissions, and moderation.
The current public deployment does not load Plausible analytics. The optional build integration remains disabled, and the site does not use advertising trackers or ad-tech profiling.
community ratings use a cookie plus a linked local profile id.
Submissions and follow-up contact details are stored for archive review, moderation, and quality control under the retention limits below.
The legal operator and data controller is Charlie Arnerstål. The Echo Archives is a Continental project, not a separate legal entity. The controller is established in Sweden and handles personal data under applicable Swedish and European Union law.
For privacy and data-protection requests, email [email protected]. For copyright, legal, or follow-up requests, you can also use the public Continental contact route. For factual archive corrections that do not involve a privacy request, the faster route is usually Submit or correct.
General page requests reach the site through Cloudflare and the archive like any normal web request. Cloudflare may process request and security data and may set cf_clearance or other challenge cookies when its zone checks require them. The exact production-zone challenge lifetime is not visible from an ordinary public response. Route-specific echo-scroll:… session-storage keys remember scroll position.
We use Cloudflare Real User Monitoring (RUM) to collect anonymous website performance metrics, such as page loading and responsiveness information. Cloudflare RUM does not use cookies or local storage to track visitors and is not used to identify individual users.
Passive show-page browsing does not create a rating profile. Submitting or clearing a rating can create a publicly anonymous, pseudonymous profile using the HTTP-only voter cookie echo-community-voter plus the linked localStorage key echo-community-profile-id. Rating actions also send the rating value and can send a Cloudflare Turnstile token when that protection is enabled.
When you send a show submission, correction, listener review, or creator verification request, the server receives the request body you send. That can include titles, links, notes, review text, proof URLs, and any contact email you choose or are required to provide for that submission type.
The site receives IP address and user-agent data with requests. Raw client IPs used for rate limiting are retained only for the configured rate-limit window and then removed by cleanup. Submission records store source IP and user agent for up to 30 days from receipt. Community rating profiles retain a voter hash while an active rating or helpful vote remains, but user-agent and profile abuse metadata are removed after 30 days of profile inactivity; stored rating abuse hashes are redacted after 30 days without a rating update. The current public deployment does not load Plausible analytics.
The site processes page requests and rating actions to provide the archive and community features you actively use. The applicable basis depends on the feature and context, including providing a requested service and the controller’s legitimate interest in operating it safely.
Submission content and any contact details are used because you asked the archive to review a correction, review, verification request, or new-show suggestion and it needs enough context to handle that request. The submission notice and Terms explain the related publication and licence purposes.
Rate limits, short-lived technical request data, hashed abuse signals, and Turnstile checks are used to reduce spam, automated voting, and moderation abuse. That is part of the archive’s legitimate interest in keeping the system trustworthy.
If you provide a contact email, the archive uses it to respond to your submission or legal request. You can ask the controller to stop that follow-up or delete the contact detail where the archive no longer needs it.
The cf_clearance lifetime follows the Cloudflare zone’s Challenge Passage setting and can be refreshed as security checks continue. The exact production-zone setting is not visible from an ordinary public response.
The voter cookie currently has a maximum lifetime of about 400 days after it is set. The linked local profile id stays in localStorage until you clear it. The server retains the pseudonymous profile and active rating state while that rating remains active, or while a helpful vote remains active. Clearing a rating deletes the active rating; related rating-event and abuse records are removed after 30 days.
Community rating abuse hashes and rating-event records are retained on a rolling 30-day window. User-agent and profile abuse metadata are removed after 30 days of profile inactivity, and an active rating’s stored abuse hash is redacted after 30 days without a rating update. Unreferenced profiles are deleted after 90 days of inactivity.
If application access observability is enabled, pseudonymized request telemetry is retained for 14 days. It records a weekly rotating keyed pseudonym, route template, status, latency, and request id rather than raw client addresses, headers, bodies, or query strings. The client pseudonym is not intended to identify a person across rotation periods. Cloudflare’s separate edge processing and retention follow its zone and provider settings.
Submission content and contact details are kept for up to 180 days after the last recorded review, or up to 180 days after receipt if the request is never reviewed. Source IP and user agent are removed after 30 days. Older unaccepted or unpublished submissions are deleted. If a listener review is already published, the live submission row is reduced to a non-contact, non-network anchor while the public review remains published.
A published listener review, including the public alias and review text that appears on the show page, is retained as public archive content while it remains published. A deletion or removal request can be sent to the controller and will be reviewed alongside the archive’s moderation and rights obligations.
Live-database cleanup does not rewrite earlier database backups. Restricted backup copies may therefore contain older data until they expire under the separate deployment backup-retention schedule. The archive does not promise instant deletion from every backup copy.
The protected maintainer session cookie currently lasts up to 12 hours after sign-in unless it is cleared earlier by logout or browser controls.
See the cookies and browser storage page for the storage-by-storage list.
The Echo Archives is a general-audience audio-drama discovery service and is not specifically directed at children. Do not submit personal information if you are below the minimum age that applies to you without a parent or guardian’s authorization.
If the controller learns that a child’s personal information was submitted in circumstances where it should not have been collected, contact [email protected] so it can be reviewed and removed where appropriate.
Depending on the law that applies to you and the archive, you may be able to ask for access to the personal data held about you, correction of inaccurate data, deletion, restriction, objection to certain processing, or withdrawal of consent where processing depends on consent.
Where GDPR applies, the archive aims to respond to valid privacy-rights requests without undue delay and within one month of receipt. Where the law permits an extension, the response period may be extended by up to two further months; the controller will explain the reason.
Cloudflare provides the site’s edge security and can perform browser or challenge checks on visits, including use of the cf_clearance cookie. Community rating requests may also use Cloudflare Turnstile when that protection is enabled, which means the browser can contact Cloudflare for human-verification checks during rating actions.
The site also links out to official show sites, listening platforms, Patreon, Ko-fi, GitHub, and the external Continental contact route. If you open those destinations, your browser connects to them directly and their own terms and privacy rules apply.
The current archive implementation does not embed Patreon or Ko-fi payment widgets or import supporter account data. Those providers handle any payment or account information directly under their own policies.
Plausible analytics is not active on the current public deployment checked on August 20, 2026. Cloudflare RUM is described above as a separate performance-measurement service. If another analytics service or processor is enabled later, this page must be updated before that deployment to identify the provider, purpose, data categories, and applicable transfer information.