Policies

Privacy Policy

Effective May 26, 2026

Four Loons is reader-supported. We don’t sell ads, we don’t take sponsored content, and we don’t run analytics or social-media pixels. We collect the small amount of data we need to run the site honestly, and we tell you what it is, where it lives, and how to make us delete it.

1. Who runs this site

Four Loons is published by Four Loons Media, an independent publication, a Minnesota organization. The full editorial picture lives on /about and /ethics. The legal rules of using the site are in our Terms of Use. This policy describes the data side.

2. What we collect and why

We collect only what these four activities require:

  • Reading the site. Our servers write a standard request log for each page or asset you load: IP address, user agent, request path, and a timestamp. We use it to keep the site running, debug problems, and stop abuse. We do not run analytics or build reader profiles from it.
  • Creating an account. We collect your email address, a password (which we never store in plaintext — see Section 6), a display name, and, if you choose to provide them, an optional location, dietary preferences, and preferred cities so we can personalize what we surface to you. The optional fields are optional in fact: you can leave them blank, change them later, or remove them.
  • Subscribing to the newsletter. We collect your email address and a short source tag noting where on the site you signed up (so we know which surfaces actually work). That is the entire newsletter record.
  • Commenting. We collect the body of your comment, your user ID, the timestamp, the IP address you submitted from, and the moderation state of the comment. The IP is kept so we can investigate abuse, brigading, and ban evasion. Comments are moderated before publishing.

That is the complete list. We do not collect anything else.

3. Cookies

We set exactly two cookies, both first-party and both functional:

  • Session cookie. Keeps you signed in. Marked HttpOnly, Secure, and SameSite=Lax. It contains a random session identifier — not your email, your password, or anything readable.
  • CSRF cookie. A short anti-forgery token that lets the site safely accept forms (comments, profile edits) from your browser.

We do not set advertising cookies. We do not embed Google Analytics, Meta pixels, or any other third-party trackers. If a future Four Loons page ever embeds a third party (for example, a video player), we will say so on that page and link back here.

4. Third parties we rely on

To run the site we use two narrowly-scoped service providers, both based in the United States:

  • Our transactional email provider sends account verifications, password resets, comment notifications, and the newsletter. They receive your email address and the body of the message we send you. They are contractually limited to providing email service for Four Loons.
  • An S3-compatible object storage provider stores media files (photographs, illustrations, audio). It does not receive your account or comment data.

That is the entire list of third parties that touch reader data. We do not currently accept payments and do not have a payment processor in the loop. If that changes — for example, if we add reader memberships — we will name the processor here before collecting a card.

5. Where data lives and how long we keep it

All Four Loons servers and storage are in the United States. Retention by category:

  • Server request logs: 30 days, then deleted.
  • Account data (email, password hash, display name, optional fields): kept while your account is active; deleted within 30 days of account closure, except for records we are legally required to retain.
  • Newsletter subscriptions: kept until you unsubscribe; the record is removed within 30 days of unsubscribe.
  • Comments: kept while the underlying review or essay is published. If you delete your account, your published comments are anonymized (author replaced with “former reader”) rather than removed, so the discussion thread stays coherent — unless you ask us to remove them outright, in which case we will.
  • IP addresses attached to comments: 90 days, then truncated and replaced with a coarse region.
  • Moderation records (notes about why a comment or account was actioned): retained as long as needed to enforce these policies consistently, typically up to two years.

6. Security

We use widely-accepted, boring engineering practices:

  • All traffic between your browser and the site is encrypted with TLS 1.2 or higher.
  • Passwords are stored as salted hashes using a modern password-hashing algorithm. We cannot tell you your password, only help you reset it.
  • Account, comment, and media data are encrypted at rest in our database and object storage.
  • Access to production data is limited to the people who need it for editorial operations and engineering, logged, and reviewed periodically.

No system is perfect. If we ever experience a security incident affecting your data, we will tell you directly, as soon as we reasonably can, and we will tell you what we know about scope, impact, and what to do next.

7. How we share data — and don’t

We do not sell, rent, or trade personal information. We do not share data with advertisers, data brokers, or social-media platforms. We share data only in these narrow situations:

  • Service providers named in Section 4, only to the extent needed to deliver email or store files for the publication.
  • Legal process, such as a valid subpoena or court order. We will tell you about a legal request for your data unless we are legally prohibited from doing so.
  • To prevent harm, such as urgent threats to safety or active abuse of the comment system.
  • Business changes, in the unlikely event the publication is transferred to a successor entity. The successor would be bound by the privacy commitments here, and we would notify account holders at least 30 days before the transfer.

8. Your rights and how to use them

You can ask us to:

  • Access the personal data we hold about you.
  • Correct anything that’s wrong.
  • Delete your account and the data attached to it.
  • Export your account data in a portable, machine-readable format.
  • Unsubscribe from the newsletter at any time (every newsletter has a one-click link; you can also email us).
  • Withdraw consent for any optional processing (the optional profile fields) at any time.

To exercise any of these rights, email privacy@fourloons.com from the address on your account, or from any address you can verify. We aim to respond within 30 days. We may ask a question or two to confirm it’s really you, and we will tell you if a request is delayed and why.

9. California residents (CCPA / CPRA)

If you live in California, the California Consumer Privacy Act gives you specific rights. The categories of personal information we collect, as the CCPA defines them, are:

  • Identifiers: email address, account ID, IP address, display name.
  • Customer records: optional location and dietary preferences you choose to provide.
  • Internet/network activity: server request logs and the IP captured at comment submission.
  • User-generated content: the comments you post.

We collect these categories for the operational purposes described in Sections 2–5. We do not collect the other CCPA categories (geolocation beyond city, biometric data, professional or employment data, education records, inferences used for profiling, or sensitive personal information as the statute defines it).

As a California resident, you have the right to know what we collect, to delete it, to correct it, and to not be discriminated against for exercising those rights — we will not deny service, charge you a different price, or degrade your experience because you made a privacy request. To exercise these rights, write to privacy@fourloons.com; we may need to verify your request. You may also designate an authorized agent in writing.

Four Loons does not sell or share personal information as the CCPA defines those terms. We do not have a “Do Not Sell” obligation because we don’t sell.

10. Visitors from the EU, UK, and EEA

Four Loons is a US publication that does not actively market to readers in the European Union, the United Kingdom, or the European Economic Area, and we do not knowingly target ads, services, or content to people there. If you happen to read us from the EU/UK/EEA, we honor the data-subject rights described in Section 8 on a best-effort basis: access, rectification, erasure, restriction, portability, and objection.

Our legal basis for processing the data we do collect is either your consent (creating an account, subscribing to the newsletter) or our legitimate interest in operating an editorial publication and protecting it from abuse (request logs, moderation IPs). Data is transferred to and stored in the United States; by using the site you understand that. If you believe we have mishandled your data, you can lodge a complaint with your national supervisory authority. We would also appreciate hearing from you first at privacy@fourloons.com.

11. Children

Four Loons is not directed at children under 16. We do not knowingly collect personal information from anyone under 16. If you are a parent or guardian and believe a child has created an account, write to privacy@fourloons.com and we will delete the account and associated data promptly.

12. AI tools and your data

We use AI tools for editorial tagging, search, layout assistance, and image illustration. These tools never receive your account profile, your email address, your IP address, or your password. We do not send personal data to AI training pipelines, and we do not allow any provider to train models on Four Loons user-generated content — including your comments. Where an AI provider processes a piece of editorial text for tagging or layout, that processing is bound by a data-processing agreement that prohibits training on, retaining, or repurposing the input. The broader editorial position on AI is on our Ethics & Methodology page.

13. Changes to this policy

We may update this policy as the site changes. When we make a material change, we will update the “Effective” date at the top, post a note on /about, and — if you have an account — email you at least 30 days before it takes effect. Minor edits (typos, clarifications that don’t change practice) are made without notice but tracked internally. If a change reduces your privacy in a material way, we will ask for your renewed consent before applying it to data we already hold about you.


Contact

privacy@fourloons.com · we respond to privacy requests within 30 days and acknowledge receipt within five business days.