In immediate danger? Call 999. Free 24/7 National Domestic Abuse Helpline: 0808 2000 247.

Legal

Privacy notice

This notice explains what personal data Stand Your Ground collects about you, why we hold it, and the rights you have under UK GDPR and the Data Protection Act 2018.

Last updated: 29 July 2026

If you are in immediate danger call 999. For confidential 24/7 support call the National Domestic Abuse Helpline on 0808 2000 247.

1. Who we are

The data controller for Stand Your Ground is [Your Organisation Name] (“we”, “us”). You can contact us about your personal data at [privacy@example.org].

If you are not satisfied with how we handle your data you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint or on 0303 123 1113.

2. What data we collect

  • Account data: your email address and, if you provide one, a display name.
  • Evidence journal: incident summaries, dates, locations, categories, notes on injuries, witnesses, police references, and edit history.
  • Evidence files: documents, photos, audio or video you upload, with file name, size, type and a cryptographic hash used to prove they have not been altered.
  • Contacts: names, roles and contact details of professionals or supporters you choose to save (e.g. solicitor, IDVA, GP).
  • Settings: preferences such as discreet mode.
  • Technical data: IP address, browser type, and diagnostic logs generated when you use the site. We do not use advertising or third-party analytics cookies.

3. Special-category and sensitive data

Evidence you log will often include information about your health, sex life, ethnicity, religion, or the alleged criminal conduct of another person. This is special-category and criminal-offence data under Articles 9 and 10 of UK GDPR.

We process it only because you have chosen to record it (your explicit consent, Art. 9(2)(a)), and to help you exercise or defend legal claims (Art. 9(2)(f)). You can withdraw consent at any time by deleting the data or your account.

4. Why we hold it and our lawful basis

  • Providing the service (journal, vault, contacts) — contract / consent (UK GDPR Art. 6(1)(a) and (b)).
  • Keeping your data safe (RLS, encryption, edit audit) — legitimate interests (Art. 6(1)(f)).
  • Responding to legal or safeguarding obligations — legal obligation (Art. 6(1)(c)).
  • Responding to your data-rights requests — legal obligation (Art. 6(1)(c)).

5. Who we share it with

We do not sell your data. We share it only with the processors we need to run the service:

  • Lovable Cloud (Supabase) — database, authentication and encrypted file storage.
  • Lovable AI Gateway — only when you use an AI-assisted feature; content is sent for that single request and not used to train models.
  • Firecrawl — when we fetch official source pages you have asked to view.
  • Hosting provider (Cloudflare) — delivers the site and applies basic DDoS protection.

Each processor is bound by a Data Processing Agreement. We will never disclose your data to your abuser, your family, or your employer.

6. International transfers

Data is primarily hosted in [EU/UK region — confirm]. Where a processor operates outside the UK/EEA, the transfer is protected by the UK International Data Transfer Addendum and the EU Standard Contractual Clauses.

7. How long we keep it

  • Account, journal, contacts and evidence: kept while your account is active.
  • After you request account deletion: a 30-day grace period during which you can cancel. After 30 days the data and evidence files are permanently deleted.
  • Server logs (IP, request path): 30 days, for security and abuse investigation.

You can export or delete your data at any time from /data-requests.

8. How we protect it

  • Row-level security so only you can read your rows.
  • Private storage bucket for evidence files — no public URLs.
  • Passwords hashed by the auth provider and checked against the Have I Been Pwned breach list at sign-up.
  • Encryption in transit (HTTPS) and at rest on the storage provider.
  • An immutable edit history on incidents so tampering is detectable.
  • Quick Exit and discreet mode to reduce the risk that someone looking over your shoulder can see what you are doing.

9. Cookies and local storage

We use browser localStorage to keep you signed in. We do not use tracking cookies, advertising cookies or third-party analytics. Clearing your browser data will sign you out and remove any locally cached preferences.

10. Your rights

Under UK GDPR you have the right to:

  • be informed about how we use your data (this notice);
  • access a copy of your data;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to processing;
  • portability — receive your data in a machine-readable format;
  • withdraw consent at any time.

Use /data-requests to export or delete your data, or email us at [privacy@example.org]. We will respond within one month.

11. Children

The service is intended for people aged 16 and over. If you are under 16, please use the service with the support of a trusted adult, and read our safety guidance at If you are being abused.

12. Changes to this notice

We will update this page when our practices change and update the “Last updated” date at the top. Material changes will be highlighted in-app.