People reporting discrimination should not have to sacrifice more privacy.
Submissions are private by default. This page explains what the project collects, why it is collected, and what is required before any publication.
What we collect
The story form may collect an alias or name, optional email address, state, EEOC office, case dates, process responses, discrimination basis, issue, narrative, impact statement, and message to Congress. The separate contact form collects an email address, subject, and message body so the project can review and respond to general messages.
What we do not need
Do not submit Social Security numbers, birth dates, home addresses, employee IDs, medical records, privileged communications, sealed records, protective-order material, or other information you are prohibited from disclosing.
Private by default
Raw submissions are stored in a private database with row-level security and no anonymous read access. The browser sends data only to a server-side endpoint; database credentials are never shipped to the browser. Publication requires editorial review and, for identifiable stories, further permission.
Aggregate research
De-identified answers may be included in aggregate analysis only when the contributor grants research permission. Public reports should use minimum sample-size thresholds and avoid combinations of fields that could re-identify a person.
Optional analytics
With your consent, this site uses Splunk Real User Monitoring to measure page performance, web requests, JavaScript errors, sessions, and user journeys. The analytics feature creates a persistent random identifier in your browser so visits can be correlated without using your name or contact information. Session replay is disabled, and submitted stories, form contents, email addresses, and message bodies are not configured as analytics attributes.
Analytics is disabled until you select “Accept analytics.” You may reject it without losing access to the site and may change your choice at any time using “Analytics preferences” in the footer. Withdrawing consent clears the analytics identifier and stops new analytics collection after the page reloads. The site stores your consent choice in your browser so it can honor that decision.
Analytics data is sent securely to Splunk Observability Cloud for site operation and performance analysis. Access is limited to authorized project operators and is subject to the project’s configured retention settings. The project does not use this data for advertising or sell it.
Deletion and correction
Before launch, the project should publish a working email address and process through which contributors can request correction or deletion of their submission.
Security
The implementation keeps the database service key on the server, rejects unrecognized values, limits request and field sizes, checks the submitting origin, throttles repeated submissions using one-way keyed network fingerprints, and does not automatically publish narratives. Rate-limit records should be deleted after 24 hours. No internet service can promise absolute security.
United States audience
This project is intended for people in the United States. The site uses the DB-IP Country Lite database to restrict access to connections identified as originating in the United States. The country lookup is performed locally at the site’s reverse proxy and is used only to allow or deny the request; visitor IP addresses are not sent to DB-IP for lookup. IP geolocation can be inaccurate, and access through travel, corporate networks, proxies, or VPNs might be denied. DB-IP Country Lite is licensed under the Creative Commons Attribution 4.0 International License.