Privacy Policy

Last updated: 2026-07-11

This policy explains what HWT collects, where it comes from, and what you can (and cannot) ask us to remove. It covers the website, the web “Submit Signal” flow, and the HWT browser extension.

TL;DR

  • The browser extension is anonymous by default. It does not require sign-in and sends only the URL of the tab you choose to submit, plus the optional pseudonym and tags you add.
  • No real-world identity is required to submit signals — no name, no email address, no account.
  • Signals are kept. Submitted URLs and tags are treated as project data and are not deleted on request, except where required by law or for safety and security reasons.
  • Pseudonyms are removable. On request we will delete or disassociate your pseudonym from stored submissions.
  • Operational logs exist. Our infrastructure logs requests, including IP addresses, to keep the service reliable and prevent abuse.
  • No ads, no third-party trackers, and we do not sell or share personal data.

Who we are

HWT (Hybrid War Tracker) is a non-commercial, public-interest OSINT project that documents hybrid warfare against Europe by collecting and reviewing publicly available web resources. HWT is the controller for the personal data described in this policy.

For anything in this policy, contact privacy@hwt.lv.

What this policy covers

This policy covers the three ways of interacting with HWT: visiting the website at hwt.lv, submitting a signal through the website’s “Submit Signal” flow, and submitting signals through the HWT browser extension. A signal is a URL plus optional context such as tags or notes.

What we collect

Everything you send to HWT is voluntary. Nothing described here is data you are required to provide, and there are no consequences for not providing it.

Website visits

When you access hwt.lv, our infrastructure logs requests for reliability, abuse prevention, and incident response. A log entry contains the IP address, time, requested path, response status code, the User-Agent header, and — only if your browser sends one — the referrer. These operational logs are not linked to submitted signals or analyst pseudonyms in normal operation; linking happens only where necessary for security or abuse investigations, or where the law requires it.

Signal submissions (web)

Submitting a signal through the website sends the signal URL (required) and optional tags and notes. The submission itself produces the same operational logs as any other request.

Browser extension

The extension is anonymous by default: it requires no sign-in and reads the URL of the active tab only when you click its toolbar icon. When you submit, it sends the URL (optionally edited by you), the page title, your optional pseudonym and tags, the extension version, and a random installation ID generated once at install time and hashed before transit. The installation ID is used only for abuse prevention and is not linked to your browser profile, device, or identity.

The extension declares the activeTab and storage permissions, plus a host permission for hwt.lv itself, so it can send your submissions to HWT — granted automatically on Chrome, and optional (requested only when needed) on Firefox. It requests access to no other website. Its background component is an event-driven service worker that stays dormant except briefly when you click the toolbar icon or when the extension is installed or updated; it does no continuous monitoring and never reads other tabs, page content, browsing history, or screenshots. Your pseudonym choice and consent flags are stored locally in your browser and reach HWT only when you explicitly submit a signal.

Signals vs. personal data

HWT distinguishes two kinds of data. Signals — the URLs, tags, and notes you submit — are treated as facts about the web and form the project’s OSINT dataset. They are not treated as personal data about the person who submitted them, and they are not deleted on request, except where the law requires removal or where removal is necessary for safety or security.

Analyst pseudonyms and IP addresses in logs can identify a person, so HWT treats them as personal data. If you ask, we will delete your pseudonym or disassociate it from stored submissions while keeping the underlying URLs.

Personal data appearing in the dataset

Signals point to publicly available reporting, which inevitably names people — journalists, officials, propagandists, and other actors in the events being documented. To the extent the dataset contains such personal data, it comes from publicly available media sources, and HWT processes it for public-interest documentation of and research into hybrid warfare (legitimate interest, Art. 6(1)(f) GDPR, alongside the GDPR’s provisions for archiving and research in the public interest).

Individually notifying every person named in publicly reported events is impossible in practice; the GDPR recognizes this (Art. 14(5)(b)) and allows this policy to serve as the public information about that processing. If you believe the dataset contains personal data about you that HWT should not process, contact privacy@hwt.lv.

Account hash

If you have an HWT account, your profile page shows an account hash in the format hwt-XXXXXXXXXXXXXXXX. Pasting it into the extension’s pseudonym field links your anonymous submissions to your account on our side. It is optional — the extension never knows what the hash means, and the public view of a signal only ever shows the hash, never your account name or email.

You can ask us to remove the account-to-signal linkage at any time; the URLs themselves are kept. You can also regenerate the hash from your profile, which immediately invalidates the old one.

Cookies

The public website works without cookies. Functional session cookies are set only when a user with an account signs in, to keep them signed in. There are no analytics cookies, no advertising cookies, and no third-party trackers of any kind — which is why there is no cookie consent banner.

Where data lives and who receives it

All HWT data is hosted in the European Union, on infrastructure in Germany provided by netcup GmbH, which acts as our hosting provider. Email, including the privacy contact, is self-hosted on the same infrastructure.

We do not sell personal data, and we do not share it with third parties. The only exception is disclosure where a law or a binding legal request requires it. Personal data does not leave the European Economic Area.

HWT makes no automated decisions that produce legal or similarly significant effects about individuals. Automated processing is used to organize and analyze the content of signals, not to decide anything about the people who submit them.

Retention

  • Signals (URLs, tags, notes): retained for the lifetime of the HWT project — the dataset is the purpose of the service.
  • Pseudonyms: retained while linked to submissions, until you ask for removal or disassociation.
  • Security and access logs: kept for a limited operational period, typically days to weeks, and longer only where a security or abuse investigation or a legal obligation requires it.

Your rights

If the GDPR applies to you, you have rights of access, rectification, restriction, objection, portability, and erasure regarding your personal data.

Requests we honor: removal or disassociation of your pseudonym; removal of the account-to-signal linkage (account hash); access to and clarification about the personal data we hold about your pseudonym or account.

Requests we generally decline: deletion of signals (submitted URLs, tags), because signals are project data — an OSINT dataset — not personal data about the submitter.

Edge cases: we may remove or restrict content where the law requires it, and we may retain relevant logs or records during abuse or security investigations to protect the service and its users.

You also have the right to lodge a complaint with your data protection supervisory authority.

Changes to this policy

When this policy changes, the updated version is posted on this page with a new “Last updated” date.

Contact

All privacy matters: privacy@hwt.lv. You may write from any email address — HWT does not require you to identify yourself beyond what is needed to handle your request.

If your request concerns a pseudonym, include the pseudonym string. If it concerns an account hash, include the hash (format hwt-XXXXXXXXXXXXXXXX) so we can locate the records.