What the form collects
The form asks for one public http or https URL and an optional note of up to 1,000 characters. The private record includes that link, the note, receipt ID, submission time, review status and the policy version shown when it was sent. No name, email, login, attachment or identity document is requested.
Please omit private contact details, identity documents and information identifying people who have not chosen to be part of a public record. A URL can itself reveal account details or private tokens; use a public published page, without credentials.
To limit abuse, the application derives a quota hash from the connecting IP using a private key. It does not store the raw IP in the report or link that hash to a report. Hosting and security providers process network-request information under their own service settings.
Private review and possible publication
A responsible reviewer must be appointed before opening intake. Access to the queue is restricted to authenticated staff assigned an editorial or moderation role. Reports are not public comments, public incident records or emergency requests. The application does not retrieve a submitted URL; a reviewer decides whether to inspect the source.
Reviewers examine the specific assertion, its date, original context, supporting evidence and relevant responses. A submission, moderation status or receipt does not establish that a statement is false, that a person was paid, or that an organisation acted unlawfully. Review does not guarantee an investigation, response or publication.
If a claim is independently suitable for publication, an editor creates a separate sourced public account and removes private details. Raw reports and private review notes are not published automatically. Public findings retain their own sources and correction history.
Retention and deletion
A 30-day or 90-day retention period must be selected before intake opens. Each record preserves the term in effect when it was submitted. Changing the term for new reports does not silently extend earlier records.
Once the term expires, the report is excluded from the staff queue. A daily maintenance job removes expired link reports and associated private review notes at the next successful run. A failed run can delay database deletion and requires an operator retry; expired report content is excluded from the staff queue and review history in the meantime. Pausing new intake does not pause this configured maintenance. An editor or administrator can remove a marked link report earlier.
Recovery backups are separate from the active queue. The production snapshot schedule retains backups for 30 days, so previously stored material may remain recoverable for that window after routine deletion. Restored data must pass retention cleanup before the newsroom is reopened. Minimal deletion-event metadata may remain for security accountability; it contains no submitted URL or note.
Keep your receipt reference. To request earlier removal, submit the same public link with a note asking for deletion and quoting the receipt. Because the form collects no contact address, the team cannot send a personal follow-up. Losing the receipt may prevent identification of a particular anonymous record. Removal of a private report does not automatically remove an independently sourced public article; public corrections follow the publication method.
Service limits
This service is open to reports regardless of political views or support for a government. It is separate from the closed general reader-submission and newsletter forms. Recruitment, booking and dialogue remain demonstrations.
Do not use the form for immediate danger, voter applications or identity documents. Use verified emergency and official voter-assistance channels. Do not submit threats, doxxing or fabricated evidence. The receipt acknowledges private storage only and provides no promise about review timing.
Return to the link-review form ↗Policy history
8 October 2026: first workflow policy prepared. Intake requires an approved reviewer, retention configuration, maintenance secret, working storage and a separate explicit enable flag.
Read the editorial review method ↗