Distill is built on trust. This statement explains how we treat your data and the signals you share.
What we collect
- Account data: email, username, password (hashed), profile fields you fill in
- Activity data: posts, replies, tags, reactions, login timestamps
- Technical data: IP address (used only for anti-spam and abuse prevention), browser metadata
- Email engagement: open and click data on transactional emails (opt-out available)
What we don’t collect
- Third-party tracking pixels or behavioral ad targeting
- Browsing history outside the Distill platform
- Unnecessary biometric or precise location data
How signals appear in published Distill reports
When a signal you contributed becomes part of a published report:
- Quotes may be paraphrased or shortened for clarity, never fabricated
- Attribution defaults to anonymized (“a member of the Distill community noted…”) unless you’ve explicitly opted in to public credit
- Personally identifiable details are removed before publication
- You can request that a specific contribution be excluded from publication at any time
Your rights
- Access: request a copy of all data associated with your account
- Correction: edit or delete your own posts at any time
- Deletion: request full account deletion — we comply within 14 days
- Export: download your contributions in a machine-readable format
Where data lives
- Application: hosted on DigitalOcean (US region)
- Backups: encrypted, retained for 90 days
- Email transactional service: Resend
- Editorial workflow: Airtable (signals only, anonymized when synced)
Contact
For data-related requests, email [privacy email TBD by Distill].
— The Distill team