In short
- No cookies on the public site. We show no ads and use no tracking tools. There is no banner for you to accept.
- A visit count without tracking. We count the visits of the last 30 days from our server log. We keep only daily totals.
- Nothing loads from third parties except article thumbnails, which come from the outlets’ own sites. Fonts, charts and portraits come from our servers.
- You must confirm your newsletter subscription yourself. Once you have signed up, we send you a confirmation email. You can unsubscribe at any time.
- Your information stays in Quebec, on machines run by the team. Two providers see it in transit: Cloudflare for the network, Google for email.
- One person is accountable: Antoine Lemor, the person in charge of the protection of personal information. Write to ccf.project.team@gmail.com: we reply within 30 days.
1Who is accountable for your information
The Canadian Climate Framing Project (CCF) is an independent research project. It is led by Alizée Pillod (Université de Montréal), Antoine Lemor (Université de Sherbrooke) and Matthew Taylor (Université de Montréal). We run the website ccf-project.ca, the data platform data.ccf-project.ca and the newsletter The Climate Journal.
Antoine Lemor is the person in charge of the protection of personal information. For any question or request, write to ccf.project.team@gmail.com with “Privacy” in the subject line.
Antoine Lemorccf.project.team@gmail.comMailing address: to come
This policy applies Quebec’s Act respecting the protection of personal information in the private sector and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). Our emails also follow Canada’s Anti-Spam Legislation (CASL).
2What the site records when you visit
Every page you request first travels through Cloudflare’s network, which protects the site and encrypts the connection. It then reaches our server in Quebec.
Our server writes to a technical log your IP address, the date and time, the page requested, the page you came from, your browser’s language and type, and the country Cloudflare associates with your address. We use this log to spot abuse, fix outages and count visits (section 3). Only the team members who administer the server read it. We delete it after 30 days.
We use no tracking tool and no advertising service. The site does not recognize you from one visit to the next.
Until 25 September 2026, Cloudflare asked your browser to report connections that fail. Our pages now ask it to stop.
Article thumbnails come from the websites of the outlets that published them. To display them, your browser contacts those sites, which then receive your IP address and our site’s name, as with any image hosted elsewhere. Their own policies apply. Everything else (fonts, charts, portraits) comes from our servers.
Links to Bluesky, GitHub, the journal Scientific Data or news articles take you to other services, with their own rules.
3The visit count
The figure shown under the site’s name and in the footer tells how many visits the public site received over the last 30 days.
A visit is defined as opening a page of the site from another site, a link or a bookmark. When you move from one page of the site to another, we do not count a new visit. This is the definition Cloudflare uses. Like Cloudflare, we leave out bots that identify themselves, such as search-engine crawlers. Programs that pass themselves off as browsers are still counted.
We make this count every hour from the technical log described in section 2. The calculation does not use your IP address. We keep only daily totals, which cannot identify anyone. Nothing is stored or run in your browser for this count.
4Cookies and storage on your device
The public site sets no cookies. It stores a single preference on your device, at the moment you press the theme button: your choice between light and dark, named ccf-theme, in your browser’s local storage. This preference is never sent to us. To remove it, clear the site’s data in your browser.
The member area and the data platform set the following. All are needed for the service you ask for:
| Name | Where | Purpose | Duration |
|---|---|---|---|
session | Member area, platform | Keeps you signed in | 4 hours after your last action |
lang | Member area, platform | Remembers your language | 1 year |
ccf-token (local storage) | Data explorer | Keeps your access key between visits | Until you sign out, at most the key’s validity (365 days) |
| Explorer preferences (local storage) | Data explorer | Basket, notes, theme and province you chose; they stay on your device | Until you clear them |
When Cloudflare needs to check that a connection does not come from a bot, it sets a short-lived security cookie (__cf_bm or cf_clearance).
None of these measures audiences or follows you across sites. None is optional, which is why the site shows no consent banner.
5The contact form
The “Write to us” form and the Contact page ask for your name, email address, a subject and your message. Your message reaches us by email, in the team’s mailbox hosted by Google (Gmail). We use it only to reply to you. It is not stored in any of our databases. We delete our exchanges no later than 24 months after the last message.
Access requests sent from the data explorer take the same route. If you report a problem with an article, we keep your description. If you leave your email address, we delete it 12 months after the report was last updated.
6The Climate Journal
You must confirm your newsletter subscription yourself. Once you have signed up, we send you a confirmation email. You can unsubscribe at any time.
To sign up, you give us your email address, the language and the frequency of editions. First and last names are optional. The confirmation link is valid for 7 days. If you do not confirm, we delete your request after 30 days.
So that we can prove your consent, we keep the date and time of your sign-up and of your confirmation, the form you used and the version of the text you saw.
Our editions contain no tracking pixel and no tracked links: we do not know whether you open them or what you click. Their images come from our server. Only the unsubscribe link carries an identifier specific to you.
Every email contains that link. It never expires. Unsubscribing takes effect immediately. Your mail app may also offer a one-click unsubscribe next to the sender’s name. To change language or frequency, fill in the form again: we will send you an email to confirm the change.
After you unsubscribe, we keep your address and the dates of your consent and of your unsubscription for 3 years. This lets us prove we honoured your choice. We then delete them. The list of editions sent to each address is deleted after 12 months. Our emails are sent through Google’s Gmail service.
7Data platform accounts
The team opens accounts on data.ccf-project.ca and in the member area at your request. We record your username, name, email address, institution, language, access tier and its end date, along with our notes on your request.
To enforce access tiers and protect the platform, we record:
- every call to the programming interface, with its path and parameters, including your searches;
- every sign-in attempt, successful or not;
- every call from an assistant connected through the MCP protocol: the tool called, the result, the volume returned and the duration;
- the articles, events and cascades you open, to count them against your quotas.
We delete call and sign-in logs after 12 months. Quota counters last as long as your account.
If you connect a conversational assistant or a code editor to the observatory, we receive only the requests it sends to the observatory, never the rest of your conversation. Queued requests and their results are deleted 30 days after they expire. The observatory’s answers go through your assistant’s provider, under that provider’s terms. The welcome message the assistant receives includes your display name and institution.
At the Founders tier, documents composed for you are deleted after 30 days. Emails composed and sent in the project’s name are kept as a record of its correspondence. For joint projects, the GitHub usernames and Overleaf addresses of invited co-authors are passed on to those two services.
During a public demonstration of the platform, we use each participating device’s IP address to share out the reading quota. We delete it 7 days after the session.
To close your account, write to us. We delete the information attached to it within 30 days, except the call logs, which keep their 12-month period.
8People named in the press
The observatory analyses news articles that have already been published. It draws out the names of people, organizations and places, then measures their place in the coverage. For a person cited often, it shows a short description drawn from the articles and from Wikipedia. It also agrees their role in French with the grammatical gender the articles give them. When a freely licensed image exists on Wikimedia Commons, it shows their portrait, credited to its author.
This processing serves research and public information about climate coverage. If this concerns you, you can ask us to correct a description, remove a portrait or stop disseminating information that harms you. Write to the person in charge (section 1).
9Our providers and Quebec
The site, the database and their backups are hosted on machines the team runs in Quebec. Every day, a copy of the database goes to a second team machine, also in Quebec, over an encrypted connection. Each copy is deleted after 30 days.
Two providers based outside Quebec process information on our behalf:
- Cloudflare, Inc. (United States). All traffic to our two domains passes through its network, which protects the site and encrypts connections. Cloudflare therefore receives your IP address and the content of the pages exchanged. Cloudflare’s privacy policy.
- Google LLC (United States). Its Gmail service sends our emails (newsletter, replies, account letters) and hosts the team’s mailbox. Google’s privacy policy.
Before entrusting them with this information, we assessed the protection they offer against the standards of Quebec law. We do not sell or rent any personal information.
10How long we keep what
| What we keep | How long |
|---|---|
| Server technical log (IP address, page, browser) | 30 days |
| Daily visit totals (no personal information) | 400 days |
| Theme preference | On your device, until you clear it |
| Contact form messages | 24 months after the last exchange |
| Email address left on an article report | 12 months after the last update |
| Unconfirmed sign-up request | 30 days (link valid for 7 days) |
| Climate Journal subscription | For as long as you stay subscribed |
| Address and dates, after you unsubscribe | 3 years |
| List of editions sent | 12 months |
| Platform account | While the account is open, then 30 days |
| Platform call and sign-in logs | 12 months |
| Failed sign-ins, counted to suspend repeated attempts | 2 days |
| Queued assistant requests | 30 days after they expire |
| Documents composed at the Founders tier | 30 days |
| IP addresses from a public demonstration | 7 days after the session |
| Database backups | 30 days |
An automated task deletes, every night, what has reached the end of its period. The team deletes the messages in its mailbox and closed accounts itself.
11How we protect your information
Connections to the site are encrypted. Only the team members who administer the servers can reach them. Within the database, each service reaches only the tables it needs.
We do not keep your password itself, only a fingerprint from which it cannot be recovered. The same goes for reset links and for the authorisations given to assistants. The secret of your second factor is encrypted. No password travels by email: when an account is opened, you choose your own through a link valid for seven days.
After several failures, sign-in to the account is suspended for a while. We keep a record of these failures for two days.
We keep a register of confidentiality incidents. If an incident presents a risk of serious injury, we promptly notify the Commission d’accès à l’information du Québec and the people concerned.
12Your rights
At any time, you can:
- find out what information we hold about you and get a copy, including in a common computer format;
- have inaccurate, incomplete or ambiguous information corrected;
- withdraw your consent, for instance by unsubscribing from the newsletter;
- ask us to delete your information, or to stop disseminating information about you;
- find out who can access it and how long we keep it.
Write to the person in charge (section 1). We may ask you to confirm your identity, for example by writing to us from the address concerned. We reply within 30 days, free of charge.
If our answer does not satisfy you, you can turn to the Commission d’accès à l’information du Québec or the Office of the Privacy Commissioner of Canada. To report an email you did not ask for, contact the Spam Reporting Centre.
13Minors
The newsletter and accounts are for people aged 14 and over. We do not knowingly collect information about a child under 14. If you believe we hold some, write to us: we will delete it.
14Changes to this policy
The effective date and version number appear at the top of the page. If we change this policy in a significant way, we will announce it on the site. If the change affects the newsletter or accounts, we will also tell the people concerned by email.
Version 1.3, effective September 25, 2026. Canadian Climate Framing Project · ccf.project.team@gmail.com.