Privacy Policy






Privacy Policy — Patriot University



Privacy at a Glance

Patriot University is built on a privacy-first, minimal-collection architecture.
You do not need an account to read our content. We do not sell, share, or rent your data.
We do not run advertising networks or behavioral tracking on our visitors.

✓ No account required
✓ No behavioral tracking
✓ No data sales
✓ No advertising cookies
ℹ Minimal data collection
ℹ Tor-friendly

1. Who We Are

Patriot University (accessible at patriot.university) is a
civic education and civil rights platform operated by IT Influentials LLC (“we,” “us,” “our”).
For purposes of the GDPR and similar data protection laws, IT Influentials LLC is the
Data Controller responsible for the processing of personal data described in this policy.
The platform provides anonymous access to constitutional knowledge, state-by-state voting guides,
community rapid-response alerts, and an AI-powered rights advisor.

Our mission is to help every person understand and exercise their constitutional rights,
regardless of background, means, or technical sophistication. Privacy is not a policy
add-on for us — it is a design principle that flows directly from that mission. A person
seeking to understand their rights before an encounter with law enforcement, during a
protest, or while navigating an immigration proceeding should be able to do so without
leaving a digital record.

2. Our Core Promise

🛡

We will never sell, rent, or otherwise monetize your data. We will never share information about your use of this platform except as required by valid legal process — and even then, we will tell you if we are legally permitted to do so.

Specifically, we commit to:

  • Minimal collection: We collect only the data technically necessary to operate the service.
  • Anonymous by default: Core civic education features are accessible without any account, login, or personally identifying information. Some WordPress platform components (described in Section 6) may process standard web request data.
  • No behavioral profiling: We do not build profiles of individual users based on their content consumption or search queries.
  • No advertising: We do not serve behavioral advertising and do not allow advertising networks to track you across sites.
  • Short retention: Technical logs are rotated frequently. We retain the minimum data for the minimum time.
  • Transparency: If our data practices change in a way that reduces your privacy, we will notify you prominently before the change takes effect.

3. Data We Collect

3.1 Visitors (No Account)

When you browse Patriot University without logging in — which is true for all core
civic education content — we collect only what is technically required to serve web pages:

Data Point What We Retain Retention Period Purpose
IP Address Our API backend fully redacts IP addresses in application logs (replaced with [IP-REDACTED]). Web server access logs managed by our hosting provider may retain standard IP data subject to the provider’s retention policy. Application logs: never stored. Hosting provider access logs: per provider policy (typically 7-30 days) Abuse prevention; DDoS protection (hosting layer)
User Agent String Our API backend does not log user agent strings (explicitly excluded to prevent fingerprinting). Standard WordPress and hosting access logs may include user agent data. Application logs: never stored. Hosting/WordPress logs: per provider policy Performance optimization (hosting layer)
Referrer URL Our application sets a Referrer-Policy: no-referrer header, instructing browsers not to send referrer data when navigating away from our site. Standard WordPress and hosting logs may capture inbound referrer headers. Application: not processed. Hosting/WordPress logs: per provider policy N/A (suppressed by policy header)
Page views (aggregate) Page path + count. Collected in aggregate by Google Analytics 4 and WordPress. Not linked to any user identifier — we do not enable User-ID, Enhanced Measurement of form interactions, or any Google Signals features. Google Analytics: governed by Google’s data retention settings (set to 14 months). WordPress: rolling 90 days Editorial decisions; understanding which content is most useful
Search queries on our site On-site search queries are processed in memory by the knowledge base search feature and are not persisted to any database or log. Transient (in-memory only, discarded after response) Returning relevant search results

Tor Browser: You may access Patriot University over the Tor network. We do not block Tor exit nodes. If you use Tor, your IP address will resolve to a Tor exit node, further separating your identity from your browsing activity.

3.2 AI Advisor Conversations

When you interact with the AI-powered rights advisor, your conversation is routed to
Anthropic’s Claude API to generate responses. The following applies:

  • Conversation content is processed transiently to generate responses.
  • We do not persistently store conversation transcripts linked to any user identifier on our servers.
  • Prompts are sent to Anthropic’s API under our enterprise data processing agreement.
    Anthropic does not use API inputs and outputs to train their models under their API
    enterprise terms. See Anthropic’s Privacy Policy.
  • Do not include personally identifying information (your name, address, ID numbers, or
    details about third parties) in advisor conversations if you want to maintain maximum anonymity.

3.3 Invite-Code Access (Authenticated Features)

Some features — such as community rapid-response alerts and certain research tools — require
an invite code. If you use an invite code:

  • You receive a JSON Web Token (JWT) that is stored in your browser’s session storage (cleared when the tab closes). This token does not contain your name, email, phone number, or any personally identifying information — only an access tier and expiry timestamp.
  • We associate your access code with usage metrics (feature accessed, timestamp) but not with your identity.
  • Invite codes themselves are one-time-use cryptographic tokens. We do not record which real-world person was issued which code.

3.4 Email Contact

This site does not have an on-site contact form. If you voluntarily email us at
factcheck@patriot.university, privacy@patriot.university, or other published addresses,
we retain the content of that communication for as long as necessary to respond
and for up to two years afterward for record-keeping. We do not use your email address for
marketing without your explicit consent.

3.5 Data We Do Not Collect

We intentionally do not collect:

  • Names, email addresses, or phone numbers (except when you voluntarily email us)
  • Payment or financial information (this site has no paid tier)
  • Social media profile information
  • Device fingerprints, canvas fingerprints, or similar cross-session identifiers used for tracking anonymous visitors (note: registered users who submit comments are subject to device fingerprinting for accountability purposes as described in Section 5; network-level TLS characteristics are classified passively for security monitoring as described in Section 9, but are not linked to individual anonymous visitors or used for cross-session tracking)
  • Precise geolocation (GPS-level location)
  • Health, biometric, or financial data
  • Racial or ethnic origin, political opinions, religious beliefs, or sexual orientation

4. How We Use Data

We use the limited data we collect solely for the following purposes:

Purpose Data Used Legal Basis (GDPR/state law)
Serving web pages and API responses Standard HTTP request data (IP redacted in application logs) Legitimate interest (technical necessity)
Security, fraud prevention, rate limiting Request metadata, abuse patterns (IP redacted in application logs) Legitimate interest (security)
Site performance and error monitoring Error messages, aggregate page load times Legitimate interest (service quality)
Content improvement (editorial decisions) Aggregate page view counts, aggregate search terms, anonymous Google Analytics 4 session statistics Legitimate interest (mission fulfillment)
Responding to email inquiries Email address, message content (only if you voluntarily contact us) Performance of a contract / consent
Generating AI advisor responses Conversation text (transient) Consent (implicit in using the feature)
Comment moderation and abuse investigation Comment metadata, device fingerprint, session logs (registered users only) Legitimate interest (community safety); consent (account registration)
Terms of Use enforcement Comment content, user account data, tracking logs Performance of a contract (Terms of Use)

We do not use your data for: advertising, profiling, automated
decision-making with legal effects, training AI models, sale or transfer to third parties,
or any purpose incompatible with those listed above.

5. Registered User & Comment Data

Patriot University allows registered WordPress users to post comments on articles and knowledge base entries.
Commenting requires a registered account and login. If you create an account and comment on our site,
the following additional data is collected:

5.1 User Account Data

When you register for an account, WordPress stores:

  • Username, email address, and display name
  • Password (stored as a cryptographic hash — we cannot read your password)
  • Account creation date
  • User role and capabilities

5.2 Comment Data (WordPress Core)

When you post a comment, WordPress core automatically stores:

  • Comment content, author name, and email address
  • IP address and user agent string (stored by WordPress core in the wp_comments table)
  • Comment date and associated post

5.3 Extended Comment Metadata (Comment Sentinel)

In addition to WordPress core data, we operate a comment monitoring plugin (“Comment Sentinel”) that captures
extended metadata when you post a comment. This data is collected to identify users who violate our
Terms of Use and to prevent abuse:

Data Point Source Purpose
Full IP address Server (with proxy/CDN resolution) Identity verification, abuse investigation
IP geolocation (country) Cloudflare header Geographic context for abuse investigation
User agent string Server Browser/device identification
Accept-Language header Server Language fingerprint
Referrer URL Server Navigation context
Screen resolution and viewport size Browser (JavaScript) Device fingerprint
Timezone name and offset Browser (JavaScript) Location signal
Browser language and platform Browser (JavaScript) Device identification
Device memory and CPU cores Browser (JavaScript) Hardware fingerprint
Touch capability Browser (JavaScript) Device type signal
Connection type Browser (JavaScript) Network signal
Do-Not-Track setting Browser (JavaScript) Privacy preference recording

Important: This extended metadata is collected only from registered, logged-in users
who submit comments. It is not collected from anonymous visitors who are simply reading content.
The fingerprint JavaScript only runs on pages where you are logged in and a comment form is displayed.

5.4 Session Logging

For registered users, we also log the following session events to support abuse investigation:

  • Login events: IP address, user agent, timestamp
  • Logout events: Timestamp
  • Failed login attempts: IP address, user agent, attempted username
  • Profile changes: Which fields were changed, by whom, and when
  • Comment edits: New content, IP address, user agent

5.5 How Comment Data Is Used

Extended comment and session data is used exclusively for:

  • Identifying and investigating users who post abusive, threatening, or illegal content
  • Enforcing our Terms of Use and comment policy
  • Responding to valid legal requests about specific commenting activity
  • Detecting sock puppet accounts and coordinated abuse campaigns

This data is never used for advertising, profiling, sale to third parties, or any purpose
other than community safety and Terms of Use enforcement.

Our Commitment to User Safety

We implemented Comment Sentinel specifically to protect our users, contributors, and staff
from abuse, harassment, and intimidation
. Patriot University covers sensitive civic topics —
constitutional rights, accountability, voting rights — and we take the safety of everyone who
participates in our community extremely seriously.

Any user found to be violating our Terms of Use — including posting
threats, harassment, doxxing, or illegal content — will be permanently banned
from the site.

If evidence demonstrates that a user’s provable intent is to cause harm to individuals
or chill constitutionally protected speech
, we will report that activity and
provide all relevant evidence to the appropriate law enforcement authorities.

5.6 Per-User Tracking Controls

Administrators can disable extended tracking for any individual user. When tracking is disabled,
comments still post normally but no extended metadata is captured (WordPress core still records
the standard comment author IP and user agent).

5.7 Your Comment Data Rights

As a registered user, you have the right to:

  • Request access to all tracking data associated with your account
  • Request deletion of all extended tracking data (comment logs, session logs, and user configuration). Note: this does not delete your WordPress comments themselves — those are managed through standard WordPress admin.
  • Request a data export in CSV or JSON format

To exercise these rights, email privacy@patriot.university
with your username and the specific request. We will respond within 10 business days.

6. Cookies & Local Storage

This section summarizes our use of cookies and similar technologies. For a detailed breakdown of
every cookie, its purpose, duration, and opt-out instructions, see our standalone
Cookie Policy.

6.1 What We Use

Name / Type Purpose Duration Required?
WordPress session cookie (wordpress_logged_in_*) Maintains authentication state if you are logged in to an administrative account Session (expires on browser close) Only for logged-in admin users
CSRF token (wp_rest, _wpnonce) Cross-site request forgery protection 24 hours Security (strictly necessary)
JWT (session storage) Stores invite-code access token for authenticated features. Contains no PII — only access tier and expiry. Stored in browser session storage (cleared when tab closes) or in-memory on native apps. Until token expiry, tab close, or manual clear Only for invite-code users
Google Analytics cookies (_ga, _ga_*) Used by Google Analytics 4 to distinguish unique sessions and maintain session state for anonymous content consumption metrics. These cookies do not contain or transmit any personally identifying information. Google may use data from these cookies in aggregate across its services. _ga: 2 years; _ga_*: 2 years Analytics (anonymous aggregate metrics only)
Yoast SEO cookies SEO plugin may set functional cookies for admin users and make external API calls Varies Admin-only; not set for anonymous visitors
AI Engine cookies Embedding sync plugin may set functional cookies for chatbot and admin operations Varies Functional — not used for tracking

6.2 What We Do Not Use

  • Third-party behavioral advertising pixels (Facebook Pixel, Google Ads, etc.)
  • Facebook Pixel or Meta advertising cookies
  • Third-party behavioral advertising cookies of any kind
  • Persistent user identifier cookies for anonymous visitors
  • Cross-site tracking technology (supercookies, fingerprinting scripts)

6.3 How to Control Cookies

You can block, delete, or manage cookies through your browser settings. Blocking
strictly necessary cookies (CSRF tokens) may affect site security functionality.
Blocking Google Analytics cookies will simply exclude you from our anonymous aggregate
metrics — it has no effect on your experience. For detailed instructions, see our
Cookie Policy.
Blocking cookies does not prevent you from reading any content on this site — all
civic education content remains fully accessible without any cookies.

Resources: All About Cookies
 |  NAI Opt-Out
 |  EFF Privacy Badger

7. Third-Party Services

We use a limited number of third-party services to operate the platform:

Provider Purpose Data Shared Privacy Policy
Google Analytics 4 Anonymous, aggregate content consumption metrics (page views, session duration, general geographic region). We use Google Analytics solely to understand which content is most useful to our audience — we do not use it to track, profile, or identify individual users. In GA4, IP addresses are used at collection time and then discarded before data is logged in any data center or server (Google documentation). Aggregate page views, session statistics, general geographic region, device category (mobile/desktop). No user IDs, no login data, no PII is collected or sent to Google by our implementation. Google may aggregate data collected through Google Analytics across its services for its own purposes, including improving Google products. For details, see How Google uses information from sites that use its services. policies.google.com/privacy
Anthropic (Claude API) AI-powered rights advisor responses Conversation text (no persistent storage; governed by enterprise API terms) anthropic.com/privacy
Pinecone Vector search for knowledge base retrieval (semantic search) Search query embeddings (no PII) pinecone.io/privacy
Tavily API Web search and content extraction for investigative research tools Search query text (no user identifiers attached) tavily.com/privacy
AI Engine (WordPress plugin) Embedding generation and knowledge base vector synchronization Article content for embedding; may set functional cookies meowapps.com/privacy-policy
Yoast SEO (WordPress plugin) Search engine optimization and metadata management May set functional cookies and make external API calls for SEO analysis yoast.com/privacy-policy
Cloudflare CDN Delivers one JavaScript library (Cytoscape.js) for the network graph visualization feature Standard CDN request data (IP address, user agent) for the specific library file only cloudflare.com/privacypolicy
Web hosting provider Serving the website Standard HTTP request data (IP address, user agent) for DDoS protection and delivery Per our hosting agreement

About Google Analytics: We use Google Analytics 4 strictly for anonymous, aggregate content consumption metrics — page views, session duration, and general geographic region — to understand which civic education topics are most useful to our audience. We do not use Google Analytics to identify, profile, or track individual visitors. We do not enable Google Signals, User-ID, or Enhanced Measurement features. However, Google may aggregate data from its analytics service across all sites that use it for Google’s own purposes, including improving its products. You can opt out of Google Analytics entirely by installing the Google Analytics Opt-Out Browser Add-on.

We do not sell or share your data with any third party for advertising or commercial
purposes. We do not use Facebook Pixel, Google Ads, LinkedIn, or any other advertising
platform’s tracking pixels or SDK on this site.

9. Data Security

We implement the following security measures:

  • HTTPS everywhere: All connections are encrypted in transit using TLS 1.2 or higher. HTTP requests are redirected to HTTPS.
  • Encryption at rest: Stored API keys and sensitive configuration data are encrypted using platform-grade encryption (WordPress application passwords with encryption, macOS Keychain for server credentials).
  • Access controls: Database access is restricted to application services. No direct public database exposure. Role-based access for administrative functions.
  • Security headers: Content Security Policy (CSP), X-Frame-Options, X-Content-Type-Options, and HSTS headers are deployed.
  • Dependency hygiene: We audit third-party dependencies and apply security updates promptly.
  • Log sanitization: Application logs are stripped of personally identifying information (IP addresses are fully redacted, email patterns removed) before storage.
  • Network access classification: Our backend classifies incoming requests by network origin (e.g., government IP ranges, cloud providers) using publicly available ASN data. This is a passive, silent process that does not collect PII, does not store IP addresses, does not block any visitors, and does not reveal its operation. It processes only network-level metadata (ASN, TLS fingerprint characteristics, request path) to monitor for potential government surveillance of our users. No visitor is treated differently based on this classification.
  • Connection integrity monitoring: Our pages include a lightweight security script that checks whether your connection to our site has been intercepted or tampered with (man-in-the-middle detection). If an anomaly is detected, the script sends a minimal, PII-free beacon to our server containing only the anomaly type and page path — no IP address, no user identifier, no browsing history. This protects users who may be accessing civic education content from monitored networks.

No system is perfectly secure. If you discover a security vulnerability, please report it
responsibly to security@patriot.university.
We will acknowledge reports within 48 hours and aim to patch critical issues within 7 days.

9.1 Data Breach Notification

If we suffer a breach that compromises personal data and we are legally required to notify
affected individuals, we will do so via the email address on file (if any) and via a
prominent notice on this website within the timeframe required by applicable law.

10. Data Retention

Data Type Retention Period Notes
Application logs (API backend) IP addresses: never stored (redacted). Other log data: rolling 30 days Hosting provider access logs follow provider policy
Google Analytics data 14 months (GA4 retention setting) Aggregate, anonymous data only
Comment tracking logs (Comment Sentinel) 365 days (configurable by administrator) Automatically purged daily by scheduled cleanup. On-demand per-user deletion available at any time.
Session logs (login/logout events) 365 days (configurable by administrator) Same retention and deletion policy as comment logs
Admin audit log Indefinite Immutable record of administrator actions on tracking data. Deleted only when the plugin is fully removed.
Email correspondence Up to 2 years after last communication Only if you voluntarily contact us
WordPress user accounts Until account deletion is requested Registered commenters may request account deletion

11. Your Privacy Rights

Depending on where you live, you may have certain rights with respect to data we hold about you:

Right Applies To How to Exercise
Access / Know — see what data we hold about you All visitors; EU/UK (GDPR); CA (CCPA/CPRA) Email privacy@patriot.university
Deletion / Erasure — request deletion of your data All visitors; EU/UK (GDPR); CA (CCPA/CPRA); most US state privacy laws Email privacy@patriot.university
Correction — correct inaccurate data EU/UK (GDPR); CA (CCPA/CPRA); most US state privacy laws Email privacy@patriot.university
Opt Out of Sale/Sharing — we do not sell data; opt-out is moot but honored CA (CCPA/CPRA); TX (TDPSA); VA (CDPA); CO (CPA); CT (CTDPA); others Automatic — we do not sell or share data for advertising
Data Portability — receive a copy of your data in a machine-readable format EU/UK (GDPR) Email privacy@patriot.university
Opt Out of Profiling — we do not engage in profiling; opt-out is moot but honored EU/UK (GDPR); US state privacy laws Automatic — we do not build individual user profiles

Response time: We will acknowledge privacy rights requests within 10 business days
and provide a substantive response within 45 days (or sooner as required by applicable law).
We will verify requests to the extent practicable given our anonymous-access architecture —
note that because we do not link usage to identity, we may genuinely have no data on file
for anonymous visitors.

California residents: Under CCPA/CPRA, you have the right to know whether we
“sell” or “share” your personal information (we do not), and to opt out of any such activity.
We do not discriminate against you for exercising any CCPA rights. To submit a CCPA request,
contact privacy@patriot.university with
“CCPA Request” in the subject line.

EU/UK residents (GDPR/UK GDPR): If you believe we have processed your data
unlawfully, you have the right to lodge a complaint with your local supervisory authority.
For EU residents, find your authority at edpb.europa.eu.

12. Children’s Privacy

Patriot University is intended for general audiences and is not directed at children under
13 years of age. We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and believe your child has provided personal information
through our platform, please contact us at privacy@patriot.university
and we will take steps to delete that information.

Reading our civic education content does not require an account and collects no personal
information, so it is technically accessible by users of all ages. Account registration
(required only for commenting) requires users to confirm they are 13 or older. Parents and
guardians are encouraged to use this platform together with younger users as a civic
education resource.

13. International Users

Patriot University is operated in the United States. If you access our platform from
outside the United States, your information (to the extent any is collected) may be
transferred to and processed in the United States.

United States law may not provide the same level of data protection as the laws of your
home country. By using our platform, you acknowledge this transfer. Where required by
applicable law (e.g., GDPR for EU residents), we rely on the following transfer mechanisms:

  • Standard Contractual Clauses (SCCs) for transfers of personal data from the EU to the US, where applicable.
  • Given our minimal collection, the practical scope of any international transfer is extremely limited — our application logs contain no IP addresses or PII, and hosting provider access logs are subject to the provider’s retention policy.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Changes that expand
data collection, reduce privacy protections, or introduce new sharing of
data will be announced with at least 30 days’ notice via a prominent notice
on the homepage and (where feasible) via any contact email we hold on file.

Minor changes — corrections, clarifications, or changes that strengthen privacy protections —
will be reflected by updating the “Last Updated” date at the top of this page.

The current version of this policy always lives at
patriot.university/privacy-policy.
Prior versions will be archived and available upon request.

15. Definitions

The following terms are used throughout this policy with these meanings:

  • Personal Data (or Data): Any information that directly, indirectly, or in
    connection with other information allows for the identification or identifiability of a
    natural person.
  • Usage Data: Information collected automatically through the platform, which
    may include IP addresses or domain names, URI addresses, time of request, method of request,
    file size, server response code, country of origin, browser and OS characteristics, time
    details per visit, and navigation path.
  • User: The individual using Patriot University who, unless otherwise specified,
    coincides with the Data Subject.
  • Data Controller (or Owner): IT Influentials LLC — the entity which determines
    the purposes and means of the processing of Personal Data.
  • Data Processor (or Processor): A natural or legal person which processes
    Personal Data on behalf of the Data Controller (e.g., our hosting provider, Anthropic for
    AI processing).
  • Cookie: A small set of data stored in the User’s browser. See our
    Cookie Policy for details.
  • Tracker: Any technology — e.g., cookies, unique identifiers, web beacons,
    embedded scripts, e-tags, and fingerprinting — that enables the tracking of Users by
    accessing or storing information on the User’s device.

16. Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or our data practices,
please contact us:

Privacy inquiries
privacy@patriot.university
Security vulnerabilities
security@patriot.university
Factual corrections (content)
factcheck@patriot.university
Legal / law enforcement requests
legal@patriot.university
Mailing address
IT Influentials LLC
[Address on file with registered agent]
United States
Response time
We aim to acknowledge all privacy-related inquiries within 2 business days and provide a substantive response within 10 business days.