Privacy Policy
Last updated: 27 July 2026.
This is the whole policy. Before writing it we looked at what the site actually sends and receives, so what follows describes real behaviour rather than a template downloaded from somewhere.
The short version
- No advertising, no analytics, no tracking pixels.
- We never sell, rent or share your personal data.
- The only personal data we hold is what you hand over yourself: a newsletter address, a comment, a submitted article, a message, or an account.
- Two things still load from other companies’ servers — a spam check on forms and a web font — and both of them see your IP address.
- You can ask what we hold about you and ask us to delete it. One email is enough.
Who is responsible for this site
WithoutCensorship.com is published and edited by Pavel Kadlec. For anything in this policy, write to info@withoutcensorship.com. The site runs on a server in the Czech Republic. Under the GDPR the editor is the data controller.
What we collect, and why
Nothing here collects data quietly in the background. Every item below happens only because you filled something in.
- Newsletter. Your email address, a name if you choose to give one, and the dates you subscribed and confirmed. The list lives in our own database and the emails are sent from our own server, not handed to an outside mailing company. Every issue contains an unsubscribe link, and unsubscribing removes you from the list.
- Comments. WordPress stores the name and email you type, the comment itself, your IP address and your browser identification string. Your email address is never published.
- Article submissions. If you send us a story, we keep the name, email, text and any files you attach, so that we can reply to you and check the material.
- Contact messages. Whatever you write in the form, so that we can answer it.
- Accounts. If you register, we store a username, an email address and a hashed password. We cannot read your password.
- Server logs. The hosting keeps ordinary web-server logs: IP address, time, the page requested and the browser string. They exist to keep the server running and to stop abuse, and they are kept only briefly.
The legal grounds are consent for the newsletter, carrying out what you asked for in the case of submissions, messages and accounts, and legitimate interest for security logs and spam protection.
Analytics: none
In July 2026 we removed the last analytics script from the site and closed the account behind it. Nothing on this site counts, profiles or follows your visit any more. We genuinely do not know which pages you read.
What loads from other companies
Three requests still leave our server. Naming them is worth more than a clean-sounding claim.
- Cloudflare Turnstile checks that a form is being filled in by a person. Cloudflare sees your IP address and limited technical information about your browser. It replaces the older kind of puzzle that had you labelling photographs for somebody else’s machine-learning model.
- Google Fonts are still delivered from Google’s servers, which means Google sees your IP address when a page loads. We intend to host the fonts ourselves; until we do, this is the one avoidable leak on the site, and we would rather write it down than hide it.
- Gravatar, run by Automattic, supplies the small pictures next to comments. If a commenter has a Gravatar account, a scrambled form of their email address is sent there to fetch the image.
What is not here: no Google Analytics, no Meta or TikTok pixel, no advertising network, no data-broker code, no session recording, no heat maps, no A/B testing service.
How long we keep things
- Newsletter addresses: until you unsubscribe.
- Comments: as long as the comment is published, unless you ask us to remove it.
- Submissions and messages: while they are still relevant, then deleted.
- Accounts: until you ask for the account to be closed.
- Server logs: a short rolling window kept by the hosting provider.
Your rights
If you are in the European Union, the GDPR gives you the right to ask what we hold about you, to receive a copy, to correct it, to have it deleted, to restrict or object to its use, to take it elsewhere, and to withdraw consent at any time. Write to info@withoutcensorship.com and we will answer within thirty days. You can also complain to the Czech data-protection authority, the Úřad pro ochranu osobních údajů.
In practice a deletion request is short work. For most readers the only thing we hold is one line in a mailing list.
Children
This site is not aimed at children and we do not knowingly collect data from anyone under sixteen.
Security
The whole site runs over HTTPS. Administrative access is limited to the editor. Backups are kept so that content can be restored, which also means a deleted comment may sit inside a backup file for a while before it ages out.
Changes to this policy
The date at the top changes when the text changes. If we ever start doing something materially different — analytics, advertising, paid content — it will be written here first and mentioned in the newsletter, rather than slipped in quietly.
What this policy does not cover
It covers this site only. We link outwards constantly, and the moment you follow a link you are under somebody else’s rules, which are usually less pleasant than ours. Our guide on reading a privacy policy in ten minutes exists partly for that reason.

