Skip to main content
Jacobrakai Foundation
Forms โ†— Research Threat data Sources About

Privacy Policy

Effective September 5, 2026 ยท Revision 2

Jacobrakai Foundation is a Washington nonprofit organization based in Tacoma, Pierce County. This policy explains how the Foundation ("we," "us") handles information associated with jacobrakai.org, its correspondence, and the security research published here.

Reading the Site does not require an account. Delivering pages still involves request data and server logs. Email contains the information you choose to send. Security research has a separate collection and publication purpose.

Different services have different data flows. Gated previews may use sign-in cookies, saved drafts, and external media. Court-form interviews run on a separate service; read the forms section before entering case information.

Information & uses Cookies & previews Security research Retention & safeguards Requests & contact

1. Scope

This policy covers the Foundation's public pages, archives, and demos on this domain, together with the related processing described below. A service-specific privacy notice supplements this policy for the activity it addresses. Linked projects and independently operated services may have different operators, infrastructure, and notices. A link does not bring another service's data under the practices of this Site.

We do not sell or rent personal information. The public Site does not use advertising trackers or build cross-site advertising profiles. Public security-data disclosures are described in Section 4.

2. Information and its uses

Correspondence. If you email us, we receive your address, message, attachments, and associated delivery information. We use correspondence to respond, coordinate Foundation work, investigate reported problems, handle requests, and maintain relevant records. Email and its copies may remain in mail systems, working records, and backups. Sending a message does not create an attorney-client relationship or an agreement to receive privileged material. Please avoid sending unnecessary identity documents, financial credentials, medical records, or sensitive case information.

Website requests. Our hosting infrastructure and Cloudflare process technical information to deliver and protect the Site. This can include IP addresses, requested URLs and query strings, timestamps, browser or device information, referring pages, response status, and security events. Our origin server keeps access and error logs. Cloudflare also processes network and security data and provides traffic reports. IP addresses and other identifiers can be personal information even when we have no account or name for the visitor.

We use these records for operation, troubleshooting, abuse prevention, security investigation, and understanding traffic. The Foundation's public-page code does not include Google Analytics or a comparable browser analytics tracker. That does not eliminate infrastructure logging or Cloudflare's security processing.

Demonstrations. The older Greenleaf, Happy Tails, and Pulse contact and newsletter forms are interface demonstrations; their controls do not deliver a message or subscribe you to a mailing list. Use the Foundation's email address for an actual inquiry. Other previews may save a draft on your device or authenticate access as described below. Use fictional information in demos.

3. Cookies, saved preferences, and previews

Preferences. The Site and its older demos use browser storage to remember display choices such as light or dark mode. These preferences remain until cleared or removed by the browser. The preference code does not transmit those saved values to us. Browser storage is accessible to software permitted to use that browser or origin; it is not a confidential document store.

Protected previews. The current password-protected preview uses an essential session cookie after password entry. The server validates the submitted password and issues a session identifier; the identifier is sent back on subsequent requests. Its current maximum lifetime is eight hours, and signing out invalidates the session. Closing a browser is not a reliable substitute for signing out. Clearing the cookie ends access from that browser, but does not itself erase server logs.

The preview's editing controls can save page-copy drafts in local browser storage. Its draft controls operate on that browser's copy; clearing site data removes that saved copy and may also remove preferences or access cookies. Downloaded or separately copied material remains wherever you saved it. A demo confirmation does not submit a real application.

Security cookies. Cloudflare may set cookies or run checks needed for bot detection, challenges, and other security features. The particular cookies depend on the feature in use. See Cloudflare's cookie documentation. Blocking these cookies can prevent access to protected pages.

External media. Some previews load fonts, images, or embedded video from external providers, including Google/YouTube, Blogger image hosting, and Wix image hosting. Loading those resources sends a request to their providers, with information such as an IP address and browser details. A privacy-enhanced video domain does not mean that no information reaches the provider. Ordinary external links contact the destination when followed. The main Foundation pages serve their fonts and AbuseIPDB badge from this Site.

4. Security observations and publication

The Foundation operates internet-facing decoy services and security sensors. They record activity directed at those systems, including source addresses, connection times, network or approximate geographic metadata, protocol details, attempted credentials, commands, and other material supplied during an interaction. These records support abuse detection, investigation, threat reporting, and security research.

Selected observations are published through the public security feed, dashboards, and research. Depending on the output, this may include source IP addresses, classifications, event counts, observed times, network information, and selected event details. Public dashboards may include attempted credential or command strings recorded by decoy services. These are observations of network activity; they do not establish the identity of a particular person.

We also submit selected abuse reports to AbuseIPDB, including source addresses, event times, categories, and descriptions of observed activity. Published material can be downloaded, copied, or redistributed by others. Correcting an entry here cannot guarantee deletion of independent copies; applicable duties to notify recipients or seek deletion remain effective.

For a suspected error or reassigned address, email us with the affected entry and the reason for review. Provide only the information needed to identify and assess it. Security and research purposes remain subject to applicable privacy law; this policy does not declare a blanket exemption for every record.

5. Providers and other disclosures

Hosting, network delivery, email, security, and administrative service providers handle information needed for their roles. Cloudflare operates the delivery and security layer in front of our origin server; it is not the only system involved. Its privacy policy describes its end-user and network-data processing. External Google services are described in Google's privacy policy. A provider's separate notice does not eliminate our own applicable responsibilities.

Information may be disclosed when required by applicable law or valid legal process, or where law permits and disclosure is reasonably necessary to investigate abuse, protect people or systems, obtain professional advice, or establish, exercise, or defend legal claims. We may seek to narrow or challenge a demand where appropriate. Applicable confidentiality duties, privileges, and nonwaivable protections continue to govern.

The Foundation operates from the United States. Our service providers may process information in other countries. Applicable transfer safeguards and privacy rights are determined by the relevant law; visiting this Site is not a substitute for consent or another lawful basis where one is required.

6. Retention

Retention depends on the record and its purpose. Correspondence may remain for the matter it concerns and relevant organizational or legal records. Technical and security records may remain for troubleshooting, investigation, research, evidence preservation, and applicable legal obligations. There is no single deletion period for all Site information.

The public blocklist's activity window determines eligibility for that feed; it is not a deletion deadline for underlying sensor records, research, reports, or copies held by recipients. Security archives can outlast the public listing. Browser preferences and demo drafts remain subject to the controls in Section 3. The separate forms service describes its session and document retention in its own notice.

We assess retention against these purposes and applicable requirements. Deletion may be limited by a lawful preservation duty or other applicable exception. Backup copies can follow a different removal cycle; where law requires deletion from backups or notification to recipients, those requirements apply. A request does not automatically erase records that we are lawfully required or entitled to retain.

7. Safeguards

The Site uses HTTPS, access controls for protected previews, and security monitoring. We use measures appropriate to the information and system involved. No network, device, or storage method can guarantee absolute security. Encryption in transit does not prevent the receiving service from processing the information needed to provide it.

We provide notices required by applicable breach-notification law. Your own device can retain browser history, saved drafts, downloads, cached pages, and synchronized copies. Private browsing and signing out do not remove files already downloaded elsewhere.

8. Requests and choices

Contact [email protected] with a privacy request. Identify the service or record involved and the action requested. You do not need to create an account. We may request information reasonably necessary to verify your identity or authority without collecting more than needed.

Depending on the applicable law, you may have rights to confirmation or access, correction, deletion, a copy or portability, information about recipients, objection or restriction, withdrawal of consent, or an applicable opt-out. Eligibility, exceptions, and response periods vary. We address requests under the law that applies and explain a refusal or extension as required. You may seek reconsideration through the same address, exercise an available appeal, or complain to the relevant regulator, including the Washington Attorney General. We do not penalize you for exercising a protected privacy right.

You can clear browser storage, restrict cookies and external content, sign out of protected previews, or choose not to send a message. These choices may affect functionality. Browser privacy signals do not themselves prevent the request data needed to serve a page. Where a legally recognized opt-out signal applies to covered processing, we honor the requirements of that law.

9. NJ Court Forms and sensitive information

The guided court-form interviews run at in.formapauperis.com on separate application infrastructure. Before entering answers, read How this works & your privacy. Its service-specific disclosures address answers, generated documents, session cookies, cleanup, and device safety. This Site's public-page practices are not a description of that application's processing.

No registration does not mean no identifying information. Court forms can ask for names, addresses, family circumstances, and case details. The service processes the answers needed to generate documents. Browser restoration, downloaded files, and third-party delivery infrastructure also matter; closing a browser does not guarantee that every copy or session credential is gone.

This general website notice does not supply consent for the collection or sharing of consumer health data or other sensitive information where separate consent is required. Applicable service-specific notices and statutory rights continue to govern that processing. Changes here do not cancel prior applicable privacy commitments for information already collected.

10. Children

The Foundation's public Site is intended for a general audience and is not directed to children under 13. Its public-page features do not request children's profiles. Adults using court-form services may nevertheless enter information about children in their care; the service-specific notice applies. If you believe a child has supplied personal information to the Foundation, contact us so we can assess and address it under applicable law.

11. Changes and relationship to the Terms

We update the effective date when this policy changes. For material changes, we provide additional notice or obtain consent when applicable law requires it. Posting a revision does not by itself authorize an incompatible use of previously collected information.

The Terms of Service address Site use and applicable dispute procedures within their stated scope. This policy is a description of information practices; it does not waive nonwaivable privacy rights, replace required consent, or expand an arbitration agreement beyond its valid scope. Statutory rights and regulatory authority remain effective.

12. Contact

Jacobrakai Foundation
Tacoma, Pierce County, Washington, United States
[email protected]

© 2026 Jacobrakai Foundation

Donate Privacy Terms