1. Who we are
The Source Radar (“we”, “us”) runs The Source Radar and is the controller of the personal data described here. Contact us about anything in this notice at alerts@thesourceradar.com.
We handle data in four different ways, and what applies to you depends on which describes you: you are a member, a journalist who posts to us, a person whose public post or feed we collect (X, Bluesky, publisher feeds), or a visitor.
2. Members (people with an account)
When you sign up and use the service we process:
- Account details: first and last name, display name, email address, a hashed password, two-factor authentication settings, your plan, and when and which version of these terms you accepted.
- Payment records: Stripe holds your card details, not us. We keep your Stripe customer reference, plan, and payment and subscription events.
- What you set up in the app: your persona, time zone, alert rules and delivery addresses (email, Slack, Discord or webhook URLs), your profile photo, saved requests, pitches and notes.
- Pitch profiles for yourself or your clients: names, job titles, biographies, expertise, websites and photos. If you enter details about other people, see clause 7 of the Terms.
- Security and usage data: IP address, sign-in and security events, session identifiers, and email delivery logs.
We use it to provide the service you signed up for and bill for it (contract), to keep accounts and the service secure and to prevent fraud and abuse (legitimate interests), to send you service messages such as verification, receipts and the alerts you asked for (contract), and to meet tax and accounting obligations (legal obligation). We only send marketing email with your consent, or, where the law allows, to existing customers about similar services with a simple way to stop.
If you list a pitch profile in the journalist directory, the details in that profile are shown to journalists who have opted in to browse it. Listing is your choice and you can remove it at any time.
3. Journalists who post requests or use the journalist workspace
When you post a request through our form we collect your name, work email, outlet, the request itself, your preferred contact method and region, and the IP address you submitted from (for spam prevention). Your email address gives you private access to your request and the responses to it through a sign-in link; we do not create a password.
The request text, your outlet and the contact method you choose are shown to members so they can respond. If you tick the option to have us share it, we also publish the request, with a link to its public page, from our Bluesky and/or X account. We do not include your contact details in those posts. We rely on your consent for the social posts (you can ask us to remove them at any time) and on our legitimate interest in running the service for the rest.
If you opt in to browse the directory of listed specialists, we keep your opt-in, your name and email, and any private notes you save about listings. Those notes are never shown to the people you write about.
4. Public posts and feeds we collect from X, Bluesky and publishers
This is the part of the service most people ask about, so plainly: we collect requests for expert sources that journalists have already published, and show them to our members.
- Where from. Public posts on X and Bluesky that use request hashtags such as #journorequest, #prrequest and #journalistrequest, collected through those services' official interfaces; curated call-out feeds published by news outlets (RSS and similar); news discovery through GDELT; and structured feeds that publishers submit to us themselves.
- What we keep. The text of the post, its link and time, and the author's public details as shown on the platform: handle, display name, account identifier and public bio. If the post itself contains an outlet, email address or other contact method, we keep and show that too, because giving it out is the point of the post.
- What we do with it. We use an AI service to read each post, decide whether it is a genuine request, and extract a title, topic, region, deadline and contact method. Posts are matched to members' alert rules and shown in the feed and in alerts. We link back to the original post.
- Reposting. We may amplify a request from our own X or Bluesky account using that platform's repost feature, so it reaches more potential sources. We also publish our own daily digests and promotional posts from those accounts. The platforms' own rules and privacy policies apply to what happens on them.
- Why we may do this. Our legitimate interest, and our members' and the journalist's, in getting a published request to the right experts. Journalists post these publicly in order to be contacted, and expect them to be seen and shared, and we take only what they published. We have weighed that against your interests and rights and think it is proportionate. Because we do not receive this data from you, we are not able to write to each person individually; this notice is how we tell you.
- You can opt out at any time, whether or not you are a member. Email alerts@thesourceradar.com with your handle or the link to a post and we will stop collecting from you, hide what we hold, and withdraw our reposts. See also how to opt out.
We keep to X's and Bluesky's developer rules when we collect from them. If a post is deleted, made private or the account is suspended on the platform, we remove our copy when we learn of it. Members are not given bulk exports of this material and agree not to build datasets from it (see the Terms).
5. Visitors to the website
Like most sites we see your IP address, browser and the pages you request in server logs, which we use for security and to keep the service running. Cookies and similar technologies are explained in our Cookie Policy. Analytics and marketing cookies (Google Tag Manager, Google Analytics and advertising tags) are only used if you accept them.
If you contact us or submit a feed to us, we keep your message and contact details to reply and for our records.
7. How long we keep it
- Member accounts: while the account is open. You can delete your account yourself at any time from Settings in the app; it removes your details and everything you set up, cancels any subscription, and keeps only payment records (without your name or email) that we must hold for tax and accounting.
- Records of accepting the Terms and Privacy Notice: as long as the account exists and for a reasonable period afterwards, as evidence.
- Journalist requests, and the sign-in and management links for them: while the request is live and for as long as it is useful as a record; we remove one on request.
- Collected public posts: while they remain useful to members and public on the platform. Anything you ask us to stop holding is hidden, and we keep only your handle on a suppression list so we do not collect it again.
- Server and security logs: kept for a limited period.
8. Your rights
Under UK data protection law you can ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it (including anything we do on the basis of legitimate interests), to move it to another service, and to withdraw consent where we rely on it. Email alerts@thesourceradar.com; we normally reply within one month, and we may need to confirm who you are first.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
9. Children
The Source Radar is for professional use by people aged 18 or over. We do not knowingly collect data from children; if you think we have, tell us and we will delete it.
10. Changes to this notice
We will update this page when what we do changes. If a change matters to you, such as a new use of your data, we will tell members by email or in the app before it applies. The date and version are at the top of this page.