MOBILIZRan initiative of HEIMLANDR Foundation

Privacy & data protection

How we handle your data

In plain language first, then in legal detail. MOBILIZR is built to hold as little personal data about you as possible, and to protect what we do hold.

The short version

  • Tips are encrypted and never publicly displayed. We follow the lead they give us against public records, then publish only what we can independently verify.
  • Backers and tipsters appear publicly only under pseudonyms (and tipsters not at all).
  • Payments are processed by our payment provider. We see only what we need to confirm a paid subscription or credit. Never your card details.
  • No accounts. No passwords. Email-only authentication via one-time signed links. Opt out from any email, instantly, no questions.
  • We do not sell your data. We do not run trackers. We do not share data with advertisers because we have none.
Who is responsible (data controller)

HEIMLANDR AB, registered in Sweden, is the personuppgiftsansvarig (data controller) under GDPR Article 4(7). See /imprint for statutory contact details.

What data we collect
  • Backers and newsletter subscribers: email address only. No name, no postal address, no phone, no demographics.
  • Tip submitters: the tip content and any files you upload. We strip uploaded-file metadata (EXIF, document author). No IP address logged, no cookies set, no fingerprinting on tip submission routes.
  • Payment records: payment amount, currency, payment-provider receipt ID, paid status. We never store card numbers, security codes, or billing addresses; those remain with the payment provider.
  • Operational logs: minimal request logs without personal data. We do not log IP addresses for tip submission or audit-feed access.
Why we process it (legal bases)
  • Contract performance (GDPR Art. 6(1)(b)): for backer subscriptions, newsletter delivery, and tip credit issuance. You pay; we deliver.
  • Journalistic purposes (Dataskyddslagen 1 kap 7 §; GDPR Art. 85): the investigative content we publish is for journalistic purposes and is exempted from most GDPR data-processing rules, including for special-category data where the public-interest justification is documented per piece. The exemption applies regardless of utgivningsbevis status; MOBILIZR currently relies on it without the YGL umbrella, with the public-interest test assessed per publication and documented in the audit trail.
  • Legal obligation (Art. 6(1)(c)): bookkeeping under Bokföringslagen.
How long we keep it
  • Subscriber email addresses: until you opt out, then deleted within 30 days. Audit records retain a one-way hash, not the email itself.
  • Tip content: stored encrypted; retained until the investigation closes; then either incorporated anonymously into the cluster's research memory or destroyed.
  • Payment records: 7 years (Bokföringslagen requirement).
  • Audit log: append-only, indefinite. Contains pseudonymous identifiers and event types; no personal data.
Your rights (GDPR Ch. III)

You have the right to:

  • Access the data we hold about you (Art. 15)
  • Correct inaccurate data (Art. 16)
  • Delete your data, subject to journalistic-purpose carve-outs for already-published content (Art. 17)
  • Restrict processing (Art. 18)
  • Portability — for the data we hold under contract performance (Art. 20)
  • Object to processing (Art. 21)
  • Complain to IMY (Integritetsskyddsmyndigheten), imy@imy.se

For most actions, the opt-out link in any email we send you is sufficient. For other requests, write to info@heimlandr.com from the email address on file.

Cookies and tracking

MOBILIZR uses session cookies only where strictly necessary for authentication. All backer and newsletter flows are email-token-based — no cookies needed. No analytics cookies. No advertising cookies. No cross-site trackers. No third-party scripts that profile you.

International transfers

Data may be processed in EU/EEA countries (where our servers are based) and the United States (where the payment provider operates). All transfers rely on adequacy decisions or Standard Contractual Clauses under GDPR Art. 46.

Children

MOBILIZR is not directed at children under 16. We do not knowingly accept subscriptions, tips, or proposals from anyone under 16.

Changes to this policy

Material changes are noted in the public audit feed and emailed to active subscribers. We do not pull tricks here.

Last updated 2026-05-19. This document is not legal advice. For questions about your data, write to info@heimlandr.com.