Draft version 0.1 – September 20, 2026
For staging and legal review; not yet approved for publication
This notice explains how Puddingstone Media, LLC, publisher of The Greylock Guardian (the “Guardian,” “we,” “us,” or “our”), collects, uses, shares, and retains information for Berkshire Heat. It supplements the Guardian’s general website privacy policy. If the two conflict concerning Berkshire Heat, this notice controls.
1. Scope
This notice applies to Berkshire Heat advertisements, protected replies, email verification, accountless management links, editorial review, safety screening, and related payments. Berkshire Heat is for adults aged 18 and older.
2. Information we collect
From advertisers
We collect:
- the advertisement headline and body;
- the advertiser’s selected identity, who they hope to meet, and the type of connection sought;
- a general town or location, but not a street address;
- an email address used for verification and protected replies;
- the advertiser’s 18+ certification;
- the versions of the terms and notices accepted and the time of acceptance;
- editorial status, decisions, notes, and publication history; and
- payment status, amount, Stripe identifiers, authorization deadline, capture, cancellation, and refund information.
We do not ask for a birthdate, government identification number, or legal name as part of the standard submission. We do not intentionally store complete card numbers or card security codes; payment details are collected and processed by Stripe.
From respondents and correspondence
We collect:
- the respondent’s verified email address;
- the advertisement code or record to which the person replied;
- reply and response bodies transmitted through the protected relay;
- delivery, report, and block status;
- possible safety-policy categories identified by automated screening or human review; and
- the versions of the terms and notices accepted and the time of acceptance.
Automatically and operationally
The service may process IP addresses, timestamps, browser or device information, request logs, email-delivery events, and security signals needed to prevent spam, rate-limit submissions, diagnose failures, and protect the service. The Berkshire Heat plugin uses a keyed hash of the requesting address for its short submission-rate limit rather than storing the address in the ad record. The web host and other infrastructure providers may maintain their own operational logs.
3. How we use information
We use Berkshire Heat information to:
- verify email addresses;
- calculate the price and request payment authorization;
- conduct editorial review and publish approved advertisements;
- operate the protected reply relay;
- screen for threats, coercion, sexual commerce, exploitation of minors, harassment, impersonation, privacy risks, spam, and other prohibited conduct;
- investigate reports, enforce the Terms, and administer blocks or appeals;
- send transaction, verification, editorial, delivery, and safety notices;
- prevent fraud and abuse, secure the service, and diagnose technical problems;
- maintain financial, consent, editorial, and compliance records; and
- comply with law and respond to serious safety concerns as described below.
We do not use private Berkshire Heat correspondence to sell advertising, build marketing profiles, or train a commercial artificial-intelligence model. We do not sell Berkshire Heat participants’ personal information.
4. Public information
An approved advertisement’s headline, body, general location, public code, and category or descriptor are published in print and on the Guardian website. The advertiser’s private email address, management link, payment information, and private replies are not published.
Individual web advertisements are intended to be shareable during their publication period but marked noindex and excluded from the Guardian’s general site search and XML sitemap. Search engines, archives, screenshots, recipients, and other third parties may nevertheless copy or preserve material that was publicly available. The Guardian cannot guarantee deletion from systems it does not control.
5. Automated screening and human review
Advertisements and replies are screened using local rules designed to identify language and patterns associated with threats, coercion, sexual commerce, minors, harassment, impersonation, privacy exposure, and evasion. Screening is intentionally cautious and may produce false positives.
A flag is not a finding of misconduct. Clean replies may be relayed without advance human review. Flagged material may be quarantined and reviewed by an authorized Guardian editor. The reviewer may release, reject, preserve, or escalate the material and may record the relevant policy category. Internal trigger terms and detection logic are not disclosed because doing so would make evasion easier.
The Guardian does not routinely read every private message.
6. Payment processing
Stripe processes payment-method information and may use transaction, device, and related information for payment processing, authentication, fraud prevention, legal compliance, and its other disclosed purposes. The Guardian receives transaction identifiers and status information needed to authorize, capture, cancel, or refund a payment, but does not receive or store a complete card number or card security code.
Stripe’s handling of information is governed by its own privacy policy, available at https://stripe.com/privacy.
7. When information may be shared
We may disclose information:
- to service providers that host the website, deliver email, process payments, provide security or spam protection, or otherwise help operate Berkshire Heat;
- within Puddingstone Media to authorized people who need the information for editorial, safety, accounting, legal, or technical work;
- when a participant directs us to share information or deliberately includes it in a message sent to another participant;
- to comply with valid legal process or another applicable legal duty;
- when reasonably necessary to investigate abuse, prevent fraud, protect the service, or establish or defend legal claims; or
- as described in the serious-harm and minors provision below.
Service providers may keep information under their own legal and operational retention requirements.
8. Serious harm, minors, and law enforcement
Replies are screened to protect participants. The Guardian does not routinely share private messages or participant information with law enforcement. We may preserve and disclose relevant information when required by law or when we reasonably believe doing so is necessary to address a credible and imminent threat of serious harm or suspected exploitation of a minor.
The Guardian does not promise to monitor every communication, investigate every allegation, or report every Terms violation to authorities. Applicability of any mandatory reporting duty will be determined according to the facts and governing law.
9. Retention
Our intended retention schedule is:
- Public advertisements: removed from public display when the following issue appears.
- Advertisement, payment-status, consent, and editorial records: retained for one year after expiration, rejection, or withdrawal.
- Private reply and response bodies: deleted after 90 days.
- Short rate-limit record: retained for approximately three minutes.
- Transaction and accounting records: limited records may be retained longer when reasonably necessary for tax, accounting, chargeback, fraud-prevention, or legal obligations.
- Safety incidents, reports, and legal holds: relevant records may be preserved longer when reasonably necessary to investigate a serious incident, comply with law, respond to legal process, or protect a participant or the service.
- Provider logs and records: retained according to the relevant provider’s practices and legal obligations.
Deletion from active records may not immediately remove information from routine backups. Backup copies are protected from ordinary use and expire according to the applicable backup cycle.
10. Your choices and requests
Before approval, an advertiser may revise or withdraw an advertisement through the private management link. Participants may report or block another participant.
You may ask us to provide information about, correct, or delete private Berkshire Heat information associated with your verified email address. We may need to verify the request. We may deny or limit a request when retention is reasonably necessary for payment, accounting, security, editorial integrity, legal compliance, legal claims, or the protection of another person. We cannot erase printed issues, messages already delivered to another participant, or copies controlled by an independent third party.
11. Security
We use administrative and technical safeguards intended to limit unauthorized access, disclosure, alteration, and destruction. These include limiting public exposure, using verified email links, keeping payment-card entry with Stripe, separating public and private fields, and restricting human access to people with an operational need.
No website, email system, payment service, or storage method can be guaranteed completely secure. Keep private management links confidential and contact us promptly if you suspect misuse.
12. Children
Berkshire Heat is not available to anyone under 18, and we do not knowingly solicit information from minors. If we learn that a minor has submitted personal information, we will take appropriate steps to restrict the accountless record, preserve information when legally or reasonably necessary for safety, and delete information that need not be retained.
13. Changes to this notice
The notice version affirmatively accepted with a submission or reply remains recorded with that transaction. If a material change affects an unfinished transaction, we will request new consent. Updated notices apply prospectively from their stated effective date unless law requires otherwise.
14. Contact
Questions, privacy requests, safety reports, and deletion requests concerning Berkshire Heat may be sent to:
Puddingstone Media, LLC / The Greylock Guardian
Email: jvelazquez@puddingstone.media