Christian Warrior Training
Privacy Notice
This notice explains how Christian Warrior Training (CWT) handles information on the CWT Intelligence Platform at intel.christianwarriortraining.com — both the public Intelligence Monitor dashboard and the Suspicious Activity Reporting form. It is written in plain language so you can make an informed decision about what to include in your report.
The Intelligence Monitor dashboard
Reading the public dashboard requires nothing from you. There is no registration, no login, and no visitor account, and simply viewing the dashboard collects no personally identifiable information about you. Incident data is sourced from public news RSS feeds, and links to external news sources are provided for verification — visiting those external sites is subject to their own privacy policies. Dashboard filter state (time range, severity, and similar settings) lives in the page URL only; it is not stored on the server or in cookies.
Two dashboard features are optional and do record something. Both are described in full under Cookies, tracking, and what is stored on your device below:
- Flagging an incident — if you use the flag control on an incident to tell CWT something looks wrong, a salted one-way hash of your IP address is stored with the flag so the same incident cannot be flagged repeatedly from one source. Your note, if you write one, is stored with it. Nothing else about you is recorded, and the flag is deleted along with the incident it belongs to.
- Turning on notifications — if you opt in to browser notifications for critical incidents, your browser issues a delivery address for your device, which CWT stores so alerts can be sent. It contains no name, email, or IP address. Turning notifications off removes it.
The rest of this notice concerns the Suspicious Activity Reporting form and what happens to the reports you submit through it.
What we collect
When you submit a report, we receive the information you choose to enter in the form. This may include:
- Your name and email address; phone number only if you choose to provide it
- Your role and organizational affiliation
- Details about the suspicious activity you are reporting
- Files you upload (photos, screenshots, documents)
You decide what to include. The required fields are your name, email address, the date, type, and description of the incident, the source of information and your confidence level, the threat assessment questions, and the acknowledgement checkbox.
We recommend submitting only the information relevant to the incident. Beyond the required contact information and details needed to describe the incident, you do not need to include any additional personal details. Uploaded files are entirely optional.
What we collect automatically
When you submit a report, the following technical information is recorded automatically:
- A hash of your IP address — a salted, one-way hash of your IP address is stored with your report and is used only for abuse prevention. The raw IP address is not retained.
- Platform request logs— the hosting platform (Vercel) records standard request logs, including IP addresses, timestamps, and pages visited. CWT does not control the hosting provider's log retention policies.
- Rate-limit records — a salted hash of your IP address is temporarily stored to prevent abuse. These records are automatically pruned within about 24 hours and contain no report content.
How we use your information
Submitted reports are stored in a private database and reviewed by authorized CWT personnel. CWT uses reports for:
- Reviewing and assessing reported activity
- Identifying patterns and trends across multiple reports
- Building situational awareness for the Christian Community
Your email address is required as part of your submission and will be used only in connection with your report, for example if CWT needs to follow up with you about it. Your email will not be added to any mailing list or used for marketing.
How we store your information
The form is served over HTTPS, so the data you type and the files you upload are encrypted while they travel from your browser to the server. After that, reports are stored in a private database on the platform's hosting infrastructure (Vercel, with Postgres storage) and reviewed by CWT personnel — there is no email inbox and no third-party form service involved.
- Report text and form data — stored in a private database that is not accessible from the public site, and reviewed by authorized CWT personnel through the private CWT admin review area.
- Uploaded files — stored outside the public site in blob storage under randomized, unguessable links. Raw files are surfaced only in the private CWT admin review area. PDFs are never published. A reviewer may publish a selected image through a protected same-site proxy only when you granted publication permission on your report.
- Rate-limit records — temporary records containing salted hashes of IP addresses and timestamps. Automatically pruned within about 24 hours. No report content is stored in these records.
What this site does not do: it does not run automatic malware or virus scanning on uploaded files, it does not provide guaranteed end-to-end encryption of your report to CWT, and encryption at rest is limited to what the hosting platform provides. If these properties matter for the information you are about to send, adjust what you include in the report, or contact CWT through the main website about an alternative channel.
Who can see your report
Reports are accessible to authorized CWT personnel responsible for reviewing suspicious activity submissions. CWT limits access to individuals with a direct need to review incoming reports.
The hosting provider (Vercel) has technical access to the underlying infrastructure, including the database and file storage, as is standard with managed cloud hosting. CWT does not share reports with the hosting provider, but the provider could technically access stored data.
Your full report and contact information are never displayed on the public dashboard. If you select the optional public-summary permission, an authorized reviewer may publish a frozen, redacted incident summary. The public copy is labeled as a community report, excludes your name, email, and phone, and can be removed without changing the private report. Declining permission does not affect CWT's private review.
Sharing with law enforcement
CWT is not a law enforcement agency and does not automatically share reports with law enforcement. However, CWT reserves the right to share information from a report with law enforcement if:
- CWT believes there is a credible and immediate threat to someone's safety
- CWT is required to do so by law (e.g., a subpoena or court order)
- The information may be relevant to an active law enforcement investigation and CWT chooses to cooperate
CWT will use its judgment in deciding whether and when to share information. If you indicated in your report that a situation involves an ongoing threat, CWT may treat that as a factor in deciding whether to involve law enforcement.
Cookies, tracking, and what is stored on your device
CWT does not set cookies for visitors to the public site and does not use tracking pixels, advertising scripts, or user accounts. No Google services load on these pages: earlier versions of this site loaded Google Fonts and Google reCAPTCHA, and both are gone — fonts are served from this site, and no request is made to Google when you view or submit the form.
Some things are stored by your browser rather than by a cookie. None of them is sent anywhere on its own, and clearing your browser's site data removes all of them:
- An offline cache— the dashboard installs a small service worker that keeps a copy of the public incident, metrics, and threat-level responses in your browser's cache, so the dashboard still shows its last known state when your connection drops. It holds only the same public data the dashboard displays, it is never sent anywhere, and clearing your browser's site data removes it.
- A notification subscription, only if you ask for one — enabling critical-incident notifications has your browser generate a delivery address for your device and two keys that let CWT encrypt messages to it. CWT stores those, plus any severity or location filter you chose, so it knows what to send. There is no name, email, or IP address in that record. It is deleted when you turn notifications off, and CWT also discards it automatically once your browser reports the address as expired. Notifications are not available at all unless CWT has configured its notification keys.
- What you type into the report form — an unsent draft is held for the life of that browser tab so a backgrounded tab or a tap on a link does not lose your narrative; it is discarded when the tab closes or the report is sent. Separately, your organization's name and address are saved for next time onlyif you tick the box asking for it, and the form has a control to clear that again. Neither is on CWT's server until you submit. If you are on a shared or public computer, leave the box unticked.
The site does use Vercel Web Analytics, which counts page views for the host. It is cookieless and sets nothing on your device: it records the page address, the referring page, and coarse details like country, browser, and device type. It does not build a profile, does not follow you to other sites, and never receives anything you type into the report form.
Instead of reCAPTCHA, the report form uses non-tracking anti-abuse checks: a hidden honeypot field, a minimum-time check, and rate limiting based on a salted hash of your IP address.
One honest caveat: a single httpOnly session cookie exists only within the private /admin area used by CWT staff. It is never set for visitors to the public site.
Data retention
Private report text and linked uploads are scheduled for automatic deletion 365 days after submission. An authorized reviewer may place a report on legal hold when it is needed for an active investigation, a preservation obligation, or a legal requirement; the hold pauses automatic deletion and is recorded in the admin audit trail.
Unfinished uploads that are never linked to a submitted report are deleted automatically on a much shorter schedule. Public redacted community-report copies use the dashboard's standard incident retention window and are removed with the private report if its 365-day expiry happens first.
Incident flags are deleted together with the incident they were filed against, on the dashboard's standard incident retention window. A notification subscription is kept only while it is in use: it is removed when you turn notifications off, and discarded automatically once your browser reports the delivery address as expired.
If you submitted a report that contains your personal information and you would like it deleted, contact CWT through the main website. CWT will make reasonable efforts to locate and remove the information, but cannot guarantee deletion from all backups or systems.
This site is not an emergency service
This form is not monitored in real time. Reports are reviewed by CWT personnel, not by law enforcement or emergency services. CWT does not dispatch responders. If you or anyone else is in immediate danger, call 911 or your local emergency services.
Contact
For questions about this privacy notice, to request deletion of your personal information, or to report a concern about data handling, contact CWT at christianwarriortraining.com.
Changes to this notice
CWT may update this notice as the site changes. The current version will always be available at this page.
Last updated: July 2026